Back to Home

Data Processing Agreement (DPA)

Last updated: June 6, 2026

Important: This DPA applies when SiteGrade AI processes personal data on behalf of customers in connection with GDPR, CCPA, or other data protection regulations. By using the Service for commercial purposes, you agree to these terms.

1. Definitions

  • • "Controller" means the customer (you) who determines the purposes and means of processing
  • • "Processor" means SiteGrade AI, who processes data on behalf of the Controller
  • • "Personal Data" means any information relating to an identified or identifiable natural person
  • • "Processing" means any operation performed on Personal Data
  • • "GDPR" means the EU General Data Protection Regulation 2016/679

2. Scope and Purpose

This DPA governs the processing of Personal Data by SiteGrade AI on your behalf when you use our website audit services. The purposes of processing include:

  • • Performing website audits and analysis
  • • Generating audit reports and recommendations
  • • Providing customer support
  • • Maintaining and improving our Services
  • • Complying with legal obligations

3. Processor Obligations

SiteGrade AI agrees to:

  • • Process Personal Data only on documented instructions from the Controller
  • • Ensure persons authorized to process data are bound by confidentiality
  • • Implement appropriate technical and organizational security measures
  • • Not engage sub-processors without prior authorization
  • • Assist the Controller in responding to data subject requests
  • • Support the Controller in ensuring compliance with GDPR obligations
  • • Delete or return all Personal Data upon termination of services
  • • Make available all information necessary to demonstrate compliance

4. Data Categories

The following categories of Personal Data may be processed:

  • • User Account Data: Name, email address, account credentials
  • • Business Contact Data: Company name, business email, phone number
  • • Payment Data: Billing information (processed by third-party payment processors)
  • • Usage Data: Audit history, website URLs submitted, feature usage
  • • Technical Data: IP addresses, browser information, device identifiers

5. Sub-processors

SiteGrade AI engages the following sub-processors:

  • • Cloud Infrastructure: Amazon Web Services, Google Cloud Platform
  • • Payment Processing: Stripe, PayPal
  • • Email Delivery: SendGrid, Amazon SES
  • • Analytics: Google Analytics, Mixpanel
  • • Customer Support: Intercom, Zendesk

We will notify you of any new sub-processors and provide an opportunity to object.

6. International Transfers

Personal Data may be transferred outside the European Economic Area (EEA). We ensure adequate safeguards through:

  • • Standard Contractual Clauses (SCCs) approved by the European Commission
  • • Adequacy decisions by the European Commission
  • • Binding Corporate Rules where applicable
  • • Other legally approved transfer mechanisms

7. Data Security

SiteGrade AI implements the following security measures:

  • • Encryption: TLS/SSL for data in transit, AES-256 for data at rest
  • • Access Controls: Role-based access, multi-factor authentication
  • • Monitoring: 24/7 security monitoring and incident detection
  • • Backups: Regular encrypted backups with tested recovery procedures
  • • Physical Security: Secure data centers with access controls
  • • Employee Training: Regular security awareness training

8. Data Breach Notification

In the event of a Personal Data breach, SiteGrade AI will:

  • • Notify the Controller without undue delay (within 48 hours of awareness)
  • • Provide details including nature of breach, categories of data, and approximate number of affected individuals
  • • Describe measures taken or proposed to address the breach
  • • Cooperate with the Controller in investigating and remedying the breach

9. Data Subject Rights

SiteGrade AI will assist the Controller in fulfilling data subject requests under GDPR, including:

  • • Right of access (Article 15)
  • • Right to rectification (Article 16)
  • • Right to erasure ("right to be forgotten") (Article 17)
  • • Right to restriction of processing (Article 18)
  • • Right to data portability (Article 20)
  • • Right to object (Article 21)

10. Audit Rights

The Controller has the right to:

  • • Request information about our data processing practices
  • • Review our compliance documentation and certifications
  • • Conduct audits (with reasonable notice and during business hours)
  • • Request third-party audits where justified

11. Data Retention and Deletion

Personal Data will be retained:

  • • For the duration of the customer relationship
  • • As required by applicable laws and regulations
  • • For the establishment, exercise, or defense of legal claims

Upon termination, we will delete or return all Personal Data within 90 days, unless legally required to retain it.

12. Liability and Indemnification

Each party shall be liable for damages caused by its breach of this DPA. SiteGrade AI's liability is limited as set forth in the Terms of Service, except where:

  • • The breach results from gross negligence or willful misconduct
  • • Death or personal injury is caused
  • • Fraud or fraudulent misrepresentation is involved
  • • Required by applicable law (e.g., GDPR Article 82)

13. Term and Termination

This DPA remains in effect for as long as SiteGrade AI processes Personal Data on your behalf. Either party may terminate this DPA if the other party materially breaches its terms and fails to cure within 30 days of notice.

14. Governing Law

This DPA shall be governed by the laws applicable to the Terms of Service between the parties. For EU customers, this includes the GDPR and applicable member state laws.

15. Contact

For DPA-related inquiries, contact our Data Protection Officer at:

Email: info@crownlightholdings.com

Exhibits

Standard Contractual Clauses (SCCs) and additional safeguards are available upon request. Contact info@crownlightholdings.com to obtain copies.