Data Processing Addendum
Ultimo aggiornamento: 2026-09-05
For business customers who need a DPA covering Semantyra processing on their behalf.
Scope
This Addendum forms part of the Terms of Service between you ("Customer", the controller) and Semantyra ("Semantyra", the processor) and applies where Semantyra processes personal data on your behalf. A separately signed copy is available on request at [email protected] and, if signed, prevails over this page.
Subject matter and details of processing
Subject matter: providing the Semantyra service. Duration: for as long as your account is active, plus the retention periods in the Privacy Policy. Nature and purpose: crawling public pages of sites you authorise, analysis, storage, and transactional communication.
Categories of data: account identifiers (name, email), workspace and project configuration, and analysis output. Categories of data subjects: your authorised users and workspace members.
Processor obligations
Semantyra will:
- Process personal data only on your documented instructions, including the Terms and your use of the product; and tell you if an instruction appears to breach applicable law.
- Ensure people authorised to process the data are under confidentiality obligations.
- Implement appropriate technical and organisational measures (see "Security measures" below).
- Assist you, taking into account the nature of processing, with data-subject requests and with your obligations on security, breach notification and impact assessments.
- Notify you without undue delay after becoming aware of a personal-data breach affecting your data.
- At your choice, delete or return the personal data at the end of the service and delete existing copies, unless retention is required by law.
- Make available information needed to demonstrate compliance and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, on reasonable notice and no more than once a year unless a supervisory authority or a breach requires otherwise.
Sub-processors
You authorise the sub-processors listed in the Privacy Policy ("Third parties and sub-processors"). Semantyra imposes data-protection terms on each sub-processor no less protective than this Addendum and remains liable for their performance. Semantyra will give at least 30 days notice of an intended new sub-processor via this page or by email; you may object on reasonable data-protection grounds, and if the matter cannot be resolved you may terminate the affected subscription.
Security measures
Current measures include:
- Encryption in transit (TLS) and encryption at rest for stored provider credentials (Fernet).
- Passwords stored only as salted hashes; short-lived access tokens with refresh rotation.
- Network isolation: only the web entrypoint is exposed; database and cache are not reachable from outside the host.
- Least-privilege API scopes, SSRF protection on the crawler, and rate limiting.
- Backups with a defined rotation and restore procedure; security logs rotated within 30 days.
International transfers
Where a sub-processor processes personal data outside the EEA, the transfer relies on the European Commission Standard Contractual Clauses (Semantyra as data exporter on your behalf) and the UK Addendum where relevant, plus the provider-specific safeguards each publishes.
Contact
Questions about this document: [email protected].