Data Processing Addendum

This Data Processing Addendum ("DPA") forms part of the agreement between Lightsite Ltd., operating as Lightsite AI, and the customer, and governs the processing of Customer Personal Data in connection with the LightSite AI platform. Last updated 6 August 2026.

Roles of the Parties

The customer acts as controller (or processor on behalf of its own controller) for Customer Personal Data, and Lightsite AI acts as processor. Lightsite AI processes Customer Personal Data only on the customer's documented instructions and as needed to provide the Services described in the Terms and Conditions.

Nature and Purpose of Processing

Processing covers deployment of machine-readable resources (AI sitemaps, structured endpoints, JSON-LD, agent manifests, Skills API endpoints), measurement of AI crawler and AI-referred visitor activity, account administration, support, and security monitoring. The website integration is designed to operate without cookies, local storage or browser fingerprinting and does not collect visitor names, credentials, payment data or form contents.

Security Measures

Lightsite AI maintains technical and organizational measures including encryption in transit (TLS 1.2 or higher) and at rest, organization-scoped access controls and tenant isolation, least-privilege internal access, managed secrets and credentials, MFA and Microsoft Entra ID SSO support, dependency and code security scanning, and logging and monitoring. See the Security & Trust page for the full overview.

Sub-Processors

Lightsite AI engages sub-processors for database, authentication, hosting, communications and AI processing functionality, each bound by written obligations no less protective than this DPA. A current sub-processor list is available on request at support@lightsite.ai.

Data Residency and International Transfers

The primary production database is hosted in Frankfurt, Germany on AWS infrastructure. Where Customer Personal Data is transferred outside the EEA or UK, transfers rely on an adequacy decision, the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, or another valid transfer mechanism.

Security Incidents

Lightsite AI notifies the customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data, and provides reasonably available information to support the customer's own notification obligations.

AI and Model Training

Lightsite AI does not use Customer Data to train general-purpose AI models and does not provide Customer Data to third-party AI providers for model training. Publicly available information and anonymized, aggregated or de-identified data that does not identify a customer or individual may be used to improve the Services.

Data Subject Requests, Return and Deletion

Lightsite AI provides reasonable assistance with data subject requests and, on termination, deletes or returns Customer Personal Data within the period stated in the applicable agreement, except where retention is required by law.

Contact

DPA execution requests and privacy questions: support@lightsite.ai. See also the Privacy Policy and SLA.