Free ROI calculator: See how much faster page speed could grow your revenue. Try now ->

Data Processing Agreement

1. Introduction and Scope

This Data Processing Agreement (“DPA”) forms part of the Master Services Agreement or Terms of Service (the “Agreement”) between saas.group LLC, doing business as Prerender.io (“Prerender”, “Processor”) and the entity identified in the Agreement (“Customer”, “Controller”). This DPA applies to the extent that Prerender processes Personal Data on behalf of the Customer in connection with the Prerender Service.

This DPA is designed to ensure compliance with: (a) Regulation (EU) 2016/679 (General Data Protection Regulation, “GDPR”); (b) the UK Data Protection Act 2018 and UK GDPR; (c) the Swiss Federal Act on Data Protection (“FADP”); and (d) any other applicable data protection laws (“Data Protection Laws”).

In the event of any conflict between this DPA and the Agreement, this DPA shall prevail with respect to the processing of Personal Data.

2. Definitions

“Personal Data” means any information relating to an identified or identifiable natural person that is processed by Prerender on behalf of the Customer in the course of providing the Service.

“Data Subject” means the identified or identifiable natural person to whom Personal Data relates.

“Subprocessor” means any third party engaged by Prerender to process Personal Data on behalf of the Customer.

“Security Incident” means any accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.

“Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of personal data to processors established in third countries, as approved by the European Commission (Implementing Decision (EU) 2021/914).

Terms not otherwise defined in this DPA shall have the meaning given to them in the Agreement or in the GDPR.

3. Nature and Purpose of Processing

Prerender provides a JavaScript rendering service. The service acts as middleware: when a search engine bot or crawler requests a page, Prerender renders the JavaScript-heavy page and returns static HTML. The details of processing are as follows:

3.1 Subject Matter

Processing of Personal Data necessary for the provision of the Prerender rendering service as described in the Agreement.

3.2 Purpose

  • Rendering publicly-available customer web pages for delivery to customer-specified search engine bots and crawlers
  • Caching rendered HTML output for performance optimization
  • Managing Customer account, billing, and support communications

3.3 Duration

Processing shall continue for the duration of the Agreement. Upon termination, Prerender shall delete or return Personal Data in accordance with Section 10 of this DPA.

3.4 Types of Personal Data

Due to the nature of the rendering service, the Personal Data processed is limited to:

  • URLs submitted for rendering (which may contain personal identifiers in query strings or path segments)
  • Customer account data: name, email address, billing information, and IP address of account administrators
  • Support communication data: email content, names, and contact information exchanged through support channels

Prerender does not separately collect or process end-user Personal Data. The Service renders publicly accessible pages that the Customer submits; any Personal Data appearing within that page content originates from and remains under the Customer’s control, is incidental to the rendering operation, and is processed only transiently in the course of executing the render (renders are stateless — see Annex II.D). Prerender does not use such content for any purpose other than returning the rendered output to the Customer

3.5 Categories of Data Subjects

  • Customer employees and administrators who manage the Prerender account
  • End users whose Personal Data may appear in publicly accessible page content rendered by the Service

4. Obligations of Prerender (Processor)

Prerender shall:

(a) Process Personal Data only on documented instructions from the Customer, including with regard to transfers of Personal Data to a third country, unless required to do so by EU or Member State law. In such a case, Prerender shall inform the Customer of that legal requirement before processing, unless that law prohibits such notification on important grounds of public interest;

(b) Ensure that persons authorized to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;

(c) Implement and maintain appropriate technical and organizational measures as set out in Annex II to ensure a level of security appropriate to the risk, including as appropriate: (i) pseudonymization and encryption of Personal Data; (ii) the ability to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems; (iii) the ability to restore the availability and access to Personal Data in a timely manner in the event of a physical or technical incident; and (iv) a process for regularly testing, assessing, and evaluating the effectiveness of technical and organizational measures;

(d) Assist the Customer, taking into account the nature of processing, by appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of the Customer’s obligation to respond to requests for exercising Data Subject rights under Chapter III of the GDPR;

(e) Assist the Customer in ensuring compliance with its obligations under Articles 32 to 36 of the GDPR, taking into account the nature of processing and the information available to Prerender;

(f) At the choice of the Customer, delete or return all Personal Data to the Customer after the end of the provision of Services relating to processing, and delete existing copies unless EU or Member State law requires storage of the Personal Data;

(g) Make available to the Customer all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR and allow for and contribute to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer.

