Legal
The Article 28 terms governing personal data we process on your behalf, including the processing details, our security measures, and the subprocessors we use.
This Data Processing Addendum ("DPA") forms part of the Terms of Service between needs input: ENTITY_NAME ("Processor", "we") and the customer identified in the account ("Controller", "you"). It applies where we process Personal Data on your behalf in the course of providing PageReflect.
This DPA takes effect automatically when you accept the Terms. If your procurement process requires a countersigned copy on your paper, email support@pagereflect.com with your entity details and we will arrange signature. In the event of a conflict, this DPA prevails over the Terms with respect to the processing of Personal Data.
"Personal Data", "processing", "controller", "processor", "data subject", and "supervisory authority" have the meanings given in the GDPR. "Data Protection Law" means the GDPR, the UK GDPR and Data Protection Act 2018, the Swiss FADP, the CCPA as amended by the CPRA, and any other applicable privacy law.
For Personal Data contained in Customer Data, including content extracted from sites you submit and leads captured through your reports, you are the controller and we are the processor.
For Personal Data relating to your account, your users, and your billing, we act as an independent controller and our Privacy Policy governs. This DPA does not apply to that processing.
You are responsible for establishing a lawful basis for the processing you instruct, for giving any notice and obtaining any consent required from data subjects, and for the accuracy and legality of the data you cause us to process. You confirm you have the right to submit each site you audit, as required by the Terms and the Acceptable Use Policy.
We will process Personal Data only on your documented instructions, which comprise this DPA, the Terms, the product documentation, and the configuration and actions you take in the Service, including the sites you submit, the schedules you set, the lead fields you define, and the integrations you connect.
We will not process Personal Data for our own purposes, will not sell or share it, and will not use it to train our own models. Where we are required by law to process beyond your instructions, we will tell you before doing so unless that law prohibits notice.
We will inform you if, in our opinion, an instruction infringes Data Protection Law. We may suspend processing of an instruction that we reasonably believe is unlawful.
We ensure that personnel authorized to process Personal Data are bound by confidentiality obligations that survive the end of their engagement, are informed of the confidential nature of the data, and receive access only to the extent necessary for their role. Access to production data is limited to personnel who require it to operate and support the Service.
We implement the technical and organizational measures set out in Annex II, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to data subjects. We may update these measures provided the level of security is not materially reduced.
You are responsible for the security configuration within your control, including who you invite to your organization, the roles you assign, how you distribute report share links, and how you protect API, CLI, and MCP credentials.
You give general written authorization for us to engage subprocessors. The current list is in Annex III and is maintained at /legal/subprocessors.
We impose data protection obligations on each subprocessor that are no less protective than this DPA, and we remain fully liable to you for their performance.
We will give at least 30 days' notice before adding or replacing a subprocessor, by email to the address you register at privacy@pagereflect.com for that purpose. You may object on reasonable data protection grounds within that period. If we cannot resolve your objection, you may terminate the affected part of the Service and receive a pro rata refund of prepaid fees for the unused term.
The Service gives you direct access to the Personal Data we process for you, so that you can retrieve, correct, export, and delete it yourself. That is the primary way we assist you.
If a data subject contacts us directly about data we process on your behalf, we will not respond substantively, other than to direct them to you, and we will notify you promptly. Where you cannot fulfil a request through the Service, we will provide reasonable additional assistance, at your cost where the assistance is substantial.
We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Personal Data we process for you.
The notice will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Where we cannot provide all of it at once, we will provide it in phases without undue delay.
We will cooperate with you and take reasonable steps to mitigate. Notification is not an admission of fault or liability. Reports and questions go to security@pagereflect.com.
Taking into account the nature of processing and the information available to us, we will provide reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities under Articles 35 and 36 of the GDPR. Our security documentation at /security and the annexes below are intended to cover most of what an assessment requires.
You may retrieve and delete Personal Data at any time through the Service. On termination, and at your choice, we will delete or return Personal Data processed on your behalf, and delete existing copies, unless law requires storage.
Deleting your account deletes the organizations you solely own, which cascades to their sites, runs, and reports. Residual copies may persist in encrypted backups for up to 30 days before rotating out, and in operational log tables until their retention window expires, as described in the Privacy Policy. Those copies remain subject to this DPA until deleted.
We will make available the information necessary to demonstrate compliance with Article 28, including our security documentation, the annexes below, and responses to reasonable security questionnaires.
You may audit our compliance no more than once in any twelve-month period, on 30 days' written notice, during business hours, without unreasonable disruption, and subject to confidentiality. An audit may not include penetration testing of our production systems or access to other customers' data. We may satisfy an audit request by providing a third-party report or a completed questionnaire where that reasonably addresses your request. You bear your own costs and our reasonable costs for audits beyond a questionnaire response.
Where processing involves transferring Personal Data out of the European Economic Area, the United Kingdom, or Switzerland to a country without an adequacy decision, the parties incorporate the European Commission's Standard Contractual Clauses (Decision 2021/914) by reference, Module Two (controller to processor), with you as data exporter and us as data importer.
For those Clauses: the optional docking clause applies; Clause 9 option 2 applies with the 30-day notice period in Section 5; Clause 11 does not include the optional independent dispute resolution body; Clause 17 selects the law of Ireland; Clause 18(b) selects the courts of Ireland; and Annexes I, II, and III of the Clauses are populated by the annexes below.
