Contact support

We reply by e-mail, usually within two days.

Google reCAPTCHA checks this submission against abuse; data is sent to Google. The script loads only once you open this form.

← All posts

Privacy, terms, and a data processing agreement

As of 19 August 2026, stats4u.net has three legal documents where it used to have one: a rewritten privacy policy, a terms of service, and — new — a data processing agreement (DPA) under Article 28 of the GDPR.

Why a DPA specifically

If you run a counter on a site that collects any personal data of its own, and your visitors are in the EU, you are the controller and Stats4U is a processor acting on your instructions — that relationship needs a written contract, not a paragraph inside a privacy policy. Article 28(9) requires it in writing, electronic form included, which is why the page itself asks you to save a copy: a DPA that changes without you having a record of which version you agreed to is worse than not having one.

What the pages actually promise

The facts table on the privacy page is generated from the same configuration the nightly cleanup job reads, not typed out separately: a daily hash gets deleted after 2 days, page-and-referrer aggregates after 400, and the raw server access log — the one place a full IP address is written at all, since this system's own database never stores one — rotates after 14. If those numbers change, the page changes with them; there is no separate copy of the truth to forget to update.

Three languages, not eleven

The interface runs in eleven languages. These three documents run in three: German, English, and Polish. The other eight fall back to English, with a notice above the text saying so — and English is named as the governing version for those readers too. A liability clause nobody has actually checked against the local wording it was translated into is not a safer position than one plain version everybody is told to expect.

What the terms don't try to do

They don't claim to exclude liability entirely. Under Polish civil code, a clause disclaiming liability for willful misconduct is void outright (Art. 473 §2 k.c.), and GDPR Article 82 doesn't let any contract sign away a data subject's own rights against a controller. A clause that reaches further than the law allows isn't a stronger protection — it's an unenforceable one, and it puts the rest of the document at risk along with it. So every liability clause here carries that carve-out on purpose, and the real protection sits elsewhere: in who is the controller and who is the processor, and in the indemnification terms both documents spell out.

None of this is new obligation dressed up as an announcement. It's the paperwork this site should already have had, written down, dated, and kept where the nightly job that enforces it can be checked against it.