Legal
Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the agreement between Kay Joosten, sole proprietor (eenmanszaak) under Dutch law ("Processor", "Site Fuel", "we") and the business customer identified in the applicable account ("Controller", "Customer"), and governs Site Fuel's processing of personal data on the Customer's behalf as required by Article 28 of the GDPR. Where the Customer's own website content includes personal data of identifiable individuals (e.g., named persons referenced in generated blog content, or visitor data surfaced through connected integrations), the Customer is the controller of that data and Site Fuel is the processor.
1. Subject Matter and Duration
Site Fuel processes personal data on the Customer's behalf for the duration of the Customer's subscription to the service, and thereafter only as needed to complete deletion obligations under Section 6.
2. Nature and Purpose of Processing
Site Fuel crawls Customer website content, generates SEO/GEO-optimised content using large language model providers, publishes that content to Customer-configured destinations, and optionally retrieves search performance metrics via Google Search Console — all as described in the Privacy Policy. Processing is limited to what is necessary to provide these functions.
3. Categories of Data and Data Subjects
Personal data processed under this DPA may include: names and contact details of Customer personnel with access to the account; and any personal data embedded in Customer website content that is crawled, processed, or referenced in generated content (data subjects: Customer's own website visitors, customers, or other individuals named in that content).
4. Subprocessors
The Customer authorizes Site Fuel to engage the following subprocessors, each bound by a data processing agreement providing GDPR-equivalent protections and, where applicable, Standard Contractual Clauses for transfers outside the EU/EEA:
| Subprocessor | Region | Purpose |
|---|---|---|
| Stripe | US | Payment processing and billing |
| Hetzner | DE | Hosting infrastructure |
| Google Search Console | US | Search performance metrics (only for sites the Customer connects) |
| Anthropic | US | AI content generation (default provider) |
| DeepSeek | CN | AI content generation — only when the Customer's account has explicitly opted in |
| [SMTP_PROVIDER] | env-dependent | Transactional email delivery |
Site Fuel will provide reasonable advance notice before adding or replacing a subprocessor, giving the Customer the opportunity to object on reasonable data-protection grounds. Engaging DeepSeek never occurs without the Customer's account first opting in explicitly; it is not added to an account's processing by default.
5. Security Measures
Site Fuel implements technical and organisational measures appropriate to the risk, including:
- Encryption at rest for sensitive stored values, including third-party publisher credentials and connected-integration tokens (encrypted using MultiFernet symmetric encryption at the application layer before persistence).
- Encryption in transit via TLS for all API and admin interface traffic.
- Access control, including role-based access to the admin interface, per-account API key scoping, and least-privilege access to production systems for personnel.
- Regular review of access and dependency security as part of normal engineering practice.
6. Deletion on Termination
Upon termination of the Customer's subscription, or upon a verified erasure request, Site Fuel will delete the Customer's account data — users, connected-site configuration, content briefs, generated posts, feed entries, usage logs, and stored integration tokens — from its production systems, and will instruct Stripe to delete the associated customer record via Stripe's API. An audit record retaining only a hashed email and the deletion timestamp is kept as evidence of the deletion and to satisfy legitimate interest in preventing abuse of the deletion mechanism. Financial records required by Dutch fiscal law are retained for 7 years via Stripe independent of this deletion, as disclosed in the Privacy Policy.
7. Breach Notification
Site Fuel will notify the Customer without undue delay, and in any event within 72 hours of becoming aware, of any personal data breach affecting the Customer's data, providing the information reasonably available at the time (nature of the breach, categories and approximate number of data subjects and records affected, likely consequences, and measures taken or proposed) in line with our internal breach response runbook.
8. Assistance and Audits
Site Fuel will provide reasonable assistance to the Customer in responding to data subject requests and in meeting its own obligations under Articles 32–36 GDPR (security, breach notification, impact assessments), taking into account the nature of processing and information available to Site Fuel. The Customer may request reasonable evidence of Site Fuel's compliance with this DPA, including a summary of security measures and subprocessor agreements; on-site audits are subject to reasonable advance notice and confidentiality.
9. Liability and Governing Law
This DPA is governed by the laws of the Netherlands and is subject to the same limitation of liability terms as the Terms of Service, to the extent permitted by applicable law. Nothing in this DPA limits either party's liability for infringement of data subjects' rights where such limitation is not permitted under the GDPR.
10. Contact
Questions about this DPA, or requests related to subprocessors or security measures, can be directed to Kay Joosten, sole proprietor (eenmanszaak) under Dutch law at [ADDRESS] or via the contact details published on the Site Fuel website.