Skip to policy
Cite N Seek
Sample reportHow it worksPricingBlog
Run Vibe Check ->

Home/Data Processing Agreement

Data Processing Agreement

Draft for review

On this page
  1. Purpose
  2. Roles
  3. Instructions
  4. Security
  5. Subprocessors
  6. Deletion
  7. Open decisions
This is an informational DPA outline, not an executed agreement.The current processing and providers are identified below, but the parties, legal roles, security schedule, transfer terms, retention schedule, jurisdiction, and signature process still require legal review.

1. Purpose and scope

Cite N Seek processes a submitted website, public website content, business intake answers, contact email, selected competitors, report evidence, and order status to provide the requested check or report. The final DPA must determine when Cite N Seek acts as a processor or service provider for a business customer and when it acts for its own operational purposes.

2. Roles of the parties

The final agreement must state when the customer acts as controller or business and when Cite N Seek acts as processor or service provider. Cite N Seek may also handle some information for its own purposes, which would need separate disclosure in the Privacy Policy.

3. Documented instructions

If Cite N Seek acts as a processor, it should process covered information only under the customer’s documented instructions, except where applicable law requires otherwise. The final agreement must explain how instructions are given and what happens if an instruction appears unlawful.

4. Confidentiality and security

The current architecture separates Cite N Seek data in a dedicated Neon Postgres database, uses server-side secrets, signed Stripe webhooks, private report tokens, and browser-held report access keys. The final security schedule still needs to cover staff access, encryption, incident response, backups, vulnerability management, and audit evidence.

No specific security certification is claimed.

5. Current service providers and transfers

Current providers are Vercel for frontend and serverless hosting, Neon for Postgres storage, Stripe for checkout and payment confirmation, and OpenAI for business analysis and paid checks with live web search. No email-delivery provider is connected at launch. The final DPA must list legal entities, processing locations, transfer safeguards, notice, and objection procedures where required.

6. Assistance, return, and deletion

The final agreement should explain assistance with rights requests, security incidents, assessments, regulator inquiries, audits, return or deletion at the end of service, and legally required retention.

7. Decisions still open

  • Parties’ full legal identities and roles
  • Covered service and processing instructions
  • Data subjects and categories of personal information
  • Security measures and incident notice timing
  • Subprocessor list and notice mechanism
  • International transfer terms
  • Return, deletion, and retention periods
  • Audit process, liability, governing law, and signatures

Review the current product context.

The homepage explains the live free check and the launch provider coverage for paid reports.

Visit the Vibe Check ->
Cite N Seek

AI visibility checks with more receipts and fewer dashboards.

Explore
HomeSample reportPricingBlog
Policies
PrivacyCookiesLegal noticeTermsDPAAI governanceRefundsPrivacy choices

Policy drafts for review. Business and legal details are not final.