5. Obligations of the Customer (Controller)

The Customer shall:

  • Ensure that it has a lawful basis for processing Personal Data and for instructing Prerender to process Personal Data on its behalf;
  • Ensure that it has provided all necessary notices and obtained all necessary consents or authorizations required under Data Protection Laws;
  • Be responsible for the accuracy, quality, and legality of the Personal Data provided to Prerender;
  • Provide documented instructions for the processing of Personal Data that comply with Data Protection Laws;
  • Promptly notify Prerender of any changes to applicable Data Protection Laws that may affect Prerender’s processing obligations.

6. Subprocessors

6.1 General Authorization

The Customer provides Prerender with general written authorization to engage Subprocessors to process Personal Data on the Customer’s behalf. The current list of authorized Subprocessors is set out in Annex III and is also available at https://trust.prerender.io/subprocessors.

6.2 Notification of Changes

Prerender shall notify the Customer of any intended changes concerning the addition or replacement of Subprocessors at least thirty (30) days before such changes take effect. Notification shall be provided via email to the address associated with the Customer’s account.

6.3 Objection Right

If the Customer has a reasonable, documented objection to a new or replacement Subprocessor based on data protection grounds, the Customer may notify Prerender in writing within fifteen (15) days of receiving notification. The parties shall discuss the concern in good faith. If the parties cannot resolve the objection within thirty (30) days, the Customer may terminate the affected Service(s) without penalty by providing written notice.

6.4 Subprocessor Obligations

Prerender shall ensure that each Subprocessor is bound by data protection obligations no less protective than those set out in this DPA. Prerender shall remain fully liable to the Customer for the performance of each Subprocessor’s obligations.

7. International Data Transfers

To the extent that the processing of Personal Data involves a transfer outside the EEA, the United Kingdom, or Switzerland to a country not recognized as providing adequate protection, Prerender shall ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) as approved by European Commission Decision 2021/914, incorporated by reference (Module Two: Controller to Processor). The Customer is the “data exporter” and Prerender is the “data importer.” Annexes I–III of this DPA serve as the corresponding annexes of the SCCs;
  • The UK International Data Transfer Addendum to the EU SCCs, issued by the ICO under S.119A(1) of the Data Protection Act 2018, incorporated by reference for transfers subject to UK Data Protection Laws;
  • Any other transfer mechanism approved under applicable Data Protection Laws that provides an adequate level of protection.

Prerender’s primary data processing occurs in the United States and the European Union. Details of data processing locations are set out in Annex I.

8. Security Incident Notification

8.1 Notification

Prerender shall notify the Customer without undue delay, and in any event within without undue delay, after becoming aware of a Security Incident affecting Personal Data processed on behalf of the Customer.

8.2 Content of Notification

Such notification shall include, to the extent available:

  • A description of the nature of the Security Incident, including the categories and approximate number of Data Subjects and Personal Data records concerned;
  • The name and contact details of Prerender’s point of contact for further information;
  • A description of the likely consequences of the Security Incident;
  • A description of the measures taken or proposed to address the Security Incident, including measures to mitigate its possible adverse effects.

8.3 Cooperation

Prerender shall cooperate with the Customer and take reasonable commercial steps to assist in the investigation, mitigation, and remediation of the Security Incident.

