PageCompose
Back to homepage
DPA

Data processing agreement

This agreement forms part of the PageCompose contract where PageCompose processes personal data on the customer's behalf.

Parties and roles

The customer named in the PageCompose account is the controller. Finn Hillebrandt, Am Brandberg 10, 21401 Thomasburg, Germany is the processor. The customer determines purposes and means for its websites and their personal data.

Subject, purpose and duration

Processing covers the website studio and its storage, publishing, form, analytics, review, export and support functions. It lasts until commissioned data is deleted after the contract, subject to statutory retention.

Data and data subjects

Depending on use, content, contact, form, communication, usage, approval and technical log data may be processed. Data subjects may include customer staff, contractors, website visitors, prospects, customers and invited reviewers. Special categories under Article 9 GDPR are not intended.

Instructions

PageCompose processes commissioned data only on documented customer instructions, including product settings, feature use and support requests. Instructions believed to violate data-protection law may be suspended pending clarification.

Processor duties

Authorized personnel are bound to confidentiality. PageCompose reasonably supports data-subject requests, assessments, consultations and evidence. Breaches within PageCompose's responsibility are reported without undue delay with available information.

Subprocessors

The customer generally authorizes Cloudflare for application execution and access-controlled storage in the managed Cloudflare runtime. Existing Vercel compatibility deployments may use Vercel for application execution and file storage and Neon for database services. Required data-protection obligations apply. Planned changes are announced at least 14 days in advance. A material data-protection objection may lead either party to terminate the affected service if no reasonable solution exists.

International transfers

Processing outside the EEA occurs only under applicable legal requirements, including adequacy decisions or safeguards such as standard contractual clauses.

Technical and organizational measures

  • TLS transport and private object storage
  • Account, project and role-based access controls
  • Passwords, sessions and agent keys stored only as hashes
  • Revocable and time-bounded MCP and review access
  • Tenant-bound project access and server-side validation
  • Rate limits, security headers and traceable changes
  • Recoverable revisions, exports and recovery snapshots
  • Processes for deleting personal leads and access

Audits and evidence

PageCompose provides information required under Article 28 GDPR. Reviews should start with existing documentation. Further audits require reasonable notice, must protect operations and other customers, and are paid by the customer unless a material breach is found.

Return and deletion

Customers may export project content during the contract. After termination, commissioned data is returned or deleted at the customer's choice unless statutory retention applies. Retained data stays blocked for that purpose.

Last updated

12 September 2026

PageCompose
ImprintPrivacyDPATermsRefund policy
Codex and Claude Code are trademarks of their respective owners.