Effective date: June 20, 2026 · Last updated: June 20, 2026
Version 1.0
This Data Processing Agreement ("DPA") forms part of the Terms of Service ("Principal Agreement") between W3 EDGE, LLC d/b/a Auctollo ("Auctollo," "Processor," "we") and the customer identified in the Principal Agreement ("Customer," "Controller," "you").
This DPA applies whenever Auctollo processes Customer Personal Data on Customer’s behalf in the course of providing the Auctollo cloud platform (the "Service"). Customer Personal Data means personal data about Customer’s end users, website visitors, or other natural persons that Auctollo processes as a processor on Customer’s instructions — distinct from data Auctollo collects as a controller of its own customer relationship (covered by the Privacy Policy).
This DPA is intended to satisfy Article 28 of the EU GDPR (Regulation (EU) 2016/679), the UK GDPR, and equivalent provisions of other applicable data-protection laws ("Data Protection Laws").
In the event of a conflict between this DPA and the Principal Agreement with respect to the processing of Customer Personal Data, this DPA controls.
Unless otherwise defined here, capitalized terms have the meanings given in the Principal Agreement or in GDPR Article 4.
For the purposes of this DPA and with respect to Customer Personal Data:
Where Auctollo processes Personal Data about Customer itself (account email, billing data, admin display name) in the course of operating the Service, Auctollo acts as a Controller of that data, governed by the Privacy Policy. This DPA does not apply to such processing.
| Item | Description |
|---|---|
| Subject matter | Auctollo’s provision of the Service to Customer under the Principal Agreement. |
| Duration | The term of the Principal Agreement plus any post-termination period required by Section 11 (data return / deletion). |
| Nature | Hosted sitemap generation, indexing-status monitoring, AI-assisted SEO analysis, redirect monitoring, 404 logging. |
| Purpose | Performing the Service for Customer’s benefit per Customer’s instructions and the Principal Agreement. |
The Service is designed to operate primarily on URLs and content metadata, not on personal data directly. Nevertheless, Customer Personal Data processed may include:
| Category | Examples |
|---|---|
| URL data | Page paths, query parameters, fragments that may identify individuals if Customer’s URL structure includes user identifiers. |
| Content metadata | Post titles, meta descriptions, schema markup, author bylines that may name individuals. |
| Crawl data | Page text excerpts and structured data ingested by AI features. |
| Redirect / 404 logs | Source URLs (which may contain query-string personal data) and HTTP referer headers. |
| End-user identifiers | Where Customer chooses to submit them, indexing-status queries against URLs that uniquely identify a person. |
Auctollo does not intentionally request or solicit special-category personal data under GDPR Article 9. Customer is responsible for not transmitting special-category data through the Service except as strictly necessary and lawful.
Customer:
If Auctollo, in its reasonable judgment, believes an instruction infringes Data Protection Laws, Auctollo will notify Customer and may suspend the disputed processing until resolved.
Auctollo will:
Customer provides general authorization for Auctollo to engage Sub-processors, subject to the conditions in this Section.
As of the Effective Date, Auctollo engages the following Sub-processors:
| Sub-processor | Role | Processing location |
|---|---|---|
| Supabase, Inc. | Database, authentication, edge functions | AWS US-East-1 (EU-region option available) |
| Vercel, Inc. | Web application hosting and CDN | Global edge network |
| Stripe, Inc. | Payment processing and subscription management | United States |
| Inngest, Inc. | Background job queue | United States |
| Resend, Inc. | Transactional email delivery | United States |
| Mailchimp (Intuit Inc.) | Marketing email and waitlist communications | United States |
| Cloudflare, Inc. | DNS, edge security, DDoS protection | Global edge network |
| Anthropic, PBC | AI feature processing (primary) | United States |
| OpenAI, OpC, L.P. | AI feature processing (fallback) | United States |
| Google LLC (Vertex AI / Gemini API) | AI feature processing (fallback) | United States |
| AWS Route 53 | DNS routing for auctollo.com and app.auctollo.com | United States |
This list is also reflected in Privacy Policy Section 3 and is kept in sync.
Customers who require EU-region processing for GDPR purposes may opt into an EU data-region configuration. Contact legal@auctollo.com to enable this for your account.
Auctollo will:
Auctollo will impose on each Sub-processor data-protection obligations no less protective than those imposed on Auctollo under this DPA, and remains fully liable to Customer for any Sub-processor breach.
Where Auctollo’s processing involves a transfer of Personal Data from the EEA, UK, or Switzerland to a country without an adequacy decision, the transfer is governed by:
Auctollo will, where applicable, conduct transfer impact assessments and implement supplementary measures per Schrems II and subsequent EDPB guidance.
Auctollo will notify Customer of a Personal Data Breach affecting Customer Personal Data without undue delay and, where feasible, within 72 hours of becoming aware. The notification will, to the extent then known, describe:
Auctollo will provide reasonable cooperation to assist Customer in meeting Customer’s own breach-notification obligations under Articles 33–34 GDPR.
Contact for security disclosures and breach notifications: legal@auctollo.com.
Taking into account the nature of the processing, Auctollo will assist Customer by appropriate measures, insofar as possible, to fulfil Customer’s obligations to respond to Data Subject requests under GDPR Articles 15–22.
Where a Data Subject contacts Auctollo directly with such a request, Auctollo will (a) inform the Data Subject that the request should be directed to Customer, and (b) promptly forward the request to Customer.
In the event of any conflict between this DPA and the Principal Agreement, this DPA prevails with respect to the processing of Customer Personal Data. Between this DPA and the SCCs incorporated under Section 9, the SCCs prevail.
Auctollo may update this DPA from time to time. Material changes (such as changes to Sub-processors, security commitments, or transfer mechanisms) will be notified to Customer by email at least 30 days before they take effect, in line with Section 7.4. Continued use of the Service after the effective date constitutes acceptance, subject to Customer’s objection rights under Section 7.4.
A signed (countersigned) PDF copy of this DPA is available on request to enterprise customers at legal@auctollo.com.
W3 EDGE, LLC d/b/a Auctollo
9450 SW Gemini Drive, PMB 22185
Beaverton, OR 97008-7105, US
Email: legal@auctollo.com
This DPA forms part of, and is governed by, the Terms of Service between you and Auctollo. Capitalized terms not defined here have the meanings given in the Terms of Service or in Article 4 of the GDPR.