Data Flows and Processing
As of: May 2026 · Annex to the DPA
This document describes the data flows within the Tugus platform. It serves as an annex to the Data Processing Agreement (DPA) pursuant to Art. 28 GDPR.
1. Overview
Tugus acts as a processor within the meaning of Art. 28 GDPR. The platform receives event data from our customers' websites, processes this data, and forwards it, at the customer's instruction, to the marketing platforms configured by the customer.
2. Phase 1 - Data Collection on the Customer's Website
The Tugus tracking script is loaded by the customer's online store. The following data is collected in the end user's browser:
- Identifiers: Anonymous client ID, session ID, and optionally a custom client ID defined by the customer
- Page context: URL, referrer, title, language
- UTM parameters: Source, Medium, Campaign, Term, Content
- Click IDs: Platform-specific identifiers (fbclid, gclid, ttclid, msclkid) — for attribution without cookies
- Event data: Event name (pageview, add_to_cart, purchase, etc.) and event-specific properties (e.g. order value, currency, product IDs)
- User data (optional, only with consent): Email address, telephone number, name — hashed before transmission
- Consent signals: Granular flags according to Google Consent Mode v2
3. Phase 2 - Transmission to Tugus
Encrypted HTTPS transmission to our collector endpoint
Server location: Germany (Netcup, Nuremberg)No transfer to third countries during this phase
4. Phase 3 - Processing in the Tugus Backend
4.1 Validation and Normalization
Incoming event data is checked for schema compliance and normalized to a standardized canonical schema. Duplicate events are identified and filtered based on a deterministic event ID (e.g. order_id + event_name).
4.2 PII Hashing
Personal data used for identification purposes when transmitted to marketing platforms is cryptographically hashed server-side before being stored:
- Email addresses
- Telephone numbers (following E.164 normalization)
- First and last names
- External customer IDs
Exception: The email address of the Tugus account holder (not the end user) is stored in plain text for the purpose of contract fulfillment.
4.3 Storage
- Event data is stored exclusively on servers located in Germany
- Retention period depends on the subscribed plan: 6 to 24 months
- After the retention period expires: automatic deletion
5. Phase 4 - Forwarding to Marketing Platforms
5.1 Trigger
Data forwarding takes place asynchronously through an internal processing pipeline. A delivery process is created for each event and enabled integration.
5.2 Consent Gate
Before any data is forwarded, Tugus checks the consent flags associated with the event:
- Without marketing consent: Only click IDs are transmitted (modeled conversions); no personal data is transmitted
- With marketing consent: Full data transmission in accordance with the respective platform API specification
- Without analytics consent: Google Analytics 4 receives only cookieless pings for statistical conversion modeling (Google Consent Mode v2)
5.3 Categories of Data Transmitted
Depending on the platform and customer configuration, the following categories may be transmitted:
- Identifiers (hashed): Email address, telephone number, name
- Platform identifiers: Click IDs, Facebook Browser Pixel ID, cookie IDs
- Event metadata: Event name, timestamp, order data (for purchase events)
- Technical context data: IP address, user agent, page URL, referrer
- Consent signals: Granular consent flags
5.4 Platform Locations
See the Subprocessor List for details regarding the locations and legal bases applicable to all marketing platforms.
6. Phase 5 - Postbacks (Optional)
If the customer has configured postback URLs, defined events are additionally sent to the configured URLs (e.g. for affiliate networks). The data transmitted and the recipients are fully configured by the customer.
7. Data Subject Rights
As Tugus acts as a processor, the customer (online store operator) is the controller responsible for the data of end users. Requests from end users (access, deletion, etc.) must be directed to the customer.
Tugus supports the customer in processing such requests through:
- Searching for events associated with a specific client ID or hashed email address in the dashboard
- Data export upon request
- Deletion of individual events or all events associated with a property upon request