Data Processing Agreement
Last updated 25/09/2025
Loading content...
Last updated 25/09/2025
WHEREAS
| Specification | Details |
|---|---|
| Subject-matter of the Processing | The processing of Content Security Policy (CSP) violation reports and related website security data generated by the Customer's websites, applications, and online services. |
| Duration of the Processing | For the term of the Principal Agreement between the Customer and the Processor, and until all Customer Data is deleted in accordance with Section 8 of the DPA. |
| Nature and Purpose of the Processing | To provide web security and compliance services to the Customer, including:
|
| Type of Personal Data Processed | The Personal Data processed is contained within the CSP violation reports and website scan data, and may include:
|
| Categories of Data Subjects | The Personal Data processed relates to End-Users of the Customer's websites, applications, and online services. |
| Sub-Processor | Purpose | Types of Data Processed | Location |
|---|---|---|---|
| OVHcloud | Cloud hosting and infrastructure provider for all core platform services and data. | All customer data, account data, service configuration, backups. | France |
| Stripe | Payment processing for subscriptions and billing. | Name, email, payment method, billing address, transaction details. | USA |
| PostHog | Analytics and performance monitoring to improve our website and services. | Usage data, device/browser info, anonymized event data. | EU |
| Brevo | Transactional and marketing email delivery. | Name, email address, email content, engagement data. | EU |
| Advertising and conversion tracking (for visitors from LinkedIn ads). | Cookie identifiers, IP address, browser/device info. | USA |