Last updated: July 21, 2026
This Data Processing Agreement (“DPA”) forms part of the Terms and Conditions between the client (“Client”, controller) and We Are Content LLC (“Hepteon”, processor), and governs the processing of third-party personal data that the Client uploads or connects to the platform. In case of conflict with the Terms regarding such processing, this DPA prevails.
1. Definitions and roles
The terms “personal data”, “processing”, “controller”, “processor”, “data subject” and “personal data breach” have the meaning of the GDPR (EU) 2016/679 and equivalent laws. With respect to the third-party data the Client incorporates into the Service, the Client acts as controller and Hepteon as processor, processing it solely on the Client’s behalf.
2. Subject matter, duration and purpose
Hepteon will process personal data only to provide the contracted service (an AI-powered marketing SaaS platform: auditing, keyword research, content generation, and the publishing, editing and management of content on the accounts the Client connects, such as Google (including the Business Profile), social networks, CMS and ecommerce platforms), for the term of the Terms and until the data is returned or deleted under clause 11.
3. Client instructions
Hepteon will process the data only on the Client’s documented instructions, including those given through the configuration and use of the platform. If Hepteon considers that an instruction infringes applicable law, it will inform the Client.
4. Types of data and categories of data subjects
Types of data: identification and contact data, credentials, URLs and site content, data from connected accounts (for example, Google services) and any other personal data the Client chooses to include. Categories of data subjects: the Client’s end customers, users and contacts. The Client is responsible for the lawfulness of the data it incorporates and for having a legal basis for its processing.
5. Confidentiality
Hepteon ensures that persons authorized to process the data have committed to confidentiality.
6. Security
Hepteon applies appropriate technical and organizational measures (art. 32 GDPR), including encryption in transit, access controls, activity logging and reasonable security practices appropriate to the risk.
7. Sub-processors
The Client authorizes Hepteon to engage the sub-processors listed in Annex A. Hepteon imposes on each sub-processor, by contract, data protection obligations equivalent to those in this DPA. Hepteon will inform of the addition or replacement of sub-processors with reasonable notice, and the Client may object on legitimate grounds.
8. Assistance to the Client
Taking into account the nature of the processing, Hepteon will assist the Client, as far as possible, in responding to data subject rights requests (arts. 15 to 22 GDPR) and in meeting its obligations regarding security, breach notification, impact assessments and prior consultations (arts. 32 to 36 GDPR).
9. Personal data breaches
Hepteon will notify the Client without undue delay after becoming aware of a personal data breach affecting the data processed on its behalf, providing the information reasonably available so the Client can meet its obligations.
10. International transfers
Where processing involves international transfers, the safeguards described in the Privacy Policy will apply (EU Standard Contractual Clauses, the UK Addendum/IDTA and, where applicable, the EU-US Data Privacy Framework).
11. Return or deletion
Upon termination of the service, and at the Client’s choice, Hepteon will return or delete the personal data processed on its behalf, unless there is a legal retention obligation.
12. Audit
Hepteon will make available to the Client the information reasonably necessary to demonstrate compliance with this DPA and will allow audits, including inspections, on reasonable terms, with prior notice and respecting confidentiality and security.
13. Governing law
This DPA is governed by the law stated in the Terms (State of Delaware, USA), without prejudice to the mandatory data protection rules applicable to the Client or the data subjects, which prevail.
Annex A — List of sub-processors
To provide the service, Hepteon relies on the providers below (sub-processors, GDPR art. 28.2). This list is generated from the platform’s code: if a new provider is added tomorrow, an automated check prevents publishing it without adding it here.
| Provider | Where it is | What it receives from you | What for |
|---|---|---|---|
| ⚠️ Anthropic | United States | Your site content and the texts written for you | Draft, edit and grade the articles and posts the platform produces |
| United States | Your domain, your pages, your Search Console and Analytics data, and the images generated | Measure your visibility, traffic and speed, and publish the measurement on your site | |
| DataForSEO | United States | Your domain and your keywords | Calculating your Hepteon Rating, your inbound links, your competitors and search volume |
| SE Ranking | |||
| SerpApi | U.S. | Your keywords | Checking who ranks in Google for those searches when our usual provider doesn’t respond | United States | Your domain and your keywords | Domain authority and competitor analysis, as a backup to the previous one |
| ⚠️ GPTZero | United States | The text of the articles written for you | Check that what is published in your name does not read as machine-written |
| Moz | United States | Your domain, and nothing but your domain | A second reading of domain authority, so as not to rely on a single source |
| Ahrefs | Singapore | Your domain, and nothing but your domain | A third reading of domain authority and of your backlinks |
| Microsoft (Bing) | United States | Your domain and your pages | Submit your pages to Bing and read how its search engine sees you |
| Cloudflare | United States | The platform’s traffic, the check that you are not a robot at signup, and —if you connect it— your domain’s configuration | Serve the platform, protect it from automated abuse, and apply technical changes to your site if you authorize us |
| ⚠️ DigitalOcean | United States | Everything the platform stores about you | It is where Hepteon’s server lives |
| Stripe | United States | Your name, your email and your payment details | Charge your subscription. Hepteon never sees or stores your card |
| Resend (Amazon SES) | United States | Your email and the content of the notices and reports we send you | Send you the platform’s emails |
| ⚠️ LinkedIn, Meta (Facebook and Instagram), X and Pinterest | United States | The posts you approve and the credentials of the accounts you connect | Publish to your networks, only those you connect and approve |
| HubSpot | United States | The contacts you choose to sync | Bring to your CRM the contacts your site captures, only if you connect HubSpot |
Those marked ⚠️ receive YOUR CONTENT (the texts written for you, or what you store in the platform), not just your domain. Those are the ones worth looking at.
You may object to a specific sub-processor by writing to contact@hepteon.com. If that makes the service impossible to deliver, we will tell you before charging you anything. All of them process your data solely on our instruction and under contract.
Annex A clarification — managed database (August 2026)
A DigitalOcean managed database in the United States (New York), where account and project data are stored, is added as a subprocessor. The same Annex A regime applies: Standard Contractual Clauses (art. 28.2 and 44-49 GDPR) and the transfer safeguards already described. The Client may object on legitimate grounds by writing to contact@hepteon.com; if that prevents providing the service, they will be told before any charge.
Última actualización de esta sección: 23 de agosto de 2026.