Important: This DPA applies when SiteGrade AI processes personal data on behalf of customers in connection with GDPR, CCPA, or other data protection regulations. By using the Service for commercial purposes, you agree to these terms.
1. Definitions
• "Controller" means the customer (you) who determines the purposes and means of processing
• "Processor" means SiteGrade AI, who processes data on behalf of the Controller
• "Personal Data" means any information relating to an identified or identifiable natural person
• "Processing" means any operation performed on Personal Data
• "GDPR" means the EU General Data Protection Regulation 2016/679
2. Scope and Purpose
This DPA governs the processing of Personal Data by SiteGrade AI on your behalf when you use our website audit services. The purposes of processing include:
• Performing website audits and analysis
• Generating audit reports and recommendations
• Providing customer support
• Maintaining and improving our Services
• Complying with legal obligations
3. Processor Obligations
SiteGrade AI agrees to:
• Process Personal Data only on documented instructions from the Controller
• Ensure persons authorized to process data are bound by confidentiality
• Implement appropriate technical and organizational security measures
• Not engage sub-processors without prior authorization
• Assist the Controller in responding to data subject requests
• Support the Controller in ensuring compliance with GDPR obligations
• Delete or return all Personal Data upon termination of services
• Make available all information necessary to demonstrate compliance
4. Data Categories
The following categories of Personal Data may be processed:
• User Account Data: Name, email address, account credentials
• Business Contact Data: Company name, business email, phone number
• Payment Data: Billing information (processed by third-party payment processors)
• Monitoring: 24/7 security monitoring and incident detection
• Backups: Regular encrypted backups with tested recovery procedures
• Physical Security: Secure data centers with access controls
• Employee Training: Regular security awareness training
8. Data Breach Notification
In the event of a Personal Data breach, SiteGrade AI will:
• Notify the Controller without undue delay (within 48 hours of awareness)
• Provide details including nature of breach, categories of data, and approximate number of affected individuals
• Describe measures taken or proposed to address the breach
• Cooperate with the Controller in investigating and remedying the breach
9. Data Subject Rights
SiteGrade AI will assist the Controller in fulfilling data subject requests under GDPR, including:
• Right of access (Article 15)
• Right to rectification (Article 16)
• Right to erasure ("right to be forgotten") (Article 17)
• Right to restriction of processing (Article 18)
• Right to data portability (Article 20)
• Right to object (Article 21)
10. Audit Rights
The Controller has the right to:
• Request information about our data processing practices
• Review our compliance documentation and certifications
• Conduct audits (with reasonable notice and during business hours)
• Request third-party audits where justified
11. Data Retention and Deletion
Personal Data will be retained:
• For the duration of the customer relationship
• As required by applicable laws and regulations
• For the establishment, exercise, or defense of legal claims
Upon termination, we will delete or return all Personal Data within 90 days, unless legally required to retain it.
12. Liability and Indemnification
Each party shall be liable for damages caused by its breach of this DPA. SiteGrade AI's liability is limited as set forth in the Terms of Service, except where:
• The breach results from gross negligence or willful misconduct
• Death or personal injury is caused
• Fraud or fraudulent misrepresentation is involved
• Required by applicable law (e.g., GDPR Article 82)
13. Term and Termination
This DPA remains in effect for as long as SiteGrade AI processes Personal Data on your behalf. Either party may terminate this DPA if the other party materially breaches its terms and fails to cure within 30 days of notice.
14. Governing Law
This DPA shall be governed by the laws applicable to the Terms of Service between the parties. For EU customers, this includes the GDPR and applicable member state laws.
15. Contact
For DPA-related inquiries, contact our Data Protection Officer at:
Email: info@crownlightholdings.com
Exhibits
Standard Contractual Clauses (SCCs) and additional safeguards are available upon request. Contact info@crownlightholdings.com to obtain copies.