EU-based RUM solution Other devs are already building with our MCP & API

Data Processing Agreement

Version 3.0 - 10 September 2026

This Data Processing Agreement ("DPA") forms part of the agreement between the customer using the RUMvision Service ("Customer") and RUMvision B.V. ("RUMvision") where RUMvision processes personal data on behalf of the Customer.

The DPA applies automatically to that processing. No separate signature is required for the standard DPA unless the parties expressly agree otherwise in writing.

1. Parties and scope

RUMvision B.V.
Ubbo Emmiussingel 21
9711 BB Groningen
The Netherlands
KvK / Chamber of Commerce: 85752762

This DPA applies where RUMvision processes personal data on behalf of the Customer in connection with the RUMvision Service.

Depending on the Customer's own role, the Customer may act as controller or as a processor acting on behalf of another controller. RUMvision acts as processor or subprocessor, as applicable, for the processing covered by this DPA.

Processing for which RUMvision independently determines the purposes and means, such as processing of RUMvision's own business contact, billing, security or account-administration data, is not governed by this DPA and is described in the RUMvision Privacy Policy.

2. Definitions

Terms such as "controller", "processor", "personal data", "processing", "personal data breach", "data subject" and "supervisory authority" have the meanings given to them in the General Data Protection Regulation (EU) 2016/679 ("GDPR").

For this DPA:

3. Customer instructions and purposes

RUMvision will process personal data only on documented instructions from the Customer, including the instructions contained in the Agreement, this DPA, the Customer's configuration of the Service and other documented instructions accepted by RUMvision.

The Customer instructs RUMvision to process personal data as necessary to:

RUMvision will not process personal data covered by this DPA for unrelated advertising, behavioural targeting or cross-site visitor profiling.

If RUMvision believes that a Customer instruction infringes the GDPR or other applicable Union or Member State data-protection law, RUMvision will inform the Customer without undue delay, unless prohibited by law.

If applicable law requires RUMvision to process personal data other than on the Customer's documented instructions, RUMvision will inform the Customer of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.

4. Customer responsibilities

The Customer is responsible for its own compliance with applicable data-protection and electronic-communications law and for the lawfulness of its instructions to RUMvision.

This includes, where applicable:

Where the Customer acts as processor for another controller, the Customer represents that it is authorised to instruct RUMvision to process the relevant personal data and to appoint RUMvision as a subprocessor.

5. Confidentiality

RUMvision will ensure that persons authorised to process personal data covered by this DPA are subject to an appropriate duty of confidentiality or statutory obligation of confidentiality.

Access to personal data will be limited to persons who need that access for the provision, support, security or operation of the Service.

6. Security

Taking into account the state of the art, implementation costs and the nature, scope, context and purposes of the processing, as well as the risks to the rights and freedoms of natural persons, RUMvision will implement appropriate technical and organisational measures designed to provide a level of security appropriate to the risk, in accordance with Article 32 GDPR.

Depending on the relevant systems and risks, these measures may include:

Further information about the technical and organisational measures applicable to the Service may be provided in RUMvision's current security documentation.

7. Subprocessors

The Customer gives RUMvision general written authorisation to engage Subprocessors for the processing covered by this DPA.

RUMvision maintains current information identifying relevant Subprocessors, their functions and applicable processing or hosting locations in its Service Providers & Subprocessors information.

Before adding or replacing a Subprocessor that will process personal data covered by this DPA, RUMvision will provide the Customer with reasonable advance notice where required by Article 28(2) GDPR. The notice will provide a reasonable opportunity for the Customer to object on substantiated data-protection grounds.

If the Customer objects, the parties will work in good faith to seek a reasonable solution. Where no reasonable solution is available, RUMvision may, depending on the circumstances, avoid use of the relevant Subprocessor for the Customer, offer an available alternative, or allow the affected Service or Agreement to be terminated in accordance with the applicable contractual terms.

RUMvision will impose data-protection obligations on each Subprocessor that are appropriate to the processing and provide substantially the same level of protection for the relevant personal data as required from RUMvision under this DPA.

RUMvision remains responsible to the Customer for the performance of its Subprocessors' data-protection obligations to the extent required by Article 28 GDPR.

8. International transfers

RUMvision's core visitor-level RUM processing infrastructure is located within the European Union.

