Skip to main content

Data Processing Agreement

How we process customer data on a customer's behalf.

Last updated:

Data Processing Agreement

Infiquik, registered in Sharjah, United Arab Emirates ("Generative Metrics", "we", "us") provides the Service described in our Terms of Service. This Data Processing Agreement ("DPA") applies to the limited personal data we process on a customer's behalf when the customer uses the Service. It forms part of the Terms of Service; capitalized terms used but not defined here have the meanings given in the Terms or in data protection law (the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR, and comparable laws).

1. Roles of the parties

  • For personal data in customer accounts (account email, billing identifiers, audit targets, audit results, uploaded logs), the customer is the controller and Generative Metrics is the processor. We process that data only on the customer's documented instructions — which are these Terms and the customer's use of the Service features — unless legally required to do otherwise.
  • Where the customer itself acts as a processor for its own clients (for example, an agency), the customer is responsible for obtaining any upstream authorizations; we follow only the customer's instructions and deal only with the customer.
  • We are an independent controller only for the limited data described in our Privacy Policy (our own website operations, account administration, and legal compliance).

2. The data we process on a customer's behalf

Annex I lists the categories of data, the data subjects, and the processing purposes. The set is deliberately small: account emails and billing identifiers, the URLs and credentials the customer submits, and the audit results derived from them.

3. Customer responsibilities

The customer confirms that it has provided this notice and obtained any consents or authorizations required to submit the data it gives us — including the authority to have each submitted URL audited and to supply any access credentials and log files. The customer must not submit special-category personal data (health, biometric, political, and similar) through the Service; the Service has no design or need for it.

4. Sub-processors

We use the sub-processors listed in Annex III to operate the Service. We maintain this list with care, and material changes to it will be announced on the site (for example, the changelog) before they take effect. A customer may object to a new sub-processor on reasonable data-protection grounds by contacting us; if we cannot reasonably accommodate the objection, the customer may stop using the affected feature. We remain fully responsible for our sub-processors' performance and contract with each of them on data-protection terms no less protective than this DPA.

5. Security

We apply the technical and organizational measures summarized in Annex II, appropriate to the small set of data involved: encryption in transit, provider-managed access controls and infrastructure (SOC-audited cloud providers), least-privilege access, and rate limiting. No method of storage or transmission is completely secure.

6. Personal data breach

If we become aware of unauthorized access to personal data processed under this DPA, we will notify the customer without undue delay and no later than 72 hours after becoming aware, by email, with the information reasonably available to us (nature of the breach, categories and approximate numbers affected, likely consequences, measures taken). Cost of notification is ours; this notice is not an admission of fault.

7. Data subject requests

If a data subject contacts us directly about data we process on a customer's behalf, we will redirect them to the customer and, where the Service's self-serve tools do not already enable the request, provide the customer with reasonable assistance to respond within the timeframes required by law.

8. International transfers

We and our sub-processors may process data outside the customer's region, including in the United States and the United Arab Emirates. Where the GDPR or UK GDPR applies, such transfers are made under the European Commission's Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, Module Two — controller to processor), which are incorporated into this DPA by reference, together with the UK International Data Transfer Addendum and, for Switzerland, the equivalent Swiss adaptations. The customer consents to these transfer mechanisms as the lawful basis for such transfers.

9. Retention and deletion

We retain personal data processed under this DPA as described in our Privacy Policy. When a customer's account is closed, we delete the account's personal data within 30 days, except: (i) minimal tombstone records that preserve the verifiability of previously issued sealed evidence (a tombstone records that data was removed, not the data itself); (ii) billing and transaction records kept as long as tax, accounting, or other law requires; and (iii) data under legal hold — where a dispute, investigation, or legal claim involving the account is ongoing or reasonably anticipated, we may suspend deletion of the data needed to establish, exercise, or defend it until the matter closes.

10. No training on customer data

We do not use customer personal data or the page content submitted for audit to train machine-learning models, and we do not sell it or use it to advertise.

11. Audit and records

We keep the records required by GDPR Article 30(2). On request, no more than once per year and with reasonable notice, we will provide the customer with documentation of our compliance with this DPA (policies, sub-processor contracts summary, security summaries). On-site or third-party audits are agreed separately and only where legally required or after a confirmed personal data breach, at the customer's expense.

12. Liability

Liability under this DPA follows the limitations and exclusions in our Terms of Service, which form part of this DPA. Nothing in this DPA limits rights that the Standard Contractual Clauses give to data subjects.

13. Precedence

If this DPA conflicts with the Terms on data-protection matters, this DPA and the Standard Contractual Clauses prevail for those matters; the Terms govern everything else. This DPA requires no signature: it applies to every customer from the moment the customer accepts the Terms.


Annex I — Processing details

  • Data subjects: the customer's authorized users (account holders).
  • Categories: account email; billing status and identifiers received from the payment provider; submitted URLs and, where enabled, access credentials supplied by the customer; the content of the pages fetched to produce those audits (used only to produce the audit results and evidence, never republished); audit results and findings.
  • Purposes: operating the Service for the customer (audits, monitoring, billing, support) as described in the Terms and Privacy Policy.
  • Duration: for the life of the customer's account, then per section 9.

Annex II — Technical and organizational measures

Encryption in transit (TLS); Supabase-managed authentication and row-level access controls; least-privilege staff access to production data; infrastructure operated by SOC-audited cloud providers (Vercel, Supabase, Cloudflare, Upstash); rate limiting and abuse controls; self-serve data export and deletion tools for customers.

Annex III — Sub-processors

Sub-processorFunction
StripePayments
ResendEmail delivery
SupabaseDatabase, authentication, storage
VercelWeb hosting, serverless functions
CloudflareEdge, DNS, CDN
SentryError monitoring
Upstash RedisQueues, rate limiting, admin audit logs
ContaboVPS hosting our self-operated Playwright rendering worker (rendered page captures for audits)