Back to homepage

Data Processing Agreement (DPA)

pursuant to Art. 28 GDPR · Last updated: September 2026

Preamble and parties

This Data Processing Agreement ("DPA") is concluded between the customer of the SiteGuard platform as controller ("Controller") and Davies Meyer GmbH, Spielbudenplatz 24-25, 20359 Hamburg, Germany, represented by its Managing Director Nikolaus Meyer, as processor ("Processor"). This DPA specifies the parties' data protection obligations under the SiteGuard terms of service. It takes effect when the service contract is concluded. In case of conflict, this DPA prevails over the terms of service in matters of data protection. The German version is legally binding.

1. Subject matter and duration

The subject matter is the processing of personal data by the Processor when providing the SiteGuard SaaS platform (automated technical checks of websites, storage of results, report generation, notifications). The duration corresponds to the term of the service contract, including any free trial. The obligations under section 10 survive termination.

2. Nature and purpose of processing

• Retrieval and analysis of the websites specified by the Controller (HTML, cookies, network requests, third-party connections) • Storage of scan results, findings and reports • Management of the Controller's user accounts (team members, roles) • Sending notifications (email, configured webhooks) • AI-assisted evaluation of aggregated scan results Processing takes place exclusively to provide the contractually agreed services.

3. Types of data and categories of data subjects

Types of data: • Contact and login data of the Controller's users (name, email address, role, password hash) • Usage and log data (IP address, timestamps, actions) • Content of scanned websites where it contains personal data (e.g. names or email addresses in a legal notice, cookie identifiers, tracker parameters) • Configuration data (website URLs, webhook targets) Data subjects: • Employees and agents of the Controller who use SiteGuard • Persons whose data is publicly available on the scanned websites

4. Controller's instructions

The Processor processes personal data only on documented instructions from the Controller unless required to do so by law (Art. 28(3)(a) GDPR). Instructions result from the service contract, the Controller's configuration of the platform and this DPA. Further instructions are given in text form to datenschutz@daviesmeyer.com. If the Processor considers an instruction unlawful, it informs the Controller without undue delay.

5. Confidentiality

The Processor only uses persons who have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and limits access to what is necessary to provide the services.

6. Technical and organisational measures (Art. 32 GDPR)

The Processor implements in particular the following measures: • Encryption in transit: all connections to the platform exclusively via TLS (HTTPS, HSTS) • Encryption at rest by the database provider Supabase (database region EU/Frankfurt) • Access control: authentication by password (stored only as a hash), sign-in link or single sign-on; rate limiting against brute-force attacks • Authorisation: role-based permissions (admin, member, viewer); all data queries are scoped to the signed-in user's organisation • Row Level Security in the database: no table access via public database keys • API keys are stored only as hashes • Security headers (including Content-Security-Policy, X-Frame-Options) • Administrative access restricted to authorised personnel of the Processor • Automatic deletion of scan data after the retention period The Processor may adapt the measures to the state of the art provided the level of protection is not reduced.

7. Sub-processors

The Controller authorises the use of the following sub-processors. The Processor contractually binds them to a level of protection equivalent to this DPA. Transfers to third countries only take place under the conditions of Art. 44 et seq. GDPR.

ProviderPurposeLocationTransfer basis
Vercel Inc.Hosting of the web application, website delivery, server logsUSAEU-US Data Privacy Framework (where certified) or EU Standard Contractual Clauses (Art. 46(2)(c) GDPR)
Supabase Inc.Database (account, organisation and scan data)Database region EU (Frankfurt, aws-eu-central-1)Stored in the EU; for any access from the USA: EU-US Data Privacy Framework (where certified) or EU Standard Contractual Clauses (Art. 46(2)(c) GDPR)
Inngest Inc.Execution of background jobs (scheduled scans, reports, notifications)USAEU-US Data Privacy Framework (where certified) or EU Standard Contractual Clauses (Art. 46(2)(c) GDPR)
Anthropic PBCAI-assisted evaluation of aggregated scan results (AI reports)USAEU-US Data Privacy Framework (where certified) or EU Standard Contractual Clauses (Art. 46(2)(c) GDPR)
ResendSending transactional emails (sign-in links, password reset, scan notifications)USAEU-US Data Privacy Framework (where certified) or EU Standard Contractual Clauses (Art. 46(2)(c) GDPR)
Stripe Payments Europe Ltd.Payment processing and subscription managementIreland (EU); Stripe sub-processors possibly in the USAWithin the EU; for transfers to the USA: EU-US Data Privacy Framework (where certified) or EU Standard Contractual Clauses (Art. 46(2)(c) GDPR)
Upstash, Inc.Rate limiting to prevent abuse (only hashed identifiers are stored)USA (provider)EU-US Data Privacy Framework (where certified) or EU Standard Contractual Clauses (Art. 46(2)(c) GDPR)
Microsoft (Entra ID)Sign-in with a Microsoft account (single sign-on) – only if you use this optionEU/USAEU-US Data Privacy Framework (where certified) or EU Standard Contractual Clauses (Art. 46(2)(c) GDPR)

7a. Changes and right to object

The Processor informs the Controller in text form at least 30 days before engaging a new or replacing an existing sub-processor (e.g. by email or by updating this page with notice by email). The Controller may object to the change within this period for an important data protection reason. If the parties cannot agree, the Controller may terminate the service contract with effect from the date the change takes effect.

8. Assistance with data subject rights and Controller obligations

The Processor assists the Controller with appropriate measures in responding to requests from data subjects (Art. 12–22 GDPR) and in complying with the obligations under Art. 32–36 GDPR (security, notification of personal data breaches, data protection impact assessment). If a data subject contacts the Processor directly, the Processor forwards the request to the Controller without undue delay. The Processor notifies the Controller of personal data breaches without undue delay after becoming aware of them.

9. Audit rights

The Processor makes available to the Controller all information necessary to demonstrate compliance with this DPA and allows for audits, including inspections, by the Controller or an auditor mandated by the Controller who is bound to confidentiality. Inspections must be announced with reasonable notice (usually 14 days) and carried out during normal business hours without disrupting operations. Compliance may also be demonstrated by current attestations, reports or certifications of the sub-processors used.

10. Deletion and return after termination

After termination of the service contract, the Processor deletes all personal data processed on behalf of the Controller unless there is a legal obligation to retain it. Before deletion, the Controller can download scan results via the platform's export functions (PDF, CSV, JSON). Independently of this, scan data is automatically deleted after 12 months at the latest during the contract term.

11. Final provisions

Amendments to this DPA require text form. German law applies; the place of jurisdiction is Hamburg. If individual provisions are invalid, the validity of the remaining provisions remains unaffected. Contact for data protection matters: datenschutz@daviesmeyer.com