This Data Processing Addendum ("DPA") forms part of the PageShield Terms of Service between CRAFTAC SRL ("PageShield", "we", "us" or "our") and the Customer ("Customer", "you" or "your"). This DPA applies to the extent PageShield processes Customer Personal Data on behalf of the Customer through the PageShield service.
This DPA is intended to satisfy the requirements applicable to a controller-processor agreement under Data Protection Laws, including Article 28 GDPR where applicable. If you use the Service on behalf of an organisation, you confirm that you have authority to bind that organisation to this DPA.
This DPA must be read together with the Terms of Service and the Privacy Policy. The Privacy Policy describes PageShield's processing as an independent controller, including Account administration, billing metadata, support, security and legal compliance. This DPA governs only processing of Customer Personal Data by PageShield on behalf of the Customer. Where the PageShield EU Data Act Addendum applies, it governs the contractual mechanics of switching, portability, transition, retrieval and deletion within its stated scope; this DPA continues to govern all processing of personal data carried out on the Customer's behalf.
For the purposes of this DPA:
• "Agreement" means the Terms of Service, this DPA and any incorporated policies or addenda applicable to the Customer's use of the Service.
• "Customer Personal Data" means personal data processed by PageShield on behalf of the Customer through the Service, including technical metadata processed for Heartbeats, Detection Events, transient IP-based location and ASN lookup, daily deduplication, bot/human/unknown classification, customer-scoped notification suppression, alerts, dashboard history, exports, webhook delivery and optional redirect functionality, and personal data included in a Customer-directed switching transfer.
• "Data Protection Laws" means the GDPR and any other data-protection, privacy or electronic-communications laws applicable to the relevant processing.
• "DPA" means this Data Processing Addendum, including its appendices.
• "GDPR" means Regulation (EU) 2016/679, as amended, replaced or supplemented from time to time.
• "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to Customer Personal Data.
• "Service" means the PageShield website, dashboard, Protection Snippet, pixel fallback, Heartbeats, Detection Events, local IP-based location and ASN lookup, daily deduplication, bot/human/unknown classification, customer-configured notification suppression, alerts, webhooks, dashboard export functionality, optional redirects and related functionality, including supported switching-transfer functionality where the EU Data Act Addendum applies.
• "Service Usage Data" means technical, operational, diagnostic and statistical information generated through the operation, security, performance and use of the Service. Service Usage Data is not Customer Personal Data to the extent PageShield determines the purposes and means of processing it for its own legitimate operational, security or legal purposes, as described in the Privacy Policy.
• "Subprocessor" means a third party engaged by PageShield to process Customer Personal Data on behalf of the Customer for purposes of providing, securing or supporting the Service.
• "Switching Transfer" means a Customer-directed export or transfer of Exportable Data or Portable Digital Assets under the EU Data Act Addendum to a destination provider, an authorised representative or an on-premises ICT environment. A Switching Transfer may include Customer Personal Data but is not itself a data-subject request under the GDPR.
Terms such as controller, processor, personal data, processing and data subject have the meanings given under applicable Data Protection Laws.
To the extent PageShield processes Customer Personal Data on behalf of the Customer, the Customer is the controller and PageShield is the processor. If the Customer acts as a processor for another controller, PageShield may act as a subprocessor. The Customer determines the purposes and essential means of installing the Protection Snippet, selecting Protected Domains, using the Service in relation to visitors of original or detected pages, configuring redirects, classification-dependent notification options, Notification Suppression Rules and webhooks, and deciding how the resulting information is used. PageShield determines non-essential technical implementation details, including the local databases, software and security measures used to carry out the Customer's documented instructions, without using Customer Personal Data for an incompatible independent purpose.
PageShield acts as an independent controller for personal data processed for its own Account administration, authentication, subscription and billing metadata, support, Service security, fraud and abuse prevention, rate limiting, reliability, legal compliance, defence of rights and internal business administration. Such processing is described in the Privacy Policy and is not governed by this DPA, except where expressly stated.
For a Switching Transfer, PageShield acts as processor for Customer Personal Data exported or transmitted on the Customer's documented instructions. PageShield acts separately as an independent controller for limited request-verification, transfer-security, fraud-prevention, compliance and evidence records that it determines are necessary for its own legal or security purposes, as described in the Privacy Policy.
If a specific processing activity cannot reasonably be characterised as processing on behalf of the Customer, this DPA will not convert that activity into processor processing. The parties acknowledge that their roles must be assessed by reference to the actual purposes and means of the processing under applicable law. If the factual assessment indicates that the parties jointly determine the purposes and essential means of a specific operation, they will cooperate in good faith to document the allocation of responsibilities required by Article 26 GDPR or another applicable rule before continuing that operation; PageShield may suspend the affected functionality until the required arrangement or another lawful allocation is in place.