For UK transfers, the parties incorporate the UK International Data Transfer Addendum to the Standard Contractual Clauses, with the tables completed by reference to this DPA and its annexes. For Swiss transfers, references to the GDPR are read as references to the FADP and the Swiss Federal Data Protection and Information Commissioner is the competent authority.
Where the CCPA applies, we act as a "service provider" with respect to Personal Data we process for you. We will not sell or share that data, will not retain, use, or disclose it outside the direct business relationship or for any purpose other than the services specified in the Terms, and will not combine it with data from other sources except as permitted for a service provider.
We certify that we understand these restrictions and will comply with them. You may take reasonable steps to ensure our use is consistent with your obligations, and we will notify you if we determine we can no longer meet them. Comparable terms apply under the Virginia, Colorado, Connecticut, Utah, Texas, and other US state privacy laws where they govern.
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms. Nothing here limits a data subject's rights under Data Protection Law or either party's liability to a supervisory authority.
Where the Standard Contractual Clauses apply and conflict with this DPA, the Clauses prevail. Otherwise this DPA prevails over the Terms as to the processing of Personal Data. This DPA terminates automatically when the Terms terminate and we have completed deletion under Section 8.
This annex populates Annex I of the Standard Contractual Clauses. The data exporter is the Controller identified in the account; the data importer is needs input: ENTITY_NAME, needs input: ENTITY_ADDRESS.
| Item | Detail |
|---|---|
| Subject matter | Provision of automated website auditing, report generation, scheduling, and optional lead capture. |
| Duration | For the term of the Terms, plus the deletion and backup rotation periods in Section 8. |
| Nature and purpose | Collecting, storing, structuring, analyzing, transmitting, and erasing data in order to produce and deliver audit reports and to route captured leads to destinations the Controller configures. |
| Categories of data subjects | The Controller's authorized users; individuals whose personal data incidentally appears on pages of a site the Controller submits for auditing; and visitors who submit a lead capture form on a report the Controller shares. |
| Categories of personal data | Names, email addresses, telephone numbers, and free-text entered into lead capture fields; personal data appearing in extracted page text, page metadata, and page screenshots; IP address and user agent of lead form submitters. |
| Special category data | None requested or required. The Controller must not configure lead fields that solicit special category data. Any special category data appearing incidentally in audited page content is not sought and is processed only as part of the page record. |
| Frequency of transfer | Continuous, on each audit run, schedule execution, and lead submission. |
| Retention | Reports and lead submissions are retained until the Controller deletes them or closes the account. Operational logs follow the fixed windows in the Privacy Policy. |
| Competent supervisory authority | Determined under Clause 13 by reference to the data exporter's place of establishment or its EU representative. |
This annex populates Annex II of the Standard Contractual Clauses and describes measures implemented in the product today.
| Measure | Implementation |
|---|---|
| Tenant isolation | Every tenant table carries an organization identifier with Postgres row-level security and default-deny policies. Server code using the privileged key sets the organization identifier on every insert. |
| Access control | Role-based membership per organization. Privileged database keys are server-only and never reach the browser. Administrative surfaces are gated on an admin role. |
| Credential protection | Organization API keys are stored as Argon2id hashes with a short public lookup prefix and shown once at issuance. Integration access tokens are encrypted at rest. |
| Encryption | TLS in transit with HSTS on all ingress. Encryption at rest for the database, object storage, and backups as provided by the hosting platform. |
| Network protection | Outbound audit fetches pass a DNS-resolving guard that blocks private, loopback, link-local, and cloud metadata address ranges, applied on every redirect hop. Nonce-based Content Security Policy, X-Frame-Options, Referrer-Policy, and Permissions-Policy on responses. |
| Integrity of inbound events | Stripe webhooks are signature-verified before any side effect and deduplicated on the provider event identifier. |
| Logging and monitoring | Owner and admin mutations write to an activity log. Tool invocations are recorded. Pipeline steps emit structured logs to the host log drain. |
| Rate limiting | Mutation routes and public form endpoints enforce server-side rate limits keyed by actor or IP address. |
| Data minimization | Durable execution payloads carry identifiers only, never full records. Lead capture stores only the fields the Controller configured. |
| Deletion | Self-serve account and organization deletion with cascade. Daily automated retention sweeps against fixed per-table windows. |
| Vulnerability management | High-severity dependency audit in continuous integration. Security reports accepted at security@pagereflect.com and triaged the same business day. |
| Personnel | Confidentiality obligations for all personnel with production access, limited to those who require it. |
This annex populates Annex III of the Standard Contractual Clauses. The current list is maintained at /legal/subprocessors. Register at privacy@pagereflect.com to receive change notices.
| Subprocessor | Purpose | Data received |
|---|---|---|
| Vercel | Application hosting + edge network | Request metadata, deploy artifacts |
| Supabase | Postgres database + auth + storage | Account data, audit artifacts, reports |
| Stripe | Payment processing | Billing metadata, Stripe customer ids (no raw card data) |
| Resend | Transactional email | Recipient email, subject, template ids |
| Inngest | Durable audit execution | Event payloads with ids only, not full records |
| Jina Reader | Primary page extraction for audits | Public URL requested and extracted text/metadata |
| Google PageSpeed Insights | Lab performance metrics | Audited public URL sent to the PSI API |
| OpenAI | Report reasoning (default tier) | Extracted page content for the audited URL |
Questions about this document? Email privacy@pagereflect.com.