Data Processing Agreement
How SiteVigilante processes personal data on your instructions, and the sub-processors involved.
Version 1.0 · in effect from 30 August 2026 · TEAMDIGITAL BV, Zaventem, Belgium
This Agreement governs the personal data you put into SiteVigilante about people who are not you: your clients, their staff, and the users of the websites you manage. For that data you are the controller and TEAMDIGITAL BV is your processor. It is incorporated by reference into the Terms of Service and takes effect when you accept them. No separate signature is required.
Personal data about you — your own account, your billing details — is a different relationship, in which we are the controller. The Privacy Policy covers that one.
1. What we process, and why
| Item | Detail |
|---|---|
| Subject matter | Providing SiteVigilante: maintaining, monitoring and reporting on the WordPress websites you connect. |
| Duration | For as long as your workspace exists. It ends when you delete the workspace or the contract ends. |
| Nature and purpose | Storing, organising, analysing and displaying the data back to you; sending the alerts and reports you configure; and running the updates and checks you ask for. |
| Categories of data subject | Your client organisations' contact people; WordPress administrators of the websites you connect; and, incidentally, any person named in error text a website produces. |
| Types of personal data | Names, email addresses and roles of client contacts; WordPress administrator usernames where a website reports them; website addresses; and free text — your own client notes, error excerpts, file content excerpts, and the answers you type into the business questionnaire — which can contain personal data we do not control the shape of. The questionnaire asks about tasks and documents rather than people, and says so beside every field, but it is free text and we do not police what is typed into it. |
| Special categories | None is asked for and none is required. The product has no field for it. If it reaches us it does so inside free text you or a website produced. |
2. What we undertake
- We act only on your instructions. Using the product is how you give them. We do not process your clients' data for our own purposes, and we do not use it to train anything.
- Confidentiality. Everyone with access is bound to keep it confidential.
- Security. The measures in section 4.
- Sub-processors. Section 3, with the full list in Annex B.
- Assistance. We help you answer a data subject who asks for access, correction or erasure — in most cases you can do it yourself in the product, immediately, without asking us.
- Breach notification. If we become aware of a personal data breach affecting your data we tell you without undue delay, with what we know and what we are doing about it.
- Deletion. Section 5.
- Audit. We give you the information you reasonably need to show we are meeting these obligations, and we will answer a security questionnaire.
3. Sub-processors
You give general authorisation for the sub-processors in Annex B. If we intend to add or replace one we will publish the change on the sub-processors page and notify account owners at the address they gave us, so you can object. If you object on reasonable data protection grounds and we cannot offer an alternative, you may terminate.
Each sub-processor is bound by obligations no less protective than these, and we remain responsible to you for what they do.
That list is kept honest by the build rather than by memory. An automated check sweeps this application for every outbound connection it makes and fails if one appears that is not declared. A new third party is therefore a broken build until somebody discloses it.
3.1 Anthropic and Google — the conditions, stated exactly
Two of the recipients in Annex B are outside the EU, and both are reached only under specific conditions. Those conditions are stated here rather than left to Annex B's summary, because "we send data to Anthropic" and "we send data to Anthropic when an update you ran has failed, if the operator has configured a key" are different facts, and only the second one is true.
Neither provider receives anything while it is unconfigured. The credential for each is a platform setting held by TEAMDIGITAL BV. Where it is absent the feature is unavailable and no request leaves the platform at all — the code returns before it would build one. This is not a policy we apply; it is the order the operations happen in.
Anthropic receives the context of an update on your website that failed or was rolled back, so it can explain in plain language what went wrong. That is sent when you run an update that then fails — which sends it automatically, without a further press — and when you press Explain on an entry in your update history. Nothing is sent for an update that succeeds, and nothing is sent on a schedule. What travels is described in Annex B: it includes an excerpt of the error text the website produced, which we do not control the shape of and which can contain a file path or a name. Your websites' content, their credentials, their databases and anything about their visitors are not sent.
Google receives the address of a page, and nothing else, on two occasions. The first is when you ask us to measure how fast it loads, on one website or across your estate. The second is when you spend a credit on a Growth Scan for a website and confirm it: that scan asks Google to measure the page as a phone and as a desktop computer would load it. Google then loads the page itself, over the public internet, as any visitor would. Nothing from the website's content and nothing about its visitors is sent, and no measurement happens on a schedule — both occasions are an action you take, and the second one additionally requires the explicit purchase and the explicit confirmation described below.
If Google cannot be reached, the scan reports that part as not measured. It does not report a score of zero. Those two look the same in a table and mean opposite things, and an agency acting on the second would rebuild a website that was working.
