Privacy
DPA + sub-processors
When you process visitor data through Tracera, you are the data controller and Tracera is the data processor. A Data Processing Agreement (DPA) formalises that relationship as required by Article 28 GDPR.
How to get the DPA
- By email: legal@tracera.eu.
What the DPA covers
- Subject matter: visitor event data described in the property's configuration.
- Duration: as long as the underlying service agreement. Data is accessible via the portal for 30 days after termination.
- Sub-processors: full current list, with notification before any addition.
- Security measures: technical and organisational measures documented in the annex.
- Sub-processor list (current):
Name Location Purpose GoTrust BV (Belgian dedicated hardware) Belgium Compute, storage, networking Let's Encrypt USA (cert issuance only, no PII) TLS certificates - International transfers: none. All processing in the EU.
- Data subject rights: responses within the GDPR statutory one-month period.
- Audit rights: customer audit clauses per Art. 28(3)(h).
Custom red-line review
Enterprise customers can submit their own DPA template; we will counter-sign anything that doesn't conflict with our security commitments to other customers.
Records of Processing Activities (RoPA)
Tracera maintains a full RoPA per Art. 30 GDPR for the processing it does as a processor on customers' behalf. A redacted copy is available to customers on request.