Legal

Data Processing Agreement

Last updated: 16 June 2026

What applies right now

Citeon is in private beta and is not processing customer data. There are no accounts and no scans running, so no personal data is being processed on anyone's behalf. This agreement is published now so it can be reviewed in advance, and takes effect when your account does.

This Data Processing Agreement ("DPA") forms part of the agreement between Citeon ("Citeon", "we", "Processor") and the customer ("you", "Customer", "Controller") who uses Citeon's services, including the optional AI traffic tracking feature. It applies where Citeon processes personal data on your behalf. By using a Citeon feature that collects personal data through your own website or accounts, you enter into this DPA with us. Where your privacy laws do not require a DPA, this document still describes how we handle your data.

1. Roles of the parties

For data you submit and for data collected through tools you deploy (such as the AI traffic snippet on your website), you are the data controller and Citeon is the data processor. Citeon processes that personal data only to provide the service to you and only on your documented instructions, which include this DPA and your use of the product.

2. Definitions

"Personal data", "processing", "data controller", "data processor", "data subject" and "personal data breach" have the meanings given in applicable data protection law, including the EU GDPR, the UK GDPR, the California Consumer Privacy Act (CCPA/CPRA) and the Australian Privacy Act 1988 (Cth) and Australian Privacy Principles. "Sub-processor" means a third party engaged by Citeon to process personal data.

3. Subject matter, nature and purpose

Citeon processes personal data to operate the Citeon platform for you: to run generative-engine visibility scans you configure, to deliver insights and reports, and, where you enable it, to record visits to your website that originate from AI assistants. Processing continues for the duration of your use of the service.

4. Categories of personal data and data subjects

Data subjects: your authorised users, and the visitors to your website where you deploy the AI traffic snippet.

Categories of data: account and contact details of your users; and, for AI traffic tracking, the AI source a visitor arrived from, the page they visited, the referring address, approximate location derived from IP, and similar online identifiers. We do not ask you to send special categories of personal data and you must not configure the service to do so.

5. Citeon's obligations as processor

Citeon will: (a) process personal data only on your documented instructions, including for international transfers, unless required to do otherwise by law, in which case we will inform you where legally permitted; (b) ensure persons authorised to process the data are under a duty of confidentiality; (c) implement appropriate technical and organisational security measures (see clause 8); (d) respect the conditions for engaging sub-processors (clause 6); (e) assist you, taking into account the nature of processing, in responding to data subject requests (clause 7); (f) assist you with security, breach notification, data protection impact assessments and consultations with regulators; and (g) at your choice, delete or return personal data at the end of the service (clause 10).

6. Sub-processors

You give Citeon general authorisation to engage the sub-processors below. We impose data-protection terms on each that are no less protective than this DPA, and we remain responsible for their performance.

  • Supabase (database, authentication and storage of your account and tracking data).
  • Cloudflare (hosting, content delivery, edge compute and security).
  • Paddle (payment processing as Merchant of Record, for billing data only).
  • Resend (delivery of transactional and, with consent, marketing email).
  • Sentry (error monitoring; configured not to collect personally identifiable information).
  • AI providers (OpenAI, Anthropic, Google, Perplexity and DeepSeek) receive only the category prompts you configure for scans, never your website visitors' data.
  • Firecrawl (crawling your own public website for the site audit).

We will give you at least 30 days' notice before adding or replacing a sub-processor that processes your personal data, during which you may object on reasonable data-protection grounds. A current list is available at any time by emailing support@citeon.dev.

7. Data subject rights

Taking into account the nature of the processing, Citeon will assist you with appropriate technical and organisational measures, insofar as possible, to fulfil your obligation to respond to requests from data subjects to exercise their rights (access, rectification, erasure, restriction, portability and objection). If a data subject contacts Citeon directly, we will, where lawful, refer them to you.

8. Security

Citeon maintains appropriate technical and organisational measures, including: encryption of data in transit; access controls and least-privilege access to production systems; row-level security so each customer can only access their own data; input validation and sanitisation; secret keys stored outside source code; and error and uptime monitoring. We review these measures and improve them as the service evolves.

9. Personal data breach

Citeon will notify you without undue delay after becoming aware of a personal data breach affecting your personal data, and will provide information reasonably available to us to help you meet your own notification obligations.

10. Return and deletion

On termination of the service, or on your written request, Citeon will delete or return your personal data and delete existing copies, unless retention is required by law. AI traffic records can be deleted on request at any time.

11. Audits

Citeon will make available to you information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, subject to reasonable notice, confidentiality, and limits to protect the security and data of other customers.

12. International transfers

Where personal data is transferred outside the EEA, the UK or Australia, Citeon relies on appropriate safeguards, including the European Commission's Standard Contractual Clauses and the UK Addendum, or other lawful transfer mechanisms. Those clauses are incorporated into this DPA by reference where they apply.

13. Liability

Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the main agreement between you and Citeon, including the Terms of Service.

14. Term and governing law

This DPA takes effect when you start using a feature that collects personal data on your behalf and continues for as long as Citeon processes that personal data. It is governed by the laws of Victoria, Australia, consistent with our Terms of Service, without prejudice to any mandatory data-protection law that applies to you.

15. Contact

To request a countersigned copy of this DPA, the current sub-processor list, or any data-protection matter, email support@citeon.dev.

This document is a standard agreement provided for convenience. For high-value or enterprise relationships, both parties should have it reviewed by their own legal advisers.