Precision Digital Architecture

00

Data Processing Addendum

Last updated: June 2026

This Addendum forms part of the agreement between Sitelytc (“we”, the Processor) and the customer (“you”, the Controller) when we process personal data on your behalf. It is designed to satisfy Article 28 of the EU GDPR and the corresponding obligations under India's DPDPA 2023. A countersigned PDF is available on request.

1. Roles & scope

You are the Controller and determine the purposes of processing; we are the Processor and act only on your documented instructions. We process personal data solely to provide the engaged services (web engineering, AI automation, and security/compliance work).

2. Nature of data

Depending on the engagement we may process contact details, account data, usage and log data, and any content within systems we are retained to build or audit. Special-category data is processed only where expressly agreed.

3. Sub-processors

We engage the following sub-processors, each under contract:

Sub-processorPurposeRegion
VercelHosting & edge deliveryUSA / global
CloudflareDNS, WAF, DDoS protectionGlobal
RazorpayPayments (India)India
StripePayments (international)USA / EU
HubSpotCRM & lead managementUSA / EU
UpstashRate-limiting storeGlobal

4. Security measures

We maintain technical and organisational measures including encryption in transit (TLS 1.3), least-privilege access with MFA, hardened application controls, rate limiting, audit logging, and a tested incident-response process. Details are on our Trust Center.

5. Breach notification

We will notify you without undue delay — and within 72 hours where feasible — after becoming aware of a personal-data breach affecting your data, with the information you need to meet your own obligations.

6. Data subject requests

We will assist you in responding to access, correction, deletion, and portability requests, and implement such requests on your instruction where the data sits in systems we operate.

7. International transfers

Where personal data is transferred outside its origin region, we rely on appropriate safeguards (e.g. Standard Contractual Clauses) and the sub-processor commitments above.

8. Return & deletion

On termination, we will return or delete personal data at your choice, save where retention is required by law.

9. Audits

We will make available the information necessary to demonstrate compliance and allow for reasonable audits, subject to confidentiality.

Request a signed copy

To execute this DPA, contact us via our contact page and we'll send a countersigned version.

Data Processing Addendum (DPA) | Sitelytc