Data Processing Agreement
This Data Processing Agreement forms part of the terms of service between Presstack AI and the customer. It applies where Presstack AI processes personal data on the customer's behalf in providing the service.
Definitions
Terms such as "Personal Data", "Processing", "Controller", "Processor", "Data Subject", "Personal Data Breach", and "Supervisory Authority" have the meanings given in Data Protection Law, meaning the UK GDPR, the EU GDPR (Regulation (EU) 2016/679), the Data Protection Act 2018, and any other applicable data protection laws, as amended.
Customer Personal Data means personal data processed by Presstack AI on the customer's behalf under the service.
Roles And Scope
2.1 As between the parties, the customer is the controller (or processor acting for a third party controller) and Presstack AI is the processor of customer personal data.
2.2 This DPA covers personal data of the customer's own website visitors, enquirers, and customers that is processed through the service, for example, data submitted through the customer's WordPress site, content placed into the knowledge base, and data handled through Presstack AI's SEO and schema features.
2.3 The details of the processing are set out in Annex 1.
Presstack AI's Obligations As Processor
Presstack AI shall:
3.1 Process Only On Instructions Process customer personal data only on the customer's documented instructions (including those given through the service's settings), and as set out in this DPA and the terms, unless required by law. Where the law requires processing without prior notice to the customer, Presstack AI will inform the customer as soon as it is permitted to do so.
3.2 Confidentiality Ensure that personnel authorised to process customer personal data are bound by appropriate confidentiality obligations.
3.3 Security Implement appropriate technical and organisational measures to protect customer personal data, as described in Annex 2 (Article 32).
3.4 Sub Processors Engage sub processors only as permitted by clause 5.
3.5 Data Subject Requests Taking into account the nature of the processing, assist the customer by appropriate measures, so far as possible, in responding to requests from data subjects exercising their rights. If Presstack AI receives such a request directly, it will not respond except on the customer's instruction (unless legally required), and will inform the customer promptly.
3.6 Assistance Assist the customer in meeting its obligations under Articles 32 to 36 of the UK GDPR and EU GDPR, taking into account the nature of the processing and the information available to Presstack AI.
Customers' Obligations
4.1 The customer shall comply with data protection law in its capacity as controller, including having a valid lawful basis and providing required notices to data subjects.
4.2 The customer is responsible for the accuracy and lawfulness of customer personal data and of its instructions, and warrants it has the right to provide that data to Presstack AI for processing.
4.3 The customer must not provide special category or other sensitive data through the service unless it has confirmed Presstack AI can lawfully process it.
Sub Processors
5.1 The customer gives general authorisation for Presstack AI to engage sub processors to provide the service.
5.2 Presstack AI will impose data protection obligations on each sub processor that are no less protective than those in this DPA, and remains responsible for its sub processors' performance.
5.3 Presstack AI will give the customer reasonable notice of any intended addition or replacement of a sub processor (at least 14 days), so the customer can object on reasonable data protection grounds. If an objection cannot be resolved, the customer may terminate the affected part of the service.
International Transfers
6.1 Presstack AI and its sub processors may transfer customer personal data outside the UK / EEA only where an adequacy decision applies, or with appropriate safeguards in
place, such as the UK International Data Transfer Agreement / Addendum or the EU Standard Contractual Clauses, together with any additional measures required.Personal Data Breach
7.1 Presstack AI will notify the customer without undue delay on becoming aware of a personal data breach affecting customer personal data, using the account contact details, and will provide the information reasonably available, including (as it becomes known) the nature of the breach, likely consequences, and measures taken or proposed.
7.2 Presstack AI will cooperate with the customer and take reasonable steps to mitigate and remediate the breach.
Audits
8.1 Presstack AI will make available information necessary to demonstrate compliance with Article 28 and this DPA.
8.2 Where the customer reasonably requires further assurance, the customer (or an independent auditor it appoints) may audit Presstack AI's relevant processing, on reasonable prior notice (30 days), no more than once per year except following a personal data breach or at a supervisory authority's request, during business hours, and without unreasonable disruption. The parties will bear their own costs unless otherwise agreed.
Liability
The liability of each party under this DPA is subject to the limitations and exclusions of liability in the terms of service, except to the extent data protection law requires otherwise.
Term, Deletion And Return
10.1 This DPA lasts as long as Presstack AI processes customer personal data under the service.
10.2 On termination or expiry, Presstack AI will, at the customer's choice, delete or return customer personal data, and delete existing copies, unless the law requires it to keep the data. The customer should export any data it wishes to keep before terminating. Standard deletion period: Within 90 days.
Governing Law
This DPA is governed by the law stated in the terms of service (England and Wales), without prejudice to mandatory provisions of data protection law.
Annex 1, Details Of Processing
Subject Matter Provision of the Presstack AI service (WordPress SEO automation, AI schema generation, GEO and AEO features, location triangulation, and data handling through the plugin and platform).
Duration For the term of the service, plus any deletion and return period.
Nature And Purpose Hosting, storing, organising, generating, analysing, and transmitting customer personal data as needed to provide the service and the features the customer uses.
Types Of Personal Data Names, email addresses, phone numbers, postal addresses, message content, and other data submitted through the customer's WordPress site, knowledge base, or content, as determined by the customer.
Categories Of Data Subjects The customer's website visitors, enquirers, leads, and customers.
Special Categories None, unless separately agreed in writing.
Annex 2, Technical And Organisational Measures (Article 32)
Encryption of data in transit (TLS), and at rest where applicable.
Access controls and least privilege access for personnel.
Authentication controls and secure credential storage.
Network and application security controls; regular patching.
Logging and monitoring of access and activity.
Backups and tested restoration procedures.
Staff confidentiality undertakings and data protection awareness.
Secure software development and change management practices.
Incident response and breach handling procedures.
Sub processor due diligence and contractual safeguards.
Annex 3, Sub Processors
Hostinger Service Hosting and Storage Stripe Subscription and payment processing Anthropic, Fal.ai AI text and image generation Hostinger Transactional and form notification email Google Product and Usage Analytics Google Maps, Places, Search Console, Analytics, Read Only Business Profile Google Google Reviews