Data Processing Agreement
Last updated: 12 July 2026
This DPA applies where TickAI processes personal data on your organisation's behalf as part of the service, and forms part of, and is incorporated into, our Terms of Service. It applies automatically for as long as we process personal data on your behalf under the Terms of Service — you don't need to sign anything separately, but contact us if your organisation needs a separately signed copy.
1. Definitions
"Applicable Data Protection Law" means UK GDPR, EU GDPR, the Data Protection (Bailiwick of Guernsey) Law, 2017, and any other data protection or privacy law that applies to the processing of Customer Personal Data under this DPA.
"Customer Personal Data" means personal data contained within the websites, pages, URLs, files, or other content that Customer (or its authorised users) submits to TickAI for scanning, analysis, or review under the Terms of Service.
"Controller", "Processor", "Data Subject", "Personal Data", "Processing", and "Personal Data Breach" have the meanings given in Applicable Data Protection Law.
"Sub-processor"means a third party engaged by TickAI to process Customer Personal Data on TickAI's behalf.
2. Roles of the parties
Customer is the Controller of Customer Personal Data. TickAI is the Processor and will process Customer Personal Data only as described in this DPA and the Terms of Service.
This DPA does not apply to personal data for which TickAI is the Controller, such as Customer's own account, billing, and organisation-administration data — that processing is described in our privacy policy.
3. Details of processing
| Subject matter | TickAI's provision of automated scanning, AI-content detection, review, and documentation services in relation to Customer's websites and content. |
| Duration | For as long as TickAI provides the Service to Customer under the Terms of Service, and thereafter only as necessary to comply with Data retention and deletion below. |
| Nature and purpose | Automated crawling and rendering of Customer's websites; analysis of images, video, and text to detect AI-generated or AI-modified content; storage of the resulting analysis, review decisions, and audit records. |
| Categories of data subjects | Individuals whose personal data appears within the websites, pages, or files Customer submits for analysis — for example, individuals depicted or named in Customer's website content. |
| Types of personal data | Typically limited to images, video, and text appearing within submitted content, which may incidentally include an individual's likeness, name, or other information present in that content. TickAI does not require or request special category data (as defined in Article 9 GDPR); Customer should not submit special category data except where doing so is necessary and lawful. |
4. Processor obligations
TickAI will:
- process Customer Personal Data only on Customer's documented instructions, including regarding international transfers, unless required to do otherwise by law — in which case TickAI will inform Customer of that legal requirement first, unless the law prohibits this;
- ensure that personnel authorised to process Customer Personal Data are subject to a duty of confidentiality;
- implement appropriate technical and organisational measures to protect Customer Personal Data, including encryption of data in transit, encryption of data at rest, database-level tenant isolation (row-level security) so one Customer's data is not accessible to another, and restricted, logged administrative access to production systems;
- engage Sub-processors only as described in Sub-processors below;
- taking into account the nature of the processing, assist Customer by appropriate technical and organisational measures with fulfilling Customer's obligations to respond to requests from data subjects exercising their rights under Applicable Data Protection Law;
- assist Customer, taking into account the nature of processing and the information available to TickAI, in ensuring compliance with obligations relating to the security of processing, breach notification, data protection impact assessments, and prior consultation with supervisory authorities;
- notify Customer without undue delay, and where feasible within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data, and provide Customer with information reasonably available to TickAI to help Customer meet its own notification obligations;
- at Customer's choice, delete or return all Customer Personal Data at the end of the provision of the relevant services, and delete existing copies, except to the extent applicable law requires TickAI to retain some or all of it (see Data retention and deletion below); and
- make available to Customer information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer — no more than once in any 12-month period (except following a Personal Data Breach, or where required by a supervisory authority), on reasonable prior notice, subject to confidentiality and to reasonable limits on scope, timing, and cost. Where information TickAI has already made available (such as this DPA, its security documentation, or a completed security questionnaire) is sufficient to demonstrate compliance, TickAI may satisfy this obligation by providing that information instead of an on-site audit.
5. Customer obligations
Customer will:
- ensure it has a lawful basis for the content and instructions it gives to TickAI, and for any Customer Personal Data contained within it;
- ensure its instructions to TickAI comply with Applicable Data Protection Law; and
- only submit websites, content, or files that it owns, operates, or is otherwise authorised to submit for review (see Third-party websites and content in our terms of service).
6. Sub-processors
Customer gives TickAI general authorisation to engage the sub-processors listed below, and any others TickAI may add from time to time in accordance with this section, to process Customer Personal Data in connection with the Service.
| Sub-processor | Role | Location |
|---|---|---|
| Supabase | Database hosting and authentication (primary datastore) | European Union |
| Vercel, Inc. | Application hosting | United States (global edge network) |
| Browserless | Renders and interacts with websites during a scan | United States |
| Replicate (a Cloudflare company) | Hosts the machine-learning models used for content analysis | United States |
| Sightengine | Image and video AI-detection analysis | France (European Union) |
TickAI will give Customer at least 30 days' notice (by email or in-product notice) before engaging a new sub-processor to process Customer Personal Data, or removing one from this list. If Customer reasonably objects to a new sub-processor on data protection grounds within that notice period, the parties will work together in good faith to resolve the objection; if it cannot be resolved, Customer may terminate the affected part of the Service without penalty.
TickAI remains liable to Customer for a sub-processor's performance of its data protection obligations, and imposes data protection terms on each sub-processor that are no less protective than those in this DPA, to the extent relevant to the service that sub-processor provides.
7. International transfers
Where TickAI or a sub-processor transfers Customer Personal Data outside the UK, EEA, or Guernsey, TickAI will ensure the transfer is subject to appropriate safeguards under Applicable Data Protection Law.
To the extent required, the parties agree that the UK's International Data Transfer Addendum, and/or the European Commission's Standard Contractual Clauses (Module 2: Controller to Processor, or Module 3: Processor to Processor, as applicable), are incorporated into this DPA by reference and apply to the relevant transfer, with TickAI as data exporter or importer as applicable. Contact us if your organisation needs a separately executed copy of these clauses.
8. Data retention and deletion
TickAI retains Customer Personal Data only for as long as described in our privacy policy. Scan, review, and audit-trail data is retained for the life of Customer's account and deleted when the account is deleted, other than residual copies in encrypted backups, which are retained for a limited period before being overwritten.
9. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in our terms of service.
10. Term and precedence
This DPA takes effect on the date Customer starts using the Service and continues for as long as TickAI processes Customer Personal Data on Customer's behalf. If there is a conflict between this DPA and the Terms of Service on a data protection matter within the scope of this DPA, this DPA prevails to that extent.
Contact
Questions about this DPA, or requests for a signed copy, can be sent through the contact details listed on our contact page.

