Welcome

Data Processing Agreement

Version 1.0 — last updated 29 July 2026

This DPA applies automatically to every customer who uses EGNITE as a processor of personal data. To receive a countersigned copy for your procurement file, email privacy@egnitegroup.com with your legal entity name and address.

1. Parties and roles

This agreement is between you (the "Customer", acting as data controller) and EGNITE (the "Processor"), and governs the processing of personal data carried out by EGNITE on your behalf when you use the platform. Where EGNITE processes data for its own account administration, marketing, and security purposes, it acts as an independent controller under the Privacy Policy.

2. Subject matter, duration, nature and purpose

EGNITE processes personal data to deliver Generative Engine Optimization analytics: AI visibility scans, GEO scoring and recommendations, competitor and citation analysis, post-quantum cryptography readiness assessments, expert verification of rewrites, reporting, and account and billing administration. Processing lasts for the duration of your account and ends on account deletion or termination.

3. Categories of data subjects and personal data

  • Data subjects: your employees and authorised users of the platform, and named contacts you submit through forms.
  • Account data: name, business email, company, job function, department, industry, optional phone number.
  • Usage data: prompts, brands, competitors, scan results, recommendations, timestamps, model and region selections.
  • Technical data: IP address, browser type, session and authentication cookies.
  • Billing metadata: plan, subscription status, billing identifiers. No card data is stored by EGNITE.
  • No special categories of data (Article 9 GDPR) are required by, or intended for, the service. Do not submit them.

4. Processor obligations

  • Process personal data only on your documented instructions, including for international transfers.
  • Ensure personnel with access are bound by confidentiality.
  • Implement the technical and organisational measures set out in section 6.
  • Engage subprocessors only under section 5.
  • Assist you with data subject requests, DPIAs, and consultations with supervisory authorities.
  • Notify you of a personal data breach without undue delay and within 72 hours of becoming aware.
  • Delete or return personal data at the end of the service, subject to legal retention duties.
  • Make available the information needed to demonstrate compliance with Article 28 GDPR.

5. Subprocessors

You give general authorisation to the following subprocessors:

SubprocessorPurposeData received
Lovable Cloud (Supabase infrastructure)Hosting, database, authentication, server functionsAll account and workspace data
Resend (via Lovable Email)Transactional and newsletter email deliveryName and email address
PaddleSubscription billing and taxBilling contact and plan metadata
OpenAI (ChatGPT, Copilot models)AI visibility scanningPrompt and brand context only
Anthropic (Claude)AI visibility scanning and rewritesPrompt and brand context only
Google (Gemini)AI visibility scanningPrompt and brand context only
PerplexityAI visibility scanning and citation retrievalPrompt and brand context only
xAI (Grok)AI visibility scanningPrompt and brand context only
DeepSeekAI visibility scanningPrompt and brand context only
FirecrawlPublic page retrieval for GEO scansPublic URLs you submit
CloudflareEdge delivery, TLS termination, bot protectionIP address and request metadata

We will inform you of any intended change to this list and give you the opportunity to object. AI providers receive only prompt and public brand context — never your account identifiers, email address, or contact details.

6. Technical and organisational measures (Article 32)

  • Encryption of all data in transit (TLS) and at rest by the hosting provider.
  • Row-Level Security on every customer table, scoping reads and writes to the authenticated account. Isolation is re-verified by an automated two-account test across all customer tables.
  • Role separation: administrative privileges are held in a dedicated role check, never client-side.
  • Plan, subscription, and role fields are server-controlled — customers cannot alter their own entitlements.
  • Breached-password screening (Have I Been Pwned) at sign-up and password change.
  • Secrets held in a managed secret store; service credentials never reach the browser.
  • Rate limiting and bot protection on public forms; input validated server-side.
  • Automated security scanning of the backend with review and remediation of findings.
  • Least-privilege database grants; internal functions are not executable by customer roles.

7. International transfers

Data is hosted in the European Union. Where a subprocessor processes data outside the EEA (for example certain AI providers in the United States), transfers rely on the European Commission's Standard Contractual Clauses together with the supplementary measure that no directly identifying account data is transmitted to those providers.

8. Data subject rights and assistance

Account holders can export a complete machine-readable copy of their data or trigger irreversible erasure at any time from Settings → Privacy. For requests you receive as controller, email privacy@egnitegroup.com and we will assist within 5 business days.

9. Audit

On reasonable written notice and no more than once per year, EGNITE will answer a security questionnaire and provide documentation of the measures in section 6. On-site audits are available where required by Article 28(3)(h), scheduled to avoid disruption and subject to confidentiality.

10. Return and deletion

On termination, you may export your data before deleting your account. Deletion erases all personal and workspace data immediately and irreversibly, except records EGNITE must retain by law (for example billing records) and anonymous statistics that cannot identify a data subject.

11. Liability and order of precedence

This DPA forms part of and is subject to the Terms of Service. In the event of conflict on data protection matters, this DPA prevails.

This document describes EGNITE's contractual data-protection commitments. It is not a certification or an independent audit report. See also Privacy Policy and Trust & Security.