Data Processing Addendum
Last updated 6 August 2026
This is our standard DPA, published in full so procurement can read it before a single email is exchanged. It is a template drafted for a small SaaS business, not legal advice — have your counsel confirm it fits your regime. For a countersigned copy, email privacy@saidfirst.ai from your account address; we sign without negotiation theatre.
1. Roles and scope
The agency (customer) is the controller of the personal data it enters into or collects through the service; SaidFirst is the processor, acting only on the agency’s documented instructions as expressed through the product’s configuration. For agency users’ own account data, SaidFirst is an independent controller (see the privacy policy).
2. Processing instructions
We process personal data solely to provide the service described in our terms: monitoring how AI assistants answer configured prompts, computing visibility metrics, generating reports and briefs, operating client portals, and sending configured notifications. We do not use customer workspace data to train models, for advertising, or for any purpose of our own.
3. Confidentiality and personnel
Access to production data is limited to personnel who need it to operate the service, and is bound by confidentiality obligations.
4. Security (Annex II summary)
The technical and organisational measures are published, with code-level evidence, at /trust — tenant isolation enforced in a central authorisation layer, bcrypt-hashed credentials, hashed single-use reset and access tokens, rate limiting, webhook signature verification, TLS in transit, and provider-managed encryption at rest. A CI gate blocks deploys on security and accessibility regressions.
5. Sub-processors (Annex III)
The current register is at /legal/subprocessorsand is incorporated by reference. Optional processors receive data only when the deployment serving the agency has that service’s credential configured; the register marks each as always-on or optional. We give 14days’ advance email notice of new sub-processors; the agency may object on reasonable data-protection grounds, and if no resolution is found may terminate the affected service with a pro-rata refund. Current register at time of publication: Vercel, Neon, Cloudflare, Anthropic, OpenAI, Perplexity, Google (Gemini API), SerpAPI, DataForSEO, Stripe, Resend, Google (OAuth), Google Search Console.
6. Breach notification
We notify the agency of a personal-data breach affecting its data without undue delay and in any event within 72 hours of becoming aware of it, with the information a controller needs for its own regulatory notifications, and cooperate fully in the response.
7. Assistance
Taking into account the nature of processing, we assist the agency with data-subject requests (access, correction, export, deletion), with security of processing, and with DPIAs, primarily through the product itself: full-history CSV export and client-workspace deletion are self-serve.
8. Deletion and return
Deleting a client workspace permanently removes its competitors, prompts, sweeps, engine answers, scores, briefs and portal access. On termination of the agreement we delete the agency’s workspace data within 30 days, except records retained under a legal obligation. Full-history export (CSV) is available self-serve before and during that window.
9. International transfers
Production data is hosted in the United States (single region; EU-hosted deployment available on request). Where a transfer of EU/UK personal data requires a safeguard, the EU Standard Contractual Clauses (module two, controller-to-processor) and the UK addendum are incorporated by reference, alongside the safeguards our sub-processors offer.
10. Audits
We answer security questionnaires and make available the information reasonably necessary to demonstrate compliance — starting with /trust, which is kept truthful by the same review gates as the codebase. On-site audits are by prior agreement and at the agency’s cost.
Annex I — Categories of data and subjects
- Agency users (SaidFirst as controller): name, email, hashed password, optional profile image, role.
- Portal viewers (processor): email, name, hashed password, sign-in timestamps — created by the agency for its clients.
- Audit-page prospects(processor): email and brand name captured by the agency’s public audit page.
- Brand and market data (processor; mostly non-personal): client and competitor names, prompts, AI answer text — which may incidentally mention identifiable people — extracted mentions, scores, briefs, fact sheets.
No special-category data is required by the service, and the terms prohibit entering it.