Compliance & Contracts

Data Processing Agreement (DPA)

Effective Date: August 2026 • Standard Contractual Clauses (EU/UK) Version 2.0

Online Execution & Precedence

This Data Processing Agreement (“DPA”) governs the processing of Personal Data by SiteMind on behalf of the Customer in connection with the SiteMind Terms of Service. This DPA is automatically incorporated by reference into the Terms of Service upon creating a workspace or subscribing to the Service.

1. Definitions and Roles

In this DPA, the terms “Personal Data”, “Processing”, “Data Controller”, “Data Processor”, “Data Subject”, and “Personal Data Breach” have the meanings given in Regulation (EU) 2016/679 (General Data Protection Regulation / GDPR) and the UK Data Protection Act 2018.

The parties acknowledge and agree that with respect to Customer Content, website crawled text, uploaded documents, end-user conversation logs, and visitor lead submissions, Customer is the Data Controller and SiteMind is the Data Processor.

2. Scope & Instructions

SiteMind shall process Personal Data solely in accordance with documented instructions from Customer, including with respect to transfers of Personal Data to a third country, unless required to do so by applicable European Union or Member State law to which SiteMind is subject.

Customer’s instructions are formalized through the configuration of the SiteMind Service, connected website domains, document uploads, and the provisions of the Terms of Service.

3. Security & Confidentiality

SiteMind shall implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as set forth in Annex 2 (Technical and Organizational Measures).

SiteMind shall ensure that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

4. Subprocessor Authorization

Customer grants SiteMind general written authorization to engage third-party Subprocessors to perform specific processing activities on behalf of Customer. The list of current authorized Subprocessors is published at /subprocessors.

SiteMind shall notify Customer of any intended changes concerning the addition or replacement of Subprocessors at least fourteen (14) days prior to authorization. Customer may reasonably object in writing to such changes within ten (10) days of receiving notice.

5. Data Subject Rights & Incident Notification

Taking into account the nature of the processing, SiteMind shall assist Customer by appropriate technical and organizational measures to fulfill Customer’s obligation to respond to requests for exercising Data Subject rights under Chapter III of the GDPR (such as access, rectification, or erasure).

In the event of a confirmed Personal Data Breach affecting Customer Personal Data, SiteMind shall notify Customer without undue delay (and in any event within 48 hours of becoming aware of the breach) and provide reasonable assistance in fulfilling breach notification obligations.

6. International Data Transfers (Standard Contractual Clauses)

To the extent that the performance of the Service involves the cross-border transfer of Personal Data from the European Economic Area (EEA), Switzerland, or the United Kingdom to countries not recognized as providing an adequate level of data protection, the parties agree to abide by:

  • EU Standard Contractual Clauses (SCCs): Module 2 (Controller-to-Processor) and Module 3 (Processor-to-Processor) pursuant to Commission Implementing Decision (EU) 2021/914, which are hereby incorporated by reference.
  • UK International Data Transfer Addendum: The UK Information Commissioner’s Office Addendum to the EU Commission Standard Contractual Clauses.

7. Deletion or Return of Personal Data

Upon termination of the Service or workspace deletion, SiteMind shall, at Customer’s choice, delete or return all Personal Data to Customer, and delete existing copies unless applicable European Union or national law requires storage of the Personal Data. Soft-deleted workspaces are permanently purged within 30 days.

Annex 1: Details of Processing

Categories of Data Subjects: Customer employees, team members, authorized users, and website visitors chatting with the embeddable widget.

Categories of Personal Data: Name, business email, IP address, user agent, chat conversation transcripts, submitted contact form leads (name, email, phone), crawled website content, and uploaded documents.

Nature & Purpose of Processing: Vector embedding generation, hybrid semantic search, grounding retrieval, and real-time AI conversational inference to answer website visitor inquiries.

Duration of Processing: For the duration of Customer’s active subscription plus 30 days post-termination retention.

Annex 2: Technical and Organizational Measures (TOMs)

1. Encryption: TLS 1.3 / 1.2 encryption in transit across all HTTP and WebSocket connections. AES-256-GCM authenticated encryption for third-party OAuth tokens and secrets at rest.

2. Multi-Tenant Scoping: Logical separation of tenant data enforced at the ORM layer with denormalized workspaceId filters on vector similarity queries.

3. Access Controls: Role-based access control (RBAC), bcrypt salted password hashing, SHA-256 session token hashing, and family rotation for refresh tokens.

4. Resilience & Redundancy: Managed PostgreSQL with daily snapshots, automated BullMQ queue retry backoffs, and Cloudflare DDoS protection.