Trust Center

We're committed to protecting your data and maintaining transparency about our security practices.

Last updated: June 3, 2026

Company Information

We are a technology company based and registered in South Africa.

Espresso Dev (Pty) Ltd

2015/437542/07

South Africa

Herman Schutte

SiteSpeakAI

[email protected]

Privacy & GDPR Compliance

SiteSpeakAI is GDPR compliant. We act as a data processor on our customers' behalf and provide the contractual and technical safeguards required to process EU and UK personal data lawfully:

  • A signable Data Processing Agreement incorporating the EU Standard Contractual Clauses
  • A published list of subprocessors with their location and transfer safeguard
  • Support for data subject rights, including access, export, and deletion
  • Cookie consent for visitors in the EEA and UK
  • Encryption in transit and at rest, and a 48-hour breach notification commitment

We also support compliance with the UK GDPR, South Africa's POPIA, and California's CCPA/CPRA.

Data Requests

If you have any questions or requests regarding your personal data, please contact us at [email protected].

Data Processing Agreement (DPA)

Our Data Processing Agreement outlines how we handle your personal data and ensures compliance with privacy regulations.

DPA Coverage

  • Data processing purposes and AI training restrictions
  • Data retention periods (conversations: 2 years, accounts: 30 days post-termination)
  • 48-hour breach notification and incident response procedures
  • Data subject rights assistance and deletion requests
  • International data transfers with adequate safeguards

Subprocessors

We work with trusted third-party service providers to deliver our services. All subprocessors are contractually bound to protect your data.

Service Provider Purpose Location Transfer Mechanism DPA Status
Anthropic AI language model processing United States Standard Contractual Clauses Available
Better Stack Log management & monitoring United States Standard Contractual Clauses Available
Cloudflare CDN, DNS & DDoS protection United States EU-US Data Privacy Framework Available
Cohere Search result reranking Canada Adequacy decision (Canada) Available
DigitalOcean Cloud hosting, database & storage United States EU-US Data Privacy Framework Available
Drip Email marketing automation United States EU-US Data Privacy Framework Available
Google AI language model processing United States EU-US Data Privacy Framework Available
LlamaIndex Document parsing United States Standard Contractual Clauses Available
Microsoft Azure Speech-to-text processing United States EU-US Data Privacy Framework Available
Nightwatch Application performance monitoring United States EU-US Data Privacy Framework Available
OpenAI AI language model processing & embeddings United States Standard Contractual Clauses Available
Paddle Payment processing (merchant of record) United Kingdom Standard Contractual Clauses Available
Pinecone Vector database (content search) United States Standard Contractual Clauses Available
PostHog Product analytics United States EU-US Data Privacy Framework Available
Pusher Real-time messaging United Kingdom / United States Standard Contractual Clauses Available
Resend Transactional email United States Standard Contractual Clauses Available
ScrapingBee Web page rendering for indexing France (EU) Not applicable (EU) Available
Sentry Error monitoring United States EU-US Data Privacy Framework Available
Tolt Affiliate tracking United States Standard Contractual Clauses Available
Upstash Caching (Redis) United States EU-US Data Privacy Framework Available
xAI AI language model processing United States Standard Contractual Clauses Available

Security Measures

Encryption

  • Data encrypted in transit (TLS 1.3)
  • Data encrypted at rest (AES-256)
  • Database encryption enabled

Access Controls

  • Role-based access control
  • Multi-factor authentication
  • Regular access reviews

Infrastructure

  • DigitalOcean SOC 2 certified infrastructure
  • Regular security updates
  • Automated backup systems

Monitoring

  • 24/7 system monitoring
  • Automated threat detection
  • Incident response procedures

Data Protection

  • PII redaction masks ID numbers, payment cards and bank accounts in visitor messages
  • Redacted values never reach AI providers or storage
  • Audit trail records every redaction for compliance evidence

AI Safety

  • Prompt injection and jailbreak protection
  • Configurable response restriction levels
  • Per-visitor rate limiting to prevent abuse

Your Data Rights

You have the following rights regarding your personal data:

Access & Portability

  • Right to access your data
  • Right to data portability
  • Right to rectification

Control & Deletion

  • Right to erasure
  • Right to restriction
  • Right to object

To exercise any of these rights, contact us at [email protected]

Legal Documents