1. Scope and order of precedence
This Data Processing Addendum (“DPA”) supplements the PagePith Terms of Service or another written agreement governing the customer’s use of the Services (the “Agreement”). It applies when PagePith processes Customer Personal Data on behalf of Customer. If this DPA conflicts with the Agreement on the processing of Customer Personal Data, this DPA controls. The Standard Contractual Clauses control over conflicting terms concerning a Restricted Transfer.
2. Definitions and roles
“Data Protection Laws” means privacy and data-protection laws applicable to the processing, including the EU GDPR, UK GDPR, and California Consumer Privacy Act as amended by the CPRA (“CCPA”). “Customer Personal Data” means personal data contained in URLs, retrieved page content, monitor configuration, callbacks, or other data submitted to the Services by or for Customer. “SCCs” means Commission Implementing Decision (EU) 2021/914.
Customer is a controller and PagePith is its processor. If Customer processes personal data for another controller, Customer is a processor and PagePith is its subprocessor. PagePith remains an independent controller for account, billing, security, and direct business data described in the Privacy Policy.
3. Processing instructions
Customer instructs PagePith to process Customer Personal Data only to provide, secure, support, and maintain the Services; comply with documented instructions consistent with the Agreement; and comply with applicable law. PagePith will notify Customer if, in its opinion, an instruction violates Data Protection Laws, unless prohibited by law.
Customer is responsible for the lawfulness, accuracy, and quality of Customer Personal Data, for providing required notices, and for obtaining a valid legal basis for retrieving and using target-page content. Customer will not submit special-category, highly sensitive, or regulated data unless PagePith has expressly agreed in writing to that processing.
4. Confidentiality and security
PagePith will ensure that people authorized to process Customer Personal Data are bound by confidentiality obligations and receive access only as necessary. PagePith will maintain appropriate technical and organizational measures proportionate to the risk, including the measures in Schedule 2, and may update them without materially decreasing overall security.
5. Data-subject requests and compliance assistance
Taking into account the nature of processing, PagePith will provide reasonable assistance for Customer to respond to data-subject requests and to meet obligations concerning security, breach notifications, data-protection impact assessments, and prior consultation. If PagePith receives a request concerning Customer Personal Data, it will direct the requester to Customer unless legally required to respond directly.
6. Personal data breaches
PagePith will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data. The notice will include available information reasonably needed for Customer’s notification obligations. PagePith’s notice is not an admission of fault or liability.
7. Subprocessors
Customer grants PagePith general written authorization to use the subprocessors on the Subprocessor List. PagePith will impose data-protection obligations substantially equivalent to those in this DPA and remains responsible for a subprocessor’s performance of those obligations.
PagePith will publish notice of a new or replacement subprocessor at least 30 days before it begins processing Customer Personal Data. Customer may object during that period on reasonable data-protection grounds by emailing support@pagepith.com. The parties will work in good faith on a reasonable alternative. If none is available, Customer may stop using the affected feature and terminate it without penalty.
8. Return and deletion
During the term, Customer may retrieve outputs through the Services. On termination or a verified request, PagePith will delete or return Customer Personal Data unless law requires retention. Data in backups will be isolated from ordinary use and deleted according to the applicable backup cycle. Service-specific retention periods are described in Schedule 1 and the Privacy Policy.
9. Information and audits
PagePith will make information reasonably necessary to demonstrate compliance with this DPA available to Customer. No more than once annually, unless required by a regulator or following a relevant breach, Customer may request a reasonable audit. Audits must protect other customers’ information, avoid unreasonable disruption, and use existing independent reports before requesting an on-site review. Customer bears its audit costs unless the audit identifies a material breach by PagePith.
10. International transfers
For a transfer of Customer Personal Data from the EEA to a country without an applicable adequacy decision, the parties incorporate the unmodified EU SCCs by reference. Module 2 applies when Customer is a controller and PagePith is a processor; Module 3 applies when Customer is a processor and PagePith is a subprocessor. Option 2 in Clause 9 applies with the 30-day notice period in Section 7. The competent supervisory authority is determined under Clause 13, Irish law governs Clause 17, and the courts of Ireland apply under Clause 18.
For UK restricted transfers, the parties incorporate the UK International Data Transfer Addendum to the EU SCCs. For Swiss transfers, references in the SCCs will be interpreted to include the Swiss Federal Act on Data Protection, with the Swiss Federal Data Protection and Information Commissioner acting as competent authority where applicable. The transfer details and safeguards in Schedules 1 and 2 complete the relevant annexes.
The official EU SCC text is available from the European Commission.
11. California service-provider terms
To the extent the CCPA applies, PagePith acts as Customer’s service provider or contractor. PagePith will not sell or share Customer Personal Data; retain, use, or disclose it outside the direct business relationship or for a purpose other than the business purposes in the Agreement; or combine it with personal information from another source except as permitted by the CCPA. PagePith certifies that it understands and will comply with these restrictions, will provide the same level of privacy protection required by the CCPA, and will notify Customer if it can no longer meet them. Customer may take reasonable and appropriate steps to stop and remediate unauthorized use after notice.
Schedule 1 — Details of processing
| Subject matter | Retrieving public URLs, generating structured page content, caching results, monitoring pages, and delivering requested callbacks and notifications. |
|---|---|
| Duration | For the Agreement term plus documented retention and deletion periods. Successful scrape results are cached for seven days by default; monitoring history is generally retained for 30 days and the current baseline while a monitor exists. |
| Nature and purpose | Collection, retrieval, organization, extraction, storage, comparison, transmission, return, and deletion as needed to provide the Services. |
| Data subjects | Customer users, Customer end users, notification recipients, and individuals whose information appears on Customer-selected public pages. |
| Personal data | Names, business contact details, online identifiers, submitted URLs, public page content, monitor settings, webhook destinations, and technical usage data. |
| Sensitive data | Not intended or permitted without a separate written agreement. |
| Frequency | Intermittently or continuously, as initiated and configured by Customer. |
Schedule 2 — Technical and organizational measures
- TLS for public Service traffic and provider-managed encryption at rest for hosted data stores.
- Credential-based authentication, scoped API keys, rate limits, and logical customer separation.
- Encryption of stored monitoring webhook secrets and restricted handling of production secrets.
- Public-URL and private-network validation designed to reduce server-side request-forgery risk.
- Structured security logging, error monitoring, health metrics, and incident investigation procedures.
- Data minimization, documented retention windows, monitor deletion, and cache invalidation controls.
- Dependency management, change review, least-privilege access, and confidentiality obligations.
- Infrastructure resilience, backups, and recovery capabilities provided through contracted hosting services.
Schedule 3 — Parties and subprocessors
PagePith’s legal party is DiCarlo Software Solutions LLC, 425 W Colonial Dr Ste 101 Orlando, FL 32801, reachable at support@pagepith.com. The executed DPA or Order Form supplies Customer’s legal name, address, contact, role, and signature date for SCC Annex I. The current authorized subprocessors and processing locations for SCC Annex III are maintained on the Subprocessor List.