PageShield will process Customer Personal Data only on documented instructions from the Customer, unless required to do otherwise by applicable law. The Agreement, this DPA, the Customer's use of the dashboard, installation of the Protection Snippet, configuration of Protected Domains, Redirect Destinations, classification-dependent notification options, Notification Suppression Rules, webhooks and Account settings, and support communications constitute the Customer's documented instructions. A complete and validated switching request, including the identified scope, destination and authorised representative where applicable, also constitutes a documented instruction for the corresponding Switching Transfer.
If, in PageShield's opinion, a Customer instruction infringes Data Protection Laws, PageShield will inform the Customer immediately, unless applicable law prohibits that notice. PageShield may suspend only the affected processing while the parties clarify or correct the instruction, and may decline the instruction where acting on it would be unlawful. PageShield may also pause affected processing where reasonably necessary to address a material security, operational or third-party risk, but will not use that right to avoid a lawful documented instruction.
The EU Data Act Addendum does not by itself establish a lawful basis for disclosing personal data to a destination provider or other recipient. PageShield may verify the Account, request, recipient, destination and transfer method and may pause or refuse a Switching Transfer where reasonably necessary to prevent unauthorised disclosure, comply with law or resolve a material security concern.
• ensuring that it has all rights, permissions, authorisations and legal bases necessary to install and use the Service on its websites, pages and domains;
• determining and documenting the lawful basis, necessity and proportionality of processing visitor technical data from original and detected pages, including transient IP processing, approximate geolocation, technical classification, deduplication and notification suppression;
• assessing and satisfying the transparency obligations applicable to the relevant collection or derivation of visitor data, including Articles 13 and/or 14 GDPR and any applicable exception, and keeping evidence of that assessment where required;
• not treating the bot/human/unknown result as a definitive determination of identity, residence, intent, fraud or unlawfulness, and not using it as the sole basis for a decision producing legal or similarly significant effects for an individual;
• providing all privacy notices, ePrivacy or terminal-equipment notices, localStorage notices, consents, disclosures and choices required for its visitors, customers, websites and jurisdictions, including where a Protection Snippet request or transmission constitutes storage of or access to information in terminal equipment under applicable law;
• determining whether any storage of or access to information in terminal equipment, or any transmission caused by the Protection Snippet, including Heartbeat localStorage and Detection Event requests, requires notice, consent or another control or falls within a statutory exception; the absence of cookies does not by itself determine that issue;
• assessing and documenting whether the processing is likely to result in a high risk and completing any required data-protection impact assessment and prior consultation before enabling the relevant feature, taking account of the nature, context, scale and systematic character of the processing, including traffic or location-related data;
• ensuring that Customer Personal Data provided or made available to the Service is lawful, accurate, relevant and limited to what is necessary;
• avoiding the intentional inclusion of unnecessary personal data, sensitive data, payment details, order details, authentication tokens or other high-risk data in URLs, referrers, Redirect Destinations, webhook URLs, webhook payloads, configuration fields or switching instructions;
• determining whether its use of the Service is lawful in the jurisdictions where it operates, targets visitors, installs the Protection Snippet, redirects traffic or processes personal data;
• not enabling or continuing an affected feature in a jurisdiction or configuration where the Customer cannot establish the required lawful basis, ePrivacy or terminal-equipment consent or exception, transparency, rights-handling and risk-assessment measures;
• responding to data-subject requests relating to the Customer's websites and visitors, unless PageShield is required to assist under this DPA;
• maintaining the security of its Account, credentials, Protected Pages, Redirect Destinations, webhook endpoints, tokens and integration secrets; and
• for a Switching Transfer, identifying an authorised destination and representative, providing complete and lawful instructions, ensuring that the recipient may lawfully receive the data, assessing any required international-transfer mechanism, and protecting credentials, tokens and export files;
• remaining responsible for the acts and omissions of destination providers and authorised third parties selected by the Customer, except to the extent responsibility cannot lawfully be allocated to the Customer;
• using the Service only in accordance with the Agreement, this DPA and applicable law.
