Data Processing Addendum
Last updated: June 2026
This Addendum forms part of the agreement between Sitelytc (“we”, the Processor) and the customer (“you”, the Controller) when we process personal data on your behalf. It is designed to satisfy Article 28 of the EU GDPR and the corresponding obligations under India's DPDPA 2023. A countersigned PDF is available on request.
1. Roles & scope
You are the Controller and determine the purposes of processing; we are the Processor and act only on your documented instructions. We process personal data solely to provide the engaged services (web engineering, AI automation, and security/compliance work).
2. Nature of data
Depending on the engagement we may process contact details, account data, usage and log data, and any content within systems we are retained to build or audit. Special-category data is processed only where expressly agreed.
3. Sub-processors
We engage the following sub-processors, each under contract:
| Sub-processor | Purpose | Region |
|---|---|---|
| Vercel | Hosting & edge delivery | USA / global |
| Cloudflare | DNS, WAF, DDoS protection | Global |
| Razorpay | Payments (India) | India |
| Stripe | Payments (international) | USA / EU |
| HubSpot | CRM & lead management | USA / EU |
| Upstash | Rate-limiting store | Global |
4. Security measures
We maintain technical and organisational measures including encryption in transit (TLS 1.3), least-privilege access with MFA, hardened application controls, rate limiting, audit logging, and a tested incident-response process. Details are on our Trust Center.
5. Breach notification
We will notify you without undue delay — and within 72 hours where feasible — after becoming aware of a personal-data breach affecting your data, with the information you need to meet your own obligations.
6. Data subject requests
We will assist you in responding to access, correction, deletion, and portability requests, and implement such requests on your instruction where the data sits in systems we operate.
7. International transfers
Where personal data is transferred outside its origin region, we rely on appropriate safeguards (e.g. Standard Contractual Clauses) and the sub-processor commitments above.
8. Return & deletion
On termination, we will return or delete personal data at your choice, save where retention is required by law.
9. Audits
We will make available the information necessary to demonstrate compliance and allow for reasonable audits, subject to confidentiality.
Request a signed copy
To execute this DPA, contact us via our contact page and we'll send a countersigned version.