Data Processing Addendum
This Data Processing Addendum (DPA) supplements the SiteOwl Terms of Service between SiteOwl (SiteOwl), and the Client. It applies only when SiteOwl processes personal data contained in or accessible through the Client’s website or connected systems solely to deliver the Client’s documented instructions.
1. Roles and scope
For processing covered by this DPA, the Client is the personal information controller or controller and SiteOwl is the personal information processor or processor. SiteOwl remains an independent controller for information it processes for its own account administration, billing, security, legal compliance and business operations, as described in the Privacy Policy.
The subject matter is focused website support, maintenance and related portal communication. Processing lasts for the service relationship and any limited retention period required for return, deletion, legal compliance or claims.
2. Documented instructions
SiteOwl will process covered personal data only on the Client’s documented instructions, including the Terms, accepted task briefs and task conversations, unless law requires otherwise. If legally permitted, SiteOwl will inform the Client before processing required by law.
SiteOwl will notify the Client if an instruction appears to violate applicable data-protection law and may pause the affected work while the issue is resolved.
3. People and data involved
Depending on the Client website and task, data subjects may include the Client’s customers, prospects, users, employees, contractors, suppliers and other website visitors.
Data may include names, business contact details, account or enquiry information, website-submission content, order or booking information, technical identifiers and other information visible in the website administration area. SiteOwl does not intentionally require special-category, sensitive, payment-card authentication, health, government-identifier or similarly high-risk data unless separately agreed with appropriate safeguards.
The Client is responsible for limiting SiteOwl’s access to what is necessary and for avoiding unnecessary personal data in task briefs, screenshots, exports and files.
4. Confidentiality and access
SiteOwl will restrict covered personal data to authorised persons who need it for the service and are subject to confidentiality obligations. SiteOwl will use reasonable least-privilege access practices and will not disclose covered data except as permitted by this DPA, the Terms, documented Client instructions or applicable law.
5. Security measures
Taking account of the nature and risk of the processing, SiteOwl will maintain reasonable administrative, technical and organisational safeguards, including as appropriate:
- protected client-portal access and permission checks;
- encrypted transport for supported systems;
- encrypted storage for website credentials in the current portal implementation;
- separate website accounts and least-privilege access where supported;
- access limitation and confidentiality practices;
- security updates and supported hosting controls; and
- secure deletion or revocation procedures when access is no longer required.
No system can guarantee absolute security. The Client remains responsible for its hosting, website configuration, user permissions, backups, legal notices and security decisions outside SiteOwl’s control.
6. Subprocessors and international processing
The Client authorises SiteOwl to use subprocessors reasonably necessary to provide the service, subject to appropriate contractual and security obligations. The current core hosting and email provider is Hostinger. SiteOwl operates from the Philippines, and Hostinger currently hosts the SiteOwl website and portal in Indonesia; provider affiliates, support, email and backup operations may involve other countries.
SiteOwl will remain responsible for a subprocessor’s performance of the data-protection obligations assigned to it to the extent required by applicable law. SiteOwl will make current material subprocessor information available and provide notice of a material new subprocessor where required, giving the Client a reasonable opportunity to raise a documented data-protection objection.
Where a restricted international transfer mechanism is required, the parties will cooperate to put an applicable mechanism in place, such as recognised standard contractual clauses or an addendum.
7. Data-subject requests and compliance assistance
Taking account of the nature of processing and information available, SiteOwl will reasonably assist the Client with:
- requests by data subjects to exercise applicable rights;
- security and breach obligations;
- data-protection impact assessments or regulator consultations where legally required; and
- information reasonably necessary to demonstrate compliance with this DPA.
If SiteOwl receives a request concerning covered Client data, it will ordinarily direct the requester to the Client unless law permits or requires SiteOwl to respond directly. Assistance outside the ordinary service scope may be charged at a disclosed reasonable rate unless the need arose from SiteOwl’s breach.
8. Personal-data incidents
SiteOwl will notify the Client without undue delay after becoming aware of a confirmed personal-data breach affecting covered Client data, to the extent required by applicable law. The notice will include information reasonably available to help the Client understand the nature, likely consequences, affected data and mitigation. SiteOwl’s notice is not an admission of fault or liability.
The Client is responsible for determining whether notice to individuals, regulators or others is legally required, with SiteOwl providing reasonable assistance.
9. Return and deletion
At the end of the relevant service, SiteOwl will, at the Client’s written choice and subject to applicable law, return or delete covered Client personal data reasonably within SiteOwl’s control. SiteOwl may retain limited information where legally required or reasonably necessary for the establishment, exercise or defence of legal claims, with access restricted to that purpose.
Stored website credentials are deleted when no longer needed and no later than the period stated in the Privacy Policy. Data remaining in managed backups is removed through the applicable backup cycle and remains protected until deletion. If a backup is restored, relevant deletion instructions will be reapplied.
10. Review and audit information
On reasonable written request, SiteOwl will provide information reasonably necessary to demonstrate compliance with this DPA. If that information is insufficient and applicable law requires an audit, the parties will agree a proportionate process that protects other clients, confidential information and system security.
Unless an audit identifies material noncompliance by SiteOwl, the Client bears its audit costs. Audits should ordinarily occur no more than once in a 12-month period and during normal business hours with reasonable notice.
11. Client obligations
The Client warrants that its instructions and disclosure of personal data to SiteOwl are lawful; that it has provided required notices and obtained any required permissions; and that it will not instruct SiteOwl to process data in violation of applicable law.
The Client remains responsible for responding to data subjects and regulators as controller, determining lawful purposes and retention, and configuring the Client website to collect no more data than necessary.
12. Priority and termination
If this DPA conflicts with the Terms on the processing of covered Client personal data, this DPA controls for that issue. The liability provisions in the Terms apply to this DPA unless applicable law requires otherwise.
This DPA ends when SiteOwl has completed the covered processing and returned or deleted covered personal data as required, except for provisions that must continue by their nature.
Processing details
| Subject matter | Elementor and WordPress website support, maintenance, task communication and related troubleshooting |
|---|---|
| Duration | Active service plus limited return, deletion, backup, legal and claims periods |
| Nature of processing | Accessing, viewing, organising, editing, storing, transmitting, deleting and troubleshooting data as needed for accepted tasks |
| Purpose | Delivering Client-requested website support and maintenance |
| Data subjects | Client customers, prospects, users, personnel, contractors, suppliers and website visitors, as applicable |
| Data types | Contact details, enquiry or account content, order or booking content, technical identifiers and other data visible in the website administration area |
| Core subprocessor | Hostinger — hosting, portal infrastructure, email, logs and related backups or support |