Data Processing Agreement
Last updated 25/09/2025
Loading content...
Last updated 25/09/2025
WHEREAS
Specification | Details |
---|---|
Subject-matter of the Processing | The processing of Content Security Policy (CSP) violation reports and related website security data generated by the Customer's websites, applications, and online services. |
Duration of the Processing | For the term of the Principal Agreement between the Customer and the Processor, and until all Customer Data is deleted in accordance with Section 8 of the DPA. |
Nature and Purpose of the Processing | To provide web security and compliance services to the Customer, including:
|
Type of Personal Data Processed | The Personal Data processed is contained within the CSP violation reports and website scan data, and may include:
|
Categories of Data Subjects | The Personal Data processed relates to End-Users of the Customer's websites, applications, and online services. |
Sub-Processor | Purpose | Types of Data Processed | Location |
---|---|---|---|
OVHcloud | Cloud hosting and infrastructure provider for all core platform services and data. | All customer data, account data, service configuration, backups. | France |
Stripe | Payment processing for subscriptions and billing. | Name, email, payment method, billing address, transaction details. | USA |
PostHog | Analytics and performance monitoring to improve our website and services. | Usage data, device/browser info, anonymized event data. | EU |
Brevo | Transactional and marketing email delivery. | Name, email address, email content, engagement data. | EU |
Advertising and conversion tracking (for visitors from LinkedIn ads). | Cookie identifiers, IP address, browser/device info. | USA |