GDPR-compliant data processing terms for Anysite services
Last updated: November 4, 2025
This Data Processing Addendum ("DPA") forms part of and is incorporated into the anysite.io General Terms and Conditions and/or any separately executed Master Service Agreement between Anysite, Inc., a Delaware corporation, with its principal place of business at Delaware, USA ("Anysite", "we", "us" or "Processor/Service Provider") and the customer identified in the applicable agreement ("Customer" or "Controller/Business") (each a "Party" and collectively, the "Parties"). This DPA governs Anysite's Processing of Personal Data on behalf of Customer in connection with the anysite.io platform and related services (the "Services").
If there is any conflict between this DPA and the Agreement, this DPA will control with respect to its subject matter. Capitalized terms not defined here have the meanings in the Agreement or under applicable Data Protection Law.
Data Protection Law means all laws and regulations relating to data privacy, data protection, data security, breach notification, or the Processing of Personal Data that apply to a Party's performance under this DPA, including as applicable: the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the UK Data Protection Act 2018 and UK GDPR, and the California Consumer Privacy Act as amended by the California Privacy Rights Act (together, "CCPA/CPRA").
EU SCCs means the European Commission's Standard Contractual Clauses for the transfer of personal data to third countries adopted by Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as amended or replaced.
UK Addendum means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK ICO (version B1.0 in force 21 March 2022), as amended or replaced.
Personal Data, Controller, Processor, Business, Service Provider, Sell, Share, Data Subject, Process/Processing, and related terms have the meanings given to them by the applicable Data Protection Law. For CPRA, "sharing" includes transfers for cross‑context behavioral advertising even when no money changes hands.
For Processing under this DPA, Customer acts as Controller/Business and Anysite acts as Processor/Service Provider.
Anysite will Process Personal Data solely:
Customer is responsible for the lawfulness of the Personal Data and instructions it provides, including providing any necessary notices and obtaining valid legal bases (e.g., consent, legitimate interests) and honoring Data Subject rights.
Unless the Parties expressly agree in writing and implement appropriate safeguards, Customer will not provide Anysite with Special Categories of data (GDPR Art. 9), data on criminal convictions/offences (Art. 10), PHI under HIPAA, PCI‑DSS data, children's data subject to parental consent regimes, FERPA data, or other sector‑specific regulated data.
Separately from Processing as a Processor, Anysite may Process certain Personal Data as its own Controller (e.g., account provisioning and management, billing, abuse detection, compliance with legal obligations, and creation of aggregated, de‑identified analytics to plan capacity and improve Services). Such Processing is described in the Anysite Privacy Policy and falls outside this DPA. This mirrors common platform practice and the approach outlined in Apify's DPA for controller‑level operations.
Anysite will ensure that personnel authorized to Process Personal Data are subject to binding duties of confidentiality and access Personal Data only as necessary to perform the Services.
Anysite implements and maintains appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the state of the art, costs, and the nature, scope, context and purposes of Processing (see Schedule D – Security Measures).
Anysite will regularly review and update its security measures to maintain an appropriate level of protection.
Upon becoming aware of a confirmed Security Incident affecting Personal Data Processed by Anysite on Customer's behalf, Anysite will notify Customer without undue delay and no later than 72 hours after confirmation, and will provide information reasonably available to assist Customer with its own notification obligations. (72‑hour timing aligns with common practice; Apify's DPA uses the same window.)
Anysite will take reasonable steps to contain, investigate, and remediate the Security Incident.
Incident notifications are not an admission of fault or liability.
Customer authorizes Anysite to transfer, store, and Process Personal Data in the United States and other jurisdictions in which Anysite operates, subject to transfer safeguards in this Section.
Where Customer's Personal Data is subject to the GDPR and is transferred to Anysite in a country without an adequacy decision, the EU SCCs are incorporated by reference and completed as set out in Schedule A (typically Module Two: Controller → Processor; Module Three may apply where Customer is a Processor). In case of conflict between this DPA and the EU SCCs, the EU SCCs prevail.
For Personal Data subject to UK GDPR, the UK Addendum is incorporated and completed as set out in Schedule A.
Where required, the Parties will cooperate in good faith to implement supplementary measures and complete transfer impact assessments.
Upon written request (no more than once in any 12‑month period), Anysite will make available information reasonably necessary to demonstrate compliance with this DPA (e.g., summaries of security controls, third‑party compliance reports, or certifications if available).
If such information does not reasonably demonstrate compliance, Customer may conduct (or have conducted by a mutually agreed independent auditor) an on‑site or remote audit of Anysite's relevant systems and facilities under reasonable confidentiality, time, scope, and cost‑reimbursement parameters, and during normal business hours, no more than once every 12 months.
Anysite will reasonably cooperate with competent supervisory authorities in relation to Processing performed under this DPA.
