Legal
Data Processing Agreement (DPA)
Last updated: August 15, 2026 · Version 0
1. Parties, roles, and scope
This Data Processing Agreement ("DPA") is between Digital Empire Holdings LLC("Digital Empire Holdings LLC", "Processor") and the customer identified in the underlying service agreement ("Customer", "Controller"). It supplements and forms part of the applicable PixelProof Terms of Service, EntryProof Terms of Service, and TariffWatch Terms of Service (each, the "Agreement").
For personal data of Customer's end users that Digital Empire Holdings LLC processes in providing the Services, Customer is the Controller and Digital Empire Holdings LLC is the Processor. For personal data of Customer's own employees or account users (e.g. login credentials, billing contact), Digital Empire Holdings LLC is an independent Controller under its own Privacy Policy.
2. Subject matter, duration, nature and purpose
- Subject matter: processing of Customer Personal Data by Digital Empire Holdings LLC for the purpose of providing PixelProof (Meta pixel / GA4 / GTM compliance monitoring), EntryProof (CPSC eFile readiness assessment), and/or TariffWatch (Section 232 / HTS exposure monitoring and comment-letter drafting), collectively the "Services".
- Duration: co-terminous with the Agreement. Ends automatically on termination of the Agreement, subject to Section 10 (Return / deletion) below.
- Nature and purpose: compliance monitoring, alerting, reporting, and delivery of the Services described in the Agreement and product documentation. No profiling, no automated decision-making with legal or similarly significant effects, no ad-targeting use of Customer Personal Data.
3. Categories of data subjects and personal data
The categories of data subjects and personal data processed under this DPA are, by product:
- PixelProof: Customer's own account/billing contacts (email, name, IP, Stripe customer id) and Customer's storefront domain, discovered scripts, pixel/tag identifiers, and (where applicable) hashed IPs of Customer's end-user visitors captured through Customer's own tracking. PixelProof does not scrape or store Customer's end-user names, checkout line items, cart contents, or order data (see extension DOM-snapshot boundary in
chrome-extensions/pixelproof/src/lib/dom-snapshot.ts). - EntryProof: Customer's own account/billing contacts, plus product HTS codes, brand names, product URLs, and readiness assessments submitted for regulatory analysis. No end-user PII processed.
- TariffWatch: Customer's own account/billing contacts, plus HTS codes, business names/contexts, and comment-letter drafts. Where Customer opts in to comment-letter delivery, the submitted business name and business context become part of the delivered regulatory record; see TariffWatch privacy policy.
Special categories of personal data (Article 9 GDPR): none intended. Customer represents that it will not submit such data through the Services.
4. Sub-processors
Customer authorizes Digital Empire Holdings LLC to engage the sub-processors listed below to provide the Services. Current authoritative lists (with DPA and privacy-policy links for each): PixelProof · EntryProof · TariffWatch.
- Supabase, Inc. (United States, US region (AWS us-east-1)) — Primary database — stores scan results, store domains, findings, email captures, waitlist signups, and account/subscription records. [DPA] [Privacy]
- Stripe, Inc. (United States, US region (Stripe global infrastructure, PCI DSS Level 1)) — Billing — processes and stores payment card details, subscription status, and invoices for paid plans. We never see or store raw card numbers. [DPA] [Privacy]
- Resend, Inc. (United States, US region) — Transactional email — delivers scan reports, receipts, coupon codes, and account notifications. No marketing/cold email sent through this processor. [DPA] [Privacy]
- Vercel Inc. (United States, US region (primary), global edge network for static/cached assets) — Hosting + edge network — serves the application, runs serverless/edge functions, and terminates HTTPS. Vercel edge logs contain IP addresses and request metadata for a limited retention window. [DPA] [Privacy]
- PostHog Inc. (United States, US region (us.i.posthog.com)) — Product analytics + masked session replay (all text/input fields masked). Only loads after cookie consent is granted — see /meta-monitor/cookies. [DPA] [Privacy]
- Functional Software, Inc. (Sentry) (United States, US region) — Client + server error tracking, so we can find and fix bugs. Client-side Sentry only loads after cookie consent is granted — see /meta-monitor/cookies. [DPA] [Privacy]
- Apollo.io (Apollo Technologies, Inc.) (United States, US region) — Business-contact prospecting for outbound cold email to potential customers, run via Instantly (see /meta-monitor/cookies for the outbound-email disclosure). Apollo does not process any data submitted by users of the product itself. [DPA] [Privacy]
Notification of new sub-processors: Digital Empire Holdings LLC will notify Enterprise Customers at least 30 days in advance of adding a new sub-processor. Customer may object in writing within 15 days; if objection cannot be resolved, Customer may terminate the affected Service and receive a pro-rated refund of unused prepaid fees.
5. Cross-border transfers
For transfers of Customer Personal Data originating in the EEA, the United Kingdom, or Switzerland to a country not deemed adequate under GDPR Art. 45, the parties incorporate by reference the European Commission's Standard Contractual Clauses of 4 June 2021 (Decision 2021/914), with Module Two (Controller-to-Processor) applying to processing under this DPA. Docking clause: the SCCs apply to any additional data importer disclosed on the sub-processors page. For UK-origin transfers, the UK International Data Transfer Addendum (Version B1.0, issued by the ICO) is incorporated. For Swiss-origin transfers, references in the SCCs to Union law and Member State supervisory authorities are read to include Swiss FADP references and the Swiss Federal Data Protection and Information Commissioner as applicable.
