WebsiteOS

Data Processing Agreement

Last updated: 27 July 2026

1. Scope and roles

This Data Processing Agreement ("DPA") forms part of the agreement between WebsiteOS LLC, a company registered in the Sharjah Media City Free Zone, UAE (the "Processor") and the customer (the "Controller"). It applies where WebsiteOS processes personal data on the Controller's behalf, in particular personal data submitted by visitors to the Controller's website. For that processing the Controller determines the purposes and means, and WebsiteOS acts only on the Controller's documented instructions. Where terms conflict, this DPA prevails on data protection matters.

2. Processing details

The subject matter, duration, nature, and purpose of the processing, the types of personal data, and the categories of data subjects are set out in Annex 1.

3. Processor obligations (GDPR Art. 28(3))

WebsiteOS will:
  • (a) Instructions. Process personal data only on the Controller's documented instructions, including on international transfers, unless required to do otherwise by applicable law (in which case it will inform the Controller, unless the law prohibits it). WebsiteOS will immediately inform the Controller if, in its opinion, an instruction infringes data protection law.
  • (b) Confidentiality. Ensure that persons authorized to process the personal data are bound by an appropriate duty of confidentiality.
  • (c) Security. Implement the technical and organizational measures required by GDPR Art. 32, as described in Annex 2.
  • (d) Sub-processors. Engage sub-processors only under the Controller's general written authorization (the current list is at websiteos.ai/subprocessors), give at least 30 days' notice of additions or replacements with an opportunity to object, and impose the same data protection obligations on each sub-processor by contract. WebsiteOS remains fully liable to the Controller for its sub-processors.
  • (e) Data subject rights. Assist the Controller, by appropriate technical and organizational measures, in responding to requests from data subjects exercising their rights.
  • (f) Assistance. Assist the Controller with security of processing, personal data breach notification (Arts. 33-34), data protection impact assessments (Art. 35), and prior consultation (Art. 36). WebsiteOS will notify the Controller without undue delay after becoming aware of a personal data breach.
  • (g) Deletion or return. At the Controller's choice, delete or return all personal data at the end of the service and delete existing copies, unless retention is required by law.
  • (h) Audits. Make available the information needed to demonstrate compliance with Art. 28 and allow for and contribute to audits, including inspections, conducted by the Controller or a mandated auditor, subject to reasonable notice and confidentiality.

4. International transfers

Where WebsiteOS or a sub-processor transfers personal data outside the EEA, the transfer is covered by an appropriate safeguard under GDPR Chapter V (an adequacy decision, or Standard Contractual Clauses with supplementary measures). Details are on the Sub-processors page. The EU Commission's Standard Contractual Clauses (Decision 2021/914), in the applicable module, are incorporated by reference for any such transfer and prevail in case of conflict.

5. Term

This DPA takes effect when the Controller accepts the WebsiteOS Terms of Service or otherwise begins using the service, and continues for as long as WebsiteOS processes personal data on the Controller's behalf.

Annex 1 — Details of processing

  • Subject matter: hosting of the Controller's website and storage of data submitted through it.
  • Duration: the term of the Controller's subscription.
  • Nature and purpose: to host the website and to receive, store, and make available to the Controller data submitted by the Controller's website visitors (for example, contact and lead form submissions).
  • Types of personal data: name, email address, phone number, message content, and technical identifiers such as IP address and analytics identifiers of the Controller's website visitors.
  • Categories of data subjects: the Controller's website visitors and prospective customers.

Annex 2 — Security measures (Art. 32)

  • Encryption of personal data in transit (TLS) and at rest.
  • Access controls and row-level security on the database, restricting access to authorized persons.
  • Data stored in the EU region (Frankfurt) where the provider offers it.
  • Regular encrypted backups held in the EU.
  • A documented incident-response process for personal data breaches.
  • Sub-processors bound by equivalent security obligations.