1) Scope
This policy explains how we handle personal data for:
- Visitors to hymetry.com and related public pages, where we act as a controller.
- Account holders and authorized users of the Hymetry application or dashboard, including our own in-app product analytics and screen/session recording, where we act as a controller.
- End users whose product activity and screen/session recordings are captured through a customer’s Hymetry integration, where the customer is the controller and Hymetry is the processor / service provider under the DPA.
If anything here conflicts with a customer contract, the DPA and Terms of Use control.
2) Roles and responsibility
For Customer Data, Customer is the controller and determines what data to collect and send, the purposes and lawful basis for processing, retention, and the instructions given to Hymetry. Hymetry is the processor and processes Customer Data only on Customer’s documented instructions under the DPA.
Customer is solely responsible for deciding what company and user data to send to Hymetry and for ensuring that its collection and disclosure are lawful, accurate, necessary, and supported by all required notices and consents. For core identification, the minimum Customer-provided fields required for account-centric analytics are a stable company/account ID and a stable user ID. Names, email addresses, company names, and any additional company or user attributes or other information are optional unless a specific feature clearly states otherwise, and are sent and stored only at Customer’s choice and instruction. This allocation does not limit Hymetry’s confidentiality, security, subprocessor, assistance, and deletion obligations under the DPA.
For our public website, account records, and our own Hymetry app usage data, Hymetry is the controller. We use Umami Cloud for public website analytics. Within the authenticated Hymetry app, we use Hymetry’s own first-party product analytics and screen/session recording to understand how authorized users use the app and to operate, support, secure, troubleshoot, and improve it. This in-app usage data is stored at rest on Linode (Akamai) infrastructure and is not sold or disclosed to third parties for their own independent purposes. Any Customer Data transmitted to or displayed within the Hymetry app remains Customer Data and is processed under the DPA.
3) What we collect
A. When we are the controller (public site, account, and Hymetry app usage)
- Account and profile: name, email, password hash, role, team/project associations.
- Public website analytics: Umami Cloud measures page views and general usage patterns, including referrer, browser, operating system, device type, and country-level location.
- Hymetry app product analytics and screen/session recordings: when authorized users use the Hymetry app, we record product-usage events and screen/session recordings of their interactions with the Hymetry interface, including navigation, clicks, timestamps, session identifiers, device/browser metadata, and interface content visible during a recording.
- Service records: login timestamps, plan/credits balance, support tickets, and limited operational telemetry such as error logs.
- Transactional communications: necessary service emails via Postmark (ActiveCampaign, LLC).
- Payment/billing (if/when enabled): payer details and transaction metadata from our processor; we do not store full card numbers.
- Device/network: IP address, browser/OS, pages viewed, referrer, server/CDN logs, and country-level geolocation derived from IP for security and sanctions/geo-restriction enforcement.
- Cookies/local storage: see Section 7.
B. When we are the processor (Customer Data)
- Minimum Customer-provided identifiers: a stable company/account ID and a stable user ID. These are the minimum identity fields required for Hymetry’s account-centric analytics.
- Product analytics and recording data: product-interaction events such as clicks and scrolls, viewport, page URLs/titles, timestamps, device/browser metadata, session identifiers, and video/image frames of the page; optional keystroke metadata, but not keystroke content, if enabled.
- Optional Customer-provided information: names, email addresses, company names, company or user attributes, and any other information beyond the required identifiers are provided only if Customer chooses and instructs Hymetry to store and process them.
- Sensitive data is not intended: customers must configure masking/suppression to prevent capture (see Section 4).
4) Prohibited or sensitive data
Our Service is not intended to collect, and customers must not intentionally collect:
- Special categories of personal data (e.g., health/PHI, biometric templates, sexual orientation, political/religious beliefs, trade-union membership).
- Government IDs, financial/PCI data, passwords or authentication secrets, precise geolocation of minors, or children's data without required verifiable consent.
Customers must configure masking/suppression and avoid placing the snippet on pages that display such data.