6. Data subject rights
Digital Empire Holdings LLC provides self-serve mechanisms to fulfill data-subject rights (access, deletion, portability, restriction):
- PixelProof: /meta-monitor/account/delete (self-serve deletion, 24h token confirmation, 30-day paid-tier completion SLA).
- EntryProof: self-serve deletion form.
- TariffWatch: /tariffwatch/account/delete.
- All products: email hello@citationsafe.com for access/portability/restriction requests.
Where Customer receives a data-subject request that concerns data processed by Digital Empire Holdings LLC under this DPA, Digital Empire Holdings LLC will provide reasonable assistance (technical and organizational measures) to enable Customer to respond within statutory deadlines (1 calendar month under GDPR Art. 12(3), 45 days under CCPA §1798.130).
7. Security measures (Article 32 GDPR)
Digital Empire Holdings LLC maintains, at minimum, the following security controls (see also /security and our full coordinated vulnerability disclosure policy):
- Encryption in transit: TLS 1.2+ enforced on all Customer-facing and processor-facing endpoints.
- Encryption at rest: Supabase-managed at-rest encryption on all primary datastores.
- Access control: row-level security enabled on every table in the pixelproof / cpsc_efile / pick3 schemas; production service-role credentials scoped to the schemas required; admin console access gated by WebAuthn.
- Audit logging: Vercel edge logs (limited retention), Supabase audit logs, Sentry error tracking, and per-route request-id correlation.
- Least-privilege sub-processing: each sub-processor listed in Section 4 has a documented purpose scope; none receives data outside that scope.
- No LLM runtime processing: Customer Personal Data is not sent to any large-language-model provider as part of any live product feature.
8. Personal-data breach notification
Digital Empire Holdings LLC will notify Customer of a Personal Data Breach affecting Customer Personal Data without undue delay, and in any event within 72 hours of Digital Empire Holdings LLC becoming aware of the breach, per GDPR Art. 33. The notification will include: (a) the nature of the breach, (b) categories and approximate number of data subjects and records affected, (c) likely consequences, and (d) measures taken or proposed to address the breach and mitigate adverse effects. See also the breach-notification section of each product privacy policy.
9. Audits and information
Digital Empire Holdings LLC will make available all information reasonably necessary to demonstrate compliance with Article 28 GDPR and applicable law. Customer may audit compliance no more than once per calendar year, on 30 days' written notice, under a mutually agreed confidentiality agreement, and at Customer's expense. Third-party audit reports (SOC 2, ISO 27001) from sub-processors listed in Section 4 satisfy the audit obligation with respect to those sub-processors and are available on request to hello@citationsafe.com.
10. Return and deletion at end of processing
On termination of the Agreement, and at Customer's written election, Digital Empire Holdings LLCwill (a) delete Customer Personal Data from active systems within 30 days, or (b) return Customer Personal Data in a commonly used, machine-readable format (JSON export via the per-product export APIs) and then delete it. Backups are purged on their normal 30-day rotation cycle after the deletion event. Digital Empire Holdings LLC may retain Customer Personal Data to the extent required by applicable law (e.g. tax records under 26 CFR §1.6001-1), for the shortest period required, in an access-restricted state.
11. CCPA / CPRA — service provider terms
For personal information subject to the California Consumer Privacy Act (as amended by the CPRA), Digital Empire Holdings LLC acts as a "service provider" under Cal. Civ. Code §1798.140(ag). Digital Empire Holdings LLC: (i) will not sell or share personal information; (ii) will not retain, use, or disclose personal information for any purpose other than the business purpose specified in this DPA and the Agreement, including for a commercial purpose other than providing the Services; (iii) will not retain, use, or disclose personal information outside the direct business relationship with Customer; and (iv) will not combine personal information received from Customer with personal information received from another source, except as permitted under §1798.140(ag)(1)(D).
12. Liability and indemnity
Each party's liability arising under or in connection with this DPA (including the SCCs and UK Addendum) is subject to the limitation of liability provisions in the Agreement. Where a claim is brought under the SCCs directly by a data subject, the parties intend that liability be apportioned pursuant to Clause 12 of the SCCs.
13. Order of precedence
In case of conflict between this DPA, the Agreement, the SCCs, and any Order Form, the following order applies (highest to lowest): (1) the SCCs (to the extent applicable), (2) this DPA, (3) the Order Form, (4) the Agreement.
14. Contact and execution
- DPA-specific requests and countersignatures: hello@citationsafe.com.
- General legal: hello@citationsafe.com.
- Data-subject requests: hello@citationsafe.com.
Full text of Commission Implementing Decision (EU) 2021/914 (Standard Contractual Clauses) is available on the EUR-Lex website; the UK International Data Transfer Addendum (B1.0) is available on the ICO website. Both are incorporated by reference and take precedence over conflicting terms in this DPA per Section 13.
Built by Andy Gaber, Digital Empire Holdings LLC.
Digital Empire Holdings LLC, 30 N Gould St Ste N, Sheridan WY 82801