Skip to content

Trust and compliance

Who processes data on our behalf, what they receive, and how long anything is kept. If you are evaluating SiteAssay for an agency with GDPR or DPDP obligations, this page and the documents below are what your data protection officer needs.

Sub-processors

Every third party that touches customer or prospect data. Nothing here is used to train anybody's models, and we buy no contact data from brokers.

Processor Purpose Data Processed in
Paddle Payment processing, as merchant of record Customer name, email address, billing address, payment method United Kingdom, European Union
OVHcloud Application hosting, and the Postgres and Redis instances that run beside it All customer and prospect data at rest European Union
Cloudflare R2 Object storage for generated reports, PDFs, social cards and uploaded media Generated reports, uploaded assets and site screenshots European Union
Brevo Transactional email: password resets, receipts, invitations and product notifications Customer name, email address and the contents of those messages European Union
Anthropic Drafting outreach copy and summarising audit findings Audit findings and the public business details of the prospect being written to United States
Google PageSpeed Insights performance measurement, business discovery, and the map tiles drawn behind a local grid Prospect website URLs, the search terms and locations a customer searches for, and the map area a grid is drawn over United States
Cloudflare CDN, DNS, Turnstile bot protection and cookieless page-view analytics on the public site Visitor IP address and request metadata Global edge network
Sentry Error monitoring Stack traces, request metadata and the acting user id European Union
PostHog Product analytics for activity that belongs to a customer workspace Workspace and user identifiers, feature usage events, and the website domains those events concern United States

How long we keep things

Each of these is enforced by the application rather than by a policy somebody remembers to apply.

Data Kept for Notes
Customer account and workspace Life of the account Deleted within 30 days of the workspace being closed.
Prospects, audits, scores and reports Until deleted Held while the customer's workspace holds them, and deleted with it.
Anonymous public scans (free audit tool) 30 days A scan carries a third party's audit and, past the email gate, someone's address. Neither is held indefinitely.
Suppression list (unsubscribes, complaints, bounces) Indefinite The deliberate exception: forgetting that somebody opted out is how they get contacted again.
Usage ledger and invoices 7 years Statutory retention for financial records.
Console and workspace activity log 365 days Who did what, including every operator action taken on a workspace.
Application and error logs 90 days Rotated automatically; not used for anything but operating the service.
Infrastructure health checks 30 days Whether our own dependencies were reachable. Contains no customer data of any kind.
Scheduled task runs 30 days Whether our own background work ran. Contains no customer data of any kind.
Transactional email records 90 days Recipient, subject and whether the transport accepted it. Never the message body, which would put reset links in a table an operator browses.
API usage counts and errors 30 days Per-day request counts per workspace, and the failures with the endpoint that produced them. No request or response bodies.
Payment and integration webhooks 90 days What our payment provider and sending provider told us, kept so a charge that did not apply can be applied.

Exercising a right, or asking a question

Access, correction, erasure and suppression requests, whether you are a customer or a business that has been researched or contacted through SiteAssay, go to hello@siteassay.com. We act on them within 30 days and pass the request to the customer whose workspace holds the record. The privacy policy covers what is collected and why; the terms cover acceptable use of outreach.

Send this page to your DPO

Then start on the free plan. The compliance questions are answered above; the product question takes one run to answer.