Data Processing Agreement
Last updated: 10 August 2026
This Data Processing Agreement (“DPA”) describes how NEGLETEK, Athens, Greece (“the processor”) processes personal data on behalf of RotSweep customers (“the controller”), as required by Article 28 of the GDPR. It supplements the Terms of Service and applies to every workspace.
Roles
For the content of your workspace — the URLs you monitor, project and tag structure, alert recipient email addresses, and the sweep results derived from them — you are the controller and we are your processor. For your own account and billing data we are the controller; that processing is described in the Privacy Policy.
Subject matter and nature of processing
We process workspace content solely to provide the RotSweep service: fetching the configured URLs on schedule, storing check outcomes and content extracts for baseline comparison, and delivering the alerts and digests you configure to the recipients you configure. Processing lasts for the duration of your subscription plus the deletion grace period.
Categories of data and data subjects
- Email addresses of workspace members and alert recipients (your team and the people you choose to notify);
- URLs and monitoring configuration, which may themselves reveal information about your business;
- extracts of the publicly accessible third-party pages you monitor, retained for change comparison.
Our obligations
We process workspace content only on your documented instructions — operating the service as configured by you is that instruction. People with access are bound by confidentiality. We apply the security measures described in the Privacy Policy, assist you with data subject requests that concern workspace content, notify you without undue delay of any personal data breach affecting your workspace, and delete workspace data when you delete the workspace (a 30-day grace period applies, then removal). Data is stored and processed in the European Union.
Sub-processors
We use the following sub-processors to provide the service:
- Hetzner — hosting and storage in EU data centres (Germany);
- Clerk — authentication of workspace members (US-headquartered; transfers covered by GDPR Chapter V safeguards);
- Stripe — payment processing for the workspace subscription;
- Mailgun — delivery of alert and digest emails, EU region.
We will inform customers before adding or replacing a sub-processor, giving you the opportunity to object. Questions about this list: privacy@rotsweep.com.
Countersigned agreements
This page is the standard DPA that applies to every workspace. A countersigned copy — including custom terms, audit provisions and EU data residency commitments — is available on the Enterprise plan. Contact sales@rotsweep.com to request one.