← www.launchatdawn.com

Data Processing Agreement

Effective date: August 26, 2026 · Last updated: August 26, 2026

1. Overview

This Data Processing Agreement ("DPA") forms part of the agreement between Launch at Dawn ("Processor") and you ("Controller") for the use of the AI visibility tracking platform at www.launchatdawn.com (the "Service").

This DPA applies when the Service processes personal data on your behalf, as required under the General Data Protection Regulation (GDPR) and other applicable data protection laws.

2. Definitions

  • "Personal Data" — any information relating to an identified or identifiable natural person
  • "Processing" — any operation performed on personal data (collection, storage, use, deletion)
  • "Controller" — the entity that determines the purposes and means of processing (you, the customer)
  • "Processor" — the entity that processes personal data on behalf of the Controller (Launch at Dawn)
  • "Sub-processor" — a third party engaged by the Processor to assist in processing

3. Scope and Purpose of Processing

Launch at Dawn processes Personal Data for the following purposes:

  • Providing AI visibility tracking, analytics, and reporting features
  • Sending transactional emails (alerts, digests, account notifications)
  • Processing payments via Stripe
  • Providing customer support
  • Security monitoring and abuse prevention

4. Types of Personal Data Processed

  • Account information (email, name, plan)
  • Business information (name, URL, category, city)
  • Tracking prompts and analytics data
  • Payment information (Stripe customer ID, subscription status — no card numbers)
  • Integration credentials (encrypted WordPress passwords, Git tokens)
  • Crawler hit logs (bot visits, paths, referrers)

5. Sub-processors

Launch at Dawn engages the following sub-processors:

Sub-processorPurposeLocation
SupabaseDatabase, auth, file storageUS (AWS)
StripePayment processingUS
ResendTransactional emailUS
VercelHosting, serverless functionsUS
OpenAIAI model (GPT-4o)US
AnthropicAI model (Claude)US
GoogleAI model (Gemini)US
PerplexityAI model (Sonar)US
GroqAI model (Llama)US
MistralAI modelEU (France)
DeepSeekAI modelChina
xAIAI model (Grok)US
OpenRouterAI model gatewayUS
SanityCMS (blog content)EU (Norway)

We will notify you of any changes to our sub-processor list via email or by posting an update on our Service.

6. International Data Transfers

Personal Data may be transferred to and processed in countries outside the European Economic Area (EEA), including the United States. We ensure adequate protection through:

  • EU-U.S. Data Privacy Framework compliance where applicable
  • Standard Contractual Clauses (SCCs) with sub-processors
  • Adequacy decisions by the European Commission

7. Data Security

Launch at Dawn implements the following technical and organizational measures:

  • Encryption in transit (TLS 1.3) and at rest (AES-256)
  • Row Level Security (RLS) on all database tables
  • AES-256-GCM encryption for stored credentials
  • Access controls and admin email allowlisting
  • Regular security audits
  • Incident response procedures

8. Data Subject Rights

We assist the Controller in responding to data subject requests (access, rectification, erasure, portability) through:

  • Built-in data export tool (dashboard settings → "Export My Data")
  • Built-in account deletion tool (dashboard settings → "Delete Account")
  • Admin API endpoints for bulk operations
  • Direct contact: privacy@launchatdawn.com

9. Data Breach Notification

In the event of a personal data breach, Launch at Dawn will notify the Controller within 72 hours of becoming aware of the breach, providing:

  • Nature of the breach
  • Categories and approximate number of data subjects affected
  • Likely consequences
  • Measures taken or proposed to address the breach

10. Data Retention and Deletion

Launch at Dawn retains Personal Data only for as long as necessary to provide the Service. Upon termination, data is deleted within 30 days. Specific retention periods:

  • Account data: duration of account + 30 days
  • Analytics data: per plan limits (0–365 days)
  • Lead data: 12 months
  • Audit logs: 24 months
  • Payment records: 7 years (legal requirement)

11. Liability

Each party shall be liable for damage caused by processing that violates this DPA or applicable data protection law. Liability is subject to the limitations set forth in the Terms of Service.

12. Termination

This DPA shall automatically terminate upon termination of the main agreement (Terms of Service). Obligations regarding data deletion and breach notification survive termination.

13. Contact

Data protection inquiries: privacy@launchatdawn.com