Effective August 19, 2026 · Version 1.2

Data Processing Agreement

This DPA governs personal data Supercenter processes on a customer’s behalf when providing the service.

1. Parties and status

This Data Processing Agreement (“DPA”) forms part of the agreement between the customer that accepts the Supercenter terms or an order (“Customer”) and Nikolaus Redl, trading as Supercenter, Kleistgasse 18/41, 1030 Vienna, Austria (“Supercenter”). It takes effect when Customer accepts the agreement or first submits Customer Personal Data to the service.

“Data Protection Law” means the GDPR, applicable national laws that implement or supplement it, and, where applicable, the UK GDPR and Swiss Federal Act on Data Protection. GDPR terms such as controller, processor, personal data, processing, and personal data breach have their statutory meanings.

Customer is the controller of Customer Personal Data or a processor acting for another controller. Supercenter is Customer’s processor or subprocessor. Supercenter remains an independent controller for its own account, security, billing, legal, and website data as described in the privacy policy.

2. Instructions and compliance

Supercenter will process Customer Personal Data only on Customer’s documented instructions and as necessary to provide, secure, support, and meter the service, unless Union or Member State law requires otherwise. The agreement, this DPA, Customer’s configuration, and requests made through the dashboard, API, MCP server, CLI, or a connected agent are documented instructions.

If law requires processing outside those instructions, Supercenter will inform Customer before processing unless the law prohibits that notice. Supercenter will promptly inform Customer if it believes an instruction infringes Data Protection Law and may pause the affected processing while the parties resolve it.

Customer is responsible for the lawfulness, fairness, accuracy, and transparency of its instructions; for providing required notices; and for having a lawful basis to retrieve, combine, use, disclose, or contact people using public-source results. Customer must not intentionally submit special-category data, criminal-offence data, children’s data, health data, payment-card data, or government identifiers unless the parties first agree appropriate written safeguards.

3. Confidentiality and personnel

Supercenter will limit access to Customer Personal Data to personnel who need it to provide or secure the service. Authorized personnel are bound by statutory or contractual confidentiality duties and receive appropriate privacy and security instructions.

4. Security

Taking into account the state of the art, implementation cost, and the nature, scope, context, purposes, and risks of processing, Supercenter will maintain appropriate technical and organizational measures under Article 32 GDPR. The launch measures are described in Annex II. Supercenter may update them without materially reducing the overall security of the service.

5. Subprocessors

Customer gives general written authorization for Supercenter to use the subprocessors in Annex III. Supercenter will impose data-protection obligations that provide at least the protection required by Article 28 GDPR for the processing they perform and remains responsible for each subprocessor’s performance to the extent required by law.

Supercenter will give at least 30 days’ prior notice by email or an in-product notice before appointing a new or replacement subprocessor that will process Customer Personal Data. Customer may object during that period on reasonable data-protection grounds. The parties will work in good faith on a reasonable alternative; if none is available, Customer may terminate the affected service before the change takes effect.

Providers that independently process sign-in, billing, or optional website analytics data are described in the privacy and cookie policies and are not subprocessors under this DPA for that independent processing.

6. Assistance and data-subject requests

Taking into account the nature of processing, Supercenter will provide reasonable assistance through appropriate technical and organizational measures so Customer can respond to requests for access, correction, deletion, restriction, portability, objection, and information about recipients. If Supercenter receives a request concerning Customer Personal Data, it will not respond on Customer’s behalf unless authorized or legally required and will forward the request where the relevant Customer can be identified.

Supercenter will also provide reasonable information and assistance for Customer’s Article 32–36 obligations, including security reviews, breach notifications, data-protection impact assessments, and prior consultation, considering the processing and information available to Supercenter.

7. Personal data breaches

Supercenter will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. As information becomes available, the notice will describe the nature of the breach, affected data and people, likely consequences, measures taken or proposed, and a contact for follow-up. Supercenter will take reasonable steps to contain, investigate, and mitigate the breach. Notice is not an admission of fault or liability.

8. Return, deletion, and duration

This DPA continues while Supercenter processes Customer Personal Data. On termination or a verified written request, and at Customer’s choice, Supercenter will return available Customer Personal Data or delete it and existing copies, unless applicable law requires storage. Customer should export needed results before termination. Active systems are normally cleared within 30 days; deletion from encrypted backups follows their ordinary overwrite cycle, during which the data remains protected and is not restored except for disaster recovery.

9. Information and audits

Supercenter will make available information reasonably necessary to demonstrate compliance with Article 28 GDPR. Customer may audit that compliance once per year and after a substantiated incident. Audits will ordinarily begin with current policies, questionnaires, and independent reports. Any additional remote or on-site audit requires reasonable notice, must protect other customers and confidential information, may not unreasonably disrupt operations, and is at Customer’s cost unless it identifies a material breach by Supercenter.