Where PageShield acts as processor for Customer Personal Data, PageShield will:
• process Customer Personal Data only for the purposes described in the Agreement, this DPA and the Customer's documented instructions;
• process raw IP addresses for Detection Event enrichment only transiently, perform location and ASN lookups locally, retain only the fields described in Appendix 1, and not use customer-scoped deduplication or notification-suppression identifiers to create a cross-customer reputation database;
• ensure that persons authorised to process Customer Personal Data are subject to appropriate confidentiality obligations;
• implement appropriate technical and organisational measures designed to protect Customer Personal Data, taking into account the nature, scope, context and purposes of processing;
• assist the Customer, taking into account the nature of processing and information available to PageShield, with data-subject requests, security obligations, breach obligations and data-protection impact assessment or prior-consultation obligations where required by Data Protection Laws;
• engage Subprocessors only in accordance with this DPA;
• notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data;
• for a Switching Transfer, process and disclose Customer Personal Data only within the validated scope of the Customer's instruction, use security measures appropriate to the transfer risk, and provide reasonable assistance required by Data Protection Laws;
• not treat a destination provider or authorised representative as a Subprocessor merely because it receives a Customer-directed export, unless PageShield separately engages that recipient to process data on PageShield's behalf;
• at the Customer's choice, after the end of provision of the relevant processing services, return Customer Personal Data and delete existing copies, or delete the Customer Personal Data, unless Union or Member State law requires storage; return and deletion are subject to secure available transfer methods, normal backup cycles and lawful retention requirements; and
• make available information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality, security, proportionality and reasonable operational limitations.
The subject matter, duration, nature, purposes, categories of data and categories of data subjects are described in Appendix 1. The parties may update Appendix 1 if the Service materially changes. The Customer acknowledges that the Service may process limited technical metadata both when the Protection Snippet runs correctly on the Customer's original domain and when it appears to run on an unexpected or unauthorised domain.
Where a Switching Transfer includes Customer Personal Data, the processing details in Appendix 1 also cover the extraction, structuring, validation, secure delivery, transfer logging, temporary retrieval and deletion activities reasonably necessary to perform the transfer.
PageShield will maintain appropriate technical and organisational measures designed to protect Customer Personal Data. Those measures are described in Appendix 2. Operational safeguards include HTTPS/TLS where applicable, hashed Account passwords, access controls, local MaxMind GeoLite2 City and GeoLite2 ASN database lookups without live disclosure of IP addresses to MaxMind or another lookup provider, non-retention of raw IP/ASN enrichment fields and internal network-type signals, daily rotation of the deduplication secret or salt, keyed HMAC identifiers and customer-scoped rule separation, automated retention, deletion and irreversible-anonymisation controls, a fourteen (14)-day database-backup rotation, a separate access-restricted deletion ledger retained for thirty (30) days to reapply Account deletions after restoration, and minimised webhook payloads with limited retries. The Customer acknowledges that no online service can be guaranteed to be completely secure and remains responsible for its own implementation, website security, credentials, scripts, redirects, webhook endpoints, integrations, destination infrastructure and handling of export files.
PageShield may update the measures as the Service evolves, provided that it does not materially reduce the overall level of protection for Customer Personal Data during an active subscription, except where necessary to respond to law, provider requirements, security risks or technical changes and subject to applicable notice obligations.
The Customer grants PageShield general authorisation to engage Subprocessors as necessary to provide, secure and support the Service. PageShield will impose on each Subprocessor, by a written contract or other binding legal act under applicable law, data-protection obligations that are no less protective than those set out in this DPA, to the extent applicable to the Subprocessor's services and the nature of the processing. PageShield remains responsible to the Customer for the performance of its Subprocessors' data-protection obligations to the extent required by applicable Data Protection Laws.
PageShield maintains an up-to-date Subprocessor register at https://pageshield.io/legal/subprocessors.html, and the principal providers and provider categories are also identified in Appendix 3. Before a new or replacement Subprocessor begins processing Customer Personal Data, PageShield will provide direct prior notice by email, dashboard notice or another durable electronic method at least fifteen (15) calendar days in advance, together with sufficient information for the Customer to assess the change. Where an urgent legal, security or continuity requirement makes advance notice impracticable, PageShield will give notice as early as reasonably possible and preserve a reasonable opportunity to object on data-protection grounds.
The register, change notice or information supplied on request will identify, to the extent relevant for the Customer's assessment, the Subprocessor's legal identity, location, function, categories of Customer Personal Data or processing involved, and the applicable international-transfer mechanism or location note. PageShield will maintain the information needed to identify processors and Subprocessors throughout the processing chain and will make it available to the Customer as required by Data Protection Laws, subject to proportionate confidentiality and security safeguards.
The Customer may object to a new Subprocessor on reasonable data-protection grounds by notifying PageShield within fifteen (15) calendar days after notice. The parties will work in good faith to address the objection. If the objection cannot reasonably be resolved, the Customer may stop using or terminate the affected Service functionality, and PageShield is not required to provide functionality that depends on the objected Subprocessor.
Customer-configured webhook endpoints, Redirect Destinations and integrations are not PageShield Subprocessors. They are selected and controlled by the Customer, which is responsible for ensuring that it is authorised to use them and that they provide an appropriate level of protection. The same applies to destination providers, authorised representatives and on-premises environments selected by the Customer for a Switching Transfer.
