Skip to content
SiteUpward

Data Processing Agreement

Last updated: September 29, 2026

This Data Processing Agreement (“DPA”) applies where SIA "MICRON" (“we”, the “Processor”) processes personal data on behalf of a business customer, wherever it is located (“you”, the “Controller”) while providing SiteUpward (the “Service”). It forms part of our Terms of Service and takes effect automatically when a business customer accepts them; no separate signature is required. A countersigned copy is available on request at privacy@siteupward.com.

1. Scope, roles and precedence

  • This DPA covers personal data that we process on your behalf when providing the Service to you (“Customer Personal Data”) – in particular personal data contained in the websites you instruct us to audit, in the resulting Reports and share links, and in information about your clients or staff that you provide to us for that purpose.
  • For Customer Personal Data, you are the controller and we are your processor within the meaning of Regulation (EU) 2016/679 (GDPR) and of the other data protection laws that apply to the processing, such as the UK GDPR, the Swiss Federal Act on Data Protection (FADP) and US state privacy laws (together with the GDPR, “Data Protection Law”); under US state privacy laws, we act as your service provider or processor. Where you act as a processor for your own clients, we are your sub-processor, and you confirm that your instructions are authorised by the relevant controller.
  • We act as an independent controller for account, sign-in, billing, security and support data, which we process for our own purposes as described in our Privacy Policy.
  • If this DPA and the Terms conflict on the protection of personal data, this DPA prevails. Terms not defined here have the meaning given to them in the GDPR or, where the GDPR does not apply, in the relevant Data Protection Law.

2. Documented instructions

  • We process Customer Personal Data only on your documented instructions, including with regard to transfers to third countries, unless EU or Member State law, or other law that applies to us, requires otherwise; in that case we inform you before processing, unless that law prohibits it.
  • Your instructions are the Terms, this DPA and the way you use and configure the Service – for example, which websites you audit and with whom you share Reports.
  • We do not sell or share Customer Personal Data; we do not retain, use or disclose it for any purpose other than providing the Service to you, or outside our direct business relationship with you (other than creating aggregated, anonymised statistics and keeping the Service secure); we do not combine it with personal data from other sources except as Data Protection Law allows; and we do not use it to train AI models. We comply with the obligations that US state privacy laws place on service providers and processors and tell you if we can no longer meet them.
  • We inform you immediately if, in our opinion, an instruction infringes Data Protection Law.

3. Confidentiality

We ensure that everyone authorised to process Customer Personal Data is bound by confidentiality obligations and has access only to the extent needed for their tasks.

4. Security of processing

We implement the technical and organisational measures described in Annex II, which are designed to ensure a level of security appropriate to the risk in accordance with Art. 32 GDPR. We may update these measures as technology develops, provided that the overall level of protection is not reduced.

5. Sub-processors

  • You give us general authorisation to engage sub-processors. The categories of sub-processors we currently use are listed in Annex III; the full list with names and locations is available on request at privacy@siteupward.com.
  • We inform you by e-mail to your account address at least 30 days before we add or replace a sub-processor that processes Customer Personal Data. You may object on reasonable data-protection grounds within that period. If we cannot resolve your objection, you may terminate the affected part of the Service before the change takes effect and receive a proportionate refund of prepaid, unused fees.
  • We impose on every sub-processor data protection obligations that provide at least the same level of protection as this DPA, and we remain responsible to you for their performance.

6. International transfers

This DPA applies to business customers worldwide. We host the Service and store Customer Personal Data in the European Union. Where a sub-processor processes Customer Personal Data outside the European Economic Area, we ensure that the transfer complies with Chapter V GDPR, relying on an adequacy decision (including the EU–U.S. Data Privacy Framework for certified providers) or on the European Commission's Standard Contractual Clauses (“SCCs”), with supplementary measures where needed.

Where Customer Personal Data is subject to the UK GDPR, such transfers rely on UK adequacy regulations or on the SCCs together with the UK International Data Transfer Addendum; where it is subject to the Swiss FADP, on adequacy decisions of the Swiss Federal Council or on the SCCs with the adjustments required by the FADP.

If you transfer Customer Personal Data to us from a country whose law requires a specific safeguard for transfers to the European Union, contact privacy@siteupward.com: we will agree to the standard clauses recognised by that law, where they exist, or to another appropriate safeguard.

7. Assistance with data subject requests

Taking into account the nature of the processing, we assist you with appropriate technical and organisational measures in responding to requests from data subjects exercising their rights under Data Protection Law. If we receive such a request directly and it concerns Customer Personal Data, we forward it to you without undue delay and do not respond to it ourselves unless you authorise us to.

8. Personal data breaches

We notify you without undue delay, and in any event within 48 hours after becoming aware of it, of a personal data breach affecting Customer Personal Data, so that you can meet your obligation to notify the supervisory authority within 72 hours under Art. 33 GDPR, or within the period set by other Data Protection Law. The notice describes, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed. We take reasonable steps to contain the breach and mitigate its effects, and we provide further information as it becomes available.

9. Impact assessments and prior consultation

We provide reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities where Data Protection Law requires them, taking into account the nature of the processing and the information available to us.