5) Why we use data (purposes) and legal bases
As controller (public site, account, and Hymetry app usage)
We process data to:
- Provide the Service (create/manage accounts, authenticate, show credit balance, send transactional emails).
- Measure and improve our public website through Umami Cloud analytics.
- Operate, support, secure, troubleshoot, and improve the Hymetry app using our own first-party product analytics and screen/session recordings.
- Compliance and enforcement (including sanctions/export-control and eligibility rules).
- Comply with law (tax, accounting, legal requests).
Legal bases (EEA/UK): performance of a contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) in operating and securing our Service and enforcing eligibility; and legal obligation (Art. 6(1)(c)). Where required, we will seek consent for optional cookies.
As processor (Customer Data)
We process solely to provide the Service under the customer's instructions and DPA.
8) International transfers
Data may be processed in the United States and other countries where our providers operate. For EEA/UK personal data, transfers rely on the EU SCCs (Controller→Processor, Module 2) and the UK Addendum incorporated into our DPA.
9) Security
We maintain reasonable technical and organizational measures (TLS in transit; access controls/least privilege; MFA for admin access; logging/monitoring; vulnerability management; backups and recovery; incident response). No method is 100% secure.
10) Retention
- Recordings and raw events (processor role): default 30 days, then scheduled deletion; backups per standard cycles.
- Aggregated analytics derived from recordings: 30 days.
- Hymetry app product analytics and screen/session recordings (controller role): screen/session recordings are retained for up to 30 days, then scheduled for deletion; related product analytics are kept only as long as reasonably necessary to operate, support, secure, troubleshoot, and improve the Service, subject to periodic review.
- Account and service records (controller role): kept for the account lifetime and then a reasonable period (typically up to 24 months) for security, audit, and legal purposes.
- Compliance logs (sanctions/geo-restriction): up to 24 months (or longer if required by law).
- Support communications: typically 24 months.
We may retain data longer if required by law or to resolve disputes. Self-service export is not currently available.
11) Your privacy rights
If you are a public-site visitor or Hymetry app user (we are the controller)
Subject to law, you may have rights to access, correct, delete, restrict, port, or object. Contact [email protected].
If your activity is analyzed or recorded through a customer’s product (we are the processor)
Please contact that customer (the website/app where the recording occurred). We will support the customer's response under the DPA.
California (CPRA) notice
We act as a service provider to customers for Customer Data. For our own public-site, account, and Hymetry app usage data, you may have rights to know, delete, and correct; we do not sell or share personal information for cross-context behavioral advertising; and we use sensitive personal information only for permitted service purposes. Submit requests to [email protected].
12) Children
Our Service is not directed to children, and customers must not use it to record users known to be children without meeting all legal requirements (e.g., verifiable parental consent). We do not knowingly collect personal data from children as a controller.
13) Third-party links
Our site may link to third-party sites or services we do not control. Their privacy practices govern those properties.
14) Changes to this policy
We may update this policy from time to time. We will post the new version with a new “Last updated” date and, if changes are material, provide additional notice. Continued use means you accept the updated policy.
15) Contact us
Questions, requests, or complaints: [email protected]. You may also lodge a complaint with your local data protection authority.
Data Processing Addendum (DPA)
Effective date: 10 July 2026
Parties: (1) Customer (controller) and (2) PE Artem Syzonenko, trading as Hymetry (processor).
Contact (processor): [email protected]
1. Scope and roles
1.1 This DPA applies to Hymetry's processing of Customer Data (as defined in the Terms of Use) that includes personal data subject to Applicable Data Protection Laws (e.g., GDPR, UK GDPR, CCPA/CPRA).
1.2 For such personal data, Customer is the controller, and Hymetry is the processor (EU/UK) and service provider (California).
1.3 The Terms of Use (the “Agreement”) remain in force. This DPA prevails over conflicting terms solely for processing of personal data.
2. Customer instructions
2.1 Hymetry will process personal data only on documented instructions from Customer: (a) to provide, secure, and support the Service; (b) as configured or initiated by Customer via the Service; and (c) as required by law.
