고객 지원 문의

이메일로 답장드리며, 보통 이틀 안에 회신합니다.

Google reCAPTCHA가 이 제출을 악용 여부에 대해 확인하며, 이 과정에서 데이터가 Google로 전송됩니다. 스크립트는 이 양식을 열 때만 불러옵니다.

← 전체 글

New privacy policy, terms and DPA

As of 19 August 2026, stats4u.net has three legal documents where it used to have one: a rewritten privacy policy, a terms of service, and — new — a data processing agreement (DPA) under Article 28 of the GDPR.

Why a DPA specifically

A counter on a site that collects any personal data of its own, with visitors in the EU, makes the site operator the controller and Stats4U a processor acting on the operator's instructions — that relationship needs a written contract, not a paragraph inside a privacy policy. Article 28(9) requires it in writing, electronic form included, which is why the page itself asks for a copy to be saved: a DPA that changes with no record of which version was agreed to is worse than not having one.

What the pages actually promise

The facts table on the privacy page is generated from the same configuration the nightly cleanup job reads, not typed out separately: a daily hash gets deleted after 2 days, page-and-referrer aggregates after 400, and the raw server access log — the one place a full IP address is written at all, since this system's own database never stores one — rotates after 14. If those numbers change, the page changes with them; there is no separate copy of the truth to forget to update.

Three languages, not eleven

The interface runs in eleven languages. These three documents run in three: German, English, and Polish. The other eight fall back to English, with a notice above the text saying so — and English is named as the governing version for those readers too. A liability clause nobody has actually checked against the local wording it was translated into is not a safer position than one plain version everybody is told to expect.

daily hash2raw server access log14page and referrer aggregates400the table on the privacy page is generated from the same configuration the nightly cleanup reads

What the terms don't try to do

They don't claim to exclude liability entirely. Under Polish civil code, a clause disclaiming liability for willful misconduct is void outright (Art. 473 §2 k.c.), and GDPR Article 82 doesn't let any contract sign away a data subject's own rights against a controller. A clause that reaches further than the law allows isn't a stronger protection — it's an unenforceable one, and it puts the rest of the document at risk along with it. So every liability clause here carries that carve-out on purpose, and the real protection sits elsewhere: in who is the controller and who is the processor, and in the indemnification terms both documents spell out.

None of this is new obligation dressed up as an announcement. It's the paperwork this site should already have had, written down, dated, and kept where the nightly job that enforces it can be checked against it.

광고