Where RUMvision or a Subprocessor transfers personal data covered by this DPA outside the European Economic Area ("EEA"), RUMvision will ensure that an applicable transfer mechanism under Chapter V GDPR is in place where required.

Depending on the destination and circumstances, this may include an adequacy decision, Standard Contractual Clauses approved by the European Commission or another legally recognised transfer mechanism.

Where required, RUMvision will take reasonable steps to assess whether supplementary measures are appropriate for the relevant transfer.

Current information about relevant processing locations and transfer mechanisms is maintained in RUMvision's Service Providers & Subprocessors information or other applicable data-processing documentation.

This section does not govern a transfer to a third-party service independently selected or configured by the Customer, for example an external AI or LLM service connected by the Customer through MCP. The Customer is responsible for the lawfulness of such Customer-directed transfers, subject to RUMvision's own obligations for the processing under its control.

9. AI-supported functionality

Where the Customer enables an AI-supported RUMvision feature, the Customer instructs RUMvision to process the prompts, inputs, outputs and other Customer Data reasonably required to provide and secure that feature.

An AI provider engaged by RUMvision that processes personal data on RUMvision's behalf will be treated as a Subprocessor where applicable and will be subject to the requirements of section 7.

RUMvision and its AI providers will not use Customer Data, prompts, inputs or outputs in identifiable or customer-linked form to train or improve general-purpose or cross-customer AI models unless the Customer has expressly agreed to such use and the processing is otherwise permitted by applicable law.

Where Customer Data is lawfully aggregated and irreversibly anonymised so that neither an individual nor the relevant Customer can reasonably be identified, the resulting anonymous information may be used as permitted by the Agreement for service evaluation and improvement. The parties acknowledge that genuinely anonymised information is no longer personal data under the GDPR.

10. Assistance with data-subject rights

Taking into account the nature of the processing, RUMvision will assist the Customer by appropriate technical and organisational measures, insofar as reasonably possible, with the Customer's obligation to respond to requests by data subjects exercising their rights under Chapter III GDPR.

If RUMvision receives a request directly from a data subject concerning personal data processed on behalf of the Customer, RUMvision will not independently fulfil that request unless authorised or legally required to do so. RUMvision will forward or otherwise make the request known to the Customer where reasonably possible.

11. Assistance with compliance obligations

Taking into account the nature of the processing and the information available to RUMvision, RUMvision will provide reasonable assistance to the Customer with obligations under Articles 32 to 36 GDPR where those obligations relate to processing covered by this DPA.

This may include reasonable assistance with:

12. Personal data breaches

RUMvision will notify the Customer without undue delay after becoming aware of a personal data breach affecting personal data processed under this DPA.

To the extent information is reasonably available to RUMvision, the notification will include information necessary to assist the Customer with its obligations under Articles 33 and 34 GDPR, such as:

Where complete information is not available at the same time, RUMvision may provide information in phases without undue further delay.

Notification of a personal data breach does not constitute an acknowledgement of fault or liability by RUMvision.

13. Deletion and return of Customer Data

During the term of the Agreement, Customer Data is retained according to the retention periods applicable to the Service and the Customer's configuration.

After termination or expiry of the Agreement, RUMvision will delete or return personal data processed on behalf of the Customer in accordance with the Agreement and the Customer's applicable instructions, unless Union or Member State law requires continued storage.

Customer RUM Data is ordinarily deleted within up to two months after termination, unless earlier deletion applies, continued retention is lawfully required, or the parties have agreed otherwise.

Where data remains temporarily in backups after deletion from active systems, it will remain protected under this DPA and will not be restored for ordinary processing except where necessary for disaster recovery, security or legal obligations.

14. Information and audits

RUMvision will make available to the Customer information reasonably necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and this DPA.

Where available, the Customer should first use relevant documentation, security information, certifications, reports or responses provided by RUMvision to assess compliance.

If that information is reasonably insufficient to demonstrate compliance, the Customer may request an audit relating to processing covered by this DPA.

Audits must:

The Customer bears its own audit costs and RUMvision may charge reasonable costs for extraordinary audit assistance beyond the information and cooperation required by Article 28 GDPR, unless the audit identifies a material breach of this DPA by RUMvision.