2.2 If an instruction violates applicable law, Hymetry will notify Customer (unless legally prohibited).
2.3 Sanctions carve-out. Notwithstanding any instruction, Hymetry may decline or suspend processing that would reasonably cause a violation of EU/UK/U.S./UN/Ukraine sanctions or export-control laws, and will notify Customer where legally permitted.
3. Confidentiality
Hymetry ensures personnel with access to personal data are bound by confidentiality obligations.
4. Security measures
Hymetry maintains reasonable technical and organizational measures appropriate to risk, including: encryption in transit (TLS), access control/least privilege, authentication (including MFA for administrative access), network segmentation, logging and monitoring, vulnerability management, secure development practices and reviews, backups and recovery procedures, and incident response processes. Details appear in Annex II.
5. Personal data breaches
Upon becoming aware of a personal data breach affecting Customer Data, Hymetry will notify Customer without undue delay and in any event within 72 hours, and provide information reasonably available to assist Customer in meeting its obligations.
6. Subprocessors
6.1 Customer authorizes Hymetry to engage subprocessors to deliver the Service, subject to written contracts imposing data-protection obligations no less protective than this DPA. Current core subprocessors are listed in Annex III.
6.2 Hymetry will provide 30 days' prior notice before adding a materially new subprocessor. If Customer reasonably objects, Customer may terminate the affected Service before the change takes effect.
7. International transfers
7.1 EU/EEA: Where Hymetry processes personal data subject to GDPR on behalf of Customer and a restricted transfer occurs, the EU Standard Contractual Clauses (SCCs) - Controller→Processor, Module 2 - are incorporated by reference between Customer (data exporter) and Hymetry (data importer). Annex I/II/III of the SCCs are completed by the Annexes to this DPA.
7.2 UK: For UK GDPR, the UK Addendum to the EU SCCs is incorporated with tables completed in Annex I-UK.
7.3 If another transfer mechanism becomes applicable, the parties may adopt it.
8. Assistance
Hymetry will provide reasonable assistance (taking into account the nature of processing and information available) with: (a) data subject requests; (b) security, breach notifications; (c) data-protection impact assessments and prior consultations, to the extent required by law and proportionate to the Service.
9. Audits and information
Upon written request (no more than annually and subject to confidentiality), Hymetry will provide information reasonably necessary to demonstrate compliance (e.g., policy summaries). On-site audits occur only where required by law, upon reasonable notice, limited to relevant controls, and at Customer's expense.
10. Return and deletion
At termination of the Agreement (or upon Customer's written request), Hymetry will delete personal data within the timelines in the Agreement and this DPA. Self-service export is not currently provided. Backups are deleted per standard cycles.
11. California (CPRA) service provider terms
For California “personal information,” Hymetry: (a) acts as a service provider; (b) processes solely to provide, secure, and support the Service for Customer in accordance with Customer’s documented instructions, not for any other purpose; (c) does not sell or share personal information; (d) will not combine personal information with data from other sources except as permitted by CPRA; (e) will assist Customer with consumer requests as required; (f) will notify Customer if it can no longer meet its obligations; and (g) grants Customer the right to take reasonable and appropriate steps, including requesting information or audits, to ensure Hymetry's CPRA compliance.
12. Liability and precedence
The parties' respective liability and limitations are governed by the Agreement. In the event of conflict, this DPA controls for processing of personal data.
13. Customer responsibilities (summary reminder)
Customer is solely responsible for: (a) deciding what Customer Data, including company and user data, to collect and send to Hymetry; (b) ensuring a lawful basis and providing all required notices and consents; (c) the accuracy, necessity, and content of that data; and (d) correctly configuring masking, suppression, and exclusions. For core identification, the minimum Customer-provided fields required for Hymetry’s account-centric analytics are a stable company/account ID and a stable user ID. Names, email addresses, company names, and any additional company or user attributes or other information are optional and are processed only because Customer chooses to provide them and instructs Hymetry to store and process them. Hymetry remains responsible for the processor obligations assigned to it under this DPA. The Service is not intended to record children absent verifiable consent and full compliance with applicable law.