Webhook alerts are available only on Pro and Business. The payload is limited to a generic message directing the Customer to the dashboard and does not include the full URL, referrer, user-agent string, IP address or profile name. PageShield makes three delivery retries after approximately five (5) seconds, thirty (30) seconds and two (2) minutes. After final failure, the failure is recorded in an error log retained for thirty (30) days without interrupting other Service functions.
Lemon Squeezy is used for merchant-of-record, payment, billing, invoicing and tax-related functions. It is not intended to receive Heartbeat records, Detection Event history or Customer-configured protection data. Lemon Squeezy may process payment and purchase-related data under its own terms and privacy documentation.
Where Customer Personal Data is transferred outside the European Economic Area or another jurisdiction requiring transfer safeguards, PageShield will put the required transfer mechanism in place before the transfer begins. Depending on the circumstances, that mechanism may include an adequacy decision, the European Commission's standard contractual clauses, a transfer impact assessment, supplementary measures or another valid safeguard. Where standard contractual clauses are required, the relevant module is incorporated or entered into as necessary, and Appendix 1 and Appendix 2 may be used to complete the processing and security descriptions. On request, PageShield will provide a copy or meaningful summary of the applicable safeguard to the extent required by law, subject to lawful confidentiality and security redactions.
The Customer is responsible for assessing whether its own use of the Service, including transfers resulting from its websites, visitors, webhook endpoints, integrations and jurisdictions, complies with laws applicable to the Customer. PageShield's main hosting infrastructure, active database and local database backups are hosted with Hetzner in Germany, subject to changes notified or reflected in applicable documentation.
A Customer may direct a Switching Transfer to a destination provider, authorised representative or on-premises environment outside the EEA. The Customer is responsible for selecting an authorised destination, determining the lawful basis for disclosure and identifying safeguards applicable to the Customer or recipient. PageShield will address the Chapter V GDPR requirements falling within its own responsibility before carrying out the transfer and will provide reasonable information and cooperation available to it. PageShield may pause the transfer until the Customer supplies the information, instructions or safeguards reasonably necessary for both parties to perform it lawfully and securely.
Taking into account the nature of the processing, PageShield will provide reasonable assistance to the Customer for the Customer to respond to requests from data subjects exercising rights under Data Protection Laws, to the extent the requests relate to Customer Personal Data processed by PageShield as processor.
If PageShield receives a request relating to Customer Personal Data and can identify the relevant Customer, PageShield may refer the requester to the Customer or notify the Customer, unless legally prohibited. PageShield may respond directly where it acts as an independent controller or where required by law.
A Switching Transfer requested by the Customer under the EU Data Act Addendum is distinct from a data-subject access, portability or erasure request under the GDPR. Neither type of request automatically initiates the other, and the Customer remains responsible for identifying and separately addressing any applicable data-subject rights.
PageShield will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. To the extent reasonably available, the notice will describe the nature of the breach; the categories and approximate number of affected data subjects and records; the relevant contact point; the likely consequences; and the measures taken or proposed to contain, mitigate and remedy the breach. PageShield may provide information in phases as it becomes available and will not delay the initial notice solely because all details are not yet known.
The Customer is responsible for determining whether the breach must be notified to a supervisory authority or data subjects, unless applicable law provides otherwise. PageShield will provide reasonable cooperation and information available to it to assist the Customer with that assessment and any required notifications.
Upon termination of the relevant processing services, Account deletion or a valid verified request, PageShield will, at the Customer's choice, (a) return Customer Personal Data using a secure method and format then available or otherwise agreed or required by law and delete existing copies, or (b) delete the Customer Personal Data, unless Union or Member State law requires storage. The Customer should communicate its choice and any reasonable return instructions before termination or within thirty (30) calendar days after PageShield requests that choice. If the Customer does not communicate a choice within that period, PageShield may securely delete the Customer Personal Data after reasonable notice. PageShield is not required to create a bespoke return format or restore data already lawfully deleted or irreversibly anonymised, except where mandatory law requires otherwise.
Plan-based history limits determine what is visible in the dashboard. Starter provides read-only access to up to seven (7) days and does not include CSV export; Pro provides access to up to ninety (90) days; Business has no separate Plan-based dashboard history window while the Business Subscription remains active. Retention is separate: raw Heartbeat records are retained for thirty (30) days; complete retained Detection Event metadata, including approximate country/city and bot/human/unknown classification, is retained for ninety (90) days; the raw IP address, ASN and internal ASN-list match result used for enrichment are not retained as Detection Event fields; daily deduplication identifiers are retained only for the applicable daily window; customer-scoped notification-suppression rules are retained for ninety (90) days from creation or the most recent match unless removed earlier. A matching event restarts that period, so a rule may remain active for longer than ninety days while matching continues. After ninety (90) days, fields and combinations of fields reasonably capable of identifying, singling out or linking an individual are deleted or irreversibly anonymised, with no conditional extension. Routine server/IP, webhook-delivery and error logs are retained for thirty (30) days. If older underlying records remain within these periods after an upgrade or resubscription, they may become visible again; no record is guaranteed to remain available until the end of a maximum period.
