Skip to main content

Data Processing Agreement (DPA)

Effective Date: May 11, 2026

1. Introduction

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Websyt ("Processor," "we," "us," or "our") and the customer ("Controller," "you," or "your") and governs the processing of personal data by Websyt on behalf of the Controller in connection with the provision of the Websyt website analysis platform (the "Services").

This DPA is effective as of the date you accept the Terms of Service and remains in effect for as long as Websyt processes personal data on your behalf.

2. Definitions

Capitalized terms used but not defined in this DPA have the meanings given in the Terms of Service. In this DPA:

  • "Personal Data" means any information relating to an identified or identifiable natural person processed by Websyt on behalf of the Controller under the Terms of Service.
  • "Processing" means any operation performed on Personal Data, whether or not by automated means, including collection, recording, organization, storage, alteration, retrieval, consultation, use, disclosure, transmission, erasure, or destruction.
  • "Sub-processor" means any third-party engaged by Websyt to process Personal Data on behalf of the Controller.
  • "Data Subject" means the identified or identifiable natural person to whom Personal Data relates.
  • "Applicable Data Protection Law" means all data protection and privacy laws applicable to the processing of Personal Data, including but not limited to the EU General Data Protection Regulation (GDPR), the UK GDPR, and the California Consumer Privacy Act (CCPA).

3. Scope and Purpose of Processing

Websyt processes Personal Data solely for the purpose of providing the Services as described in the Terms of Service and in accordance with the Controller's documented instructions. The processing activities include:

  • Analyzing website URLs provided by the Controller to generate SEO, performance, design, accessibility, security, and technical reports.
  • Storing analysis results, screenshots, and report data for the Controller's account.
  • Sending analysis reports and notifications to email addresses provided by the Controller.
  • Managing user accounts, authentication, and billing information necessary to provide the Services.

Categories of Data Subjects:The Controller's end users, website visitors, and authorized users of the Services.

Categories of Personal Data: Account information (name, email address), website URLs submitted for analysis, analysis results and reports, billing information, and technical data (IP addresses, browser information) collected during website analysis.

4. Controller Obligations

The Controller warrants and represents that:

  • It has a lawful basis for the processing of Personal Data as required by Applicable Data Protection Law.
  • It has provided all necessary notices and obtained all necessary consents from Data Subjects for the processing activities described in this DPA.
  • Its instructions to Websyt regarding the processing of Personal Data comply with Applicable Data Protection Law.
  • It is responsible for the accuracy, quality, and legality of the Personal Data provided to Websyt.

5. Processor Obligations

Websyt shall:

  • Process Personal Data only on documented instructions from the Controller, including with regard to transfers of Personal Data to a third country or international organization, unless required to do so by applicable law.
  • Ensure that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
  • Implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as detailed in Section 6 (Security Measures).
  • Assist the Controller in responding to Data Subject requests to exercise their rights under Applicable Data Protection Law, to the extent possible.
  • Assist the Controller in ensuring compliance with its obligations regarding security of processing, notification of personal data breaches, and data protection impact assessments.
  • Notify the Controller without undue delay upon becoming aware of a personal data breach affecting the Controller's Personal Data.
  • At the Controller's choice, delete or return all Personal Data to the Controller after the end of the provision of Services, and delete existing copies unless storage is required by applicable law.
  • Make available to the Controller all information necessary to demonstrate compliance with the obligations set out in this DPA and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller.

6. Security Measures

Websyt implements and maintains the following technical and organizational security measures:

  • Encryption: All Personal Data is encrypted at rest using AES-256 encryption and in transit using TLS 1.3.
  • Access Controls: Role-based access control (RBAC) with least-privilege principles. Multi-factor authentication is required for all administrative access.
  • Network Security: Firewalls, DDoS protection, and intrusion detection systems are deployed to protect infrastructure.
  • Monitoring & Logging: Continuous security monitoring with automated alerting for suspicious activity. Access logs are retained for a minimum of 90 days.
  • Vulnerability Management: Regular vulnerability scanning, penetration testing, and security patch management.
  • Business Continuity: Automated backups with geo-redundant storage, disaster recovery procedures, and documented incident response plans.
  • Personnel: All employees undergo background checks and complete annual security awareness training. Confidentiality agreements are signed by all personnel with access to Personal Data.