14. Term
This DPA becomes effective on the Effective date above and remains in force for as long as Hymetry processes personal data for Customer under the Agreement.
Annex I - Description of processing (SCCs Annex I, Sec. A and B)
A. Parties
Exporter (controller): Customer (contact: as provided in Customer's account)
Importer (processor): PE Artem Syzonenko (Hymetry), 149/100 Kalynova Str., Dnipro, Ukraine; contact: [email protected]
B. Description
- Subject matter: Provision of account-centric product analytics and screen/session recording services for Customer’s websites and apps.
- Duration: Term of the Agreement; standard retention 30 days for recordings/events; backups per cycles.
- Nature and Purpose: Collection and processing of stable company/account IDs and user IDs, product-interaction events, screen/session recording frames, diagnostics, metrics, optional Customer-provided attributes and metadata, and derived analytics to provide, maintain, secure, and support the Service for Customer in accordance with Customer’s documented instructions.
- Categories of data subjects: End users of Customer’s sites/apps, including Customer personnel when they use those sites/apps.
- Categories of personal data: Stable company/account IDs and user IDs (minimum Customer-provided identity fields); optional names, email addresses, company names, company or user attributes, and metadata; interaction events such as clicks and scrolls; page URLs/titles; timestamps; device/browser metadata; IP-address-derived data; session identifiers; optional keystroke metadata, but not keystroke content; and screen/session recording frame data if enabled. Not intended to collect special-category or other prohibited data; Customer must configure masking/suppression accordingly.
- Sensitive data: Not intended / contractually prohibited.
- Frequency: Continuous as initiated by Customer's integration/configuration.
- Retention/erasure: As per Section 10 and Agreement (default 30 days).
- Competent Supervisory Authority (EU): Exporter's lead supervisory authority where applicable.
C. Authorized subprocessors: See Annex III.
Annex II - Technical and organizational measures (SCCs Annex II)
Information security program
- Governance and risk: Documented security policies; periodic risk assessment; least-privilege access model.
- Access control: Unique accounts; MFA for administrative access; role-based permissions; session timeouts; logging of privileged actions.
- Physical and network: Provider data centers (Linode/Cloudflare); network segmentation; DDoS protections via CDN; firewalls; secure remote access.
- Encryption: TLS for data in transit; encryption at rest where supported by underlying services; key management per provider capabilities.
- Application security: Secure SDLC, code review, dependency scanning, vulnerability management and patching.
- Monitoring and logging: Centralized logs, anomaly detection, alerting.
- Backup and recovery: Regular backups; restore testing; geo-redundancy per provider services.
- Incident response: Documented plan; investigation, containment, eradication, recovery; post-incident review.
- Personnel: Background/eligibility checks where lawful, confidentiality agreements, security training.
- Data minimization and masking: Controls for field suppression/masking; configuration guidance to prevent capture of sensitive fields.
- Supplier management: Subprocessor due diligence and contractual controls.
- Business continuity: Redundancy and recovery procedures proportionate to scale.
Annex III - Subprocessors
- Linode (Akamai) - US: application hosting, compute, databases, and persistent Customer Data storage, including product analytics events and screen/session recordings
- Cloudflare, Inc. - Global: CDN, WAF, DDoS mitigation, proxy caching
- Postmark (ActiveCampaign, LLC) - US: transactional email delivery
Annex I-UK - UK Addendum tables (summary)
- Table 1 (Parties): Exporter = Customer; Importer = PE Artem Syzonenko (Hymetry), contact [email protected]
- Table 2 (Selected SCCs): EU SCCs (Controller→Processor, Module 2)
- Table 3 (Annexes): Annex I/II/III as above
- Table 4 (Ending): Neither party may vary the Addendum beyond permitted formatting; governing law for SCCs = Ireland (for interpretation of EU SCCs)
Acceptance and countersignature
Click-through acceptance: This DPA applies automatically under the Terms.
Countersigned PDF: If needed, email [email protected] for a signable PDF (Customer → Company name, signatory, title, date; Hymetry → PE Artem Syzonenko, proprietor).