Nothing in this section limits the powers of a competent supervisory authority.

15. Records and regulatory cooperation

RUMvision will maintain records of processing activities for which it acts as processor as required by Article 30(2) GDPR.

RUMvision will cooperate with competent supervisory authorities to the extent required by applicable law in relation to processing covered by this DPA.

16. Liability

The liability provisions and limitations in the Agreement apply to this DPA to the extent permitted by applicable law.

Nothing in this DPA excludes or limits either party's liability to the extent that such liability cannot lawfully be excluded or limited under the GDPR or other applicable law.

17. Duration and termination

This DPA takes effect when RUMvision begins processing personal data on behalf of the Customer and remains in effect for as long as RUMvision processes such personal data.

The DPA terminates when RUMvision no longer processes personal data on behalf of the Customer, subject to provisions that by their nature continue to apply, including confidentiality, deletion, audit, liability and legal-retention obligations.

18. Changes to this DPA

RUMvision may update this standard DPA where reasonably necessary to reflect changes in applicable law, regulatory guidance, the Service or RUMvision's data-processing arrangements.

RUMvision will not make a change that materially reduces the protection of personal data processed on behalf of the Customer without appropriate notice or another lawful basis for the change.

Where a change materially affects the Customer's rights or obligations, RUMvision will provide notice in accordance with the Agreement or applicable law.

19. Order of precedence and governing law

If there is a conflict between this DPA and the Agreement concerning processing of personal data on behalf of the Customer, this DPA prevails to the extent of that conflict.

Except where mandatory data-protection law requires otherwise, this DPA is governed by the same law and dispute-resolution provisions as the Agreement.

Annex 1 - Details of the processing

A. Subject matter and purpose

Processing of visitor-level RUM Data on behalf of the Customer to provide Real User Monitoring, website-performance analysis, reliability and responsiveness diagnostics, technical troubleshooting and related functionality enabled by the Customer.

Where enabled, this may also include Business Metrics, conversion measurement, JavaScript and browser error monitoring, responsiveness and interaction-health diagnostics and AI-supported RUMvision features.

B. Duration

Processing takes place for the duration of the Agreement, subject to the Service retention periods and deletion arrangements described below.

DataGeneral retention
Persistent first-party Browser IdentifierMaximum 90 days
Temporary sessionStorage informationRelevant browser tab/session
Server-side RUM measurement dataUp to 13 months
Business Metrics forming part of the RUM ServiceUp to 13 months
JavaScript and browser error-monitoring dataUp to 13 months
Responsiveness and interaction-health dataUp to 13 months
Customer RUM Data following terminationOrdinarily deleted within up to 2 months

C. Categories of data subjects

D. Categories of personal data

Depending on the Customer's configuration and enabled functionality, processing may include:

E. Data intentionally excluded from the Service

The Service is not intended to collect or process the following through visitor-level RUM fields unless separately and lawfully agreed for a specific supported purpose:

Customer-controlled fields must be configured so that unnecessary or prohibited personal data is not intentionally sent to RUMvision.

F. Special categories of personal data

No special categories of personal data are intended to be processed as part of the standard RUM Service. Customers must not intentionally submit such data through the Service unless RUMvision has expressly agreed to a separate lawful and supported processing arrangement.

G. Nature of the processing

Automated collection, receipt, transmission, storage, organisation, structuring, aggregation, analysis, retrieval, display, diagnostic processing, deletion and, where applicable, irreversible anonymisation of data necessary to provide the Service according to the Customer's configuration and instructions.

H. Customer instructions

The Customer's instructions are determined by the Agreement, this DPA, the Customer's configuration of the Service, documented support requests and any other written instructions accepted by RUMvision.

Annex 2 - Technical and organisational measures

RUMvision maintains technical and organisational measures appropriate to the risk of the processing. The measures applicable to the Service may evolve over time as technologies and security practices change, provided that the overall level of protection is not materially reduced.

Measures may include, as appropriate:

Annex 3 - Service Providers & Subprocessors

RUMvision maintains its current Service Providers & Subprocessors information separately from this DPA so that provider, purpose, role, location and transfer information can be kept up to date without requiring the DPA itself to be replaced whenever a provider changes.

The current register forms the reference for Subprocessors authorised under section 7 of this DPA.