Sitebase
Legal

Data processing addendum

This DPA forms part of the Terms of service between Sitebase ([PLACEHOLDER: legal entity name]) as processor and you, the customer, as controller. It applies whenever Sitebase processes personal data of your website visitors on your behalf. Last updated June 12, 2026.

1. Scope of processing

  • Subject matter and nature: storage, display, aggregation, and export of data collected through Sitebase features embedded on your websites.
  • Duration: the term of your subscription, plus the deletion window in section 8.
  • Purpose: providing the Sitebase service — no other purpose. We never use your visitors' data for our own purposes, advertising, or model training.
  • Categories of data subjects: visitors to your websites and people who submit data through your embedded features.
  • Categories of personal data: contact details and message content from forms (name, email, free-text); subscriber email addresses and consent records; testimonial author names and quotes; pseudonymized analytics (daily-rotating hashed visitor identifiers, page, referrer, country, device class); anonymous cookie consent records; keyed hashes of IP addresses for spam protection.
  • Special categories: none. The Terms prohibit collecting sensitive data through Sitebase features.

2. Instructions

We process your visitors' data only on your documented instructions: the configuration you set in the dashboard, the features you embed, and the actions you take (approve, export, erase). We will inform you if we believe an instruction violates data protection law.

3. Confidentiality

Access to customer data is restricted to personnel who need it to operate the service and who are bound by confidentiality obligations.

4. Security (Art. 32)

Technical and organizational measures include:

  • each workspace's data stored in its own isolated database (no shared tables between customers);
  • encryption in transit (TLS) and at rest (provider-managed);
  • authentication tokens stored only as cryptographic hashes; no passwords held at all;
  • role-based access control and per-website collaborator scoping;
  • audit logging of administrative actions;
  • rate limiting and bot protection on public endpoints;
  • data minimization by design: cookieless analytics, daily-rotating visitor hashes, hashed IPs, scheduled deletion of raw detail.

5. Subprocessors

You give general authorization for the subprocessors listed at /legal/subprocessors. We will update that page at least 14 days before adding or replacing a subprocessor; if you object on reasonable data protection grounds and we cannot accommodate you, you may terminate and we will delete your data per section 8. Each subprocessor is bound by data protection terms at least as protective as this DPA.

6. Assistance with data subject requests

Taking into account the nature of the processing, we assist you in fulfilling access, portability, rectification, and erasure requests through built-in dashboard tools: per-person search across submissions, subscribers, and testimonials with export (JSON) and permanent erasure actions, plus CSV export of feature data. If a data subject contacts us directly, we will refer them to you.

7. Personal data breaches

We will notify you without undue delay after becoming aware of a personal data breach affecting your data, providing the information reasonably needed for your own notification obligations (nature of the breach, categories and approximate volumes affected, measures taken).

8. Deletion and return

You can export your data at any time from the dashboard. Deleting a workspace permanently deletes its database. After termination of your subscription, we delete remaining personal data within 90 days, unless retention is required by law (billing records held by our merchant of record).

9. Audits

We make available the information reasonably necessary to demonstrate compliance with Article 28 — this DPA, the subprocessor list, and our security documentation — and will respond to reasonable written security questionnaires. Where this is insufficient, you may request an audit at your expense, no more than once per year, with reasonable notice and without access to other customers' data.

10. International transfers

Our subprocessors may process data in the United States. Transfers from the EEA/UK rely on the EU–US Data Privacy Framework and/or Standard Contractual Clauses, as incorporated in each subprocessor's data processing agreement (Cloudflare DPA, Resend DPA, Polar DPA). Where Sitebase itself acts as data exporter, the SCCs (Module 2, controller-to-processor) are incorporated by reference, with you as exporter and Sitebase as importer, completed with the processing details in section 1 and the measures in section 4.

11. Liability and precedence

Liability under this DPA is subject to the limitations in the Terms of service. If this DPA conflicts with the Terms, this DPA prevails for data protection matters.

Note: this document is a working draft prepared for launch and has not yet been reviewed by counsel.