New — Instant agent preview + live AI-readiness scoring. Try it on your site, free →
Legal

Data Processing Addendum

Terms that apply when SiteGPT processes personal data on your behalf under GDPR and similar laws.

Last updated July 5, 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Service between the customer ("Controller") and SiteGPT by Omazy ("Processor") and applies where we process personal data on your behalf. To countersign a copy for your records, email legal@sitegpt.omazy.ai.

Roles

You are the Controller of personal data contained in the content you connect and in visitor conversations. We act as your Processor and process that data only on your documented instructions, which include your configuration of the Service.

Subject matter & nature of processing

ItemDetail
PurposeProvide the SiteGPT agent, answering and lead capture
DurationFor the term of the subscription
Data subjectsYour website visitors and end-users
Data typesContent you connect; messages, and any details visitors share

Sub-processors

You authorize us to engage sub-processors (hosting, LLM inference, analytics, email, payments) under written terms no less protective than this DPA. We maintain a current list and will give notice of changes so you can object on reasonable grounds.

Security measures

We maintain technical and organizational measures appropriate to the risk, including encryption in transit (TLS 1.3) and at rest (AES-256), role-based access controls, network isolation, and logging. See our Security overview.

Data-subject requests

We will assist you, taking into account the nature of processing, in responding to requests from data subjects to exercise their rights. Most requests can be actioned directly by deleting sources or conversations in the dashboard.

Personal-data breach

We will notify you without undue delay after becoming aware of a personal-data breach affecting your data, and provide information reasonably needed for you to meet your obligations.

Return & deletion

On termination, we will delete or return personal data within 30 days, unless retention is required by law.

International transfers

Where personal data is transferred outside the EEA/UK, we rely on Standard Contractual Clauses (and the UK Addendum where applicable) or another lawful transfer mechanism.

Audits

We will make available information reasonably necessary to demonstrate compliance with this DPA and allow for audits under reasonable, confidential arrangements.

Contact

Email legal@sitegpt.omazy.ai for a signed copy or questions.