Data Processing Agreement

Last updated: April 12, 2026

This DPA supplements the Terms of Service and Privacy Policy and applies to customers on paid plans who need a data processing agreement for their own compliance requirements.

1. Parties and Definitions

This Data Processing Agreement ("DPA") is entered into between:

"Personal Data" means any information relating to an identified or identifiable natural person, as defined by applicable data protection law (including GDPR, CCPA/CPRA, and similar frameworks).

2. Scope and Purpose of Processing

NewSiteLead processes data on your behalf for the following purposes:

Categories of Data Processed

CategoryData ElementsRetention
Account dataEmail, hashed password, Stripe customer IDUntil account deletion + 30 days
Login historyIP address, timestamp12 months
Usage logsAPI calls, searches, exports, page views12 months
Diagnostic dataDomain, business context notes, generated reports200 days (auto-deleted)
Payment dataStripe customer/subscription IDs (no card numbers)Until account deletion

3. Processor Obligations

NewSiteLead shall:

4. Sub-Processors

NewSiteLead uses the following sub-processors:

Sub-ProcessorPurposeData ProcessedLocation
Stripe, Inc.Payment processingEmail, payment detailsUnited States
Anthropic PBCAI report generationDomain name, business context notesUnited States
MXrouteTransactional email deliveryRecipient email, email contentUnited States
Contabo GmbHInfrastructure hostingAll data at restUnited States

We will notify active subscribers by email at least 14 days before adding a new sub-processor. If you object to a new sub-processor, you may terminate your subscription before the change takes effect.

5. Security Measures

NewSiteLead implements the following technical and organizational measures:

6. Data Breach Notification

In the event of a personal data breach, NewSiteLead shall:

7. Data Subject Rights

NewSiteLead will assist the Controller in fulfilling data subject requests including:

Requests should be directed to contact@newsitelead.com. We aim to respond within 15 business days.

8. International Data Transfers

All data processing occurs within the United States. NewSiteLead and all sub-processors are U.S.-based. If you are subject to GDPR or similar frameworks requiring specific transfer mechanisms, please contact us to discuss applicable safeguards (e.g., Standard Contractual Clauses).

9. Audit Rights

Upon reasonable written request (no more than once per calendar year), the Controller may request information about NewSiteLead's data processing practices and security measures to verify compliance with this DPA. NewSiteLead will provide written responses to audit questionnaires within 30 business days. On-site audits are not supported, but we will cooperate with reasonable alternative verification methods.

10. Term and Termination

This DPA is effective for the duration of your subscription. Upon termination:

11. Governing Law

This DPA is governed by the same terms as the Terms of Service — the laws of the State of California, with disputes resolved per the dispute resolution procedures in the ToS.

12. Contact

For DPA-related inquiries, data subject requests, or breach notifications:

NewSiteLead
25422 Trabuco Rd STE 184
Lake Forest, CA 92630
contact@newsitelead.com