Where the EU Data Act Addendum applies, its switching, retrieval and erasure mechanics supplement this Section for Exportable Data and Portable Digital Assets. Customer Personal Data included in a Switching Transfer remains governed by this DPA and Data Protection Laws. PageShield may retain the transferred data during the retrieval period stated in the EU Data Act Addendum and will then delete or anonymise it in accordance with the Addendum, this DPA, applicable law and normal backup cycles. Completion of a switch does not authorise PageShield to retain Customer Personal Data for continued provision of a terminated Service.
The Customer should confirm successful receipt or retrieval where the applicable process requires it. PageShield may retain a minimal transfer record as independent controller where necessary to document authority, scope, delivery, security or legal compliance, but that record will not be used to continue processing Customer Personal Data on the Customer's behalf after the applicable instruction ends.
Following verified self-service Account deletion, Customer Personal Data is removed from the active database synchronously, subject to any data that PageShield must retain under Union or Member State law. Database backups are automatically rotated on a fourteen (14)-day cycle, so deleted data may remain in an existing backup for up to fourteen (14) days. Backups remain protected and are not returned to ordinary active processing. If a backup is restored, a separate deletion ledger containing only a keyed cryptographic hash (HMAC or equivalent) of the deleted Account email and the deletion date is used to identify and automatically re-delete any Account that reappears. The ledger is treated as pseudonymised personal data, access is restricted and logged, and each entry is automatically deleted thirty (30) days after the corresponding Account deletion.
Upon reasonable request, PageShield will make available to the Customer all information reasonably necessary to demonstrate compliance with this DPA and with the obligations applicable to PageShield as a processor under Data Protection Laws.
The Customer may conduct an audit itself or appoint an independent auditor that is subject to appropriate confidentiality obligations. Audits may be conducted at reasonable intervals, where there are reasonable grounds to suspect non-compliance, following a Personal Data Breach affecting Customer Personal Data, or where required by a competent supervisory authority or applicable law.
Where reasonably possible, the parties will first rely on documentation, written responses, security summaries, policies, Subprocessor information, certifications, independent assurance reports or other appropriate evidence. Reliance on such evidence does not prevent the Customer from requesting an on-site audit or technical inspection where the available information is insufficient to demonstrate compliance, where there are reasonable indications of non-compliance or where an inspection is required by applicable law or a competent supervisory authority.
Any on-site audit or technical inspection will be conducted on reasonable prior written notice, during normal business hours and in a manner designed to minimise unnecessary disruption to PageShield’s operations. The parties will coordinate in good faith regarding the scope, timing, duration, confidentiality, security and practical arrangements of the audit. PageShield will not unreasonably withhold, condition or delay an audit permitted under this Section or required under Data Protection Laws.
An audit must be limited to the processing of Customer Personal Data and PageShield’s obligations as a processor. It must not provide the Customer or its auditor with access to another customer’s data, systems or confidential information and must not compromise the security, availability or integrity of the Service. Access to source code, penetration-testing environments, internal security configurations or trade secrets will not be required unless strictly necessary, proportionate and required by applicable law or a competent supervisory authority.
Unless required by a competent supervisory authority, applicable law, a Personal Data Breach or reasonable indications of material non-compliance, the Customer may not request more than one audit in any twelve-month period.
Each party will bear its own internal costs relating to a routine audit. The Customer will bear the reasonable external costs of an audit requested solely for its own assurance purposes. Where an audit establishes a material breach of this DPA by PageShield, PageShield will bear the reasonable audit costs directly attributable to the verification of that breach.
If there is a conflict concerning the processing, protection, disclosure, transfer, return or deletion of Customer Personal Data, this DPA and mandatory Data Protection Laws prevail over the Terms and the EU Data Act Addendum to the extent of the conflict. The EU Data Act Addendum governs switching mechanics, categories of Exportable Data and Portable Digital Assets, notice, transition, retrieval and related non-personal-data matters only to the extent consistent with this DPA and applicable law. The Terms continue to govern commercial terms, acceptable use, subscriptions, fees, refunds, suspension, liability, disclaimers and other non-data-processing matters.
