BlogPilot Data Processing Agreement
Version: 1.0 Effective date: 2026-09-29 Owner: Data HQ Limited Review cycle: On any change to the Tracking Script or its sub-processors, and at least annually
About this agreement
This Data Processing Agreement ("DPA") sets out the terms required by Article 28 of the UK GDPR for personal data that Data HQ Limited processes on your behalf when you use the BlogPilot website tracking script. It forms part of, and is incorporated into, the BlogPilot Terms of Service (the "Terms"). Words defined in the Terms have the same meaning here.
You accept this DPA when you accept the Terms. It applies from the first time the Tracking Script sends data from your website to BlogPilot.
1. Parties
- Data HQ Limited (company number 04193862), registered office 46-54 High Street, Ingatestone, Essex CM4 9DW ("Data HQ", "we" or "us"), as processor; and
- the customer named in the Order ("you"), as controller.
2. Definitions
In this DPA:
- "Data Protection Law" means the UK GDPR, the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003, each as amended or replaced from time to time.
- "UK GDPR", "controller", "processor", "personal data", "personal data breach", "data subject" and "processing" have the meanings given in the UK GDPR.
- "Tracking Data" means the data collected through the Tracking Script from visitors to your website, as described in Annex 1, to the extent it is personal data.
- "Sub-processor" means a third party we engage to process Tracking Data on your behalf.
3. Scope and roles
3.1 This DPA applies to Tracking Data. For Tracking Data, you are the controller and Data HQ is your processor.
3.2 This DPA does not apply to personal data that you or your Users include in Customer Content or that appears in Output. That content is covered by sections 12, 17 and 20 of the Terms.
3.3 This DPA does not apply to personal data we hold about you and your Users to run your Account and bill you. We are the controller of that data, and the Privacy Notice explains how we use it.
3.4 Some or all Tracking Data may not be personal data, because the Tracking Script is designed to avoid storing IP addresses, query strings and other direct identifiers (see Annex 1). This DPA applies to the extent that any Tracking Data is personal data.
4. Details of the processing
The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex 1.
5. Your obligations as controller
5.1 You are responsible for having a lawful basis for the processing of Tracking Data and for giving your website visitors the information required by Articles 13 and 14 of the UK GDPR, for example in your website privacy notice.
5.2 You are responsible for deciding whether any consent is required under the Privacy and Electronic Communications Regulations 2003 (as amended) for your use of the Tracking Script on your website, and for obtaining it or providing any required opt-out where needed. You are also responsible for the notice about the Tracking Script on your own website. To help you, we will give you the information in Annex 1 and suggested wording for your website's privacy information, but we do not give legal advice.
5.3 You will install the Tracking Script only on websites that you control or are authorised to act for.
5.4 The Tracking Script records the path and title of each page viewed, but not query strings or fragments (see Annex 1). You will take care that personal data (such as names, email addresses, telephone numbers or account numbers) does not appear in the paths or titles of pages on which the Tracking Script is installed.
5.5 Your instructions to us must comply with Data Protection Law.
6. Processing on your instructions
6.1 We will process Tracking Data only on your documented instructions, unless the law requires otherwise, in which case we will tell you before processing unless the law prohibits it.
6.2 Your instructions are: the Terms, this DPA, your installation of the Tracking Script, and your use of the Service's settings and analytics features. You may give additional reasonable instructions in writing to legal@datahq.co.uk. We will tell you promptly if we believe an instruction breaches Data Protection Law.
6.3 We will use Tracking Data only to provide the analytics features of the Service to you. We will not use it for our own purposes, combine it with data from other customers' websites, sell it, or use it to train artificial intelligence models.
7. Confidentiality
We will make sure that everyone we authorise to process Tracking Data is bound by an appropriate duty of confidentiality.
8. Security
8.1 We will implement appropriate technical and organisational measures to protect Tracking Data, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing, as required by Article 32 of the UK GDPR. The measures in place at the date of this DPA are described in Annex 2.
8.2 We may update these measures from time to time, provided that the overall level of protection is not reduced.
9. Sub-processors
9.1 You give us general authorisation to engage Sub-processors to process Tracking Data. The Sub-processors engaged at the date of this DPA are listed in Annex 3 and in the Sub-processor List.
9.2 We will give you at least 30 days' notice of any intended addition or replacement of a Sub-processor that processes Tracking Data. You may object on reasonable data protection grounds within that period. If we cannot resolve your objection, you may stop using the Tracking Script, or cancel the affected part of the Service, without penalty.
