SiteVelox ENDE

Data Processing Agreement

under Article 28 of the General Data Protection Regulation (GDPR) · effective from 2026-10-09

Controller: the customer of the SiteVelox service (website owner), as stated in the sign-up.
Processor: RealDropHunt Labs Ltd, 71-75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom, info@sitevelox.com.
Processor’s EU representative (Art. 27 GDPR): Matevž Filej, Trg vstaje 8, 2342 Ruše, Slovenia.

This agreement is concluded by accepting it at sign-up and forms part of the Terms of Service. On request, the processor also provides it for signature.

1. Subject, nature and purpose

On behalf of the controller, the processor passes the traffic of visitors to the controller’s website to the controller’s server and optimises and caches public website content (the SiteVelox service). Processing lasts as long as the subscription.

2. Types of data and data subjects

  • Data subjects: visitors to the controller’s website.
  • Data: IP address, request data (page address, browser, language, screen size), cookies and form contents travelling to the controller’s server.
  • The processor does not intentionally process special categories of data; if the controller’s website collects them, the processor only passes them on.

3. How the processor handles data

  • Visitor data is only passed on; it is not stored or used for the processor’s own purposes.
  • Only public page content is cached. Requests with logins, carts, sessions, admin areas and form submissions always go directly to the controller’s server and are never cached.
  • The visitor’s IP address is passed to the controller’s server (X-Forwarded-For header) so the controller can apply its own security measures.
  • Anonymous speed measurements and JavaScript error counts (page path, device type, timings) are collected; they contain no IP addresses, cookies or other identifiers and are kept for 35 days. Assignment to the comparison group (original page) uses a one-way hash of the IP address and browser, which is not stored.
  • Technical infrastructure logs (for troubleshooting) are kept for up to 7 days. The entry servers do not keep access logs.

4. Obligations of the processor

  1. Processes data only on documented instructions of the controller; this agreement and the service settings are those instructions.
  2. Persons with access to the systems are bound by confidentiality.
  3. Implements the technical and organisational measures in the annex.
  4. Assists the controller in responding to data subject requests and in meeting obligations under Articles 32–36 GDPR.
  5. Notifies the controller of a personal data breach without undue delay, at the latest within 48 hours of becoming aware of it.
  6. Deletes all data related to the controller’s website within 30 days after the end of the subscription.
  7. Makes available the information needed to demonstrate compliance and allows audits to a reasonable extent, with at least 30 days’ notice.

5. Sub-processors

The controller generally authorises the sub-processors below. The processor informs the controller by e-mail at least 30 days before intended changes; the controller may object and cancel without cost.

Sub-processorServiceLocation and transfer safeguard
Cloudflare, Inc.network for passing, optimising and caching trafficglobal (location nearest to the visitor); USA – EU-US Data Privacy Framework and standard contractual clauses
OVH SASentry servers for the root domain, page preparationEU

Annex: technical and organisational measures

  • Encryption of all connections (TLS) between the visitor, the processor’s network and the controller’s server.
  • Server access only with SSH keys; password login disabled; firewall allows only necessary ports; automatic security updates.
  • Internal connections between system components are protected with secret keys.
  • Cache separated by domain; personal content is never cached; the controller’s security headers are preserved.
  • On a service error, requests are passed to the controller’s server (no loss of visitor data).
  • Least-privilege principle and regular review of access.
© SiteVelox Terms · Privacy · Home