PageShield may update this DPA to reflect changes in the Service, providers, Subprocessors, law, security measures or operational needs. PageShield will not materially reduce the overall level of protection for Customer Personal Data during an active Subscription, except where necessary to comply with law or address a material security or provider requirement. Material changes will be notified and applied in accordance with the Terms, applicable law and any consent or termination right legally required. An update will not retroactively reduce obligations applicable to processing performed before its effective date.
| Item | Description |
|---|---|
| Subject matter | Provision of the PageShield clone-detection, Heartbeat, local IP-based location and ASN lookup, daily deduplication, bot/human/unknown classification, dashboard-alert, customer-configured notification-suppression, limited webhook, export and optional traffic-redirection Service, including Plan-based activation and deactivation of protection profiles. Supported Switching Transfers are included where the EU Data Act Addendum applies. |
| Duration | For the term of the Customer Account or Subscription and, for retained records, only for the applicable periods in the Privacy Policy: Heartbeats 30 days; complete retained Detection Event metadata 90 days, deleted or irreversibly anonymised thereafter with no conditional extension; daily deduplication identifiers only for the applicable daily window; customer-scoped notification-suppression rules 90 days from creation or last match; routine technical and webhook logs 30 days; backups 14 days; deletion-ledger entries 30 days; request/compliance records up to 3 years. Earlier return or deletion applies where required by this DPA, a verified Account deletion, a valid instruction or applicable law. |
| Nature of processing | Collection, transient receipt and in-memory use, local lookup, derivation, pseudonymisation, classification, comparison and matching, recording, storage, organisation, structuring, display, notification suppression, export, deletion, anonymisation, security and operational analysis, alert delivery, webhook delivery and optional redirect-related processing, together with extraction, validation, structured export, secure transfer, temporary retrieval and transfer logging for a Switching Transfer. |
| Purpose | To confirm that protection is active on the Customer's original domain through Heartbeats; detect possible cloned or unauthorised pages; derive approximate country and city; generate a per-event bot/human/unknown result; deduplicate events within a daily window; apply customer-configured notification-suppression rules; record Detection Events; notify Customers; operate Plan-dependent redirects; provide dashboard history and permitted exports; deliver limited generic webhook alerts; secure, maintain and troubleshoot the Service; and provide support. |
| Heartbeat metadata | Customer or protection-profile identifier, hostname, timestamp and limited request metadata generated on an authorised original domain. Raw Heartbeat records are retained for thirty (30) days. |
| Detection Event metadata | Customer or profile identifier, unexpected hostname or page, timestamp, URL/referrer and user-agent information, approximate country and city, bot/human/unknown classification and related detection metadata. The raw IP address is used transiently in memory for local GeoLite2 City and GeoLite2 ASN lookup, daily deduplication and customer-scoped rule comparison. The transient ASN is compared against a locally stored, manually maintained list of known cloud/hosting ASNs that is not dynamically populated from an external service; a match is treated as a data-centre signal and a non-match as a non-data-centre or residential-ISP signal solely for the classification heuristic. The raw IP, ASN, list-match result, network signal and technical classification reasons are not retained as Detection Event fields. Complete retained metadata is kept for ninety (90) days; identifying or linkable technical fields, including approximate country, city and the Classification Result, are then deleted or irreversibly anonymised after that period, with no conditional extension. |
| Other Customer Personal Data | Protection-profile data, Protected Domain or page configuration, Redirect Destination, webhook endpoint configuration, customer-scoped Notification Suppression Rules and rule metadata, dashboard and export history, support context relating to Customer Personal Data, and personal data that may accidentally appear in URLs, referrers or configuration fields. A suppression rule contains a keyed HMAC-based matching value, Customer/profile scope, status, creation time, last-match time and expiry time; it does not contain the raw IP address or HMAC secret. The HMAC-derived matching value is internal to PageShield and is not included in customer-facing or switching exports; any exported rule identifier is a separate non-secret record identifier. Webhook payloads are generic teasers and do not include the full URL, referrer, user-agent string, IP address or profile name. |
| Categories of data subjects | Visitors to the Customer's original domains or pages where the Protection Snippet is installed; visitors to cloned or unauthorised pages where the snippet executes; Customer Account users or team members to the extent processed on behalf of the Customer; and other persons whose data may accidentally appear in URLs, referrers, logs or webhook and configuration data. |
| Special categories and high-risk data | The Service is not designed to process special categories of personal data, payment-card details, order details, authentication secrets, children's data or other high-risk data. The Customer must not intentionally configure or use the Service to process such data. |
