Data processing agreement
Effective .
Last updated 1 August 2026.
This agreement forms part of the terms of service and applies whenever a customer's use of SiteAssay involves the processing of personal data. It needs no signature to take effect: creating a workspace accepts it, and it is versioned here so you can show your auditor exactly which text applied on a given date. If your procurement process requires a counter-signed copy, write to hello@siteassay.com and we will sign this text.
Terms used here (controller, processor, data subject, personal data, processing, supervisory authority) carry the meanings given to them in the UK GDPR and EU GDPR, and their equivalents under India's Digital Personal Data Protection Act, 2023.
Who is the controller
For the prospect records, contacts and outreach in a workspace, the customer is the controller and we are the processor. You decide which businesses to research, which to contact, and what to say to them. We provide the machinery.
For the customer's own account data, meaning the name, email address and billing record of the people who hold a login, we are the controller, and the privacy policy governs it.
For the data we collect from public sources before it is attributed to any workspace, we act as controller, and we become your processor for the copy held in your workspace.
Subject matter, duration, nature and purpose
We process personal data for as long as your workspace exists, in order to provide the service: discovering businesses from public sources, measuring their websites, scoring and reporting on those measurements, and drafting, sending and tracking outreach you approve.
The categories of data subject are the owners, staff and published contacts of the businesses in your workspace, and the people you invite into it. The categories of personal data are business contact details (name, role, business email address, business telephone number, public social profiles, business address) and the metadata of messages sent to them.
We do not process special-category data, and the product is not designed to profile individuals: it profiles websites.
Our instructions
We process personal data only on your documented instructions, which for these purposes means: your use of the product's features, the configuration of your workspace, and any written instruction you send us. We will tell you if an instruction appears to us to breach data-protection law, and we may decline to act on it.
If we are required by law to process personal data other than on your instructions, we will tell you before doing so unless that law forbids it.
Confidentiality and security
Everyone with access to personal data in your workspace is bound by a duty of confidence. Access by our staff is limited to what is required to operate the service or to help you with a problem you have raised, and every such access is written to an audit trail you can be shown.
The technical and organisational measures we maintain are described in the security overview, which forms part of this agreement. We may change them, provided the level of protection is not reduced.
Sub-processors
You give general authorisation for us to engage sub-processors. The current list, what each receives and where it processes it, is published on the trust page, and the notification and objection process is set out in the sub-processor document.
Each sub-processor is engaged under a written contract that imposes obligations no less protective than these, and we remain liable to you for their performance.
International transfers
Personal data is stored in the European Union. Where a sub-processor processes data outside the UK, EU or India, the transfer relies on the EU standard contractual clauses, the UK international data transfer addendum where the UK GDPR applies, and a transfer risk assessment we maintain and will share on request.
Assisting you
Taking account of the nature of the processing and the information available to us, we will assist you:
to respond to a data subject exercising a right of access, rectification, erasure, restriction, portability or objection, and where a request reaches us directly about data in your workspace, we will pass it to you rather than answer it ourselves, unless the law requires otherwise;
to meet your obligations to keep processing secure, to notify a personal data breach, and to carry out a data protection impact assessment or prior consultation.
Personal data breaches
We will notify you without undue delay, and in any case within 48 hours of becoming aware, of any personal data breach affecting personal data processed on your behalf. The notice will describe what happened, the categories and approximate number of records concerned, the likely consequences, and the measures taken.
Deletion and return
You can export or delete the data in your workspace at any time from within the product. On termination we delete personal data processed on your behalf within 30 days, except:
backups, which age out on their own retention cycle and are not restored selectively;
suppression records, meaning the addresses that have unsubscribed, complained or hard-bounced, which we keep indefinitely and in minimised form, because forgetting that somebody asked not to be contacted is precisely how they get contacted again;
anything we are required by law to retain, including financial records.
Audits
We will make available the information reasonably necessary to demonstrate compliance with this agreement, and will contribute to audits conducted by you or an auditor you mandate. Audits are once per year unless a supervisory authority requires otherwise or a breach has occurred, must be at reasonable notice, must not disrupt the service, and are subject to confidentiality.
India: DPDP
Where the Digital Personal Data Protection Act, 2023 applies, the customer is the Data Fiduciary and we are a Data Processor engaged under this agreement. Our obligations under it, which are to process only on your instructions, to maintain reasonable security safeguards, to assist with the rights of Data Principals, to notify you of a personal data breach, and to erase on termination, apply equally under that Act.
Order of precedence
Where this agreement conflicts with the terms of service, this agreement prevails on matters of data protection. Where it conflicts with a signed agreement between us, that agreement prevails.