10. Information and audits

  • We make available the information reasonably necessary to demonstrate compliance with Art. 28 GDPR and other Data Protection Law, such as a description of our security measures and our list of sub-processors.
  • If that information is not sufficient, you or an independent auditor bound by confidentiality may audit our compliance once in any 12-month period, with at least 30 days' written notice, during normal business hours, without disrupting our operations and without access to other customers' data. You bear the costs of the audit.
  • Audits required by a supervisory authority, or following a personal data breach affecting Customer Personal Data, are not subject to the frequency limit above.

11. Deletion and return

  • You can view, print and export your Reports in the Service at any time, and so retrieve Customer Personal Data before the Service ends.
  • When the Service ends, or earlier at your request, we delete Customer Personal Data or, at your choice, return it to you before deletion, within 30 days, unless EU or Member State law requires us to keep it. Copies in backups are overwritten in the normal backup cycle, normally within 30 days, and remain protected until then.
  • Detailed data of free checks is also deleted automatically as described in our Privacy Policy.

12. Your obligations

You are responsible for having a lawful basis for the processing you instruct us to carry out, for informing data subjects where required, and for ensuring that your instructions comply with Data Protection Law. The Service is not designed for special categories of personal data or data relating to criminal convictions and offences; do not instruct us to process such data other than incidentally as part of public website content.

13. Liability

Each party's liability under this DPA is subject to the limitations of liability in the Terms. This does not limit either party's liability to data subjects under Art. 82 GDPR or any liability that cannot be limited by law.

14. Term, changes and governing law

This DPA applies for as long as we process Customer Personal Data on your behalf. We may update it to reflect changes in law, regulatory guidance or the Service, with notice as described in the Terms; updates will not reduce the level of protection of Customer Personal Data.

This DPA is governed by the laws of the Republic of Latvia, and the courts of Latvia have exclusive jurisdiction, unless the SCCs or the UK International Data Transfer Addendum require otherwise.

Annex I – Details of the processing

ItemDescription
Subject matterProvision of the SiteUpward service: automated crawling and analysis of websites and delivery of audit reports.
DurationFor the term of the Terms and until deletion under section 11.
Nature of the processingCollection by fetching public web pages, storage, structuring, automated and AI-assisted analysis, display in Reports, sharing through share links at your instruction, and deletion.
PurposeProviding the Service to you as described in the Terms.
Categories of data subjectsIndividuals whose personal data appears on the websites you audit (for example authors, employees or contacts named on those websites); your clients or staff, where you provide their information to us in connection with Reports.
Categories of personal dataNames, job titles, contact details and other information published on audited websites, as contained in page addresses, titles, headings and short excerpts; information about your clients or staff that you provide to us.
Special categories of dataNot intended. Public websites may incidentally contain them; they are processed only as part of page content and are not analysed separately.
FrequencyContinuous, each time you run an Audit or view or share a Report.
RetentionAs described in section 11 and in our Privacy Policy.

Annex II – Technical and organisational measures

  • Encryption in transit: all connections to the Service use HTTPS with current TLS versions and strict transport security.
  • Access control: access to production systems is limited to authorised personnel on a least-privilege basis; administrative functions are available only to designated accounts; administrative access requires strong authentication.
  • Authentication: password-less, single-use sign-in links that expire after 20 minutes to 24 hours; session, sign-in and browser tokens are stored only as keyed hashes; share links are derived cryptographically and can be revoked at any time.
  • Application security: input validation, protection against cross-site request forgery, security headers and a content security policy, and protection against server-side request forgery when fetching websites.
  • Isolation: databases and internal services are not reachable from the internet; the component that loads audited web pages is isolated from internal systems and blocked from private networks.
  • Abuse prevention: rate limiting per IP address, network, recipient and domain; human verification on public forms.
  • Data minimisation and retention: only public page content is sent for AI-assisted analysis; expired sign-in links and sessions, detailed free-check data after 30 days and free checks without an account after 12 months are deleted automatically; IP addresses stored with checks are cleared after 30 days; logs are kept for up to 30 days with query parameters removed.
  • Availability and resilience: daily backups checked for integrity, with an off-site copy that cannot be altered after it is written; documented restore procedure; monitoring and alerting.
  • Personnel: confidentiality obligations and need-to-know access.
  • Sub-processor management: data processing agreements and transfer safeguards with every sub-processor.

Annex III – Sub-processor categories

CategoryProcessingLocation and safeguard
Hosting providerServers, database and backupsEuropean Union
Backup storage providerOff-site backup copiesEuropean Union
AI analysis providerAI-assisted analysis of public page content (page address, title and text); no use for training AI modelsMay be outside the EEA; adequacy decision or Standard Contractual Clauses (with the UK Addendum for UK data)
E-mail delivery providerDelivery of service e-mails, such as report-ready notificationsMay be outside the EEA; adequacy decision or Standard Contractual Clauses (with the UK Addendum for UK data)
Internal team messagingOperational notifications that may contain audited domain namesMay be outside the EEA; adequacy decision or Standard Contractual Clauses (with the UK Addendum for UK data)

The full list with names and locations is available on request at privacy@siteupward.com.