Data Processing Agreement
Version 1.0
This Data Processing Agreement ("DPA") forms part of the Terms of Service ("Principal Agreement") between W3 EDGE, LLC d/b/a Auctollo ("Auctollo," "Processor," "we") and the customer identified in the Principal Agreement ("Customer," "Controller," "you").
This DPA applies whenever Auctollo processes Customer Personal Data on Customer’s behalf in the course of providing the Auctollo cloud platform (the "Service"). Customer Personal Data means personal data about Customer’s end users, website visitors, or other natural persons that Auctollo processes as a processor on Customer’s instructions — distinct from data Auctollo collects as a controller of its own customer relationship (covered by the Privacy Policy).
This DPA is intended to satisfy Article 28 of the EU GDPR (Regulation (EU) 2016/679), the UK GDPR, and equivalent provisions of other applicable data-protection laws ("Data Protection Laws").
In the event of a conflict between this DPA and the Principal Agreement with respect to the processing of Customer Personal Data, this DPA controls.
1. Definitions
Unless otherwise defined here, capitalized terms have the meanings given in the Principal Agreement or in GDPR Article 4.
- "Controller," "Processor," "Data Subject," "Personal Data," "Processing," and "Supervisory Authority" have the meanings set out in GDPR Article 4.
- "Sub-processor" means any third party engaged by Auctollo to process Customer Personal Data on Auctollo’s behalf.
- "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses adopted by the European Commission Implementing Decision (EU) 2021/914 (Module 2: Controller-to-Processor) for transfers to third countries.
- "Personal Data Breach" has the meaning given in GDPR Article 4(12).
2. Roles of the Parties
For the purposes of this DPA and with respect to Customer Personal Data:
- Customer is the Controller.
- Auctollo is the Processor.
Where Auctollo processes Personal Data about Customer itself (account email, billing data, admin display name) in the course of operating the Service, Auctollo acts as a Controller of that data, governed by the Privacy Policy. This DPA does not apply to such processing.
3. Subject Matter and Duration
| Item | Description |
|---|---|
| Subject matter | Auctollo’s provision of the Service to Customer under the Principal Agreement. |
| Duration | The term of the Principal Agreement plus any post-termination period required by Section 11 (data return / deletion). |
| Nature | Hosted sitemap generation, indexing-status monitoring, AI-assisted SEO analysis, redirect monitoring, 404 logging. |
| Purpose | Performing the Service for Customer’s benefit per Customer’s instructions and the Principal Agreement. |
4. Categories of Data Subjects and Personal Data
4.1 Categories of Data Subjects
- Visitors to Customer’s website(s).
- Individuals named, identified, or referenced in content published on Customer’s website(s) (authors, subjects of articles, comment authors).
- Individuals submitting forms, queries, or other inputs that produce URLs containing identifying parameters.
4.2 Categories of Customer Personal Data
The Service is designed to operate primarily on URLs and content metadata, not on personal data directly. Nevertheless, Customer Personal Data processed may include:
| Category | Examples |
|---|---|
| URL data | Page paths, query parameters, fragments that may identify individuals if Customer’s URL structure includes user identifiers. |
| Content metadata | Post titles, meta descriptions, schema markup, author bylines that may name individuals. |
| Crawl data | Page text excerpts and structured data ingested by AI features. |
| Redirect / 404 logs | Source URLs (which may contain query-string personal data) and HTTP referer headers. |
| End-user identifiers | Where Customer chooses to submit them, indexing-status queries against URLs that uniquely identify a person. |
Auctollo does not intentionally request or solicit special-category personal data under GDPR Article 9. Customer is responsible for not transmitting special-category data through the Service except as strictly necessary and lawful.
5. Customer’s Obligations and Rights
Customer:
- Represents and warrants that it has the legal right to disclose Customer Personal Data to Auctollo and to instruct Auctollo to process it under this DPA.
- Is solely responsible for the accuracy, quality, and legality of Customer Personal Data.