Search Console and Google Analytics
You can connect a website to a Google Search Console property and to a Google Analytics property. Nothing is connected unless you connect it, and we never infer a property from a website's address: a domain property and a URL-prefix property for the same domain hold different data, and guessing would report a different website's figures inside a report you resell.
Once connected, a Growth Scan you buy and confirm asks Google for that property's own figures. We send a property name and a date range and nothing else, and we read what is already yours. Access is read only, it is granted by you inside your own Google account, and you can withdraw it there at any time. This product never writes to your Google account.
A website you have not connected is reported in the scan as not measured. It is never reported as having no search traffic and never as having no visitors: those are different statements and only one of them is true.
Websites you name for comparison
A Growth Scan can compare a website against competitors you type in yourself when you confirm the scan. This product never chooses, guesses or infers a competitor: if you name none, none is fetched. Each address you give is checked against the same outbound rules as every other destination here and is refused if it does not resolve to a public website, and each refusal is reported back to you with its reason rather than dropped.
What those websites receive is an ordinary request for their public home page, exactly as a visitor's browser would make. They are sent nothing about you, nothing about your clients, and nothing that identifies the website being scanned. They are not sub-processors and appear in no annex, because they receive no personal data from us.
The written analysis in a Growth Scan
When you buy a Growth Scan and confirm it for a named website, the measurements that scan took and the answers you typed into its questionnaire are sent to Anthropic so the analysis can be written. This requires an explicit purchase or credit and an explicit confirmation for that website, both recorded before anything runs. An AI Growth Scan is never performed automatically, never on a schedule, and never as a side effect of anything else you do in the product.
What is sent is the measurements themselves: an identifier, a label, a value, and which part of this product produced it. Your website's pages and their content are not sent, nor its credentials, nor your account details, nor anything about your visitors, nor any other website of yours, nor any earlier scan. Nothing is sent at all if the analysis step is not configured on this installation.
We record which model answered, when, and a fingerprint of the evidence that went in and the answer that came back, so that an analysis can be traced to the measurements that produced it. We do not store the model's reasoning and we never store a credential.
4. Security measures
- Encryption in transit, with HTTP Strict Transport Security in force.
- Passwords stored only as hashes; optional two-factor authentication; session cookies marked HttpOnly and Secure.
- Each workspace is isolated from every other, enforced where the application resolves a record rather than by a check in each controller — so a route added later cannot quietly skip it.
- Credentials are excluded from what the application serialises, held by an automated check over the controllers.
- Role separation inside a workspace, and an audit log of actions taken.
- Access to production is restricted to the operator.
- Destructive actions on a connected website require a person to authorise that exact action, and a separate technical check must independently establish that it is safe. Neither substitutes for the other.
4.1 Backups — stated as measured
TEAMDIGITAL BV does not currently operate a backup or snapshot mechanism of its own for the SiteVigilante platform database. This was investigated rather than assumed: there is no backup job, no scheduled database dump and no backup tooling on the platform.
Whether our infrastructure provider retains snapshots or backups at the infrastructure layer is NOT ESTABLISHED. It cannot be determined from the platform itself, and we will not state a retention period we have not verified.
The practical consequence, which matters for your own compliance position: the deletion in section 5 is not silently undone by a backup of ours, and equally there is no backup of ours to restore your data from. This paragraph concerns the SiteVigilante platform database only.
Separately from the platform database above, SiteVigilante can take a copy of a connected website's database, and has done so during controlled testing. When this happens it is started by a named person at TEAMDIGITAL BV and never on a schedule; there is no control in the product for you or your clients to start one.
Stated exactly, because the distinction matters: such a copy contains the website's database only. It does not contain files, uploads, themes or plugins, and it is not a website backup. A copy is verified before it is kept and is held outside any web-reachable location.
A verified copy is now stored off-site in encrypted form, in a private object-storage bucket located in Germany. It is encrypted on our own server before it is transmitted, so the storage provider holds ciphertext and never the contents of your clients' databases. Each agency's copies live in a separate repository under a separate key: one agency's key cannot open another agency's copies. Retention is 7 daily, 4 weekly and 12 monthly copies; older ones are removed. The unencrypted copy is deleted from our server once the encrypted copy is stored.
What this is not: it is not a website backup, because files, uploads, themes and plugins are not in it; there is no control in the product for you or your clients to start, schedule or restore one; and nothing here is offered as a backup service you can rely on. If you need your clients' websites backed up, that remains something you arrange yourself.
5. Return and deletion
You can delete a single website or your entire workspace from inside the product at any time, without asking us. Deleting a website erases the data attached to that website; deleting the workspace erases every table carrying your account, your users and their sessions, and the account itself, in a single transaction that either completes or changes nothing. Both are held by automated checks that read the database schema at run time, so a new table without an erasure rule fails the build.