9.3 We will impose on each Sub-processor, by written contract, data protection obligations that give at least the level of protection required by this DPA, and we remain responsible to you for the performance of each Sub-processor's obligations.
10. International transfers
10.1 Tracking Data is stored and processed in the United Kingdom, in Microsoft Azure's UK South region.
10.2 Tracking Data is not sent to the AI providers used by other BlogPilot features.
10.3 We will not transfer Tracking Data outside the United Kingdom unless we have first put in place a transfer mechanism recognised by Data Protection Law, such as the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, and have given notice under section 9 where a new Sub-processor is involved.
11. Assistance
11.1 Data subject requests. Taking into account the nature of the processing, we will help you, by appropriate technical and organisational measures, to respond to requests from data subjects to exercise their rights. If we receive a request directly from one of your website visitors, we will pass it to you without undue delay and will not respond to it ourselves except on your instructions. Because the Tracking Script does not store names, contact details, IP addresses or persistent identifiers, it will usually not be possible to identify the records of a particular visitor.
11.2 Other assistance. We will provide reasonable assistance to help you meet your obligations under Articles 32 to 36 of the UK GDPR (security, breach notification, data protection impact assessments and prior consultation with the Information Commissioner), taking into account the nature of the processing and the information available to us. Reasonable assistance is free of charge. If you ask for assistance that is exceptional in scope or volume, we may charge for it at our cost, and we will tell you before we start.
12. Personal data breaches
12.1 We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Tracking Data.
12.2 Our notice will describe, as far as the information is available: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Where not all information is available at once, we will provide it in stages without further undue delay.
12.3 We will take reasonable steps to contain and investigate the breach and to reduce its effects, and will cooperate with you in dealing with it.
13. Retention, deletion and return
13.1 Retention during the subscription. We keep Tracking Data for as long as your Account is open, so that you can compare performance over time, unless you ask us to delete it sooner under section 13.2. When your Account is closed, Tracking Data is deleted under section 13.3.
13.2 Deletion on request. You may ask us at any time to delete all Tracking Data for your Account by emailing support@datahq.co.uk. We will delete it from our live systems within 30 days of your request and confirm when this has been done.
13.3 At the end of the Service. When your Account is closed, we will delete all Tracking Data for your Account from our live systems as part of the account closure process. Account closure takes effect after a grace period of 7 days, during which the closure can be cancelled. Residual copies in our system backups are overwritten as the backup window rolls forward, within a further 7 days, and are not used for any operational purpose in the meantime. We will not keep Tracking Data after that unless the law requires us to.
13.4 Return. The Service does not include a self-serve export of Tracking Data. If you would like a copy of your analytics before your Account closes, please ask us at support@datahq.co.uk before the closure date and our staff will provide the Tracking Data we hold for your Account in a commonly used electronic format.
14. Information and audit
14.1 We will make available to you the information reasonably necessary to demonstrate our compliance with Article 28 of the UK GDPR and this DPA, including a summary of our security measures.
14.2 We will allow for and contribute to audits, including inspections, conducted by you or an independent auditor you appoint and who is bound by confidentiality, where the information in section 14.1 is not reasonably sufficient to demonstrate compliance or where a regulator requires it. You will give us at least 30 days' written notice, agree the scope with us in advance, carry out the audit during business hours with minimum disruption, and bear its costs. No more than one audit may take place in any 12-month period unless a regulator requires it or a personal data breach has occurred.
15. Liability
Each party's liability under or in connection with this DPA is subject to the limitations and exclusions of liability in the Terms. The caps in the Terms apply to the Terms and this DPA together and are not cumulative.
16. Duration and termination
This DPA continues for as long as we process Tracking Data on your behalf. Sections 13 and 15 continue to apply after the Terms end until all Tracking Data has been deleted.
17. Changes
We may update this DPA where required by changes in Data Protection Law, guidance from the Information Commissioner, or changes to the Tracking Script, and we will give you at least 30 days' notice of any change that reduces your rights or the protection of Tracking Data.
18. Precedence, governing law and jurisdiction
18.1 If there is a conflict between this DPA and the Terms on a matter of personal data processing, this DPA prevails.
18.2 This DPA is governed by the law of England and Wales, and the courts of England and Wales have exclusive jurisdiction.
