Data Processing Agreement
Last updated: 20/09/2026
This Data Processing Agreement ("DPA") forms part of, and is subject to, the Terms of Service between Steve Homan, a sole trader, trading as AI My Site ("we", "us", "Processor") and the customer ("you", "Controller"). It applies wherever we process Personal Data on your behalf. Terms not defined here have the meaning given to them in the UK GDPR. By using our Services you agree to this DPA.
1. Roles
For Personal Data we process to provide the Services, you are the Controller and we are the Processor. Where our Services host a website that itself collects personal data from its visitors, you remain the Controller of that visitor data and we act as your Processor.
2. Subject-matter, duration, nature and purpose
We process Personal Data only to provide the Services described in the Terms. For One Site, this includes hosting your website, migrating it where applicable, and making changes that you have approved. For all plans, it includes scanning and analysing your website and providing reports and support. Processing lasts for the term of your subscription and any short wind-down period afterwards.
3. Types of data and categories of data subjects
(a) Your account and billing contact details (you and your staff). (b) The content of your website, which may contain personal data. (c) For One Site, personal data submitted by your website's visitors (for example via contact forms), to the extent it passes through systems we operate — note that our template contact forms deliver messages directly to your inbox and we do not store them.
4. Our obligations
We will: (a) process Personal Data only on your documented instructions (the Terms and your use of the Services being such instructions), unless required by law; (b) ensure persons authorised to process Personal Data are under an obligation of confidentiality; (c) implement appropriate technical and organisational security measures (see clause 6); (d) not engage a sub-processor except in accordance with clause 5; (e) assist you, taking into account the nature of the processing, in responding to requests to exercise data-subject rights; (f) assist you in ensuring compliance with your obligations on security, breach notification, and data-protection impact assessments; (g) at your choice, delete or return Personal Data at the end of the Services (see clause 8); and (h) make available information reasonably necessary to demonstrate compliance and allow for audits in accordance with clause 9.
5. Sub-processors
You give general authorisation for us to engage the sub-processors listed below. We impose data-protection terms on each sub-processor that are equivalent to those in this DPA. We will give you reasonable notice of any intended addition or replacement of a sub-processor, and you may object on reasonable data-protection grounds.
Current sub-processors:
-
Vercel — website and application hosting (EU/US)
-
Supabase — database for customer account data, hosted in the EU (AWS eu-west-1, Ireland)
-
Stripe — payment processing (UK/EU/US)
-
Resend — transactional email (EU/US)
-
GitHub — source code and customer website repositories (US)
-
ActiveCampaign — marketing and customer email (US)
-
OpenAI, Google and Anthropic — AI processing of website content for analysis (US)
6. Security measures
We maintain measures appropriate to the risk, including: encryption in transit (TLS); encryption at rest provided by our infrastructure providers; access controls and multi-factor authentication; least-privilege access; and, for One Site, an approval-before-change process, pre-change snapshots (version history), the ability to roll back a change, and a per-change record. We do not hold your website-platform passwords in the One Site hosting model. We carry professional indemnity and cyber insurance.
7. Breach notification
We will notify you without undue delay after becoming aware of a Personal Data Breach affecting your data, providing information reasonably available to help you meet your own notification obligations (including the duty to notify the ICO within 72 hours, which rests with you as Controller).
8. Return or deletion
On termination of the Services or on your request, we will delete or return the Personal Data we process on your behalf, unless retention is required by law. For One Site, your website is built on portable code that is downloadable and yours to keep, and your domain remains registered to you.
9. Audit
We will make available information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior notice and no more than once a year (or following a Personal Data Breach), allow you or an auditor you mandate to review that compliance, subject to confidentiality and to not disrupting our operations.
10. International transfers
Where Personal Data is transferred outside the UK/EEA (for example to sub-processors in the United States), we rely on the UK International Data Transfer Agreement (IDTA), the EU Standard Contractual Clauses with the UK Addendum, or another lawful transfer mechanism.
11. Liability and governing law
Liability under this DPA is subject to the limitations set out in the Terms of Service. This DPA is governed by, and construed in accordance with, the laws of England and Wales. A signed copy of this DPA is available to customers on request.