You can export or copy what you need before you delete. After deletion we cannot return it, because it is gone.
6. International transfers
The platform runs in Germany. Two sub-processors process data in the United States — Anthropic and Google — for the narrow purposes named in Annex B and under the conditions stated exactly in section 3.1, on the transfer safeguards those providers offer, including Standard Contractual Clauses where they apply. A transfer to either one happens only when something you did causes it, and no transfer happens at all while that provider's credential is unconfigured. Everything else in Annex B runs in the EU, except Stripe, which operates in Ireland and the United States.
7. Liability and precedence
This Agreement forms part of the Terms of Service and the liability provisions there apply to it. Where this Agreement and the Terms conflict on the processing of personal data, this Agreement wins. It is governed by Belgian law, before the courts of Brussels, Belgium.
Annex A — the processing, in one line
TEAMDIGITAL BV processes the personal data described in section 1, on your documented instructions, for the purpose of providing SiteVigilante to you, for as long as your workspace exists.
Annex B — authorised sub-processors
Recipients: parties we send data to
Stripe
Subscription billing.
- What it receives
- Your agency name, billing email address, payment details you enter on Stripe's own form, and the number of websites you have connected. We never see or store a card number.
- Where it runs
- Ireland and the United States.
Mailgun EU
Sending email: alerts, digests, invites, password resets and verification.
- What it receives
- The recipient address and the contents of the message, which can name your websites and what happened on them.
- Where it runs
- European Union.
Anthropic
Explaining an update that failed or was rolled back, in plain language, and writing the analysis in a Growth Scan you have bought.
- What it receives
- The name and type of the plugin or theme, the version it moved between, what the outcome was, the WordPress and PHP versions, the active theme, how many plugins are installed, the last steps of the run, and an excerpt of the error text from the website. Error text is written by the website and can contain a file path or a person's name. Your website's content, its credentials, its database and anything about its visitors are not sent.
- What causes it to be sent
- Running an update that then fails or is rolled back, which sends this automatically; pressing Explain on an entry in your update history; or buying a Growth Scan and confirming it for a named website. All three are actions you take. Nothing is sent for an update that succeeds, and no scan runs without an explicit purchase and an explicit confirmation.
- While it is not configured
- Nothing is sent unless an Anthropic key is configured on this installation by the operator. Without one the explanation is simply unavailable and no request leaves the platform.
- Where it runs
- United States.
Measuring how fast a page loads and how it behaves on a phone, through PageSpeed Insights.
- What it receives
- The address of the page being measured, and nothing else. Google then loads that page itself, over the public internet, exactly as any visitor would. We send no content from the website, nothing about its visitors, and nothing that identifies you.
- What causes it to be sent
- Two things you do, and nothing else. Pressing Measure on a website, or starting a performance measurement across your estate. And buying or spending a credit on a Growth Scan for a website and confirming it: a scan measures the page on a phone and on a desktop. Nothing is measured on a schedule and no scan runs without that explicit confirmation.
- While it is not configured
- PageSpeed answers without a key, at a lower rate, so this one is reachable on any installation. It is still only reached by one of the two actions above. If it cannot be reached, the scan reports that part as not measured rather than as a score of zero.
- Built, but not yet reachable
- Search Console and analytics are built to be read here and are NOT YET REACHABLE: no website can be connected to a Search Console or analytics property in this product, so no property is named, no figures are requested, and neither API has been contacted. When a connection becomes possible it will be one you make yourself, inside your own Google account, with read-only access you can withdraw there.
- Where it runs
- United States.
RDAP bootstrap (rdap.org), and through it the registry for each domain
Reading the published expiry date of a website's domain name (T-52), so an agency is warned before a domain lapses and takes the website and its email with it.
- What it receives
- The domain name of one of your websites, and nothing else. No address inside it, no account, and nothing saying which agency asked.
- Where it runs
- The registry that operates each top-level domain. Location varies by domain.
WordPress.org
Looking up whether a plugin is still published and what it requires.
- What it receives
- The slug of a plugin installed on one of your websites. No address, no account and nothing identifying which website it came from.
- Where it runs
- United States.
Infrastructure: where the platform itself runs
Hetzner Online GmbH
Hosting the SiteVigilante platform: the application server, its database, its queue and its uploaded files.
- What it holds
- Everything SiteVigilante stores. The server holds the database, so every fact on this page that we keep rather than send is kept here.
- Where it runs
- Germany.
Vulnerability matching is deliberately absent from both lists. The public CVE list is copied to our own servers and every comparison happens there, so no website, no component inventory and no question about your estate is sent to that source.
Questions, or a request about your data, go to support@sitevigilante.com.