Privacy choices

We use necessary technologies to make the website work. You can choose whether we may also use optional technologies.

PrivacyCookie declaration
Skip to main content
Envra Envra
  • Analytics
  • Privacy and data
  • FAQ
  • Contact
  • Platform
  • About
  • 🇳🇴 Norsk
  • 🇬🇧 English
Envra Envra
  • Analytics
  • Privacy and data
  • FAQ
  • Contact
  • Platform
  • About
  1. Home
  2. Data Processing Agreement (DPA) – Envra

Data Processing Agreement (DPA) – Envra

Effective date
05/11/2026
Last updated
05/12/2026

1. Introduction

This Data Processing Agreement governs Envra AS’ processing of personal data on behalf of the customer.

This Data Processing Agreement forms part of the Terms of Service available at /terms.

2. Parties and Roles

The customer is the data controller for personal data processed through the customer’s websites, services, and tracking setup.

Envra AS acts as the data processor for such processing.

3. Purpose of Processing

Envra processes personal data on behalf of the customer to provide the service, including:

  • analytics and reporting

  • tracking and attribution

  • dashboards and insights

  • technical operation

  • security and abuse prevention

  • support

  • troubleshooting and performance improvement

4. Categories of Personal Data

Processing may include:

  • IP addresses

  • visitor and session identifiers

  • browser and device information

  • page views and events

  • UTM parameters and attribution data

  • referrer data

  • technical logs

  • error reporting

  • geographic information based on IP

5. Categories of Data Subjects

Processing may include:

  • visitors to the customer’s websites

  • the customer’s users

  • the customer’s employees or representatives

  • individuals submitting forms or performing actions tracked by the customer

6. Instructions

Envra processes personal data only according to the customer’s instructions, unless processing is required by law.

The customer’s instructions follow from:

  • this agreement

  • the Terms of Service

  • the customer’s configuration in the platform

  • any written instructions agreed between the parties

7. Security

Envra uses organizational and technical security measures, including:

  • role and access management

  • site isolation

  • company isolation

  • CSRF protection

  • rate limiting

  • security logging

  • password hashing

  • access control

  • monitoring and abuse prevention

8. Confidentiality

Persons with access to personal data at Envra are subject to confidentiality obligations or equivalent statutory obligations.

9. Subprocessors

Envra may use subprocessors to operate the service.

An updated list is available at /subprocessors.

Envra is responsible for ensuring that subprocessors are subject to data protection obligations equivalent to those set out in this agreement.

10. Transfers Outside the EEA

Any transfers outside the EEA are carried out in accordance with applicable regulations and appropriate safeguards.

11. Assistance to the Customer

Envra shall, where reasonable and relevant, assist the customer with:

  • handling data subject requests

  • deletion or rectification

  • assessment of security incidents

  • documentation of technical and organizational measures

  • compliance with relevant GDPR obligations

12. Security Incidents

In the event of a personal data breach affecting customer data, Envra shall notify the customer without undue delay after becoming aware of the breach.

The notification shall include relevant information to the extent available.

13. Deletion and Return

Upon termination of the customer relationship, data may be deleted, anonymized, deactivated, or returned according to the applicable agreement, retention policy, and legal requirements.

Envra may maintain a limited grace period following subscription termination during which historical data and settings are temporarily retained for possible service reactivation.

During the grace period, tracking and new data collection may be disabled or restricted.

If the subscription is not reactivated before the grace period expires, Envra may anonymize identifiers, analytics links, and related resources in accordance with the applicable lifecycle policy.

Aggregated and anonymized analytics data may be retained to the extent permitted under applicable law.

Backup data may remain for a limited period before final overwriting.

14. Audit

Envra shall make relevant documentation available to demonstrate compliance with this agreement.

Audits or inspections must be agreed in advance and conducted in a manner that does not compromise security, operations, or other customers’ data.

15. Duration

This Data Processing Agreement remains valid as long as Envra processes personal data on behalf of the customer.

Contact
  • team@envra.ai
Envra is currently in pilot phase

The platform is being continuously improved with a focus on performance, insights, and user experience. We highly appreciate feedback from our pilot customers.

Send feedback

© 2026 Envra AS. All rights reserved.
Terms Privacy Policy Cookies Data Processing Agreement Subprocessors Status