Last updated: July 21, 2026

This Data Processing Agreement (“DPA”) forms part of the Terms and Conditions between the client (“Client”, controller) and We Are Content LLC (“Hepteon”, processor), and governs the processing of third-party personal data that the Client uploads or connects to the platform. In case of conflict with the Terms regarding such processing, this DPA prevails.

1. Definitions and roles

The terms “personal data”, “processing”, “controller”, “processor”, “data subject” and “personal data breach” have the meaning of the GDPR (EU) 2016/679 and equivalent laws. With respect to the third-party data the Client incorporates into the Service, the Client acts as controller and Hepteon as processor, processing it solely on the Client’s behalf.

2. Subject matter, duration and purpose

Hepteon will process personal data only to provide the contracted service (an AI-powered marketing SaaS platform: auditing, keyword research, content generation, and the publishing, editing and management of content on the accounts the Client connects, such as Google (including the Business Profile), social networks, CMS and ecommerce platforms), for the term of the Terms and until the data is returned or deleted under clause 11.

3. Client instructions

Hepteon will process the data only on the Client’s documented instructions, including those given through the configuration and use of the platform. If Hepteon considers that an instruction infringes applicable law, it will inform the Client.

4. Types of data and categories of data subjects

Types of data: identification and contact data, credentials, URLs and site content, data from connected accounts (for example, Google services) and any other personal data the Client chooses to include. Categories of data subjects: the Client’s end customers, users and contacts. The Client is responsible for the lawfulness of the data it incorporates and for having a legal basis for its processing.

5. Confidentiality

Hepteon ensures that persons authorized to process the data have committed to confidentiality.

6. Security

Hepteon applies appropriate technical and organizational measures (art. 32 GDPR), including encryption in transit, access controls, activity logging and reasonable security practices appropriate to the risk.

7. Sub-processors

The Client authorizes Hepteon to engage the sub-processors listed in Annex A. Hepteon imposes on each sub-processor, by contract, data protection obligations equivalent to those in this DPA. Hepteon will inform of the addition or replacement of sub-processors with reasonable notice, and the Client may object on legitimate grounds.

8. Assistance to the Client

Taking into account the nature of the processing, Hepteon will assist the Client, as far as possible, in responding to data subject rights requests (arts. 15 to 22 GDPR) and in meeting its obligations regarding security, breach notification, impact assessments and prior consultations (arts. 32 to 36 GDPR).

9. Personal data breaches

Hepteon will notify the Client without undue delay after becoming aware of a personal data breach affecting the data processed on its behalf, providing the information reasonably available so the Client can meet its obligations.

10. International transfers

Where processing involves international transfers, the safeguards described in the Privacy Policy will apply (EU Standard Contractual Clauses, the UK Addendum/IDTA and, where applicable, the EU-US Data Privacy Framework).

11. Return or deletion

Upon termination of the service, and at the Client’s choice, Hepteon will return or delete the personal data processed on its behalf, unless there is a legal retention obligation.

12. Audit

Hepteon will make available to the Client the information reasonably necessary to demonstrate compliance with this DPA and will allow audits, including inspections, on reasonable terms, with prior notice and respecting confidentiality and security.

13. Governing law

This DPA is governed by the law stated in the Terms (State of Delaware, USA), without prejudice to the mandatory data protection rules applicable to the Client or the data subjects, which prevail.

Annex A — List of sub-processors

ProviderPurposeLocation
Google LLCGoogle APIs the Client connects (Search Console, Analytics, Ads, Tag Manager, Business Profile)USA / global
Stripe, Inc.Payment processingUSA / global
Cloudflare, Inc.Security, CDN and performanceUSA / global
DigitalOcean LLCHosting and infrastructureUSA / global
AI model providersAI-assisted content generationUSA / global
SEO toolsSEO data and metricsGlobal

Contact for data protection matters: [email protected].