Legal

Data Processing Agreement

How Cube27 processes personal data on a customer’s behalf when it provides CiteLadder.

Last updated · 24 September 2026

Scope and roles

This Data Processing Agreement (“DPA”) forms part of the agreement between Cube27 IT Private Limited (“Cube27”) and the customer (“Customer”) under the Terms of Service at /terms, wherever Cube27 processes personal data on the Customer’s behalf through CiteLadder (“Customer Personal Data”).

The Customer is the controller, or Data Fiduciary, of Customer Personal Data, or a processor acting for its own controller. Cube27 acts as the Customer’s processor or subprocessor. Personal data Cube27 processes for its own account, billing and security purposes is covered by the Privacy Policy at /privacy, not by this DPA.

Instructions and responsibilities

Cube27 processes Customer Personal Data only to provide and secure the Service, on the Customer’s documented instructions. Those instructions are given through the Customer’s configuration and use of the Service, through a signed agreement, or where law requires. Cube27 will tell the Customer if an instruction appears to break the law, unless the law prohibits telling it.

The Customer is solely responsible for the lawfulness of its instructions and of the data it submits, connects or asks the Service to collect, including having a lawful basis, the necessary notices and permissions, and the right to submit any third party’s information. Cube27 is not responsible for processing carried out on the Customer’s instructions, or for the Customer’s own use of data or outputs obtained from the Service.

Processing details

Details of the processing
ItemDescription
Subject matterProviding CiteLadder website analysis, search and AI-visibility measurement, content assistance, integrations, reports, API and MCP access.
DurationThe service term, plus the export, deletion and legally required retention periods in the Privacy Policy.
OperationsCollection, storage, organisation, extraction, analysis, transmission, display, return and deletion.
Data subjectsThe Customer’s users and personnel; its clients’ users; people whose information appears in material the Customer supplies, on websites it asks the Service to analyse, or in accounts it connects.
Data categoriesBusiness contact details and identifiers; project configuration and prompts; page, search and analytics data; returned evidence and generated outputs; usage and support information.
Sensitive dataNot intended. The Customer must not submit special-category, children’s or other highly sensitive personal data.

Confidentiality and security

Cube27 limits access to Customer Personal Data to authorised personnel bound by confidentiality. It maintains measures appropriate to the risks, including authentication and workspace permissions, encrypted provider and integration credentials, encrypted transport, restricted infrastructure access, and bounded, network-restricted web acquisition.

No certification is implied by this DPA, and no online service can guarantee absolute security.

Subprocessors

The Customer authorises Cube27 to use the subprocessors listed at /subprocessors for the purposes stated there. Cube27 imposes data-protection obligations on each subprocessor that are no less protective than the law requires, and remains responsible for their performance of those obligations.

Cube27 will give at least 30 days’ notice before adding or replacing a subprocessor, by updating that page and notifying the Customer’s workspace owners. The Customer may object on reasonable data-protection grounds within 15 days of the notice. If the parties cannot resolve the objection, either may end the affected part of the Service, and Cube27 will refund any unused prepaid fees for it. A change urgently needed for security or service continuity may take effect sooner, with notice as soon as practicable.

Providers the Customer connects under its own credentials, such as its own AI provider keys or its Google and Bing accounts, act under the Customer’s agreement with that provider and are not Cube27’s subprocessors.

Requests and assistance

Cube27 will promptly pass to the Customer any request it receives from an individual about Customer Personal Data, and will give reasonable help with access, correction, deletion and other requests, security obligations and impact assessments, taking into account the information available to it.

Personal-data breaches

Cube27 will notify the Customer without undue delay after becoming aware of a breach affecting Customer Personal Data, and within any shorter period the law requires. It will share what it knows as it becomes available, take reasonable steps to contain the breach, and cooperate with the Customer. The Customer remains responsible for its own notifications to authorities and individuals unless the law provides otherwise.

International transfers

CiteLadder is hosted in India. Some subprocessors process data in other countries, as the subprocessor list shows. Where the law requires a transfer mechanism for that processing, Cube27 will put it in place.

Return and deletion

When the Service ends, or earlier on a verified instruction, Cube27 will return supported Customer Personal Data or delete it, as described in the Privacy Policy. Cube27 may keep records the law requires it to keep, protected and used only for that purpose.

Copies already delivered to an external client the Customer authorised, such as an AI assistant connected through MCP or the API, are outside Cube27’s control and are not covered by this obligation.

Information and audits

Cube27 will make available the information reasonably needed to show compliance with this DPA, starting with its documentation. Any further audit the law requires is subject to reasonable notice, confidentiality and scope, and must not expose other customers’ data.

Liability and precedence

Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms of Service, to the extent the law permits. This DPA prevails over the Terms only for Customer Personal Data, and a signed enterprise agreement prevails where it expressly says so.

Contact: contact@cube27.com.