Legal

Data Processing Agreement

Last updated: 6 June 2026

This Data Processing Agreement ("DPA") forms part of the agreement between Pipelit Ltd ("Processor", "we") and the customer ("Controller", "you") for the provision of Scanner Pro and related services.

1. Definitions

2. Scope of processing

The Processor processes Personal Data solely to provide the Scanner Pro service, including:

Data categoryData subjectsPurposeRetention
Account data (name, email)Customer team membersAuthentication, communicationDuration of account + 30 days
Scan resultsN/A (no personal data of website visitors)Compliance analysisDuration of account
Fix ticket dataCustomer team members (names in audit trail)Workflow trackingDuration of account
GTM configuration dataN/A (tag configuration only)Compliance comparisonDuration of connection
AI query contextN/A (scan data, no visitor PII)AI compliance guidanceNot persisted beyond the query

3. Processor obligations

The Processor shall:

4. Sub-processors

The Processor currently uses the following Sub-processors:

Sub-processorPurposeLocationData processed
AnthropicAI processing (Revelio)United StatesScan context for AI queries (no visitor PII)
StripePayment processingUnited StatesPayment method, billing address
GoogleGTM OAuth integrationUnited StatesOAuth tokens, GTM configuration
SmartproxyUK residential proxyLithuaniaTarget URL only (no personal data)

The Controller is deemed to have authorised the above Sub-processors. The Processor will notify the Controller before adding or replacing Sub-processors, providing the Controller an opportunity to object.

5. International transfers

Where Personal Data is transferred outside the UK, the Processor ensures appropriate safeguards are in place, including UK International Data Transfer Agreement (IDTA) or Standard Contractual Clauses (SCCs) as applicable.

6. Security measures

Full details at pipelit.co.uk/security.

7. Data subject rights

The Processor shall assist the Controller in fulfilling data subject requests (access, rectification, erasure, portability, restriction, objection) within the timeframes required by UK GDPR.

8. Breach notification

In the event of a Personal Data breach, the Processor shall notify the Controller without undue delay and no later than 72 hours after becoming aware. The notification shall include the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed.

9. Term and termination

This DPA remains in effect for the duration of the service agreement. Upon termination, the Processor shall delete all Personal Data within 30 days unless retention is required by applicable law.

10. Governing law

This DPA is governed by the laws of England and Wales and supplements the main Terms of Service.

11. Contact

For DPA queries, data subject requests, or breach notifications:
Email: lalarukh@pipelit.co.uk

To execute this DPA: If you require a countersigned copy of this DPA, email lalarukh@pipelit.co.uk with your company name, signatory name, and title. We will return a signed copy within 2 business days.