We’re upgrading our email infrastructure — for immediate response, email andrewjgaber@gmail.com meanwhile.
Skip to main content
v0 — attorney-review-pending. This Data Processing Agreement is drafted in-house for transparency and enterprise procurement diligence. It has not yet been reviewed or executed by outside counsel. Individual clauses may be non-binding until such review completes. For a countersigned production copy, email hello@citationsafe.com — Andy will forward to counsel and return an executable version. Do not rely on this v0 as a complete legal instrument.

Legal

Data Processing Agreement (DPA)

Last updated: August 15, 2026 · Version 0

1. Parties, roles, and scope

This Data Processing Agreement ("DPA") is between Digital Empire Holdings LLC("Digital Empire Holdings LLC", "Processor") and the customer identified in the underlying service agreement ("Customer", "Controller"). It supplements and forms part of the applicable PixelProof Terms of Service, EntryProof Terms of Service, and TariffWatch Terms of Service (each, the "Agreement").

For personal data of Customer's end users that Digital Empire Holdings LLC processes in providing the Services, Customer is the Controller and Digital Empire Holdings LLC is the Processor. For personal data of Customer's own employees or account users (e.g. login credentials, billing contact), Digital Empire Holdings LLC is an independent Controller under its own Privacy Policy.

2. Subject matter, duration, nature and purpose

3. Categories of data subjects and personal data

The categories of data subjects and personal data processed under this DPA are, by product:

Special categories of personal data (Article 9 GDPR): none intended. Customer represents that it will not submit such data through the Services.

4. Sub-processors

Customer authorizes Digital Empire Holdings LLC to engage the sub-processors listed below to provide the Services. Current authoritative lists (with DPA and privacy-policy links for each): PixelProof · EntryProof · TariffWatch.

Notification of new sub-processors: Digital Empire Holdings LLC will notify Enterprise Customers at least 30 days in advance of adding a new sub-processor. Customer may object in writing within 15 days; if objection cannot be resolved, Customer may terminate the affected Service and receive a pro-rated refund of unused prepaid fees.

5. Cross-border transfers

For transfers of Customer Personal Data originating in the EEA, the United Kingdom, or Switzerland to a country not deemed adequate under GDPR Art. 45, the parties incorporate by reference the European Commission's Standard Contractual Clauses of 4 June 2021 (Decision 2021/914), with Module Two (Controller-to-Processor) applying to processing under this DPA. Docking clause: the SCCs apply to any additional data importer disclosed on the sub-processors page. For UK-origin transfers, the UK International Data Transfer Addendum (Version B1.0, issued by the ICO) is incorporated. For Swiss-origin transfers, references in the SCCs to Union law and Member State supervisory authorities are read to include Swiss FADP references and the Swiss Federal Data Protection and Information Commissioner as applicable.

6. Data subject rights

Digital Empire Holdings LLC provides self-serve mechanisms to fulfill data-subject rights (access, deletion, portability, restriction):

Where Customer receives a data-subject request that concerns data processed by Digital Empire Holdings LLC under this DPA, Digital Empire Holdings LLC will provide reasonable assistance (technical and organizational measures) to enable Customer to respond within statutory deadlines (1 calendar month under GDPR Art. 12(3), 45 days under CCPA §1798.130).

7. Security measures (Article 32 GDPR)

Digital Empire Holdings LLC maintains, at minimum, the following security controls (see also /security and our full coordinated vulnerability disclosure policy):

8. Personal-data breach notification

Digital Empire Holdings LLC will notify Customer of a Personal Data Breach affecting Customer Personal Data without undue delay, and in any event within 72 hours of Digital Empire Holdings LLC becoming aware of the breach, per GDPR Art. 33. The notification will include: (a) the nature of the breach, (b) categories and approximate number of data subjects and records affected, (c) likely consequences, and (d) measures taken or proposed to address the breach and mitigate adverse effects. See also the breach-notification section of each product privacy policy.

9. Audits and information

Digital Empire Holdings LLC will make available all information reasonably necessary to demonstrate compliance with Article 28 GDPR and applicable law. Customer may audit compliance no more than once per calendar year, on 30 days' written notice, under a mutually agreed confidentiality agreement, and at Customer's expense. Third-party audit reports (SOC 2, ISO 27001) from sub-processors listed in Section 4 satisfy the audit obligation with respect to those sub-processors and are available on request to hello@citationsafe.com.

10. Return and deletion at end of processing

On termination of the Agreement, and at Customer's written election, Digital Empire Holdings LLCwill (a) delete Customer Personal Data from active systems within 30 days, or (b) return Customer Personal Data in a commonly used, machine-readable format (JSON export via the per-product export APIs) and then delete it. Backups are purged on their normal 30-day rotation cycle after the deletion event. Digital Empire Holdings LLC may retain Customer Personal Data to the extent required by applicable law (e.g. tax records under 26 CFR §1.6001-1), for the shortest period required, in an access-restricted state.

11. CCPA / CPRA — service provider terms

For personal information subject to the California Consumer Privacy Act (as amended by the CPRA), Digital Empire Holdings LLC acts as a "service provider" under Cal. Civ. Code §1798.140(ag). Digital Empire Holdings LLC: (i) will not sell or share personal information; (ii) will not retain, use, or disclose personal information for any purpose other than the business purpose specified in this DPA and the Agreement, including for a commercial purpose other than providing the Services; (iii) will not retain, use, or disclose personal information outside the direct business relationship with Customer; and (iv) will not combine personal information received from Customer with personal information received from another source, except as permitted under §1798.140(ag)(1)(D).

12. Liability and indemnity

Each party's liability arising under or in connection with this DPA (including the SCCs and UK Addendum) is subject to the limitation of liability provisions in the Agreement. Where a claim is brought under the SCCs directly by a data subject, the parties intend that liability be apportioned pursuant to Clause 12 of the SCCs.

13. Order of precedence

In case of conflict between this DPA, the Agreement, the SCCs, and any Order Form, the following order applies (highest to lowest): (1) the SCCs (to the extent applicable), (2) this DPA, (3) the Order Form, (4) the Agreement.

14. Contact and execution

Full text of Commission Implementing Decision (EU) 2021/914 (Standard Contractual Clauses) is available on the EUR-Lex website; the UK International Data Transfer Addendum (B1.0) is available on the ICO website. Both are incorporated by reference and take precedence over conflicting terms in this DPA per Section 13.


Built by Andy Gaber, Digital Empire Holdings LLC.
Digital Empire Holdings LLC, 30 N Gould St Ste N, Sheridan WY 82801