Data Processing Agreement (DPA)

Data Processing Agreement for the GA4audit service.

Last updated: 1 June 2026

This is the English version of the Data Processing Agreement. The Operator is established in Poland and the Service is provided under Polish law, including the GDPR. In the event of any discrepancy between the English and Polish versions, the Polish version prevails.

Introduction and roles of the parties

This Data Processing Agreement (the DPA) supplements the agreement for the provision of the GA4audit service concluded on the basis of the Terms of Service (the Main Agreement) and sets out the rules for processing personal data entrusted by the User.

The parties to the DPA are:

Controller - the User using the Service on the basis of the Terms of Service, being the controller of the entrusted personal data (and where the User is itself a processor for its own client - a processor; in such case the Operator acts as a sub-processor);
Operator (Processor) - Wojciech Bednarski Data Wolves, with its registered office at ul. Fabryczna 3/9, 97-545 Wojciechów, Poland, NIP (Tax ID): 7722307415, REGON: 382702660, operating under the brand Data Wolves, providing the GA4audit Service (referred to in the Terms of Service and Privacy Policy as the Operator / Controller).

Important distinction of roles. With respect to User data (Account, payment, and contact data), the Operator is the controller within the meaning of the Privacy Policy. This DPA concerns a different set of data - personal data that may be present in the User's Google Analytics 4 environment or on the scanned Website, and which the User makes available to the Operator in connection with using the Service. With respect to such data, the User remains the controller and the Operator is the processor.

The DPA is incorporated into the Main Agreement by reference and is accepted by the Controller upon acceptance of the Terms of Service or commencement of use of the Service. By accepting the DPA, the Controller declares that it is authorized to conclude it on behalf of the data controller. At the Controller's request, the Operator will provide a version of the DPA for signature together with the full text of the standard contractual clauses.

1. Definitions

Capitalized terms not defined in the DPA have the meaning given to them in the Terms of Service and the Privacy Policy. Other terms (including controller, processor, sub-processor, data subject, personal data breach, supervisory authority) have the meaning given to them in the GDPR.

Entrusted Data - personal data that the Controller makes available to the Operator in connection with using the Service, in particular personal data that may occur in GA4 Property data (e.g. as a result of incorrect configuration leading to the collection of personal data by the User) and on the scanned Website.
Data Protection Law - the GDPR and other applicable personal data protection regulations.
Standard Contractual Clauses (SCC) - the standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914 of 4 June 2021, in the appropriate module.

2. Subject matter, nature, and purpose of processing

2.1. The Operator processes Entrusted Data solely for the purpose and to the extent necessary to provide the GA4audit Service in accordance with the Main Agreement, i.e. to perform the automated audit of GA4 Property configuration and Website tagging and to generate Reports.

2.2. The nature of the processing comprises automated operations: reading (in read-only mode) the settings and reporting data of the GA4 Property via Google APIs, retrieving and analyzing the publicly available content of the Website, and storing and making available the analysis results (Reports) in the Application. The Operator does not have the technical ability to modify the configuration of the Controller's GA4 Property.

2.3. The Operator does not determine the scope or type of data that the Controller collects in its own GA4 Property or on the Website. The feature for detecting potential personal data (PII) is solely signaling in nature and serves to indicate to the Controller possible irregularities in its configuration.

2.4. The DPA constitutes a documented processing instruction. The Operator processes Entrusted Data solely on the documented instruction of the Controller (which is the use of the Service in accordance with the Main Agreement and any separate instructions provided in writing or electronically), unless processing is required by law - in which case the Operator informs the Controller before processing, unless the law prohibits this. If, in the Operator's opinion, an instruction infringes Data Protection Law, the Operator informs the Controller without delay.

3. Type of data and categories of data subjects

3.1. Type of Entrusted Data: personal data that may occur in the GA4 environment or on the Website, in particular online identifiers, IP addresses, user/device identifiers, and - in the event of incorrect configuration on the Controller's side - other data entered into GA4 (e.g. an email address passed in event parameters).