Annex 1: Details of the processing (Tracking Data)
| Item | Detail |
|---|---|
| Subject matter | Measuring visits to your website so that page views, visitors, traffic sources, campaigns, devices and time on page can be shown to you in BlogPilot's analytics. |
| Duration | For as long as the Tracking Script is installed on your website and your Account is open, subject to section 13. |
| Nature of processing | Collection through a script you add to your website, which sends a small message to our servers each time a page is viewed and every 30 seconds while the page remains visible; filtering out known automated traffic; storage; aggregation and display to you in the Service; deletion. |
| Purpose | To provide you with website and content performance analytics as part of the Service. |
| Data subjects | Visitors to the websites on which you install the Tracking Script. |
| Special category data | None is intended to be collected. See section 5.4 about personal data in page paths and titles. |
| Frequency | Continuous, while the Tracking Script is installed. |
What is stored for each page view or heartbeat
| Field | Description |
|---|---|
| Visitor identifier | A one-way SHA-256 hash of: a random value that is generated fresh each day and held only in server memory, never stored; your tracking key; the visitor's IP address; and the browser's User-Agent string. It lets us count unique visitors within a day. Because the random value changes every day and is not stored, the hash cannot be recalculated later or linked to the same visitor on another day. |
| Event type | Whether the message is a page view or a "heartbeat" (sent every 30 seconds while the page is visible), and the heartbeat count, used to estimate time on page. |
| Page address | The origin and path of the page viewed (for example https://www.example.co.uk/blog/post), with any query string or fragment removed before storage (up to 2,000 characters). |
| Page path | The path part of the page address (up to 1,000 characters). |
| Page title | The page's title as shown in the browser tab (up to 500 characters). |
| Referrer | The origin and path of the page the visitor came from, where the browser provides it, with any query string or fragment removed before storage (up to 2,000 characters), and its domain name. On single-page websites, the previous page on your own site is recorded as the referrer. |
| Campaign parameters | The utm_source, utm_medium and utm_campaign values, if present in the page address, each stored in its own field. No other part of the query string is stored. |
| Device type | Mobile, tablet or desktop, worked out from the width of the browser window. The width itself is not stored. |
| Blog page flag | Whether the page matches your blog address pattern or a post published through BlogPilot. |
| Time | The date and time the message was received. |
What is used only in passing and not stored
| Item | How it is used |
|---|---|
| IP address | Read in memory from the forwarded address header added by our own web proxy, used only to create the visitor identifier, then discarded. It is not written to the Tracking Data tables, and our web proxy keeps no access logs. |
| User-Agent string | Used in memory to create the visitor identifier and to filter out known search engines, crawlers and other automated traffic, then discarded. It is not written to the Tracking Data tables. |
| Browser window width | Used to work out the device type, then discarded. |
| Query string and fragment | Removed from the page address and referrer before storage. Only the utm_source, utm_medium and utm_campaign values are kept, each in its own field. |
What the Tracking Script does not do
The Tracking Script does not set cookies and does not use the browser's local storage or session storage. It does not collect names, email addresses or form contents. It does not record the visitor's country or location, and no geolocation database or geolocation provider is used.
Annex 2: Security measures
- Encryption in transit. The Tracking Script and our servers communicate over HTTPS (TLS 1.2 or higher).
- Encryption at rest. Databases and backups are encrypted at rest using Microsoft Azure's managed encryption.
- Data minimisation by design. IP addresses and User-Agent strings are not stored. Query strings and fragments are removed from page and referrer addresses before storage. The daily random value used for the visitor identifier is held only in server memory and is never stored, so identifiers cannot be linked across days. Field lengths are capped on receipt.
- Separation between customers. Each customer has its own tracking key, and Tracking Data is stored against the customer's account and shown only to that customer's Users.
- Access control. Access to production systems is restricted to named Data HQ personnel on a need-to-know basis, with mandatory multi-factor authentication.
- Automated traffic filtering. Requests from known search engines, crawlers and other automated agents, and requests with no User-Agent, are discarded without being stored.
- Backups. Database backups are kept on a 7-day rolling basis.
- Incident response. We maintain procedures to detect, investigate and respond to security incidents, and to notify you under section 12.
- Certification. Data HQ holds a current Cyber Essentials (Basic) certificate.
Annex 3: Sub-processors for Tracking Data
| Sub-processor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Microsoft Azure (Microsoft Corporation and its affiliates) | Hosting of the servers that receive Tracking Data, and the database in which it is stored | UK South | Not applicable for Tracking Data (stored in the UK). Microsoft Data Processing Addendum applies. |
For clarity: no geolocation database or geolocation provider is used, and Tracking Data is not sent to any AI provider.
Version history
| Version | Date | Notes |
|---|---|---|
| 1.0 | 2026-09-29 | First BlogPilot Data Processing Agreement, covering personal data collected through the BlogPilot website tracking script |
