Last updated: July 21, 2026
This Data Processing Agreement (“DPA”) forms part of the Terms and Conditions between the client (“Client”, controller) and We Are Content LLC (“Hepteon”, processor), and governs the processing of third-party personal data that the Client uploads or connects to the platform. In case of conflict with the Terms regarding such processing, this DPA prevails.
1. Definitions and roles
The terms “personal data”, “processing”, “controller”, “processor”, “data subject” and “personal data breach” have the meaning of the GDPR (EU) 2016/679 and equivalent laws. With respect to the third-party data the Client incorporates into the Service, the Client acts as controller and Hepteon as processor, processing it solely on the Client’s behalf.
2. Subject matter, duration and purpose
Hepteon will process personal data only to provide the contracted service (an AI-powered marketing SaaS platform: auditing, keyword research, content generation, and the publishing, editing and management of content on the accounts the Client connects, such as Google (including the Business Profile), social networks, CMS and ecommerce platforms), for the term of the Terms and until the data is returned or deleted under clause 11.
3. Client instructions
Hepteon will process the data only on the Client’s documented instructions, including those given through the configuration and use of the platform. If Hepteon considers that an instruction infringes applicable law, it will inform the Client.
4. Types of data and categories of data subjects
Types of data: identification and contact data, credentials, URLs and site content, data from connected accounts (for example, Google services) and any other personal data the Client chooses to include. Categories of data subjects: the Client’s end customers, users and contacts. The Client is responsible for the lawfulness of the data it incorporates and for having a legal basis for its processing.
5. Confidentiality
Hepteon ensures that persons authorized to process the data have committed to confidentiality.
6. Security
Hepteon applies appropriate technical and organizational measures (art. 32 GDPR), including encryption in transit, access controls, activity logging and reasonable security practices appropriate to the risk.
7. Sub-processors
The Client authorizes Hepteon to engage the sub-processors listed in Annex A. Hepteon imposes on each sub-processor, by contract, data protection obligations equivalent to those in this DPA. Hepteon will inform of the addition or replacement of sub-processors with reasonable notice, and the Client may object on legitimate grounds.
8. Assistance to the Client
Taking into account the nature of the processing, Hepteon will assist the Client, as far as possible, in responding to data subject rights requests (arts. 15 to 22 GDPR) and in meeting its obligations regarding security, breach notification, impact assessments and prior consultations (arts. 32 to 36 GDPR).
9. Personal data breaches
Hepteon will notify the Client without undue delay after becoming aware of a personal data breach affecting the data processed on its behalf, providing the information reasonably available so the Client can meet its obligations.
10. International transfers
Where processing involves international transfers, the safeguards described in the Privacy Policy will apply (EU Standard Contractual Clauses, the UK Addendum/IDTA and, where applicable, the EU-US Data Privacy Framework).
11. Return or deletion
Upon termination of the service, and at the Client’s choice, Hepteon will return or delete the personal data processed on its behalf, unless there is a legal retention obligation.
12. Audit
Hepteon will make available to the Client the information reasonably necessary to demonstrate compliance with this DPA and will allow audits, including inspections, on reasonable terms, with prior notice and respecting confidentiality and security.
13. Governing law
This DPA is governed by the law stated in the Terms (State of Delaware, USA), without prejudice to the mandatory data protection rules applicable to the Client or the data subjects, which prevail.
Annex A — List of sub-processors
| Provider | Purpose | Location |
|---|---|---|
| Google LLC | Google APIs the Client connects (Search Console, Analytics, Ads, Tag Manager, Business Profile) | USA / global |
| Stripe, Inc. | Payment processing | USA / global |
| Cloudflare, Inc. | Security, CDN and performance | USA / global |
| DigitalOcean LLC | Hosting and infrastructure | USA / global |
| AI model providers | AI-assisted content generation | USA / global |
| SEO tools | SEO data and metrics | Global |
Contact for data protection matters: [email protected].