9. Audits and Compliance Verification

Prerender shall make available to the Customer, on request, all information reasonably necessary to demonstrate compliance with this DPA. The Customer may exercise its audit rights as follows:

  • The Customer may request copies of such certifications, audit reports, or attestations as Prerender maintains from time to time at no additional cost;
  • If the Customer reasonably determines that documentation provided is insufficient, the Customer may once annually conduct or commission an audit of Prerender’s processing activities, subject to at least thirty (30) days’ written notice, during normal business hours, and without unreasonably disrupting Prerender’s operations;
  • The Customer shall bear audit costs unless the audit reveals a material breach by Prerender, in which case Prerender shall bear reasonable audit costs;
  • Audit results shall be treated as Confidential Information of Prerender under the Agreement.

10. Data Return and Deletion

Upon termination or expiry of the Agreement:

  • Prerender shall, at the Customer’s election, return or delete all Personal Data within thirty (30) days of receiving a written request, unless EU or Member State law requires continued storage;
  • Cached rendered pages (HTML content) shall be automatically purged within agreed-upon period specified by the data retention policy;
  • Customer account data shall be retained for the duration of the Agreement and deleted within ninety (90) days of account cancellation or termination, as further described in Prerender’s data retention policy, provided that Prerender may retain billing and financial records for the period required by applicable tax, accounting, and audit obligations;
  • Prerender shall provide written confirmation of deletion upon the Customer’s request.

11. Data Subject Rights

Prerender shall assist the Customer by appropriate technical and organizational measures for the fulfillment of the Customer’s obligation to respond to Data Subject requests under Data Protection Laws, including rights of access, rectification, erasure, restriction, portability, and objection.

If Prerender receives a request from a Data Subject directly, Prerender shall promptly redirect such request to the Customer and shall not respond directly unless instructed by the Customer or required by applicable law.

12. Liability

The liability of each party under this DPA shall be subject to the limitations and exclusions of liability set out in the Agreement. Nothing in this DPA shall limit either party’s liability for breaches of Data Protection Laws to the extent such limitation is not permitted under applicable law.

13. Term and Termination

This DPA shall come into effect on the date of the Agreement and shall remain in force for as long as Prerender processes Personal Data on behalf of the Customer. The obligations imposed on Prerender under this DPA shall survive for as long as Prerender retains any Personal Data.

14. Governing Law

This DPA shall be governed by the governing law and jurisdiction provisions of the Agreement, provided that: (a) where the SCCs apply, Clause 17 of the SCCs shall designate the law of the EU Member State in which the data exporter is established; and (b) where the UK Addendum applies, English law shall govern.

15. Execution

This DPA is entered into and becomes binding upon execution of the Agreement. The parties’ authorized signatories have executed this DPA as of the date set forth above.

Annex I — Details of Processing

A. List of Parties

Role
Details
Data Exporter (Controller)
The Customer as identified in the Agreement
Data Importer (Processor)
saas.group LLC (Prerender.io), 304 South Jones Boulevard, #1205, Las Vegas, Nevada 89107, USA Contact: privacy@prerender.io

B. Description of Processing

Element
Description
Subject matter
Rendering of JavaScript web pages for search engine optimization and bot delivery
Nature of processing
Automated rendering, caching, storage, and delivery of web page content; account management; support communications
Purpose
Provision of the Prerender rendering service as described in the Agreement
Duration
Duration of the Agreement plus data retention periods specified in Section 10
Data subjects
Customer employees/administrators; end users whose data appears on publicly accessible rendered pages
Personal data types
URLs (which may contain identifiers); publicly accessible page content; account data (name, email, billing info, IP); support communications
Sensitive data
None expected. If Customer pages contain sensitive data, Customer is responsible for ensuring a lawful basis.
Processing locations
United States (primary), European Union (rendering nodes). See Annex III for Subprocessor locations.