3.2. Categories of data subjects: users of the Controller's websites and applications covered by GA4 measurement.

3.3. Special categories of data. The Controller undertakes not to enter into the GA4 Property or make available to the Operator special categories of data within the meaning of Article 9 GDPR, nor data relating to criminal convictions and offences (Article 10 GDPR). The Operator is not liable for the consequences of the Controller's breach of this undertaking.

4. Duration of processing

The Operator processes Entrusted Data for the duration of the Main Agreement. After it ends, the provisions of point 11 (deletion or return of data) apply.

5. Obligations of the Operator (processor)

The Operator undertakes to:

5.1. process Entrusted Data solely on the documented instruction of the Controller and solely for the purpose specified in point 2;

5.2. ensure that persons authorized to process Entrusted Data have committed to confidentiality or are under an appropriate statutory obligation of confidentiality, and limit access to data to persons for whom it is necessary;

5.3. implement and maintain appropriate technical and organizational measures ensuring the security of Entrusted Data, appropriate to the risk (Article 32 GDPR), described in Annex 1;

5.4. comply with the conditions for engaging sub-processors set out in point 7;

5.5. assist the Controller, as far as possible and through appropriate technical and organizational measures, in fulfilling the obligation to respond to data subjects' requests to exercise their rights (Articles 12-23 GDPR);

5.6. assist the Controller in fulfilling the obligations set out in Articles 32-36 GDPR (security of processing, breach notification, impact assessment, prior consultation), taking into account the nature of the processing and the information available to it;

5.7. inform the Controller without undue delay after becoming aware of a breach of the protection of Entrusted Data, providing information enabling the Controller to fulfill its obligations (the nature of the breach, the approximate categories and number of data subjects, the likely consequences, and the measures taken or proposed);

5.8. inform the Controller of any request for disclosure of Entrusted Data addressed to the Operator by a public authority, unless prohibited by law;

5.9. after the Service ends, delete or return Entrusted Data in accordance with point 11;

5.10. make available to the Controller the information necessary to demonstrate compliance with the obligations set out in Article 28 GDPR and allow audits on the terms set out in point 9.

6. Obligations of the Controller

6.1. The Controller ensures that it has a valid legal basis for processing all Entrusted Data and that making it available to the Operator complies with Data Protection Law. The Controller bears sole responsibility for the lawfulness, accuracy, and scope of data collected in its GA4 Property and on the Website.

6.2. The Controller issues lawful processing instructions and undertakes not to provide the Operator with special categories of data (point 3.3).

6.3. The Controller is responsible for the correct configuration of GA4 in accordance with Google's documentation, including not collecting personal data in GA4 (in accordance with Google Analytics rules).

6.4. The Controller is responsible for implementing appropriate security measures on its side and for the use of the Service by persons to whom it has granted access to the Account.

7. Sub-processing

7.1. The Controller grants the Operator general authorization to engage sub-processors to provide the Service.

7.2. The Operator ensures that sub-processors are bound by data protection obligations corresponding to those set out in the DPA and that the scope of Entrusted Data made available to them is limited to the necessary minimum.

7.3. The current list of sub-processors is available in the Privacy Policy (https://ga4audit.io/privacy) and on request. With respect to Entrusted Data, the sub-processors are in particular the providers of the infrastructure on which the Service is provided:

No.Sub-processorRoleLocation
1.Google Cloud / Firebase (Google)Hosting, database, application infrastructure, and storage of Audit resultsEU (European region); possible transfers to Google outside the EEA
2.Google - Google Analytics APIsSource of data read in read-only mode for the purposes of the AuditGoogle; possibly outside the EEA

7.4. The Operator informs the Controller in advance of intended changes concerning the addition or replacement of sub-processors, allowing a reasoned objection to be raised. If an objection is raised that cannot be resolved, either party may terminate the Main Agreement in the part to which the objection relates.

Note: tools such as Google Tag Manager, reCAPTCHA / App Check, and the Payment Processor (Stripe) serve the operation of the Operator's own Service and the processing of data for which the Operator is the controller (Privacy Policy), and not the processing of Entrusted Data within the meaning of the DPA. They therefore do not appear in the sub-processor table above.

