Data Processing Addendum
Last updated: July 18, 2026
This Data Processing Addendum (“DPA”) supplements the Terms of Service between you (“Customer”) and SiteDocket LLC (“SiteDocket”) and applies where, in your use of the Service, we process personal data on your behalf that is subject to data-protection laws such as the EU/UK GDPR or the CCPA/CPRA. If you require a signed copy, contact privacy@sitedocket.com.
1. Roles
As between the parties, Customer is the controller (or business) and SiteDocket is the processor (or service provider) of personal data contained in Customer Data. SiteDocket processes such personal data only to provide the Service and on Customer’s documented instructions, including as set out in the Terms and this DPA.
2. Scope of Processing
- Subject matter: provision of the SiteDocket website-audit service.
- Duration: for the term of the Customer’s subscription, plus deletion periods below.
- Nature and purpose: hosting, auditing, crawling, monitoring, reporting, AI-assisted analysis, and support.
- Types of data: account and contact details, website/audit data, connected-account data, and usage data.
- Data subjects: Customer’s authorized users and individuals whose data may appear in audited sites or connected accounts.
3. Confidentiality
SiteDocket ensures that personnel authorized to process personal data are bound by confidentiality obligations.
4. Security
SiteDocket implements appropriate technical and organizational measures to protect personal data, including encryption in transit, access controls, and monitoring, taking into account the state of the art and the risks of processing.
5. Subprocessors
Customer authorizes SiteDocket to engage subprocessors to provide the Service. Current subprocessors include Stripe (payments), Anthropic (AI analysis), Google (Search Console integration), DigitalOcean (hosting), and our email delivery provider. SiteDocket imposes data-protection obligations on subprocessors substantially similar to those in this DPA and remains responsible for their performance. We will give reasonable notice of new subprocessors, and you may object on reasonable data-protection grounds.
6. Data Subject Requests
Taking into account the nature of the processing, SiteDocket will assist Customer by appropriate measures, insofar as possible, in responding to requests from data subjects to exercise their rights.
7. Personal Data Breach
SiteDocket will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Data, and will provide information reasonably available to assist Customer in meeting its notification obligations.
8. Deletion and Return
On termination of the Service, SiteDocket will delete or return Customer’s personal data within a reasonable period, except where retention is required by law. See the retention section of our Privacy Policy.
9. Audits
SiteDocket will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to reasonable audits, subject to confidentiality and reasonable scheduling.
10. International Transfers
Where personal data is transferred across borders, SiteDocket relies on appropriate safeguards, such as the Standard Contractual Clauses, where required.
11. Liability
Each party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service.
12. Contact
Data-protection questions: privacy@sitedocket.com.