Skip to main content
LLM Metrix

Legal

Data Processing Agreement

Effective date: June 10, 2026

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between LLM Metrix, Inc. (“Processor”) and each customer (“Controller”) that uses the LLM Metrix platform.

1. Definitions

In this DPA, terms have the meanings given in the EU General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) and the UK GDPR where applicable. “Personal Data” means any information relating to an identified or identifiable natural person processed by LLM Metrix on behalf of the Customer.

2. Scope and Purpose

LLM Metrix processes Personal Data only to the extent necessary to provide the services described in the Terms of Service. The subject matter, nature, purpose, type of Personal Data, and categories of data subjects are described in Schedule 1 of this DPA.

3. Processor Obligations

LLM Metrix agrees to:

  • Process Personal Data only on documented instructions from the Controller (including as set out in the Terms of Service and this DPA).
  • Ensure that persons authorised to process Personal Data have committed to confidentiality.
  • Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk (Article 32 GDPR).
  • Not engage sub-processors without prior written authorisation from the Controller, except as set out in Schedule 2.
  • Assist the Controller in fulfilling its obligations to respond to data subject requests (Articles 15–22 GDPR).
  • Notify the Controller without undue delay (and in any event within 72 hours) after becoming aware of a Personal Data breach.
  • Delete or return all Personal Data upon termination of the services, at the Controller's choice, unless storage is required by law.

4. Controller Obligations

The Controller warrants that:

  • It has a lawful basis for transferring Personal Data to LLM Metrix for processing.
  • It has provided all required notices and obtained all required consents from data subjects.
  • Its instructions to LLM Metrix comply with applicable data protection law.

5. Security Measures

LLM Metrix implements the following measures, at minimum:

Encryption in transit (TLS 1.2+)
Encryption at rest (AES-256)
Role-based access controls
Regular security reviews
Penetration testing (annual)
Audit logging for admin actions
Multi-factor authentication for staff
Vendor security assessments

6. Sub-processors

LLM Metrix uses the following approved sub-processors. We will provide 30 days' notice before adding new sub-processors.

Sub-processorPurposeLocation
SupabaseDatabase, authentication & file storageUSA (AWS us-east-1)
VercelHosting, CDN & AI Gateway (routes prompt text to model providers)Global (edge)
StripePayment processingUSA
ResendTransactional & digest email delivery; receives recipient email addressesUSA
Upstash (QStash)Async job queue; carries scan and notification payloadsGlobal (edge)
OpenAI, Anthropic, Google, xAI, Meta, PerplexityAI engines queried via the Vercel AI Gateway; receive your brand name, domain and prompt textUSA
Anthropic (direct)Web-search-grounded Claude queries, which the AI Gateway cannot proxy; receives prompt textUSA
SerpAPI / DataForSEOGoogle AI Overviews and SERP results; receives the search query derived from your brand and promptsUSA
DataForSEO (authority & keyword data)Citation-source authority and keyword volume; receives the domains you trackUSA
Google (Analytics 4 & Search Console)Traffic and search-performance connectors; we hold an OAuth token for a property you verified and read its metricsUSA
CloudflareTraffic connector; we hold an API token for your zone and read its request analyticsGlobal (edge)
Google Knowledge Graph, Wikidata & WikipediaEntity presence checks; receive your brand nameUSA / Global
IPQualityScoreDomain safety screening (the Malicious URL Scanner check that runs before a new domain is accepted for tracking); receives the domain only, never scan contentsUSA
Better StackStatus page and uptime monitoring. Our public status page is hosted by them, so following a link to it sends your IP address and browser details to their servers. Browsing our own pages does notEU (Czechia)

7. International Transfers

Where Personal Data is transferred outside the European Economic Area (EEA) or the United Kingdom, LLM Metrix relies on the European Commission's Standard Contractual Clauses (SCCs) or the UK International Data Transfer Agreement (IDTA) as the lawful transfer mechanism.

8. Audit Rights

LLM Metrix will make available all information necessary to demonstrate compliance with this DPA and contribute to audits and inspections conducted by the Controller or a mandated auditor. Audits require 30 days' prior written notice and must occur during normal business hours.

9. Term and Termination

This DPA remains in force for as long as LLM Metrix processes Personal Data on behalf of the Controller. It terminates automatically upon expiry or termination of the Terms of Service, subject to the data deletion provisions in Section 3.

10. Governing Law

This DPA is governed by the same law as the Terms of Service. Where the Controller is established in the EEA or UK, the applicable supervisory authority is the authority in the Controller's member state.

11. Contact

To execute a signed copy of this DPA or for data protection enquiries, contact our Data Protection team at privacy@llmmetrix.com.

Accept this DPA

If you are signing this DPA on behalf of your organization as a Controller, you can record your acceptance below. Your name, email address, timestamp, and IP address will be stored as a record of acceptance.