Data Processing Addendum
Effective date: August 18, 2026
1. Introduction
This Data Processing Addendum ("DPA") supplements the GetWebsiteBuilt Terms of Service and applies whenever GetWebsiteBuilt LLC ("Processor") processes Personal Data on behalf of a customer ("Controller") in connection with the Service. It reflects the parties' agreement on processing personal data under the EU General Data Protection Regulation (GDPR), the UK GDPR, and the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA).
2. Definitions
- Personal Data: any information relating to an identified or identifiable natural person, as defined in the GDPR.
- Processing: any operation performed on Personal Data, whether or not by automated means.
- Sub-processor: a third party engaged by Processor to process Personal Data on behalf of Controller.
- Data Subject: the identified or identifiable person to whom Personal Data relates (typically, your end users or site visitors).
3. Scope and Roles
Controller determines the purposes and means of processing. Processor processes Personal Data only on documented instructions from Controller, including with respect to international transfers, unless required by law (in which case Processor will inform Controller, where permitted). Controller is responsible for having a lawful basis for processing and for any notices or consents required from Data Subjects.
4. Subject Matter and Details
- Subject matter: providing the Service described in the Terms.
- Duration: the term of the agreement plus retention periods described in our Privacy Policy.
- Nature and purpose: hosting, generating, and serving Controller's website content; account management; billing; support; abuse prevention.
- Categories of Data Subjects: Controller's personnel and Controller's site visitors.
- Categories of Personal Data: contact information; account credentials; content submitted to the Service; usage and log data. Site visitor data is limited to anonymous page-view events (page path, site name, and a random one-time ID). Processor does not store visitor IP addresses and sets no identifiers on visitors.
5. Confidentiality
Processor ensures that personnel authorized to process Personal Data are bound by confidentiality obligations and receive appropriate data protection training.
6. Security Measures
Processor implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- TLS encryption for data in transit.
- Encryption at rest for primary databases.
- Role-based access controls and least-privilege principles.
- Audit logging on production access.
- Vendor security review for sub-processors.
- Regular backups with controlled retention.
7. Sub-processors
Controller provides general authorization for Processor to engage sub-processors to provide the Service. Current sub-processors:
- Vercel, Inc.: application hosting and CDN (United States).
- Supabase, Inc.: database, authentication, and storage (United States).
- Stripe, Inc.: payment processing (United States, EU).
- PostHog, Inc.: product analytics and error tracking (United States).
- Resend, Inc.: transactional email delivery (United States).
- Anthropic, PBC: site content generation (United States).
We notify Controller of changes to the sub-processor list with at least 30 days' notice (via in-product notice or email). Controller may object on reasonable data protection grounds; if the objection cannot be resolved, either party may terminate the affected portion of the Service.
8. International Data Transfers
Where Personal Data is transferred from the EEA, UK, or Switzerland to a country not subject to an adequacy decision, the parties incorporate the Standard Contractual Clauses (EU Commission Decision 2021/914) and, for UK transfers, the UK International Data Transfer Addendum issued by the UK Information Commissioner's Office. Module Two applies to transfers from Controller to Processor.
9. Data Subject Requests
Processor will, taking into account the nature of processing, provide reasonable assistance to enable Controller to respond to Data Subject requests (access, rectification, erasure, restriction, portability, objection). If Processor receives a request directly from a Data Subject related to Controller's data, Processor will forward it to Controller without undue delay.
10. Personal Data Breach
Processor will notify Controller without undue delay, and where feasible within 72 hours, after becoming aware of a Personal Data Breach affecting Controller's Personal Data, and will provide information reasonably required for Controller to meet its own notification obligations.
11. Audits
Processor will make available to Controller information reasonably necessary to demonstrate compliance with this DPA, including summaries of third-party audit reports (e.g., SOC 2) where available. On Controller's reasonable written request and at Controller's expense, Processor will permit audits, including inspections, once per year by Controller or a mutually agreed independent auditor, subject to confidentiality and reasonable scheduling.
12. Return and Deletion
Upon termination of the Service or on Controller's written request, Processor will delete or return all Personal Data, subject to legal retention requirements and the rolling deletion of encrypted backups described in our Privacy Policy.
13. CCPA / CPRA
For California residents, Processor acts as a "service provider" as defined by the CCPA/CPRA. Processor will not: (a) sell or share Personal Data; (b) retain, use, or disclose Personal Data outside the direct business relationship or for any purpose other than performing the Service; or (c) combine Personal Data received from Controller with data from other sources, except as permitted by law.
14. Liability and Order of Precedence
Each party's liability under this DPA is subject to the limitations of liability in the Terms of Service. In the event of a conflict between this DPA and the Terms, this DPA controls with respect to the processing of Personal Data.
15. Requesting a Signed Copy
Business customers who require a counter-signed copy of this DPA, including executed Standard Contractual Clauses, may request one by emailing legal@getwebsitebuilt.com.