Data Processing Agreement
Last updated September 22, 2026
When you connect a site, we process data about your visitors on your behalf. Article 28 of the UK and EU GDPR says that has to be governed by a contract. This page is that contract.
It applies automatically. You do not need to sign it, request a copy, or write to us to put it in place. It takes effect when you connect a site and it stays in place for as long as we process anything for you. It forms part of the terms of service, and where the two disagree about personal data, this page is the one that governs.
Who this is between
You, the site owner, are the controller. Complete Web Resources LLC, a Texas limited liability company based in Austin, Texas, United States, operating as Visibility Kit, is the processor. In this agreement “we” and “us” mean that company.
Terms like controller, processor, personal data, processing, and personal data breach carry the meanings the GDPR gives them.
What we process for you
| Subject matter | Attributing visits to your site to the AI tool that referred them, and reporting that back to you. |
| Duration | For as long as your site is connected. Individual visitor records are deleted 30 days after they are written. |
| Nature and purpose | Collection, storage, organization, and deletion, for the sole purpose of providing AI referral analytics to you. |
| Personal data | Pseudonymous identifiers generated in the browser (visitorId, sessionId), the referring URL, the landing page URL, campaign and click parameters present in the URL, and timestamps. No IP addresses, no user agents, no device or browser fingerprints, no form contents, and no special category data. |
| Data subjects | Visitors to your website who arrived from an AI tool. |
| Frequency | Continuous, for as long as the script is installed. |
The privacy policy sets this out in more detail, including the fields we discard on receipt and never write down.
We act only on your instructions
We process personal data only on your documented instructions, including about transfers to another country. Your instructions are these terms, the privacy policy, and the settings you choose in the plugin and the dashboard. If we think an instruction breaks data protection law, we will tell you and we may pause that processing until it is resolved.
We do not sell visitor data, share it with advertisers or data brokers, use it to train AI models, or use it for any purpose of our own.
Confidentiality
Everyone we allow to access personal data processed under this agreement is bound by a duty of confidentiality, and only the people who operate the service have that access.
Security
We take appropriate technical and organizational measures under Article 32. In practice:
- Traffic to and from the service is encrypted in transit.
- Data is encrypted at rest by our hosting provider, and access to the production database is limited to the people who operate the service and is authenticated individually.
- The dataset is deliberately narrow. It holds no IP addresses, no user agents, and no contact details, so the amount of personal data at risk in any incident is small by design.
- Records are deleted automatically 30 days after they are written, by a scheduled job, without anyone having to ask.
- Identifiers are random and generated in the visitor’s browser. They are not derived from anything about the person or their device.
Other companies we use
You give us general authorization to engage subprocessors. The current list, with what each one does and where it is located, is on the subprocessor page. Today it is Railway Corporation and Cloudflare, Inc. for visitor data, and Resend for account data only.
We will update that page at least 30 days before a new subprocessor starts touching visitor data. If you object on reasonable data protection grounds, write to us within those 30 days and we will either find another way or you can disconnect, which ends the processing. Every subprocessor is bound by obligations no weaker than the ones in this agreement, and we stay responsible to you for what they do.
Helping you answer your visitors
If one of your visitors asks you to give them a copy of their data, correct it, delete it, restrict it, or object to it, we will help you respond, taking into account the nature of the processing and what we actually hold. If a visitor comes to us directly, we will refer them to you unless the law requires otherwise. There is no charge for this.
Because the identifiers are random and we hold no contact details, the practical way to find a visitor’s records is the value of their _vk_vid cookie.
If something goes wrong
If we become aware of a personal data breach affecting data we process for you, we will tell you without undue delay and in any event within 72 hours of becoming aware of it. We will include what we know about what happened, who is affected, the likely consequences, and what we are doing about it, and we will keep you updated as we learn more. Reporting to a supervisory authority is yours to do as the controller, and we will give you what you need to do it.
Assessments
If you have to carry out a data protection impact assessment or consult a supervisory authority about this processing, we will give you the information you reasonably need, to the extent only we have it.
Deletion
Visitor records are deleted 30 days after they are written, throughout the life of this agreement and without you having to ask. When you disconnect, collection stops immediately and any remaining records age out on that same schedule. Account data is deleted on request. We will not keep copies except where the law requires it.
Showing our work
We will make available the information you reasonably need to verify that we are meeting these obligations, and will respond to a written security questionnaire once a year. Given the size of the service and how narrow the dataset is, we do not host on-site audits. If your regulator requires more than this, write to us and we will work out what is needed.
Transfers out of the UK and the EEA
We run on servers in the United States. Where you are in the UK or the European Economic Area, or your visitors are, that means personal data is transferred to the United States.
For those transfers, the European Commission’s Standard Contractual Clauses of 4 June 2021 (Decision 2021/914) are incorporated into this agreement in full, Module Two, controller to processor. They are completed as follows:
- The optional docking clause in Clause 7 does not apply.
- In Clause 9, Option 2 applies, general written authorization, with the 30-day notice period described above.
- The optional wording in Clause 11 about an independent dispute resolution body does not apply.
- For Clause 17, the Clauses are governed by the law of Ireland. For Clause 18(b), disputes go to the courts of Ireland. This applies to the Clauses only, and does not change the governing law of the terms of service.
- Annex I is the table above, together with our contact details at the bottom of this page. You are the data exporter and we are the data importer. Our contact point for data protection is [email protected]. The competent supervisory authority is the one for the EEA country you are established in, or where you are not established in the EEA, the authority of the member state where your representative is or where the relevant data subjects are.
- Annex II is the Security section above.
- Annex III is the subprocessor page.
For transfers from the United Kingdom, the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, version B1.0, is incorporated as well. Tables 1 to 3 are populated by this agreement as set out above, and in Table 4 neither party may end the Addendum as set out in Section 19. For transfers from Switzerland, references in the Clauses to the GDPR are read as references to the Swiss Federal Act on Data Protection, and the Federal Data Protection and Information Commissioner is the competent authority.
If the Clauses and the rest of this agreement ever conflict, the Clauses win.
How long this lasts
This agreement starts when you connect a site and runs until we no longer process any personal data for you. The obligations that are meant to outlive it, confidentiality and deletion among them, survive it.
Contact
Complete Web Resources LLC, Austin, Texas, United States.
[email protected]