| Processing frequency | Continuous, periodic, event-based or Customer-triggered, depending on snippet execution, Heartbeat throttling, clone detection, local enrichment, daily deduplication, classification, notification-suppression matching, dashboard use, Plan status, export actions, support requests and security or operational needs. Webhook delivery, where enabled, may involve the initial attempt and three retries after approximately 5 seconds, 30 seconds and 2 minutes. |
| Customer instructions | Instructions are given through the Agreement, this DPA, dashboard configuration, installation of the Protection Snippet, selection of Protected Domains or pages, redirect settings, classification-dependent notification settings, Notification Suppression Rules, webhook settings and support communications, and through a complete and validated switching request identifying the scope and destination. |
| Measure | Description | |
|---|---|---|
| Access controls | Controls designed to limit access to administrative systems and Customer Personal Data to authorised persons with an operational, support, security or legal need. The Customer controls access to its own Account. | |
| Authentication | Password-based authentication with passwords stored in hashed form for user Accounts; additional authentication controls may be added as the Service evolves. | |
| Transmission security | HTTPS or TLS for data in transit where technically applicable. | |
| Infrastructure security | Use of Hetzner hosting in Germany for the main application environment, active database and backups. Cloudflare provides authoritative DNS and basic DNS-layer protection and is not configured as an application reverse proxy; application payloads are sent directly to the Hetzner-hosted environment. | |
| Export and Switching Transfer security | Authenticated delivery, access-controlled or expiring links where used, structured machine-readable export files, destination and authority validation, transfer logging and secure transfer methods. Where the EU Data Act requires an open interface, a documented authenticated export API or equivalent open machine-to-machine interface is made available without a separate interface fee and on an equal basis to Customers and authorised destination providers, subject to authentication and proportionate security controls. Currently supported formats, packaging methods and interfaces are identified in the then-current public switching documentation. Customers and authorised recipients must protect credentials, tokens, files and transfer instructions. | |
| Backups | Database backups are protected within the Hetzner-hosted environment in Germany and are automatically rotated and deleted on a fourteen (14)-day cycle. Restored backups are subject to the deletion-ledger cleanup procedure before ordinary use. | |
| Logical segregation | Logical separation of Customer Accounts and protection profiles within the Service. | |
| Data minimisation by design | The Protection Snippet is designed not to solicit names, payment-card details, order details, checkout or form content. Heartbeats and Detection Events are limited to the technical data required for the relevant functionality, subject to information automatically included in requests, URLs or referrers. The geolocation, ASN lookup, classification, daily deduplication and notification-suppression functions are performed server-side and do not add cookies, localStorage entries or browser-fingerprinting signals. | |
| Local enrichment and transient classification | Country and city lookups are performed through a locally hosted MaxMind GeoLite2 City database and ASN lookup through a locally hosted MaxMind GeoLite2 ASN database. No live external geolocation, ASN or IP-intelligence API or additional external database is used for the described functions. Raw IP addresses are not sent to MaxMind or another data provider and are not retained as Detection Event fields. ASN values are compared transiently against a locally stored, manually maintained cloud/hosting ASN list that is not dynamically populated from an external service; the ASN, list-match result, data-centre/residential signal and technical classification reasons are not retained. | |
| Pseudonymisation and key separation | Daily deduplication uses a secret or salt that rotates daily. Persistent notification-suppression matching uses a keyed HMAC rather than an unkeyed hash. Secrets are stored separately from rule records and access is restricted to authorised operational processes and personnel. The HMAC-derived matching value is treated as pseudonymous Customer Personal Data, is not exposed in customer-facing or switching exports and is not reused across Customers. | |
| Customer scoping and expiry | Notification-suppression rules are logically segregated and matched only within the Customer scope in which they were created. They do not populate a global reputation database and are deleted automatically ninety (90) days after creation or the most recent match, unless removed earlier by the Customer. A matching event restarts the ninety-day period, so the rule may remain active for longer than ninety days while matching continues. | |
| Logging and monitoring | Operational, security and webhook delivery/error logging is limited to what is necessary. Routine logs are automatically deleted after thirty (30) days. A limited subset isolated for a documented incident, fraud investigation or dispute may be retained for up to twelve (12) months after closure or longer where required for a live legal claim or binding obligation. | |
| Confidentiality | Persons authorised to access Customer Personal Data are subject to appropriate confidentiality obligations. | |
| Incident response | Procedures designed to investigate, contain and mitigate Personal Data Breaches; preserve relevant evidence; notify the Customer without undue delay; and provide the breach information required by Section 11 as it becomes reasonably available. | |
| Deletion-restoration safeguard | A separate, access-restricted and logged deletion ledger stores only a keyed cryptographic hash (HMAC or equivalent) of the deleted Account email and the deletion date. It is outside the ordinary database-restoration set, is used solely to re-delete Accounts reintroduced by restoration, and each entry is automatically deleted 30 days after Account deletion. | |