- Will comply with all applicable Data Protection Laws in its use of the Service, including obtaining valid consent where required, providing notices, and honoring Data Subject rights.
- Will give Auctollo clear, lawful, documented instructions for processing. The Principal Agreement, this DPA, and Customer’s use of the Service constitute Customer’s documented instructions.
If Auctollo, in its reasonable judgment, believes an instruction infringes Data Protection Laws, Auctollo will notify Customer and may suspend the disputed processing until resolved.
6. Auctollo’s Obligations as Processor
Auctollo will:
- Process Customer Personal Data only on Customer’s documented instructions, except where required by EU, member-state, or other applicable law (in which case Auctollo will inform Customer first unless the law prohibits notice).
- Ensure that persons authorized to process Customer Personal Data are bound by confidentiality obligations.
- Implement and maintain the technical and organizational security measures in Section 8.
- Respect the conditions on engaging Sub-processors in Section 7.
- Assist Customer, by appropriate measures, in fulfilling Customer’s obligation to respond to Data Subject requests under GDPR Chapter III.
- Assist Customer in ensuring compliance with GDPR Articles 32–36 (security, breach notification, DPIAs, prior consultation).
- At Customer’s choice, delete or return all Customer Personal Data after the end of the Principal Agreement, per Section 11.
- Make available all information necessary to demonstrate Article 28 compliance, and allow for audits per Section 10.
7. Sub-processors
7.1 General Authorization
Customer provides general authorization for Auctollo to engage Sub-processors, subject to the conditions in this Section.
7.2 Current Sub-processors
As of the Effective Date, Auctollo engages the following Sub-processors:
| Sub-processor | Role | Processing location |
|---|---|---|
| Supabase, Inc. | Database, authentication, edge functions | AWS US-East-1 (EU-region option available) |
| Vercel, Inc. | Web application hosting and CDN | Global edge network |
| Stripe, Inc. | Payment processing and subscription management | United States |
| Inngest, Inc. | Background job queue | United States |
| Resend, Inc. | Transactional email delivery | United States |
| Mailchimp (Intuit Inc.) | Marketing email and waitlist communications | United States |
| Cloudflare, Inc. | DNS, edge security, DDoS protection | Global edge network |
| Anthropic, PBC | AI feature processing (primary) | United States |
| OpenAI, OpC, L.P. | AI feature processing (fallback) | United States |
| Google LLC (Vertex AI / Gemini API) | AI feature processing (fallback) | United States |
| AWS Route 53 | DNS routing for auctollo.com and app.auctollo.com | United States |
This list is also reflected in Privacy Policy Section 3 and is kept in sync.
7.3 EU Data-Region Option
Customers who require EU-region processing for GDPR purposes may opt into an EU data-region configuration. Contact legal@auctollo.com to enable this for your account.
7.4 Notification of Changes
Auctollo will:
- Maintain a current list at /legal/dpa#sub-processors.
- Notify Customer of any intended addition or replacement of a Sub-processor at least 30 days before the change takes effect.
- Allow Customer to object on reasonable data-protection grounds within the notice period. If Auctollo cannot accommodate the objection, Customer may terminate the affected Service for a pro-rated refund of prepaid fees.
7.5 Sub-processor Obligations
Auctollo will impose on each Sub-processor data-protection obligations no less protective than those imposed on Auctollo under this DPA, and remains fully liable to Customer for any Sub-processor breach.
8. Security Measures
- Encryption in transit: All Customer Personal Data is transmitted over TLS 1.2 or higher.
- Encryption at rest: Sub-processor managed encryption for primary stores.
- Authentication credentials: API keys and OAuth tokens stored as SHA-256 hashes; full secrets never retained.
- Row-level isolation: Supabase RLS policies enforce per-Customer data isolation at the database layer.
- Access control: Production access restricted to authorized Auctollo personnel with MFA required.
- Logging and monitoring: Security-relevant events are logged and reviewed.
