Data Processing Agreement
Data Processing Agreement (DPA)
Our terms for processing personal data on behalf of enterprise customers.
Last updated: 18 August 2026
Reach us through the contact page — we'll send a counter-signed PDF within 1 business day.
Counter-sign online
1. Parties
This DPA governs the processing of personal data between AuditToDesk (operated by SAGBRAIN CORPORATION, the "Processor") and the customer using the AuditToDesk service (the "Controller").
2. Data in scope
Data the Controller registers or submits to AuditToDesk, including (i) user account information (email, name), (ii) scanned URLs, (iii) public website content surfaced by scans, and (iv) billing and usage logs.
3. Processing purpose
Generating site-diagnosis reports, agency matching, account operations, fraud detection, statutory retention, and any activity necessary to deliver the service.
4. Processing duration
For as long as the Controller maintains an account. After deletion, data is erased per our retention policy (backups retained for up to 90 days).
5. Sub-processors
Current sub-processors: Amazon Web Services (hosting), Google Gemini API (AI diagnosis), Google PageSpeed Insights API (performance), Stripe (payments), SendGrid or AWS SES (email). New sub-processors will be notified by email ≥30 days in advance.
6. Security measures
TLS 1.2+ in transit, AES-256 at rest, dual-layer multi-tenant isolation via PostgreSQL Row-Level Security, bcrypt (cost 12) password hashing, short-lived JWT access tokens, SOC 2-compliant AWS infrastructure.
7. Personal-data breach notification
We will notify the Controller by email within 72 hours of becoming aware of any breach of personal data, including the nature of the breach, an estimate of affected records, and the steps we have taken.
8. Data-subject rights
On the Controller's reasonable request we will provide technical assistance for data-subject access, rectification, erasure, and portability requests. Send written requests to the contact in Section 12.
9. Audit rights
Controllers may conduct a security-questionnaire-based audit once per year with ≥30 days' notice.
10. International data transfers
Primary infrastructure is hosted in Japan, but sub-processors may process data in the US or EU. Cross-border transfers are protected by GDPR-compliant Standard Contractual Clauses (SCCs).
11. Termination
On service-agreement termination, personal data will be returned or erased within 30 days at the Controller's choice, subject to statutory retention obligations.
12. Contact
DPA-related inquiries: info@sagbrain.com / SAGBRAIN CORPORATION.