Data protection
Data Processing Addendum
The Article 28 terms that apply when we process personal data on your behalf. Public, pre-signed, and already in force — this is the document your security reviewer is looking for.
Last updated
The short version
This DPA applies to every customer automatically. You do not need to negotiate or sign it, though we will sign a copy if your procurement process needs one.
You are the controller of the website content we process for you. We are the processor, and we act only on your instructions.
The Standard Contractual Clauses and the UK Addendum are incorporated by reference for international transfers.
We notify you of a personal data breach within 72 hours, give 30 days’ notice before adding a subprocessor, and never sell your data or use it to train models.
This summary is for orientation only. The numbered sections below are the agreement.
1.Scope and incorporation
This Data Processing Addendum (“DPA”) applies whenever ReadyLayer processes personal data on your behalf in the course of providing the service. It forms part of, and is governed by, our Terms of Service.
You do not need to sign this
This DPA applies automatically to every customer, with no countersignature and no negotiation required. If your procurement process needs an executed copy on paper, email legal@readylayer.io and we will sign this document as it stands.
Where this DPA conflicts with the Terms of Service on the subject of personal data, this DPA wins. Where it conflicts with a signed order form or a negotiated data processing agreement, that document wins.
2.Definitions
Data Protection Laws means all laws applicable to the processing of personal data under this agreement, including the EU General Data Protection Regulation (2016/679) and its UK equivalent, the Swiss Federal Act on Data Protection, and US state privacy legislation including the California Consumer Privacy Act as amended.
Controller, Processor, Data Subject, Personal Data, Processing and Personal Data Breach have the meanings given in the GDPR. Business, Service Provider, Sell and Share have the meanings given in the CCPA.
Customer Personal Data means personal data we process on your behalf: personal data contained in the website content we collect when auditing sites you nominate, and any personal data reaching us through the ReadyLayer script tag installed on your sites.
SCCs means the Standard Contractual Clauses approved by European Commission Implementing Decision (EU) 2021/914.
3.Our respective roles
- You are the controller of Customer Personal Data. You decide which sites we audit, what content those sites carry, and what purpose the processing serves.
- We are the processor of Customer Personal Data, acting only on your documented instructions.
- We are an independent controller of your own account data — the email address, name and billing details of the people who use ReadyLayer. That is governed by our Privacy Policy, not by this DPA, because we decide what to collect and why.
Your instructions are: this DPA, the Terms of Service, and your use of the product’s features. We will tell you if, in our opinion, an instruction infringes Data Protection Laws, and we may suspend the processing concerned until it is resolved.
4.Details of the processing
The description required by Article 28(3) of the GDPR, and by Annex I of the SCCs:
Subject matter. Provision of the ReadyLayer service: auditing websites you nominate, generating and hosting a machine-readable Agent Layer from their content, monitoring for changes, and reporting crawler activity.
Duration. For as long as your account is open, plus any period during which residual data is retained as described in deletion and return.
Nature and purpose. Fetching publicly accessible pages; extracting, storing, analysing and transforming their content; generating derived files; hosting and serving those files; recording aggregate counts of AI crawler visits; and providing support. (Our own website analytics are outside this Annex: visitors to readylayer.io are not Customer Personal Data, and we act as controller for them — see our Privacy Policy.)
Categories of personal data. We do not require or request personal data, and the service is not designed to collect it — but it will be present in Customer Personal Data to the extent it appears in your published website content. That typically means:
- Names, job titles, photographs, biographies and business contact details published on your pages — team pages, author bylines, testimonials, case studies.
- Any other personal data you have chosen to publish on a page we audit, including within its structured data and metadata.
- Technical data transmitted by the script tag. In practice this is limited to a site identifier and, for automated crawler traffic only, a user-agent string that is used in memory and discarded — see what the script tag sends.
Special category data. The service is not intended for special category data under GDPR Article 9, or for criminal offence data. Do not publish it on pages you ask us to audit, and do not submit it to us. If you must, tell us first so we can agree appropriate additional safeguards.
Categories of data subjects. Individuals whose personal data appears in your website content — for example your personnel, authors, customers featured on your site, and named third parties. And, in the limited technical sense described above, visitors to sites where you have installed the script tag.
Frequency. Continuous for the duration of the service, and on each audit, monitoring run and page load of a site carrying the script tag.
5.Our obligations
We will:
- Process Customer Personal Data only on your documented instructions, including for international transfers, unless required otherwise by law — in which case we will tell you first, unless the law forbids it.
