Last updated: July 21, 2026

This Data Processing Agreement (“DPA”) forms part of the Terms and Conditions between the client (“Client”, controller) and We Are Content LLC (“Hepteon”, processor), and governs the processing of third-party personal data that the Client uploads or connects to the platform. In case of conflict with the Terms regarding such processing, this DPA prevails.

1. Definitions and roles

The terms “personal data”, “processing”, “controller”, “processor”, “data subject” and “personal data breach” have the meaning of the GDPR (EU) 2016/679 and equivalent laws. With respect to the third-party data the Client incorporates into the Service, the Client acts as controller and Hepteon as processor, processing it solely on the Client’s behalf.

2. Subject matter, duration and purpose

Hepteon will process personal data only to provide the contracted service (an AI-powered marketing SaaS platform: auditing, keyword research, content generation, and the publishing, editing and management of content on the accounts the Client connects, such as Google (including the Business Profile), social networks, CMS and ecommerce platforms), for the term of the Terms and until the data is returned or deleted under clause 11.

3. Client instructions

Hepteon will process the data only on the Client’s documented instructions, including those given through the configuration and use of the platform. If Hepteon considers that an instruction infringes applicable law, it will inform the Client.

4. Types of data and categories of data subjects

Types of data: identification and contact data, credentials, URLs and site content, data from connected accounts (for example, Google services) and any other personal data the Client chooses to include. Categories of data subjects: the Client’s end customers, users and contacts. The Client is responsible for the lawfulness of the data it incorporates and for having a legal basis for its processing.

5. Confidentiality

Hepteon ensures that persons authorized to process the data have committed to confidentiality.

6. Security

Hepteon applies appropriate technical and organizational measures (art. 32 GDPR), including encryption in transit, access controls, activity logging and reasonable security practices appropriate to the risk.

7. Sub-processors

The Client authorizes Hepteon to engage the sub-processors listed in Annex A. Hepteon imposes on each sub-processor, by contract, data protection obligations equivalent to those in this DPA. Hepteon will inform of the addition or replacement of sub-processors with reasonable notice, and the Client may object on legitimate grounds.

8. Assistance to the Client

Taking into account the nature of the processing, Hepteon will assist the Client, as far as possible, in responding to data subject rights requests (arts. 15 to 22 GDPR) and in meeting its obligations regarding security, breach notification, impact assessments and prior consultations (arts. 32 to 36 GDPR).

9. Personal data breaches

Hepteon will notify the Client without undue delay after becoming aware of a personal data breach affecting the data processed on its behalf, providing the information reasonably available so the Client can meet its obligations.

10. International transfers

Where processing involves international transfers, the safeguards described in the Privacy Policy will apply (EU Standard Contractual Clauses, the UK Addendum/IDTA and, where applicable, the EU-US Data Privacy Framework).

11. Return or deletion

Upon termination of the service, and at the Client’s choice, Hepteon will return or delete the personal data processed on its behalf, unless there is a legal retention obligation.

12. Audit

Hepteon will make available to the Client the information reasonably necessary to demonstrate compliance with this DPA and will allow audits, including inspections, on reasonable terms, with prior notice and respecting confidentiality and security.

13. Governing law

This DPA is governed by the law stated in the Terms (State of Delaware, USA), without prejudice to the mandatory data protection rules applicable to the Client or the data subjects, which prevail.

Annex A — List of sub-processors

To provide the service, Hepteon relies on the providers below (sub-processors, GDPR art. 28.2). This list is generated from the platform’s code: if a new provider is added tomorrow, an automated check prevents publishing it without adding it here.

ProviderWhere it isWhat it receives from youWhat for
⚠️ AnthropicUnited StatesYour site content and the texts written for youDraft, edit and grade the articles and posts the platform produces
⚠️ GoogleUnited StatesYour domain, your pages, your Search Console and Analytics data, and the images generatedMeasure your visibility, traffic and speed, and publish the measurement on your site
DataForSEOUnited StatesYour domain and your keywordsCalculating your Hepteon Rating, your inbound links, your competitors and search volume
SE Ranking
SerpApi U.S. Your keywords Checking who ranks in Google for those searches when our usual provider doesn’t respond
United StatesYour domain and your keywordsDomain authority and competitor analysis, as a backup to the previous one
⚠️ GPTZeroUnited StatesThe text of the articles written for youCheck that what is published in your name does not read as machine-written
MozUnited StatesYour domain, and nothing but your domainA second reading of domain authority, so as not to rely on a single source
AhrefsSingaporeYour domain, and nothing but your domainA third reading of domain authority and of your backlinks
Microsoft (Bing)United StatesYour domain and your pagesSubmit your pages to Bing and read how its search engine sees you
CloudflareUnited StatesThe platform’s traffic, the check that you are not a robot at signup, and —if you connect it— your domain’s configurationServe the platform, protect it from automated abuse, and apply technical changes to your site if you authorize us
⚠️ DigitalOceanUnited StatesEverything the platform stores about youIt is where Hepteon’s server lives
StripeUnited StatesYour name, your email and your payment detailsCharge your subscription. Hepteon never sees or stores your card
Resend (Amazon SES)United StatesYour email and the content of the notices and reports we send youSend you the platform’s emails
⚠️ LinkedIn, Meta (Facebook and Instagram), X and PinterestUnited StatesThe posts you approve and the credentials of the accounts you connectPublish to your networks, only those you connect and approve
HubSpotUnited StatesThe contacts you choose to syncBring to your CRM the contacts your site captures, only if you connect HubSpot

Those marked ⚠️ receive YOUR CONTENT (the texts written for you, or what you store in the platform), not just your domain. Those are the ones worth looking at.

You may object to a specific sub-processor by writing to contact@hepteon.com. If that makes the service impossible to deliver, we will tell you before charging you anything. All of them process your data solely on our instruction and under contract.

Annex A clarification — managed database (August 2026)

A DigitalOcean managed database in the United States (New York), where account and project data are stored, is added as a subprocessor. The same Annex A regime applies: Standard Contractual Clauses (art. 28.2 and 44-49 GDPR) and the transfer safeguards already described. The Client may object on legitimate grounds by writing to contact@hepteon.com; if that prevents providing the service, they will be told before any charge.

Última actualización de esta sección: 23 de agosto de 2026.