7. Sub-processors

The Controller provides general written authorization for Websyt to engage Sub-processors to process Personal Data. Websyt maintains an up-to-date list of Sub-processors and will notify the Controller of any intended changes concerning the addition or replacement of Sub-processors at least 14 days in advance.

Current Sub-processors and their processing activities:

Sub-processorPurposeData Location
Clerk, Inc.User authentication and identity managementUnited States
Stripe, Inc.Payment processing and subscription managementUnited States
Neon, Inc.Database hosting (PostgreSQL)United States
Resend, Inc.Transactional email deliveryUnited States
Anthropic PBCAI-powered analysis and fix generationUnited States
OpenAI, LLCAI-powered content and design analysisUnited States
Upstash, Inc.Redis caching and rate limitingGlobal
Bright Data Ltd.Web scraping infrastructureGlobal

Websyt will enter into written agreements with each Sub-processor containing data protection obligations no less protective than those in this DPA.

8. International Data Transfers

Personal Data may be transferred to and processed in countries outside the European Economic Area (EEA) or the United Kingdom. Websyt ensures that such transfers comply with Applicable Data Protection Law through the use of:

  • European Commission Standard Contractual Clauses (SCCs) with Sub-processors.
  • Adequacy decisions where applicable.
  • Binding Corporate Rules or other approved transfer mechanisms as required.

9. Data Subject Rights

Websyt will, to the extent legally permitted, promptly notify the Controller if it receives a request from a Data Subject to exercise their rights under Applicable Data Protection Law (including rights of access, rectification, erasure, restriction, portability, and objection). Websyt will not respond to such requests directly unless authorized by the Controller or required by law.

10. Audit Rights

Upon the Controller's written request and no more than once per calendar year (except in the event of a data breach or regulatory requirement), Websyt will make available to the Controller information necessary to demonstrate compliance with this DPA. Audits shall be:

  • Conducted during normal business hours.
  • At the Controller's sole expense.
  • Subject to reasonable advance notice of at least 30 days.
  • Conducted in a manner that minimizes disruption to Websyt's operations.

In lieu of an on-site audit, Websyt may provide the Controller with a summary of its most recent third-party security audit or certification report (e.g., SOC 2 Type II report), where available.

11. Data Retention and Deletion

Websyt retains Personal Data only for as long as necessary to provide the Services or as required by applicable law. Upon termination of the Services or at the Controller's written request:

  • Websyt will, at the Controller's election, delete or return all Personal Data within 30 days.
  • Websyt will certify the deletion of Personal Data in writing upon request.
  • Any Personal Data that must be retained for legal or regulatory compliance will be securely archived and not further processed.

12. Limitation of Liability

Each party's liability arising out of or related to this DPA shall be subject to the limitations of liability set forth in the Terms of Service. Notwithstanding the foregoing, nothing in this DPA limits either party's liability for:

  • Breach of its data protection and security obligations under this DPA.
  • Any processing of Personal Data outside the scope of this DPA.
  • Liability that cannot be limited or excluded under applicable law.

13. Term and Termination

This DPA shall remain in effect for as long as Websyt processes Personal Data on behalf of the Controller. Upon termination:

  • Websyt shall cease all processing of Personal Data, unless otherwise required by applicable law.
  • Websyt shall, at the Controller's election, securely delete or return all Personal Data within 30 days.
  • Provisions that by their nature should survive termination (including Sections 6, 11, and 12) shall continue in effect.

14. Governing Law

This DPA is governed by the laws specified in the Terms of Service. For data protection matters, the laws of the Controller's primary place of establishment shall apply to the extent required by Applicable Data Protection Law.

15. Contact Information

For questions about this DPA or to exercise your rights, contact our Data Protection team:

Email: privacy@websyt.dev
Address: Available upon request — contact us for our registered business address.