- Ensure that everyone we authorise to process Customer Personal Data is bound by an appropriate duty of confidentiality.
- Implement and maintain the technical and organisational measures described in security measures.
- Assist you, taking into account the nature of the processing, in responding to data subject requests, and in meeting your obligations under Articles 32 to 36 of the GDPR — security, breach notification, and data protection impact assessments.
- Notify you of a Personal Data Breach as set out in breach notification.
- Make available the information reasonably necessary to demonstrate our compliance, and permit audits as set out in audits.
- Delete or return Customer Personal Data as set out in deletion and return.
- Never sell or share Customer Personal Data, and never use it for our own purposes, for advertising, or to train machine learning models.
6.Your obligations
You are responsible for:
- Having a lawful basis for the processing you instruct, and having given data subjects any notice their rights require.
- Being entitled to submit each domain you nominate — the representation you give in the Terms of Service. We cannot verify authorisation on your behalf, and this DPA does not create one.
- The accuracy and legality of the content on the sites you ask us to audit, and for not publishing special category data on them.
- Assessing whether the script tag requires any notice or consent on your site under your local law, and providing it if so.
- Configuring the service appropriately, and managing who you invite into your workspace and what they can see.
7.Subprocessors
You give us general written authorisation to engage subprocessors. We impose data protection obligations on each of them that are no less protective than those in this DPA, and we remain fully liable to you for their performance.
Our current subprocessors:
| Subprocessor | Service provided | Data processed |
|---|---|---|
| Supabase | Authentication and our primary application database | Account email, display name, sign-in identity, and all data stored by the product, including the page content we collect when auditing your sites |
| Stripe | Subscription billing and payment processing | Your name, email, billing address and payment method, collected directly by Stripe at checkout. We store only the resulting customer and subscription identifiers — never card numbers |
| Amazon Web Services (S3) | Storage of the Agent Layer files we generate for you | Content derived from the pages we audit on your sites |
| Cloudflare | DNS, TLS, content delivery, Turnstile anti-abuse challenges, and access control for our internal admin tools | Network metadata for requests to our services, including IP address and browser user agent. Turnstile additionally receives an IP address and challenge token when a challenge is shown |
| Resend | Transactional and product email, and our marketing contact list | The recipient's email address and the contents of the message, such as a team invitation. We also keep a standing contact record for each account holder — email address, display name, and your account's plan and status — so that product announcements reach the right people; it is removed when your account is deleted, and you can unsubscribe at any time from the link in any such message |
| Sentry | Error monitoring and performance diagnostics | Technical diagnostics when something breaks: stack traces, request context and the account associated with the error |
| Hetzner | Hosting for our application and background job servers | Data processed by the product while it runs on our servers |
Notice and objection
We will give at least 30 days’ notice before a new subprocessor begins processing Customer Personal Data, by updating this page and notifying account owners. To be notified directly, email privacy@readylayer.io and ask to be added to the list.
You may object on reasonable data protection grounds within those 30 days. We will work with you to find an alternative. If we cannot, you may terminate the affected part of the service and we will refund the unused portion of what you have paid.
8.Data subject requests
If a data subject contacts us directly about Customer Personal Data, we will not respond to the substance of the request. We will tell them to contact you, and let you know it happened, unless we are legally prohibited from doing so.
Most requests you can satisfy yourself: your dashboard lets you delete any site, which permanently removes its stored page content, audit history and generated files. Where you need more than the product offers, email privacy@readylayer.io and we will assist within a timeframe that lets you meet your own statutory deadline.
9.Personal data breach notification
We will notify you without undue delay, and in any case within 72 hours of becoming aware of a Personal Data Breach affecting Customer Personal Data.
Our notice will describe, so far as we know it at the time:
- the nature of the breach and the data and data subjects affected;
- the likely consequences;
- the measures taken or proposed to address it and limit harm;
- a contact point for further information.
Where we cannot provide all of that at once, we will give what we have and follow up as the investigation progresses rather than delay the first notice. We will not require you to wait for a complete picture before starting your own regulatory clock.
10.Security measures
The technical and organisational measures we maintain, as required by Article 32 of the GDPR and Annex II of the SCCs:
- Encryption in transit. All traffic to our services uses TLS. Our crawler communicates with target sites over their own transport.
- Tenant isolation. Every table in our database enforces row-level security, so one workspace’s data is unreachable from another’s session even if application code is at fault. This is verified on every deployment, which fails if any table lacks it.