At termination or upon written request, Anysite will delete or return Personal Data (at Customer's choice), unless retention is required by law (in which case Anysite will continue to protect the data per this DPA and delete as soon as legally permissible).
Taking into account the nature of the Processing, Anysite will provide reasonable assistance to Customer, by appropriate technical and organizational measures, to enable Customer to respond to Data Subject requests (access, deletion, portability, objection, restriction, etc.). Where a request is made directly to Anysite, Anysite will redirect it to Customer without responding (unless legally required). (This mirrors the approach outlined in Apify's DPA.)
Anysite will provide reasonable assistance to Customer in carrying out data protection impact assessments and consultations with supervisory authorities where required by Data Protection Law, considering the nature of Processing and information available to Anysite. (Comparable to Apify's DPIA section.)
Customer's use of the Services must comply with the Anysite Acceptable Use Policy and Privacy Policy, each incorporated by reference.
To the extent Anysite Processes Personal Information subject to CCPA/CPRA on behalf of Customer, Anysite will act as Service Provider and will not:
Each Party's liability arising under or in connection with this DPA is subject to the limitations and exclusions set out in the Agreement.
In case of conflict: EU SCCs/UK Addendum (Schedule A) prevail over this DPA; this DPA prevails over the Agreement.
This DPA is effective as of the Effective Date of the Agreement (or the date accepted by Customer, if later) and remains in force while Anysite Processes Personal Data for Customer.
Anysite may update this DPA to reflect legal or operational changes, with notice to Customer in accordance with the Agreement and applicable law.
This DPA (excluding the EU SCCs/UK Addendum, which specify their own governing law/forum) is governed by the laws of the State of Delaware, with exclusive venue as set out in the Agreement.
DPO/Privacy contact: privacy@anysite.io (or as updated on our Website).
The EU SCCs (2021/914) are incorporated by reference and deemed executed between the Parties as follows:
For Personal Data subject to UK GDPR, the UK Addendum (version B1.0 in force 21 March 2022) is incorporated and completed as follows:
If the Parties later adopt alternative or additional transfer tools (e.g., adequacy decisions or certification schemes), they may supersede or supplement the above by written agreement.
Service Provider. Anysite acts as a Service Provider (Cal. Civ. Code §1798.140) in Processing Personal Information on Customer's behalf.
No Sale/Share. Anysite will not sell or share Personal Information, including no cross‑context behavioral advertising use, and will not retain, use, or disclose it outside the business purpose of providing the Services, except as permitted by CCPA/CPRA.
Assistance. Anysite will provide reasonable assistance to enable Customer to honor consumer rights requests, opt‑out signals, and to implement deletion/retention obligations.
Subcontractors. Anysite will impose Service‑Provider‑level restrictions on any subcontractors and remains responsible for their compliance.
Certifications. Upon Customer's written request, Anysite will certify compliance with this Schedule B.
Data Exporter: Customer (name and contact details as set forth in the Agreement or account profile). Role: Controller (or Processor, where applicable).
Data Importer: Anysite, Inc. (Delaware, USA); contact: privacy@anysite.io. Role: Processor.
Continuous or as determined by Customer's use.
Anysite maintains the following technical and organizational measures (non‑exhaustive and subject to reasonable updates):
Governance & Access Control: role‑based access; unique credentials; MFA for privileged access; least‑privilege and need‑to‑know; periodic access reviews; timely revocation.
Data Security: encryption in transit (TLS) and at rest (industry‑standard); key management with restricted access; data segregation/tenant isolation; hardened storage.
Network & Infrastructure: firewalls and network segmentation; baseline hardening; system patching cadence; vulnerability scanning and risk‑based remediation; DDoS protections.
Monitoring & Logging: centralized logging; security event monitoring and alerting; audit trails for administrative actions; time synchronization.
Application Security: secure SDLC; code reviews; dependency management; secrets management; regular security testing (including third‑party testing where appropriate).
Business Continuity & DR: documented backup and recovery procedures; redundancy for critical components; recovery objectives aligned to service tier.
Incident Response: documented plan; defined roles; triage/containment/eradication steps; post‑incident reviews; customer communications workflow (see Section 5).
Personnel Security & Training: background checks where lawful; confidentiality undertakings; periodic security and privacy training.
Vendor Management: security due diligence; contractual flow‑down of obligations; ongoing monitoring aligned with risk.
Physical Security: data center controls provided by reputable hosting providers; visitor management; access logs.
Privacy by Design/Default: minimization; purpose limitation; configurable retention; de‑identification/aggregation where feasible.
Change Management: documented change control; emergency change procedures; rollback plans.
These security controls are comparable to the security control families commonly referenced in DPAs; Apify's DPA describes similar categories of measures.
For questions about this Data Processing Addendum, contact us at: