Legal
Data Processing Agreement
Effective date: June 10, 2026
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between LLM Metrix, Inc.(“Processor”) and each customer (“Controller”) that uses the LLM Metrix platform.
1. Definitions
In this DPA, terms have the meanings given in the EU General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) and the UK GDPR where applicable. “Personal Data” means any information relating to an identified or identifiable natural person processed by LLM Metrix on behalf of the Customer.
2. Scope and Purpose
LLM Metrix processes Personal Data only to the extent necessary to provide the services described in the Terms of Service. The subject matter, nature, purpose, type of Personal Data, and categories of data subjects are described in Schedule 1 of this DPA.
3. Processor Obligations
LLM Metrix agrees to:
- Process Personal Data only on documented instructions from the Controller (including as set out in the Terms of Service and this DPA).
- Ensure that persons authorised to process Personal Data have committed to confidentiality.
- Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk (Article 32 GDPR).
- Not engage sub-processors without prior written authorisation from the Controller, except as set out in Schedule 2.
- Assist the Controller in fulfilling its obligations to respond to data subject requests (Articles 15–22 GDPR).
- Notify the Controller without undue delay (and in any event within 72 hours) after becoming aware of a Personal Data breach.
- Delete or return all Personal Data upon termination of the services, at the Controller's choice, unless storage is required by law.
4. Controller Obligations
The Controller warrants that:
- It has a lawful basis for transferring Personal Data to LLM Metrix for processing.
- It has provided all required notices and obtained all required consents from data subjects.
- Its instructions to LLM Metrix comply with applicable data protection law.
5. Security Measures
LLM Metrix implements the following measures, at minimum:
6. Sub-processors
LLM Metrix uses the following approved sub-processors. We will provide 30 days' notice before adding new sub-processors.
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication & file storage | USA (AWS us-east-1) |
| Vercel | Hosting, CDN & AI Gateway (routes prompt text to model providers) | Global (edge) |
| Stripe | Payment processing | USA |
| Resend | Transactional & digest email delivery — receives recipient email addresses | USA |
| Upstash (QStash) | Async job queue — carries scan and notification payloads | Global (edge) |
| OpenAI, Anthropic, Google, xAI, Meta, Perplexity | AI engines queried via the Vercel AI Gateway; receive your brand name, domain and prompt text | USA |
| Anthropic (direct) | Web-search-grounded Claude queries, which the AI Gateway cannot proxy; receives prompt text | USA |
| SerpAPI / DataForSEO | Google AI Overviews and SERP results; receives the search query derived from your brand and prompts | USA |
| DataForSEO (authority & keyword data) | Citation-source authority and keyword volume; receives the domains you track | USA |
| Google (Analytics 4 & Search Console) | Traffic and search-performance connectors; we hold an OAuth token for a property you verified and read its metrics | USA |
| Cloudflare | Traffic connector; we hold an API token for your zone and read its request analytics | Global (edge) |
| Google Knowledge Graph, Wikidata & Wikipedia | Entity presence checks; receive your brand name | USA / Global |
| Better Stack | Status page and uptime monitoring. Our public status page is hosted by them, so following a link to it sends your IP address and browser details to their servers — browsing our own pages does not | EU (Czechia) |
7. International Transfers
Where Personal Data is transferred outside the European Economic Area (EEA) or the United Kingdom, LLM Metrix relies on the European Commission's Standard Contractual Clauses (SCCs) or the UK International Data Transfer Agreement (IDTA) as the lawful transfer mechanism.
8. Audit Rights
LLM Metrix will make available all information necessary to demonstrate compliance with this DPA and contribute to audits and inspections conducted by the Controller or a mandated auditor. Audits require 30 days' prior written notice and must occur during normal business hours.
9. Term and Termination
This DPA remains in force for as long as LLM Metrix processes Personal Data on behalf of the Controller. It terminates automatically upon expiry or termination of the Terms of Service, subject to the data deletion provisions in Section 3.
10. Governing Law
This DPA is governed by the same law as the Terms of Service. Where the Controller is established in the EEA or UK, the applicable supervisory authority is the authority in the Controller's member state.
11. Contact
To execute a signed copy of this DPA or for data protection enquiries, contact our Data Protection team at privacy@llmmetrix.com.
Accept this DPA
If you are signing this DPA on behalf of your organisation as a Controller, you can record your acceptance below. Your name, email address, timestamp, and IP address will be stored as a record of acceptance.