10. International transfers

Supercenter is established in Austria. Where Customer Personal Data is transferred to a country without an adequacy decision, Supercenter will use a lawful transfer mechanism and appropriate supplementary measures. This includes requiring eligible subprocessors to use the European Commission’s Standard Contractual Clauses or another valid safeguard.

Where the parties’ direct transfer requires the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, they are incorporated by reference: Module Two applies where Customer is controller and Module Three where Customer is processor; the docking clause applies; clause 9 option 2 uses general authorization with the notice period in section 5; the optional clause 11 language does not apply; Austria is the governing Member State and the courts of Vienna are selected for clauses 17 and 18. Annexes I and II below complete the corresponding SCC annexes. The UK Addendum or applicable Swiss modifications apply where required.

11. Liability and precedence

Each party’s liability under this DPA is subject to the agreement’s lawful liability limits. If this DPA conflicts with the agreement on protection of Customer Personal Data, this DPA controls; the Standard Contractual Clauses control over inconsistent terms. Austrian law governs this DPA except where mandatory Data Protection Law or the Standard Contractual Clauses require otherwise.

Annex I: Details of processing

Data exporter
Customer, using the contact and establishment information in its account or order; controller or processor as applicable.
Data importer
Nikolaus Redl, trading as Supercenter, address above; privacy contact security@supercenter.app; processor or subprocessor as applicable.
Subject matter and purpose
Providing public web, people, company, news, social, advertising, commerce, and marketplace data to Customer’s workspace, API, MCP client, CLI, or connected AI agent; storing sourced results; metering; security; troubleshooting; and support.
Nature and frequency
Collection, transmission, retrieval, structuring, normalization, storage, consultation, disclosure to Customer, deletion, and related operations; continuous or whenever Customer submits a request during the service term.
Data subjects
Customer users and personnel; prospects, customers, suppliers, creators, public-profile owners, company representatives, and other people identified in Customer queries or public sources.
Personal data
Account identifiers; query text; public names, professional and employment details, profile and post data, public contact details, company associations, advertisements and marketplace activity; source URLs; result content; IP address; request, usage, and audit metadata. No sensitive category is required.
Duration
The agreement term and the deletion period in section 8, subject to documented legal retention requirements.
Supervisory authority
The Austrian Data Protection Authority, without prejudice to another authority competent under Data Protection Law.

Annex II: Security measures

  • TLS for data in transit and provider-managed encryption at rest for production databases and private object storage.
  • Server-side secret handling; API keys and one-time codes stored as hashes where authentication requires comparison rather than recovery.
  • Authenticated sessions, role-based workspace permissions, scoped API keys, and server-side workspace authorization on protected routes.
  • Logical tenant separation by workspace identifiers and access checks on workspace data and execution records.
  • Input validation, request limits, abuse controls, idempotency for billing-sensitive operations, and restricted production access.
  • Operational logs, failure records, dependency management, backups, restoration capabilities, and incident-response procedures.
  • Provider review, contractual confidentiality, subprocessor management, and deletion or return procedures.

Annex III: Authorized subprocessors

Vercel

Processing:
Hosting, serverless execution, content delivery, private object storage, and operational logs.
Location:
United States and other Vercel processing locations.
Safeguards:
Vercel DPA, EU Standard Contractual Clauses, and applicable supplementary measures.

Neon

Processing:
Managed PostgreSQL database.
Location:
Selected production database region and support locations.
Safeguards:
Neon DPA, EU Standard Contractual Clauses, and regional hosting configuration.

Resend

Processing:
Transactional email and delivery records.
Location:
United States and Resend subprocessor locations.
Safeguards:
Resend DPA and EU Standard Contractual Clauses.

Exa Labs

Processing:
Web, people, company, and news search and retrieval.
Location:
United States and Exa subprocessor locations.
Safeguards:
Applicable data-processing terms, EU Standard Contractual Clauses, and supplementary measures.

ScrapeCreators (Web Scraping Guy LLC)

Processing:
Public social-network, advertisement, and related API retrieval.
Location:
United States and service-provider locations.
Safeguards:
Article 28 terms, EU Standard Contractual Clauses, and supplementary measures where required.

Apify Technologies

Processing:
Fallback public-site extraction and selected data-retrieval actors.
Location:
Czech Republic and Apify subprocessor locations.
Safeguards:
Apify Data Processing Addendum and EU Standard Contractual Clauses where applicable.

Acceptance and contact

Electronic acceptance of the Supercenter terms, an order referencing this DPA, or use of the service to process Customer Personal Data constitutes signature by the parties where electronic acceptance is legally effective. Signature copies or privacy questions may be sent to security@supercenter.app.