Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the agreement between 4D Services Limited ("Processor", "we") and the customer or agency identified in the applicable order form ("Controller", "you"), and applies whenever we process personal data on your behalf as a processor — see the controller/processor table in our Privacy Notice §2 for which of your data that covers.
1. Subject matter, duration, nature and purpose
We process personal data to provide the AuditCrow visibility-audit service: crawling the sites you submit, ingesting data from Google/Microsoft accounts you connect, and generating AI-drafted analysis and recommendations. Processing continues for the term of your subscription and for a limited period afterwards per our retention schedule.
2. Categories of data subjects and personal data
- Your own staff/users who access the account.
- Where applicable, individuals incidentally identifiable in crawled content, connected Google Business Profile reviews, or Search Console query data — see the Third-Party Data section of our Privacy Notice.
3. Processor obligations
We will:
- Process personal data only on your documented instructions;
- Ensure anyone processing the data is subject to confidentiality;
- Implement the security measures described in Annex 2;
- Engage sub-processors only as listed in Annex 1, with advance notice of changes;
- Assist you with data-subject rights requests and with your own breach-notification obligations;
- Delete or return personal data at the end of the relationship, except where retention is required by law;
- Make available the information necessary to demonstrate compliance with this DPA.
4. Annex 1 — Sub-processors
The current, maintained list is published at /sub-processors and incorporated by reference. We will give at least 14 days' notice before adding a sub-processor that will process your personal data, during which you may object on reasonable grounds.
5. Annex 2 — Security measures
The technical and organisational measures below reflect the current build. This annex describes the measures at a level appropriate for a customer-facing agreement; it does not name specific internal file paths, scripts, or implementation detail.
| Area | Measure |
|---|---|
| Data isolation | Every query is scoped by tenant/account at the database level (row-level security), independent of the application-layer access checks. |
| Secrets at rest | Connected-account OAuth tokens and connector credentials are encrypted at rest in a dedicated secrets vault; the application database never stores a usable copy of the raw credential. |
| Transport & response hardening | Enforced HTTPS/HSTS, a restrictive frame-ancestors content-security policy, and standard anti-clickjacking/MIME-sniffing headers on every response. |
| Outbound request safety | Outbound fetches to a customer-supplied URL (e.g. during a crawl) re-validate the resolved network address at fetch time to prevent server-side request forgery, including DNS-rebinding style attacks. |
| Integrity verification | Signed-request verification (e.g. webhooks, the site-plugin API) uses constant-time comparison to prevent timing attacks, with a bounded time-skew window. |
| Privileged access (impersonation) | Support access to a customer's account requires a logged, mandatory reason recorded before access is granted, is visibly disclosed to the session, cannot target another staff account, and cannot be used to mutate customer data — read-only diagnosis only. |
| Retention enforcement | Automated, scheduled deletion of check-level audit data once it passes the documented retention window (see §1); further data categories are being brought under the same automated enforcement. |
| Rate limiting | Per-site ceilings on high-frequency data ingestion (e.g. performance telemetry) to prevent uncontrolled data growth or abuse. |
Planned, not yet built: a fuller content-security-policy covering script/style/connect sources (currently limited to frame-ancestors); usage-based spend controls on third-party API calls; automated retention enforcement extended to every data category, not only check-level audit data. We will not represent these as complete until they are.
A fuller internal technical annex (naming specific controls and their implementation) is available to customers under NDA on reasonable request, once this DPA has been reviewed and signed.
6. International transfers
Where a sub-processor is located outside the UK, transfers rely on the UK Extension to the EU-US Data Privacy Framework where the provider is certified, or an International Data Transfer Agreement otherwise. See /sub-processors for the transfer basis per vendor.
7. Insight / aggregation layer
Where you participate in the cross-client insight-aggregation feature, you permit 4D Services Limited to include anonymised, aggregated signals derived from your data in cross-client benchmarks, subject to: (a) a minimum contributing-site threshold before any aggregate figure is produced; (b) your ability to opt out at the tenant level at any time; and (c) your ability to exclude a specific client site from aggregation even while otherwise participating. Regulated (FCA-adjacent) tenants are opted in only by explicit action, never by default. This feature is not yet live; this clause takes effect only once it is, and only for tenants who have not opted out.
8. Assistance & audit
We will provide reasonable assistance with data protection impact assessments and, on reasonable notice, permit an audit of our compliance with this DPA (or provide equivalent independent assurance) where required by applicable law or your own regulatory obligations.
9. Contact
4D Services Limited · Data Protection Officer: Ben Foord · privacy@4dservices.co.uk