- Access control. Administrative access to customer accounts is limited to named staff, is granted only from the command line rather than through the admin interface, and sits behind a separate access layer requiring single sign-on and multi-factor authentication.
- Accountability. Every administrative action on a customer account writes an audit record in the same database transaction as the change, so an action cannot succeed unlogged.
- Secret handling. Credentials and tokens are stripped from diagnostic and error reports before they leave our systems.
- Input and egress controls. Every URL submitted to the service is validated, and requests resolving to private, loopback, link-local or cloud-metadata addresses are refused — at submission, at fetch time, at every redirect hop, and for every subresource the headless browser requests.
- Abuse controls. Public endpoints are rate limited by IP address and protected by anti-abuse challenges.
- Minimisation by design. The script tag stores no identifier on a visitor’s device and transmits no visitor identity; visitor URLs and user-agent strings sent by the crawler beacon are discarded rather than stored.
- Resilience. Our database provider maintains automated backups with point-in-time recovery.
- Change control. Schema changes ship as reviewed, version-controlled migrations, and the test suite runs on every change.
11.International transfers
We are operated from the United States, and our subprocessors run infrastructure in the United States and Europe.
Where Customer Personal Data is transferred out of the UK, the European Economic Area or Switzerland to a country without an adequacy decision:
- The SCCs are incorporated into this DPA by reference and apply automatically. Module Two (controller to processor) applies where you are a controller; Module Three (processor to processor) where you are yourself a processor.
- For the SCCs, you are the data exporter and we are the data importer. The optional docking clause applies. For Clause 17 the governing law is that of Ireland, and for Clause 18 the forum is the courts of Ireland. The Annexes are populated by details of the processing, subprocessors and security measures.
- For UK transfers, the UK International Data Transfer Addendum to the SCCs applies, with the tables completed by reference to the same sections.
- For Swiss transfers, references to the GDPR are read as references to the Swiss FADP, and the Swiss Federal Data Protection and Information Commissioner is the competent authority.
We will tell you if we become subject to a legally binding request from a public authority for Customer Personal Data, and will challenge requests that appear unlawful, unless we are prohibited from doing either.
12.Audits
On reasonable written request, and no more than once a year unless a Personal Data Breach or a regulator requires otherwise, we will provide the information reasonably necessary to demonstrate our compliance with this DPA — including answering a security questionnaire.
Where documentation genuinely does not satisfy your obligations under Article 28(3)(h), we will agree a further audit with you in advance: conducted during business hours, without unreasonable disruption, subject to confidentiality, and at your cost. An auditor who is a competitor of ours is not acceptable.
13.California
For personal information subject to the CCPA, you are the Business and we are a Service Provider. We are prohibited from, and will not:
- sell or share that personal information, as those terms are defined in the CCPA;
- retain, use or disclose it for any purpose other than performing the service specified in the Terms of Service, or as otherwise permitted by the CCPA;
- retain, use or disclose it outside the direct business relationship between us;
- combine it with personal information received from another source, except as the CCPA permits a service provider to do.
We certify that we understand and will comply with these restrictions, and we will notify you if we determine we can no longer meet them.
14.Deletion and return
You can delete Customer Personal Data yourself at any time. Deleting a site from your dashboard permanently removes its stored page content, including the stored page HTML, along with its audit history and generated files.
On termination, we will delete Customer Personal Data within 30 days of your request, or return it to you first if you ask before then. Export what you need before you close your account.
Two honest exceptions. We may retain Customer Personal Data where law requires it, for as long as it requires — in which case we keep processing it protected and process it for no other purpose. And copies may persist in routine encrypted backups until those backups age out on their normal cycle; they are not restored into service except for disaster recovery.
15.Liability, changes and precedence
- Liability under this DPA is subject to the limitations and exclusions in the Terms of Service. Where the SCCs apply, nothing here limits any liability the SCCs themselves do not permit to be limited, or a data subject’s rights under them.
- Changes. We may update this DPA to reflect changes in law, in our subprocessors, or in the service. Material changes get at least 30 days’ notice, as under the Terms.
- Precedence. The SCCs prevail over this DPA where they conflict; this DPA prevails over the Terms of Service on personal data; a signed order form or negotiated agreement prevails over all of them.
- Contact. Data protection questions and requests under this DPA go to privacy@readylayer.io; contractual matters to legal@readylayer.io.