haAplo
Run a free audit

Data Processing Agreement

Last updated: 18 August 2026 · Company details final · Pending legal review

This Data Processing Agreement ("DPA") supplements the Terms of Service between the customer ("you", the controller) and PRIMEBUILD s.r.l., Piazza Pio XI 1, 20123 Milano (MI), Italy, VAT IT11516910962 ("haAplo", the processor), under Article 28 GDPR. To sign it: print this page (your browser's Print → Save as PDF gives you the downloadable copy), fill in the signature block at the bottom, and send it to info@haaplo.com; we countersign and return it.

1. Subject matter and duration

haAplo processes personal data on your behalf to provide the service described in the Terms: auditing websites you own or manage, generating and installing fixes, and monitoring results. The DPA lasts as long as your account exists and ends when your data is deleted under §9.

2. Nature, purpose, categories

Processing consists of crawling publicly available pages of your websites, analysing their content (including through the AI providers listed in the sub-processor list), generating content you review, and counting AI-bot visits reported by the optional plugin. Data subjects: you and your team; people whose personal data appears on the audited public pages (for example a name on a contact page). Categories: account data, public website content, technical usage data. haAplo does not ask for and does not want special categories of data.

3. Documented instructions

haAplo processes personal data only to provide the service as configured by you in the product — which audit to run, which site to connect, which draft to approve. We do not use your data for our own purposes, we do not sell it, and we do not enrich it with other sources.

4. No AI training — a written commitment

haAplo does not use your data, your websites' content or your visitors' data to train AI models. Our AI providers process content under API terms that exclude use for training. Content is sent to them only to analyse the audited pages and generate the outputs you asked for.

5. Confidentiality and security

Access to personal data is limited to what the service needs. The measures in force are documented publicly: security headers and strict CSP, row-level isolation between accounts in the database, secrets only in environment variables, credentials and tokens encrypted at rest, an append-only registry of sensitive actions that the database itself refuses to edit, and daily verified copies of the database. The detailed, honest list — including what is not in place — is in our security documentation and pre-filled security questionnaire, available on request at info@haaplo.com.

6. Sub-processors

The live list of sub-processors — each with its purpose and location — is public in our Privacy Policy, §4. That page is the single source: it changes there first. We inform account holders by email before adding or replacing a sub-processor, so you can object; if you object and we cannot accommodate it, you can cancel before the next renewal.

7. Transfers outside the EU/EEA

Where a sub-processor processes data outside the EU/EEA, transfers rely on an adequacy decision or on Standard Contractual Clauses, as stated per provider in the public list.

8. Assistance and breaches

We assist you with data-subject requests and with your own compliance obligations, within what the service can technically see. If a personal data breach affects your data, we notify you without undue delay after becoming aware of it, with what we know at that moment; our internal procedure (72-hour supervisory notification included) is written and rehearsed.

9. Deletion and return

Retention times are public in the Privacy Policy, §5. When your account is deleted, your data is deleted as described there — a scheduled deletion you can cancel for 7 days, or an immediate one; copies age out of our short-lived database snapshots within 30 days. You can download your fixes and approved content from the product at any time before deleting.

10. Audits

We make available the documentation needed to demonstrate compliance with this DPA (security documentation, questionnaire, sub-processor list). Where that is genuinely not enough, you or an auditor you mandate may audit, at reasonable notice and at your expense, without access to other customers' data.

11. Liability

Liability under this DPA follows the limitations in the Terms of Service.

Signatures

For the customer (controller)For PRIMEBUILD s.r.l. (processor)
Company: ______________________________Name: ______________________________
Name and role: ______________________________Role: ______________________________
Date and signature: ______________________________Date and signature: ______________________________
haAplo — user and AI-friendly websites. · Terms · Privacy · DPA · AI transparency