Trust and compliance
Who processes data on our behalf, what they receive, and how long anything is kept. If you are evaluating SiteAssay for an agency with GDPR or DPDP obligations, this page and the documents below are what your data protection officer needs.
Data processing agreement
The processing terms, the roles, the transfer mechanism and the security schedule. What your DPO signs.
Effective
Read itSub-processors
Who else touches the data, what each one receives, and where it is processed. The table below, as a document.
Effective
Read itSecurity overview
How the service is built and operated: access control, encryption, isolation between workspaces, and how incidents are handled.
Effective
Read itSub-processors
Every third party that touches customer or prospect data. Nothing here is used to train anybody's models, and we buy no contact data from brokers.
| Processor | Purpose | Data | Processed in |
|---|---|---|---|
| Paddle | Payment processing, as merchant of record | Customer name, email address, billing address, payment method | United Kingdom, European Union |
| OVHcloud | Application hosting, and the Postgres and Redis instances that run beside it | All customer and prospect data at rest | European Union |
| Cloudflare R2 | Object storage for generated reports, PDFs, social cards and uploaded media | Generated reports, uploaded assets and site screenshots | European Union |
| Brevo | Transactional email: password resets, receipts, invitations and product notifications | Customer name, email address and the contents of those messages | European Union |
| Anthropic | Drafting outreach copy and summarising audit findings | Audit findings and the public business details of the prospect being written to | United States |
| PageSpeed Insights performance measurement, business discovery, and the map tiles drawn behind a local grid | Prospect website URLs, the search terms and locations a customer searches for, and the map area a grid is drawn over | United States | |
| Cloudflare | CDN, DNS, Turnstile bot protection and cookieless page-view analytics on the public site | Visitor IP address and request metadata | Global edge network |
| Sentry | Error monitoring | Stack traces, request metadata and the acting user id | European Union |
| PostHog | Product analytics for activity that belongs to a customer workspace | Workspace and user identifiers, feature usage events, and the website domains those events concern | United States |
How long we keep things
Each of these is enforced by the application rather than by a policy somebody remembers to apply.
| Data | Kept for | Notes |
|---|---|---|
| Customer account and workspace | Life of the account | Deleted within 30 days of the workspace being closed. |
| Prospects, audits, scores and reports | Until deleted | Held while the customer's workspace holds them, and deleted with it. |
| Anonymous public scans (free audit tool) | 30 days | A scan carries a third party's audit and, past the email gate, someone's address. Neither is held indefinitely. |
| Suppression list (unsubscribes, complaints, bounces) | Indefinite | The deliberate exception: forgetting that somebody opted out is how they get contacted again. |
| Usage ledger and invoices | 7 years | Statutory retention for financial records. |
| Console and workspace activity log | 365 days | Who did what, including every operator action taken on a workspace. |
| Application and error logs | 90 days | Rotated automatically; not used for anything but operating the service. |
| Infrastructure health checks | 30 days | Whether our own dependencies were reachable. Contains no customer data of any kind. |
| Scheduled task runs | 30 days | Whether our own background work ran. Contains no customer data of any kind. |
| Transactional email records | 90 days | Recipient, subject and whether the transport accepted it. Never the message body, which would put reset links in a table an operator browses. |
| API usage counts and errors | 30 days | Per-day request counts per workspace, and the failures with the endpoint that produced them. No request or response bodies. |
| Payment and integration webhooks | 90 days | What our payment provider and sending provider told us, kept so a charge that did not apply can be applied. |
Exercising a right, or asking a question
Access, correction, erasure and suppression requests, whether you are a customer or a business that has been researched or contacted through SiteAssay, go to hello@siteassay.com. We act on them within 30 days and pass the request to the customer whose workspace holds the record. The privacy policy covers what is collected and why; the terms cover acceptable use of outreach.
Send this page to your DPO
Then start on the free plan. The compliance questions are answered above; the product question takes one run to answer.