Data Processing Addendum

Last updated October 1, 2026

Template notice: this DPA is a summary template, not a legal instrument. Replace with a version prepared by counsel, including the Standard Contractual Clauses where applicable.

This Data Processing Addendum ("DPA") forms part of the agreement between Citeroot Labs, Inc. ("Processor") and the customer ("Controller") and applies where Citeroot processes personal data on the customer's behalf.

#1. Scope and roles

Customer is the controller and Citeroot is the processor of personal data contained in Customer Data. Details of processing:

  • Subject matter: providing the Service.
  • Duration: the term of the agreement plus deletion period.
  • Nature and purpose: storing, analysing and presenting data submitted by the customer.
  • Categories of data subjects: the customer's personnel and any individuals named in submitted content.
  • Types of personal data: names, business contact details and any personal data included in prompts or imported analytics data.

#2. Instructions

Citeroot processes personal data only on documented instructions from the customer, including as set out in the agreement and this DPA.

#3. Confidentiality

Personnel authorised to process personal data are bound by confidentiality obligations.

#4. Security

Citeroot implements technical and organisational measures described on the security page, including encryption in transit, hashed passwords and tokens, access controls scoped to each account, and rate limiting. Our hosting and database providers encrypt stored data at rest.

#5. Subprocessors

The customer authorises the subprocessors listed at /legal/subprocessors. Citeroot will give notice of new subprocessors and the customer may object on reasonable grounds.

#6. Assistance

Citeroot will assist the customer, taking into account the nature of processing, with data subject requests, security, breach notification, impact assessments and consultations.

#7. Personal data breaches

Citeroot will notify the customer without undue delay after becoming aware of a personal data breach affecting Customer Data.

#8. Return and deletion

On termination, Citeroot will make Customer Data available for export and then delete it within a reasonable period, unless law requires retention.

#9. Audits

Citeroot will make available information necessary to demonstrate compliance and allow for audits as described in the agreement.

#10. International transfers

Where personal data is transferred outside the EEA/UK, the parties will rely on an approved transfer mechanism such as Standard Contractual Clauses.

#Contact

privacy@citeroot.app