| Retention and deletion controls | Automated lifecycle controls delete raw Heartbeats after 30 days and complete retained Detection Event technical metadata after 90 days. Raw IP addresses, ASN values and internal ASN-list match results used for enrichment are not retained as Detection Event fields. Daily deduplication identifiers are deleted or rendered unusable when the daily secret or salt rotates. Customer-scoped notification-suppression rules are deleted after 90 days from creation or last match unless removed earlier; each matching event restarts that period, so a rule may remain active for longer while matching continues. After 90 days, fields and combinations of fields reasonably capable of identifying, singling out or linking an individual are deleted or irreversibly anonymised, with no conditional extension. Routine technical and webhook logs are deleted after 30 days. Each export link expires after 7 days, while at least one retrievable package or the ability to regenerate it remains available throughout any applicable Data Act retrieval period. Temporary and intermediate packages are deleted promptly when superseded, and all remaining temporary packages are deleted within 14 days after that period closes, unless law or a live claim requires longer retention. | |
| Availability and recovery | Reasonable operational and backup practices designed to support continuity and recovery, subject to the actual hosting and backup configuration and without a guarantee of uninterrupted availability. | |
| Provider / category | Function | Location / transfer note | Data note | Status |
|---|---|---|---|---|
| Hetzner | Hosting, server infrastructure, active database and database backups subject to a fourteen (14)-day rotation. | Germany / EEA. | May process Customer Personal Data, Account data and technical or security logs hosted on the infrastructure. | Subprocessor where it processes Customer Personal Data on PageShield's behalf. |
| Cloudflare | Authoritative DNS and basic DNS-layer protection; not configured as an application proxy. | Cloudflare service locations are governed by its applicable documentation; application data remains hosted with Hetzner in Germany. | Application, API, Protection Snippet, detection and switching payloads are not proxied through Cloudflare. Cloudflare may process limited Account, zone and DNS-operational data under its own applicable documentation. | Not treated as a Subprocessor for Customer Personal Data on the described DNS-only architecture. PageShield will reassess that conclusion before any configuration change that materially changes processing. |
| Lemon Squeezy | Merchant of Record, checkout, payment, invoicing, tax, refunds and chargebacks. | Processing locations and transfers are governed by Lemon Squeezy's own documentation. | Receives payment and purchase data through its checkout and provides PageShield with limited subscription and transaction-reference metadata. It is not intended to receive Heartbeat or Detection Event history. | Generally acts for its own Merchant-of-Record purposes rather than as a Subprocessor for Customer Personal Data. |
| Google Workspace | Transactional email delivery for Account and billing notifications, support correspondence and statutory notices, including withdrawal confirmations. | Processing locations and transfers are governed by Google's applicable documentation and data-processing terms. | Not intended to receive Heartbeat records, Detection Event history, raw Detection Event IP addresses, location/classification fields or Customer protection configurations. | Processor for PageShield-controlled Account, support and notice data. It is a Subprocessor under this DPA only to the extent a PageShield-directed communication contains Customer Personal Data processed on the Customer's behalf. |
| MaxMind | Supplier of downloadable GeoLite2 City and GeoLite2 ASN database files used for local IP-based enrichment. | Database files are stored and queried on PageShield infrastructure; no live lookup request is sent to MaxMind. | Does not receive raw Detection Event IP addresses, Detection Event records, Classification Results or Notification Suppression Rule data under the described architecture. | Not a Subprocessor for this local-database processing. Reassessment is required before any live API or other disclosure of Customer Personal Data. |
| Future operational providers | Email delivery, support, uptime monitoring, error monitoring, logging, backup, security or similar functions if activated. | Depends on the selected provider. | Limited to the data required for the relevant operational function. | A provider is treated as a Subprocessor where it processes Customer Personal Data on PageShield's behalf. The live Subprocessor register identified in Section 8 and the direct prior-notice and objection process apply before such processing begins, subject to the urgent-change exception stated there. |
Customer-selected destination providers, authorised switching representatives and on-premises environments are not listed as PageShield Subprocessors merely because they receive a Switching Transfer. They are recipients selected and controlled by the Customer unless PageShield separately engages them to process Customer Personal Data on PageShield's behalf.
MaxMind supplies the downloadable GeoLite2 City and GeoLite2 ASN datasets that PageShield stores and queries locally for the processing described in this DPA. MaxMind is not treated as a Subprocessor for that processing because no Customer Personal Data is disclosed to MaxMind through a live lookup or otherwise made available to it under the described architecture. PageShield will reassess and update the Subprocessor register before using a live external lookup service, adding another external IP-intelligence service or otherwise allowing a dataset provider to process Customer Personal Data.