Draft — not yet reviewed by counsel
SITEFUEL

Legal

Data Processing Agreement

Version / effective date: 2026-07-14

This Data Processing Agreement ("DPA") forms part of the agreement between Kay Joosten, sole proprietor (eenmanszaak) under Dutch law ("Processor", "Site Fuel", "we") and the business customer identified in the applicable account ("Controller", "Customer"), and governs Site Fuel's processing of personal data on the Customer's behalf as required by Article 28 of the GDPR. Where the Customer's own website content includes personal data of identifiable individuals (e.g., named persons referenced in generated blog content, or visitor data surfaced through connected integrations), the Customer is the controller of that data and Site Fuel is the processor.

1. Subject Matter and Duration

Site Fuel processes personal data on the Customer's behalf for the duration of the Customer's subscription to the service, and thereafter only as needed to complete deletion obligations under Section 6.

2. Nature and Purpose of Processing

Site Fuel crawls Customer website content, generates SEO/GEO-optimised content using large language model providers, publishes that content to Customer-configured destinations, and optionally retrieves search performance metrics via Google Search Console — all as described in the Privacy Policy. Processing is limited to what is necessary to provide these functions.

3. Categories of Data and Data Subjects

Personal data processed under this DPA may include: names and contact details of Customer personnel with access to the account; and any personal data embedded in Customer website content that is crawled, processed, or referenced in generated content (data subjects: Customer's own website visitors, customers, or other individuals named in that content).

4. Subprocessors

The Customer authorizes Site Fuel to engage the following subprocessors, each bound by a data processing agreement providing GDPR-equivalent protections and, where applicable, Standard Contractual Clauses for transfers outside the EU/EEA:

SubprocessorRegionPurpose
StripeUSPayment processing and billing
HetznerDEHosting infrastructure
Google Search ConsoleUSSearch performance metrics (only for sites the Customer connects)
AnthropicUSAI content generation (default provider)
DeepSeekCNAI content generation — only when the Customer's account has explicitly opted in
[SMTP_PROVIDER]env-dependentTransactional email delivery

Site Fuel will provide reasonable advance notice before adding or replacing a subprocessor, giving the Customer the opportunity to object on reasonable data-protection grounds. Engaging DeepSeek never occurs without the Customer's account first opting in explicitly; it is not added to an account's processing by default.

5. Security Measures

Site Fuel implements technical and organisational measures appropriate to the risk, including:

6. Deletion on Termination

Upon termination of the Customer's subscription, or upon a verified erasure request, Site Fuel will delete the Customer's account data — users, connected-site configuration, content briefs, generated posts, feed entries, usage logs, and stored integration tokens — from its production systems, and will instruct Stripe to delete the associated customer record via Stripe's API. An audit record retaining only a hashed email and the deletion timestamp is kept as evidence of the deletion and to satisfy legitimate interest in preventing abuse of the deletion mechanism. Financial records required by Dutch fiscal law are retained for 7 years via Stripe independent of this deletion, as disclosed in the Privacy Policy.

7. Breach Notification

Site Fuel will notify the Customer without undue delay, and in any event within 72 hours of becoming aware, of any personal data breach affecting the Customer's data, providing the information reasonably available at the time (nature of the breach, categories and approximate number of data subjects and records affected, likely consequences, and measures taken or proposed) in line with our internal breach response runbook.

8. Assistance and Audits

Site Fuel will provide reasonable assistance to the Customer in responding to data subject requests and in meeting its own obligations under Articles 32–36 GDPR (security, breach notification, impact assessments), taking into account the nature of processing and information available to Site Fuel. The Customer may request reasonable evidence of Site Fuel's compliance with this DPA, including a summary of security measures and subprocessor agreements; on-site audits are subject to reasonable advance notice and confidentiality.

9. Liability and Governing Law

This DPA is governed by the laws of the Netherlands and is subject to the same limitation of liability terms as the Terms of Service, to the extent permitted by applicable law. Nothing in this DPA limits either party's liability for infringement of data subjects' rights where such limitation is not permitted under the GDPR.

10. Contact

Questions about this DPA, or requests related to subprocessors or security measures, can be directed to Kay Joosten, sole proprietor (eenmanszaak) under Dutch law at [ADDRESS] or via the contact details published on the Site Fuel website.