GDPR / Data Processing Addendum
Last updated: 14 July 2026
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between you (the “Customer”) and KO Data operating WebSpeed (“Processor”, “we”). It applies whenever we process personal data on your behalf — principally when we accelerate your website through our reverse proxy and your visitors’ requests pass through our systems. It reflects Article 28 of the GDPR.
Roles. For processing under this DPA the Customer is the controller and KO Data is the processor. For our own site, marketing and audit tool we act as controller — see the Privacy Policy instead. To put a countersigned copy in place, email hi@webspeed.pro.
1. Subject matter and duration
The subject matter is the processing of personal data needed to provide the Service. Processing lasts for the term of the Terms and until deletion or return of personal data as set out below.
2. Nature and purpose of processing
We process personal data solely to deliver the Service: fetching, caching, transforming and re-serving your website’s pages and assets so they load faster, and routing your visitors’ requests through our proxy. We do not use the data for our own purposes.
3. Categories of data and data subjects
| Data subjects | Categories of personal data |
|---|---|
| Visitors and users of the Customer’s website | IP address, device/browser (user-agent), pages and assets requested, referrer, timestamps, and any personal data contained in request data, cookies or form submissions passing through the proxy. |
| Customer’s staff / account users | Contact and account identifiers (covered mainly under the Privacy Policy). |
The Customer must not route special-category data through the proxy unless it has a lawful basis and has told us of any resulting requirements.
4. Our obligations as processor
We will:
- process personal data only on the Customer’s documented instructions (including this DPA and use of the Service), and tell you if we believe an instruction breaches data-protection law;
- ensure people authorised to process the data are bound by confidentiality;
- implement appropriate technical and organisational security measures (Article 32) — see Annex 2;
- respect the conditions for engaging sub-processors (Section 5);
- assist you, taking account of the nature of processing, to respond to data subject requests and to meet your obligations on security, breach notification and data-protection impact assessments;
- notify you without undue delay after becoming aware of a personal data breach affecting your data;
- at your choice, delete or return personal data at the end of the Service and delete existing copies, unless law requires retention;
- make available information needed to demonstrate compliance and allow for and contribute to audits, subject to reasonable notice and confidentiality.
5. Sub-processors
You give general authorisation for us to engage sub-processors to provide the Service. We impose data-protection obligations on them no less protective than this DPA and remain responsible for their performance. Our current sub-processors are listed in Annex 1. We will give reasonable notice of changes and you may object on reasonable data-protection grounds.
6. International transfers
Where personal data is transferred outside the EU/EEA, we ensure an appropriate safeguard is in place — an adequacy decision or the European Commission’s Standard Contractual Clauses (which are incorporated by reference where they apply), with supplementary measures as needed.
7. Liability
Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms of Service. This DPA does not limit rights that data subjects have under the GDPR.
Annex 1 — Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Google (PageSpeed Insights API) | Runs the performance measurement for a submitted URL. | EU / US (SCCs) |
| Hetzner Online GmbH | Hosting of the website, proxy and audit engine. | Germany (EU) |
That is the current list in full. We engage no analytics, email-delivery or other sub-processor today; we will update this Annex and give notice before adding one.
Annex 2 — Technical and organisational measures
We maintain measures appropriate to the risk, including:
- encryption of data in transit (HTTPS/TLS);
- access control on a least-privilege basis and authentication for administrative access;
- network and infrastructure hardening, and separation of environments;
- logging and monitoring for security and abuse detection;
- data minimisation and limited retention of logs and cached content;
- procedures to detect, report and respond to personal data breaches.
Measures are reviewed as the Service evolves and may be updated, provided the level of protection is not reduced.
Questions about this document? Email hi@webspeed.pro.