Legal

Data Processing Agreement

Last updated: September 1, 2026

This Data Processing Agreement (“DPA”) forms part of the Terms of Servicebetween you (“Customer”) and AnswerPeek. It applies automatically, with no signature required, whenever you use the Service to process personal data for which you are the controller — in practice, when you are an agency running AnswerPeek on behalf of your own clients.

If your organization requires a countersigned copy, email support@answerpeek.com and we will sign this document as it stands.

1. Roles

For personal data you submit or generate through the Service, you are the controller and we are the processor. You decide which brands, domains and prompts to track, and on whose behalf. We process that data only to provide the Service.

For data about your own AnswerPeek account — your name, your email, your billing record, how you use the product — we are the controller, and our Privacy Policy governs it rather than this DPA.

2. Subject matter, duration and scope

  • Subject matter: measuring how AI assistants answer about a brand, and generating recommendations from those answers.
  • Duration: for as long as your account is active, plus the deletion period in section 7.
  • Categories of data subject:your personnel and your clients’ personnel, to the extent their names or contact details appear in content you submit or in an answer we retrieve.
  • Categories of personal data: business contact details and any personal data contained in brands, domains, prompts, notes or retrieved answers. The Service is not designed for special categories of data under Article 9 GDPR, and you agree not to submit them.

3. Our obligations

  • We process personal data only on your documented instructions. Your use of the Service, and this DPA, are those instructions. If we believe an instruction breaches data protection law, we will tell you.
  • We ensure that anyone authorised to process the data is bound by confidentiality.
  • We do not sell personal data, and we do not use your content to train models. What the third-party AI providers do with an API request once it reaches them is governed by their own terms, which is a limit we state plainly in section 7 of the Terms rather than paper over.
  • We assist you, so far as we reasonably can, with data subject requests, impact assessments and consultations with a supervisory authority.

4. Security

We maintain technical and organisational measures appropriate to the risk, including encryption in transit (TLS) and at rest, row-level security in the database so one workspace cannot read another’s data, access controls limiting who can reach production, and separate credentials for administrative access.

5. Subprocessors

You give general authorisation for us to engage subprocessors. The current list, with each provider’s purpose, the data it receives and where it processes, is published at answerpeek.com/subprocessors and is kept current. We remain responsible for their performance, and we impose data protection terms on them no less protective than these.

We will update that page before a new subprocessor begins handling customer data, and will notify customers who have asked to be told. If you reasonably object to a new subprocessor on data protection grounds, tell us within 30 days and we will work with you to find an alternative; if none exists, you may terminate the affected subscription and receive a pro-rata refund of the unused period.

6. International transfers

AnswerPeek is operated from Ukraine and several subprocessors are in the United States. Where personal data is transferred out of the EEA or the UK, we rely on the European Commission’s standard contractual clauses, the UK Addendum where applicable, or another lawful transfer mechanism. The location of each subprocessor is stated on the subprocessors page.

7. Deletion and return

You can export your data at any time from the product. On termination, or on your written request, we delete the personal data we process on your behalf within 30 days, except where we are required by law to retain it. Deleting a project or your account triggers that deletion. What survives an account deletion, and why, is set out in section 3 of our Privacy Policy — we would rather name the exceptions than promise a clean sweep we do not perform.

8. Audits

On reasonable written request, and no more than once a year unless a supervisory authority requires otherwise, we will provide the information reasonably necessary to demonstrate compliance with this DPA. We are a small team: we will answer a questionnaire and provide documentation rather than host an on-site audit, and we will say so plainly rather than agree to something we cannot staff.

9. Personal data breach

We notify you without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting data we process for you, with the information you need to meet your own notification duties.

10. Liability and precedence

Liability under this DPA is subject to the limitations in the Terms of Service. If this DPA conflicts with the Terms on the processing of personal data, this DPA prevails. Everything else in the Terms continues to apply, including governing law.