Accord de traitement des données

Dernière mise à jour : 12 août 2026

Accord de traitement des données de Sortlist

This Data Processing Agreement (the "DPA") applies where a customer of Sortlist installs a Sortlist tracking snippet, such as the Sortlist Radar snippet, on a website that the customer operates. In that situation the customer determines the purposes and means of processing the personal data of its own website visitors and acts as the controller, and Sortlist processes that personal data on the customer's behalf as a processor within the meaning of Article 28 GDPR.

This DPA forms part of, and is subject to, the General Terms & Conditions. Capitalised terms not defined here have the meaning given to them in those terms. Where this DPA conflicts with the General Terms & Conditions in respect of the processing of personal data, this DPA prevails.

1. Parties

Processor: Sortlist SA, Av. Zénobe Gramme 29, 1300 Wavre, Belgium, registered with the Belgian Crossroads Bank for Enterprises under number 0537.665.555 ("Sortlist").

Controller: the customer that has subscribed to the relevant Sortlist service and installed a Sortlist snippet on a website it operates (the "Customer").

2. Subject matter, nature, purpose and duration

Subject matter and nature. Sortlist collects and processes data about visitors to the Customer's website through the snippet the Customer has installed, in order to identify the organisation a visit originates from and to present the resulting information to the Customer.

Purpose. Providing the Sortlist services the Customer has subscribed to, and no other purpose. Sortlist does not sell the Customer's visitor data and does not use it to build profiles for other customers.

Duration. This DPA applies for as long as Sortlist processes personal data on the Customer's behalf, which begins when the snippet is installed and ends in accordance with the section on deletion below.

3. Categories of data subjects and personal data

3.1 Categories of data subjects

Visitors to the Customer's website.

3.2 Categories of personal data

The snippet collects:

  • the visitor's IP address, and the country, region and city derived from it;
  • a device identifier and a pseudonymous visitor identifier;
  • technical data about the visitor's browser, operating system and device type, and the user agent string;
  • device and browser characteristics used to derive a device fingerprint, including a canvas rendering, WebGL vendor and renderer information, an audio-processing measurement, the list of available fonts, browser plugins, a summary of media devices, the number of logical processors, the reported device memory, the maximum number of touch points, whether an ad blocker is present, the "Do Not Track" signal, and automation-detection indicators;
  • the pages visited, page titles, the referring URL, and time and engagement data for each page;
  • interaction events, namely clicks, downloads and form submissions, including data about the element interacted with and the content entered into form fields other than password fields and fields whose name indicates sensitive data;
  • the organisation identified from the IP address, where identification is possible.

The snippet is not intended to collect special categories of personal data within the meaning of Article 9 GDPR, and the Customer must not use it in a way that causes such data to be collected.

4. Instructions

Sortlist processes personal data only on documented instructions from the Customer, including with regard to transfers, unless required to do otherwise by Union or Member State law. The Customer's instructions are given through this DPA, the General Terms & Conditions, and the configuration options the Customer selects in the Sortlist application.

Sortlist will inform the Customer if, in its opinion, an instruction infringes the GDPR or other applicable data protection law.

5. Customer obligations

As controller, the Customer is responsible for the lawfulness of the processing carried out through the snippet on its website. In particular, the Customer must:

  • describe the processing carried out via the snippet in its own privacy notice, including the categories of data listed above, the recipients, and the applicable legal basis;
  • establish and document a valid legal basis for the processing;
  • where consent is required for the storing of or access to information on the visitor's device, obtain that consent before the snippet stores or reads such information, and pass the consent signal to the snippet;
  • handle requests from its website visitors exercising their rights as data subjects, with Sortlist's assistance as described below.

6. Confidentiality

Sortlist ensures that persons authorised to process the personal data are bound by an appropriate obligation of confidentiality, and that access is limited to those who need it to provide the services.

7. Security of processing

Sortlist implements appropriate technical and organisational measures pursuant to Article 32 GDPR, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risk to data subjects. These measures include encryption of data in transit and at rest, access controls and authentication, logical separation of customer data, logging and monitoring, and regular review of the measures in place.

