Data Processing Agreement
Effective date: August 26, 2026 · Last updated: August 26, 2026
1. Overview
This Data Processing Agreement ("DPA") forms part of the agreement between Launch at Dawn ("Processor") and you ("Controller") for the use of the AI visibility tracking platform at www.launchatdawn.com (the "Service").
This DPA applies when the Service processes personal data on your behalf, as required under the General Data Protection Regulation (GDPR) and other applicable data protection laws.
2. Definitions
- "Personal Data" — any information relating to an identified or identifiable natural person
- "Processing" — any operation performed on personal data (collection, storage, use, deletion)
- "Controller" — the entity that determines the purposes and means of processing (you, the customer)
- "Processor" — the entity that processes personal data on behalf of the Controller (Launch at Dawn)
- "Sub-processor" — a third party engaged by the Processor to assist in processing
3. Scope and Purpose of Processing
Launch at Dawn processes Personal Data for the following purposes:
- Providing AI visibility tracking, analytics, and reporting features
- Sending transactional emails (alerts, digests, account notifications)
- Processing payments via Stripe
- Providing customer support
- Security monitoring and abuse prevention
4. Types of Personal Data Processed
- Account information (email, name, plan)
- Business information (name, URL, category, city)
- Tracking prompts and analytics data
- Payment information (Stripe customer ID, subscription status — no card numbers)
- Integration credentials (encrypted WordPress passwords, Git tokens)
- Crawler hit logs (bot visits, paths, referrers)
5. Sub-processors
Launch at Dawn engages the following sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database, auth, file storage | US (AWS) |
| Stripe | Payment processing | US |
| Resend | Transactional email | US |
| Vercel | Hosting, serverless functions | US |
| OpenAI | AI model (GPT-4o) | US |
| Anthropic | AI model (Claude) | US |
| AI model (Gemini) | US | |
| Perplexity | AI model (Sonar) | US |
| Groq | AI model (Llama) | US |
| Mistral | AI model | EU (France) |
| DeepSeek | AI model | China |
| xAI | AI model (Grok) | US |
| OpenRouter | AI model gateway | US |
| Sanity | CMS (blog content) | EU (Norway) |
We will notify you of any changes to our sub-processor list via email or by posting an update on our Service.
6. International Data Transfers
Personal Data may be transferred to and processed in countries outside the European Economic Area (EEA), including the United States. We ensure adequate protection through:
- EU-U.S. Data Privacy Framework compliance where applicable
- Standard Contractual Clauses (SCCs) with sub-processors
- Adequacy decisions by the European Commission
7. Data Security
Launch at Dawn implements the following technical and organizational measures:
- Encryption in transit (TLS 1.3) and at rest (AES-256)
- Row Level Security (RLS) on all database tables
- AES-256-GCM encryption for stored credentials
- Access controls and admin email allowlisting
- Regular security audits
- Incident response procedures
8. Data Subject Rights
We assist the Controller in responding to data subject requests (access, rectification, erasure, portability) through:
- Built-in data export tool (dashboard settings → "Export My Data")
- Built-in account deletion tool (dashboard settings → "Delete Account")
- Admin API endpoints for bulk operations
- Direct contact: privacy@launchatdawn.com
9. Data Breach Notification
In the event of a personal data breach, Launch at Dawn will notify the Controller within 72 hours of becoming aware of the breach, providing:
- Nature of the breach
- Categories and approximate number of data subjects affected
- Likely consequences
- Measures taken or proposed to address the breach
10. Data Retention and Deletion
Launch at Dawn retains Personal Data only for as long as necessary to provide the Service. Upon termination, data is deleted within 30 days. Specific retention periods:
- Account data: duration of account + 30 days
- Analytics data: per plan limits (0–365 days)
- Lead data: 12 months
- Audit logs: 24 months
- Payment records: 7 years (legal requirement)
11. Liability
Each party shall be liable for damage caused by processing that violates this DPA or applicable data protection law. Liability is subject to the limitations set forth in the Terms of Service.
12. Termination
This DPA shall automatically terminate upon termination of the main agreement (Terms of Service). Obligations regarding data deletion and breach notification survive termination.
13. Contact
Data protection inquiries: privacy@launchatdawn.com