- Vendor security: All Sub-processors reviewed for security posture (SOC 2, ISO 27001) prior to engagement.
- Incident response: Auctollo maintains an internal incident-response runbook.
9. International Data Transfers
Where Auctollo’s processing involves a transfer of Personal Data from the EEA, UK, or Switzerland to a country without an adequacy decision, the transfer is governed by:
- The EU Standard Contractual Clauses (Module 2: Controller-to- Processor, Implementing Decision (EU) 2021/914), incorporated by reference.
- For UK transfers, the UK International Data Transfer Addendum to the EU SCCs, incorporated by reference.
- For Swiss transfers, the EU SCCs with adaptations recommended by the FDPIC.
Auctollo will, where applicable, conduct transfer impact assessments and implement supplementary measures per Schrems II and subsequent EDPB guidance.
10. Audit Rights
- Auctollo will make available, on reasonable request and subject to confidentiality, the most recent third-party audit reports (e.g., SOC 2 Type II of relevant Sub-processors) and security documentation reasonably necessary to demonstrate compliance.
- Where that information is insufficient, Customer (or an independent auditor bound by confidentiality) may conduct an audit no more than once per 12-month period, on at least 30 days’ notice, during business hours, without unreasonably interfering with Auctollo’s operations.
- Customer bears audit costs unless the audit reveals a material breach by Auctollo, in which case Auctollo bears the reasonable costs.
11. Data Return and Deletion
- Upon termination, Auctollo will, at Customer’s choice and at no additional cost, either return all Customer Personal Data in a commonly used, machine-readable format, or delete it (including from routine backups within the standard 30-day backup rotation).
- Customer may exercise this choice by written request to legal@auctollo.com within 30 days after termination. If not exercised within that period, Auctollo will delete.
- Auctollo may retain Customer Personal Data after termination only as required by law, keeping it confidential and protected per this DPA.
12. Personal Data Breach Notification
Auctollo will notify Customer of a Personal Data Breach affecting Customer Personal Data without undue delay and, where feasible, within 72 hours of becoming aware. The notification will, to the extent then known, describe:
- The nature of the breach, including categories and approximate number of Data Subjects and records affected.
- The contact point for further information.
- The likely consequences.
- The measures taken or proposed to address the breach and mitigate its effects.
Auctollo will provide reasonable cooperation to assist Customer in meeting Customer’s own breach-notification obligations under Articles 33–34 GDPR.
Contact for security disclosures and breach notifications: legal@auctollo.com.
13. Assistance with Data Subject Requests
Taking into account the nature of the processing, Auctollo will assist Customer by appropriate measures, insofar as possible, to fulfil Customer’s obligations to respond to Data Subject requests under GDPR Articles 15–22.
Where a Data Subject contacts Auctollo directly with such a request, Auctollo will (a) inform the Data Subject that the request should be directed to Customer, and (b) promptly forward the request to Customer.
14. Order of Precedence
In the event of any conflict between this DPA and the Principal Agreement, this DPA prevails with respect to the processing of Customer Personal Data. Between this DPA and the SCCs incorporated under Section 9, the SCCs prevail.
15. Changes to this DPA
Auctollo may update this DPA from time to time. Material changes (such as changes to Sub-processors, security commitments, or transfer mechanisms) will be notified to Customer by email at least 30 days before they take effect, in line with Section 7.4. Continued use of the Service after the effective date constitutes acceptance, subject to Customer’s objection rights under Section 7.4.
A signed (countersigned) PDF copy of this DPA is available on request to enterprise customers at legal@auctollo.com.
16. Contact
W3 EDGE, LLC d/b/a Auctollo
9450 SW Gemini Drive, PMB 22185
Beaverton, OR 97008-7105, US
Email: legal@auctollo.com
This DPA forms part of, and is governed by, the Terms of Service between you and Auctollo. Capitalized terms not defined here have the meanings given in the Terms of Service or in Article 4 of the GDPR.