8. Sub-processors

The Customer gives Sortlist general written authorisation to engage sub-processors. Sortlist imposes on each sub-processor data protection obligations no less protective than those set out in this DPA, and remains fully liable to the Customer for the performance of that sub-processor's obligations.

The following sub-processors are engaged for the processing described in this DPA:

  • Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg. Provides the content delivery layer through which the snippet is served and visitor events are received, and hosts the Sortlist application and database infrastructure in the AWS Ireland region (eu-west-1). The content delivery layer operates from Amazon's global network of edge locations, which includes locations outside the European Economic Area.
  • Snitcher B.V., Oude Enghweg 2, 1217 JC Hilversum, Netherlands. Operates the tracking and visitor identification service behind the Sortlist snippet. [PENDING: Snitcher's processing region and its own sub-processors, to be confirmed in writing by Snitcher.]
  • Google. Hosts the Sortlist analytics warehouse, in which Radar-derived data is stored and modelled for reporting. The warehouse datasets holding this data are located in the United States. [PENDING: contracting Google entity and its registered address, to be confirmed.]
  • Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, United States. Provides authoritative DNS for the Sortlist domains used by the snippet.

Sortlist will inform the Customer of any intended addition or replacement of a sub-processor, giving the Customer the opportunity to object to those changes.

9. International transfers

The Sortlist application and database infrastructure that stores the personal data processed under this DPA is located in the European Union, in the AWS Ireland region (eu-west-1).

Visitor events are received through a content delivery network that operates from edge locations worldwide. Where a website visitor is located outside the European Economic Area, their request is therefore terminated at an edge location outside the EEA before the data is forwarded to the processing infrastructure described above.

Radar-derived data is additionally copied to the Sortlist analytics warehouse, where it is stored and modelled for reporting. The warehouse datasets holding this data are located in the United States. This is a transfer of personal data outside the European Economic Area, and it is ongoing rather than incidental to a visitor's location.

Sortlist relies on the Standard Contractual Clauses adopted by the European Commission for any transfer of personal data to a country outside the European Economic Area that is not covered by an adequacy decision, and will inform the Customer of any change to the transfer mechanisms it relies on.

[PENDING: the transfer impact assessment for the analytics warehouse transfer described above, and the retention period after which Radar-derived data is deleted from the warehouse. Both are being completed and this section will be updated with them.]

10. Assistance with data subject rights

Taking into account the nature of the processing, Sortlist assists the Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Customer's obligation to respond to requests from data subjects exercising their rights under Chapter III GDPR.

If Sortlist receives such a request directly from one of the Customer's website visitors, it will not respond to it itself, other than to direct the visitor to the Customer, and will inform the Customer without undue delay.

11. Assistance with compliance and personal data breaches

Sortlist assists the Customer in ensuring compliance with the obligations under Articles 32 to 36 GDPR, taking into account the nature of the processing and the information available to Sortlist.

Sortlist notifies the Customer without undue delay after becoming aware of a personal data breach affecting personal data processed on the Customer's behalf, and provides the information the Customer reasonably requires in order to meet its own notification obligations.

12. Deletion and return of data

On termination of the services, Sortlist deletes or returns the personal data processed on the Customer's behalf, at the Customer's choice, and deletes existing copies, unless Union or Member State law requires continued storage.

13. Audits

Sortlist makes available to the Customer the information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR, and allows for and contributes to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer. Audits are conducted on reasonable prior notice, during normal business hours, no more than once per year unless a personal data breach or a supervisory authority requires otherwise, and subject to confidentiality obligations.

14. Contact

Questions about this DPA, requests for a signed copy, and privacy enquiries relating to the processing described here can be sent to hello@sortlist.com.

Index

1. Parties
2. Subject matter, nature, purpose and duration
3. Categories of data subjects and personal data
4. Instructions
5. Customer obligations
6. Confidentiality
7. Security of processing
8. Sub-processors
9. International transfers
10. Assistance with data subject rights
11. Assistance with compliance and personal data breaches
12. Deletion and return of data
13. Audits
14. Contact