Data processing agreement (for agencies)
Last updated 5 October 2026 · Version 1.0. Written in plain words from how Sitecomb works, and not yet reviewed by a solicitor.
This agreement applies when you buy a Sitecomb agency plan and send us websites that belong to your clients. It is the data protection contract that Article 28 of the GDPR asks for. It applies from the day you buy, with no separate signature.
Who is who?
You, the agency, are the controller. You decide which websites we check and what you do with the reports.
Sahbis Limited, a company registered in Ireland (no. 821013, registered office 77 Camden Street Lower, Dublin 2, D02 XE80), which runs Sitecomb, is the processor. We process personal data for you, on your instructions.
If you are yourself acting for your client, who is the real controller, then we are your sub-processor, and this agreement applies in the same way.
Our terms and privacy notice cover everything else. For personal data in the websites you send us, this agreement comes first if they differ.
What do we do, and for how long?
We check public websites that you send us and produce reports about them. That is the only purpose.
We do this while your agency plan lasts, and for as long as we then hold your data until we delete it (see "What happens when it ends?" below).
What personal data is involved?
The check reads the public pages of the websites you send. Those pages can show personal data: for example the name, email address or phone number of a business owner, a member of staff, or a customer in a testimonial. A report can show a small piece of it as evidence, such as a phone number it found on the page.
We don't gather this into a list or profile, and we don't look for sensitive kinds of data. A public page may show some by chance. We only handle it as part of reading the page.
We also hold your own details as our customer: your name, your email address and the websites you send.
The people concerned are those shown on the pages we read, and your own staff who deal with us.
What do we promise as your processor?
We will:
- Act only on your instructions. Your instructions are: check the websites you send us, make the reports, and what this agreement says. Asking us for a report by email or form counts as an instruction. If we think an instruction breaks the law, we'll tell you.
- Keep it confidential. Anyone who can see your data must keep it confidential.
- Keep it secure. See "How do we keep it secure?" below.
- Use only the providers on the subprocessors page, and tell you before that list changes (see below).
- Help you with requests from people: if someone asks us for their data and it is yours, we'll pass it to you. We'll help you answer people, and help you with security, breach notices and impact assessments, as far as they concern our processing.
- Tell you about a breach without undue delay (see below).
- Delete or return your data at the end (see below).
- Give you the information you need to show that we follow this agreement. If you need more, we'll agree a sensible way, such as a call or a written questionnaire.
How do we keep it secure?
These are the measures we have in place today. We have no security certification, and we don't claim one.
- The website is served only over HTTPS, with browser security headers set.
- Stored orders and reports are in a private storage area, not on public web addresses. A report link is a long random code, and there is no login to guess.
- The server that runs the checks accepts requests only with a secret key.
- Network addresses and website names in our limit counters are stored only as one-way codes, never as the address or name.
- Our error reports are cleaned of personal data, report links and query strings, and never record screens or typing.
- Small limits per network address and website guard the service against abuse.
Who else handles the data?
You agree to the providers on the subprocessors page. Not every provider touches every agency's data.
If we want to add or replace one, we'll email you at least 14 days before it starts. If you object to the change in that time, tell us. If we can't find a way that works for you, you can end your plan.
We only use providers that publish data protection terms, and we stay responsible to you for what they do for us.
Sahbis Limited is in Ireland. Where one of our providers is outside the European Economic Area, the transfer relies on an adequacy decision or on the EU standard contractual clauses, and, for data from the UK, the UK addendum to them.
What if something goes wrong?
If we become aware of a personal data breach that affects your data, we'll tell you without undue delay. We'll say what happened, what data was involved, and what we are doing about it, as far as we know at that point.
What happens when it ends?
When your plan ends, or earlier if you ask us in writing, we delete the reports and website addresses we hold for you. If you ask, we give you a copy first. We'll do it within 30 days of your request, or of the plan ending.
We may keep what the law requires us to keep, such as accounting records.
What do you promise as the controller?
You'll have a lawful reason to send us each website, and you'll have told the people concerned what you are doing, as the law requires of you.
You'll send only websites you are allowed to check, following our acceptable use rules. We never look behind a login, so please don't ask us to.
Which law applies?
Irish law governs this agreement, as it does our terms. As in our terms for business buyers, the Irish courts decide any dispute. We'll always try to sort things out by email first.
Ask us: hello@sitecomb.com