8. Transfers of data outside the EEA

8.1. The Operator stores Entrusted Data on infrastructure located in the European Union.

8.2. If providing the Service involves the transfer of Entrusted Data outside the European Economic Area (in particular in connection with the use of Google services), the Operator ensures appropriate safeguards required by Data Protection Law, in particular the standard contractual clauses (SCC) or transfer on the basis of an adequacy decision. By accepting the DPA, the Controller authorizes the Operator to make such a transfer and - to the extent necessary - to conclude SCC on its behalf with sub-processors. The Operator provides the full text of the SCC on request.

9. Audit and demonstration of compliance

9.1. The Operator makes available to the Controller, upon its written request, the information necessary to demonstrate compliance with the obligations under Article 28 GDPR and allows audits, including inspections, conducted by the Controller or an auditor authorized by it.

9.2. The Controller notifies the Operator of a planned audit at least one month in advance. The parties agree on the date, scope, and conditions of the audit, respecting confidentiality and the need to ensure the continuity of the Service. The audit is limited to verifying the Service's compliance with the security measures set out in the DPA and the Privacy Policy.

9.3. The costs of an audit conducted at the Controller's request, including the Operator's reasonable costs and the costs of external auditors, are borne by the Controller.

10. Breach notification

In the event of a breach of the protection of Entrusted Data, the Operator notifies the Controller without undue delay after becoming aware of the breach and provides it with reasonable assistance necessary to fulfill the obligations arising from Articles 33-34 GDPR. This obligation does not cover incidents caused by an act or omission of the Controller or persons it engages.

11. Deletion or return of data

11.1. After the Service ends, the Operator, at the Controller's choice, returns or deletes the Entrusted Data and deletes existing copies, within 30 days, unless the law requires longer retention.

11.2. Before deletion, the Controller may export the data available in the Application (including Reports). Where further retention is necessary to establish, pursue, or defend claims, the Operator limits processing to the minimum and processes the data on the basis of legitimate interest.

12. Liability

12.1. The Operator is liable for damage caused by failure to fulfill the obligations arising from the DPA or the obligations imposed directly on the processor by the GDPR. The Operator is not liable for damage resulting from an act or omission for which the Controller is responsible, in particular for the lack of a legal basis or the lawfulness of data entered by the Controller.

12.2. The Operator's liability under the DPA is subject to the liability limitations set out in the Terms of Service (Main Agreement), to the extent permitted by mandatory provisions of law.

13. Term and termination

The DPA remains in force for the duration of the Main Agreement and terminates together with it, without prejudice to the provisions that by their nature should survive its termination (in particular points 11 and 12).

14. Final provisions

14.1. In the event of a conflict between the DPA and the other provisions of the Main Agreement, the provisions of the DPA prevail with respect to the processing of Entrusted Data.

14.2. Amendments to the DPA require documentary form. The Operator may update the DPA in connection with changes in regulations or the manner of providing the Service, informing the Controller in accordance with the rules for amending the Terms of Service.

14.3. The DPA is governed by Polish law. Disputes are settled by the court having jurisdiction in accordance with the Terms of Service.

14.4. At the Controller's request sent to contact@ga4audit.io, the Operator will provide the DPA with the full text of the standard contractual clauses or a version intended for signature.


Annex 1 - Technical and Organizational Measures (TOMs)

The Operator applies in particular the following security measures:

access to GA4 Property data solely in read-only mode; no technical ability to modify the Controller's GA4 configuration;
storage of data on infrastructure in the EU (Google Cloud / Firebase, European region);
encryption of data in transit (TLS) and at rest in accordance with the infrastructure provider's standards;
access control based on the need-to-know and least-privilege principles; authentication of access to systems;
confidentiality commitments of authorized persons;
protection against abuse and unauthorized access (including reCAPTCHA / App Check mechanisms on the Service side);
event logging and security monitoring;
incident response and breach notification procedures.

This DPA forms an integral part of the Terms of Service.

Other documents

Didn't find an answer?

Write to us - we reply clearly and fast, including implementation questions.

Contact us