Legal
Data Processing Addendum
Effective September 2, 2026
This Data Processing Addendum (“DPA”) supplements the SiteFixPlan Terms of Service when Media Yard LLC processes personal data on behalf of a business customer.
Parties and scope
This DPA is between the customer using SiteFixPlan (“Customer”) and Media Yard LLC, doing business as SiteFixPlan, PO Box 73, Pennsauken, NJ 08110 (“SiteFixPlan”). It applies only to personal data contained in URLs, audit inputs, technical findings, reports, and related customer content that SiteFixPlan processes to provide the service. Capitalized terms not defined here have the meaning given in the Terms of Service.
Roles and instructions
Customer is the controller or business and SiteFixPlan is the processor or service provider for customer content. If Customer acts for another organization, Customer may be a processor and SiteFixPlan its subprocessor. Customer instructs SiteFixPlan to process that data only to provide, secure, support, and maintain SiteFixPlan; comply with documented lawful instructions; and meet legal obligations. Customer is responsible for the lawfulness of its instructions and submitted data.
Processing details
- Subject matter: automated public-website audits and report generation.
- Duration: the account term plus the limited retention described in our Privacy Policy.
- Data: submitted public URLs, page titles, technical measurements, findings, reports, and user-provided audit context.
- People: Customer users and individuals whose information appears on submitted public pages.
- Operations: collection, transmission, analysis, storage, organization, retrieval, sharing at Customer’s direction, and deletion.
SiteFixPlan is not intended for passwords, private pages, payment-card data, health information, government identifiers, or special-category or highly sensitive personal data. SiteFixPlan does not act as a HIPAA business associate.
SiteFixPlan commitments
SiteFixPlan will:
- process customer personal data only on documented instructions unless law requires otherwise;
- require personnel with access to keep it confidential;
- maintain appropriate technical and organizational safeguards;
- notify Customer without undue delay after confirming a personal-data breach affecting customer content;
- reasonably assist Customer with data-subject requests, security inquiries, and legally required assessments; and
- make information reasonably necessary to demonstrate compliance available on request, subject to confidentiality and security limits.
Security
Safeguards include access controls, authenticated sessions, database row-level security, encryption in transit and provider-managed encryption at rest, logging and monitoring, restricted production access, dependency and vulnerability maintenance, and backup and recovery measures appropriate to the service. No system can guarantee absolute security.
Subprocessors
Customer authorizes SiteFixPlan to use subprocessors necessary to provide the service. Principal subprocessors are Vercel for hosting and analytics, Supabase for authentication and database services, Google for PageSpeed website analysis, and OpenAI for AI-assisted explanations. Stripe independently processes billing information and is generally not a subprocessor for customer audit content. We remain responsible for subprocessors to the extent required by applicable data-protection law.
International transfers
Data may be processed in the United States and other countries where our providers operate. When applicable law requires a transfer mechanism, the relevant EU Standard Contractual Clauses and UK transfer addendum are incorporated to the extent legally required, using the module appropriate to the parties’ roles. Contact us for information about the mechanism applicable to your account.
US state privacy laws
Where US state privacy law applies, SiteFixPlan acts as a service provider or processor and will not sell or share customer personal data for cross-context behavioral advertising, retain or use it outside the business purposes described here, or combine it with unrelated personal data except as permitted by law.
Return, deletion, and precedence
Customer can export or request deletion of account data through the service. At termination, SiteFixPlan will delete or return customer personal data in accordance with the Privacy Policy, subject to legal, security, fraud-prevention, backup, and shared-workspace exceptions. If this DPA conflicts with the Terms regarding processing of customer personal data, this DPA controls.
Contact
Questions or requests regarding this DPA may be sent to privacy@sitefixplan.comor mailed to Media Yard LLC, PO Box 73, Pennsauken, NJ 08110.