Annex II — Technical and Organizational Measures

Prerender implements and maintains the following technical and organizational measures to protect Personal Data:

A. Access Control

  • Role-based access control (RBAC) across all production systems
  • Multi-factor authentication (MFA) enforced for all administrative access
  • SSH key-based authentication for infrastructure access; no shared credentials
  • Principle of least privilege applied to all system access
  • Centralized credential management via 1Password

B. Encryption

  • TLS 1.2+ encryption for all data in transit between Customer systems and Prerender
  • Encryption at rest for databases and backups
  • HTTPS prioritized for all outbound rendering connections to Customer websites

C. Network Security

  • Firewalled production environments with deny-by-default rules
  • DDoS protection via Cloudflare
  • Network segmentation between rendering infrastructure and customer-facing services
  • Intrusion detection and log monitoring

D. Data Isolation

  • Each page rendering uses a new, isolated browser instance with no cookies or data carryover
  • Stateless rendering: no resources are stored between rendering executions
  • Rendering infrastructure is network-segmented with no inbound public access; outbound connections are limited to fetching the Customer-designated pages required for rendering.

E. Incident Response

  • Documented Incident Response Plan with defined severity levels, response targets, and escalation procedures
  • On-call rotation with defined response SLAs
  • Post-incident root cause analysis and corrective action tracking

F. Organizational Measures

  • Security awareness practices for all personnel with access to production systems
  • Confidentiality obligations in all employment and contractor agreements
  • Regular review and testing of security controls
  • Vendor risk assessment for all Subprocessors

G. Business Continuity

  • Multi-region infrastructure across Hetzner, AWS, DigitalOcean, and Cloudflare
  • Automated backups with tested recovery procedures
  • Kubernetes-based orchestration with auto-scaling and self-healing capabilities

Annex III — Authorized Subprocessors

The following Subprocessors are authorized as of the effective date of this DPA. An up-to-date list is maintained at https://trust.prerender.io/subprocessors.

Subprocessor
Purpose
Location
Data Processed
Amazon Web Services
Cloud hosting, storage, CDN
USA / EU
Rendered page content, account data
Apollo.io
Marketing
USA
Customer and prospect contact
DigitalOcean LLC
Kubernetes hosting (DOKS), database hosting
USA / EU
Application data, account metadata
Cloudflare Inc.
CDN, DNS, DDoS protection, WAF
Global (edge)
URLs, HTTP headers
Chargebee Inc.
Subscription billing and invoicing
USA
Account data, billing information
HubSpot Inc.
CRM, marketing, and sales operations
USA / EU
Name, email, company, usage data
Grafana Labs
Infrastructure monitoring and observability
USA / EU
System logs (may contain URLs)
Mixpanel Inc.
Product analytics
EU
Anonymized usage events, account metadata
Google LLC
Workspace (email, calendar, drive)
USA / EU
Email, internal documents
Docusign Inc
Contracts and e-signature
USA
Contract information
Lempire (Lemlist)
Sales & Lead Generation
EU
Name, email, company
Stripe LLC
Payment Processing
USA
Name, email, company
Usersnap GmbH
Customer Analytics
EU
User feedback
Captiwate Inc.
Sales & Lead Generation
USA
Name, email, company
Fathom Video Inc.
Meeting Intelligence
USA
Name, email, company
Strategy11, LLC (Formidable Forms)
Marketing & Advertising
USA
Name, email, company details (size, website, phone number)
Granola Inc.
Meeting Intelligence
USA
Name, email
wespond UG (haftungsbeschränkt) (Jamie)
Meeting Intelligence
EU
Name, email
Productboard Inc.
Customer Data & Analytics
USA
Name, email, company name, User feedback
Tremendous
Customer contact info
USA
Name, email

Note: Hetzner provides bare-metal server hosting for rendering infrastructure. These providers supply physical hardware only and do not have logical access to Personal Data.

Changes to Subprocessors: Prerender will notify the Customer at least 30 days before adding or replacing a Subprocessor, as described in Section 6.2 of this DPA.