GDPR
Last updated: August 18, 2026
This page explains in plain language how we handle personal data under the GDPR. It is a summary written to be read, not a contract. The binding terms live in our Terms of Service, Privacy Policy, and Data Processing Addendum.
1. What is GDPR?
The General Data Protection Regulation is the European Union's data protection law, in force since May 25, 2018. The United Kingdom keeps its own version, the UK GDPR. It gives people rights over the personal data that companies hold about them:
- The right to be informed about how their data is used.
- The right of access to the data held about them.
- The right to rectification of data that is wrong or incomplete.
- The right to erasure.
- The right to restrict processing.
- The right to data portability.
- The right to object to processing.
- Rights relating to automated decision-making and profiling.
It applies to us whenever we handle personal data belonging to people in the EEA or the UK, no matter where our company is based.
2. Why it matters to your business
You decide what goes on your website, and we handle that data on your behalf. In GDPR language, you are the controller and we are the processor. That split is the point: you keep the promises you made to your own customers, and we are bound to do only what you have asked us to do. Our Data Processing Addendum puts that in writing and applies to every customer automatically. There is nothing to sign up for, nothing to negotiate, and no upgrade required.
3. Where your data is stored
Our infrastructure and our sub-processors are based in the United States. When personal data moves from the EEA, the UK, or Switzerland to the United States, we rely on the European Commission's Standard Contractual Clauses (Decision 2021/914) and, for UK transfers, the International Data Transfer Addendum issued by the UK Information Commissioner's Office. The full terms are in section 8 of the DPA.
4. Who we share data with
We do not sell personal data and we never have. We share it only with the vendors we need to run the service, each of them under a data processing agreement with us:
- Vercel, Inc.: application hosting and CDN (United States).
- Supabase, Inc.: database, authentication, and storage (United States).
- Stripe, Inc.: payment processing (United States, EU).
- PostHog, Inc.: product analytics and error tracking (United States).
- Resend, Inc.: transactional email delivery (United States).
- Anthropic, PBC: site content generation (United States).
We give at least 30 days' notice before we add or change a sub-processor, and you can object on reasonable data protection grounds. Section 7 of the DPA covers this.
5. How we protect personal data
The measures we have in place today:
- TLS encryption for data in transit.
- Encryption at rest for primary databases.
- Role-based access controls and least-privilege principles.
- Audit logging on production access.
- Vendor security review for sub-processors.
- Regular backups with controlled retention.
We also collect as little as we can get away with. Visitors to the website we host for you are not tracked: page views are counted on our servers with no cookies, no persistent identifiers, and no stored IP addresses. That is why your website carries no cookie banner. There is nothing for your visitors to consent to.
6. Are we GDPR certified?
No, and neither is anyone else. GDPR is a regulation rather than a standard, so there is no official certificate to be awarded. What a company can do is assess itself honestly and publish the result, so here is ours. We have published a DPA that meets the Article 28 processor obligations, we keep a current sub-processor list, we rely on Standard Contractual Clauses for transfers, and we built account deletion directly into the product so you never have to ask us for it. We have not completed a SOC 2 or ISO 27001 audit and we do not claim one. If that changes, this page changes with it.
7. Your rights, and your customers' rights
Most of your own rights are self-serve. Your name, email, and language are editable in Settings, your website content is yours to change or remove at any time, and deleting your account in Settings permanently erases your account, organization, and websites right away. For anything else, email support@getwebsitebuilt.com and we will respond within 30 days. We may need to verify your identity first.
If one of your customers contacts us directly about data on your website, we do not act on it ourselves. We pass the request to you without undue delay, because it is your data and your decision.
If a data breach ever affects your personal data, we will tell you without undue delay, and within 72 hours of becoming aware of it wherever that is feasible. You also have the right to complain to the supervisory authority in your country.
8. GDPR resources
- Data Processing Addendum: our Article 28 processor terms, sub-processor list, and transfer mechanisms.
- Privacy Policy: what we collect, why we are allowed to, how long we keep it.
- Cookie Policy: the cookies we set and how to control them.
9. Questionnaires and signed DPAs
Need a counter-signed copy of the DPA with executed Standard Contractual Clauses, or a security questionnaire filled in? Email support@getwebsitebuilt.com. We are a small team and we answer these ourselves, which also means we will tell you plainly when the honest answer is "not yet".