BuiltWith

Last Reviewed: 03 Jun 2026

GDPR Addressed

At a Glance

BuiltWith's DPA addresses EU GDPR and Australian Privacy Act requirements, with SCCs, processor-only processing and strong flowdown obligations in place. The notable limitation is that on-site audits are explicitly excluded — adherence is demonstrated through documentation and information requests only.

Company & Product Details

HQ

Australia

Products

BuiltWith website technology intelligence

Product description

Technology profiling / sales intelligence service that identifies technologies used by websites and related web attributes.

What data is being processed?

Personal data processed on behalf of customers is defined through Section A of the DPA and may include customer account / contact data and any other personal data the customer submits or causes BuiltWith to process.

Document Details

Date of DPA

01 Jan 2025

Additional date information

Document states "Revision Year: 2025" without a specific day. PDF metadata creation date is 18 November 2025. Stored date of 2025-01-01 represents the revision year; the precise effective date is uncertain from the document text alone.

What jurisdictions are covered?

GDPR and Australian Privacy Act-style processor terms; international transfer clauses refer to GDPR Chapter V / SCCs.

Is the DPA incorporated into service or customer agreements?

Yes

Location & Transfers

Where is data held or processed?

Canada Section A of the DPA explicitly states that the Data Processing Location is Canada. Processing takes place at the business address of BuiltWith and its approved sub-processors as listed in Section A. Sub-processors (Postmark, Stripe, Braintree/PayPal, Persona, Coinbase, CoinPayments, Google, Amazon) may process data in their own locations; international transfers to countries outside Canada are governed by GDPR Chapter V and SCCs where applicable (Section A; clause 5.7).

Could there be a transfer out of the EU/UK?

Yes

Are there SCCs or other measures in place?

Yes
The DPA refers to Chapter V GDPR transfers and use of standard contractual clauses between processor and sub-processor where needed.

Security Measures

Are the technical measures contractual?

Yes

Detail of measures

Section C of the DPA sets out comprehensive organisational and technical measures: security policy and procedures, defined roles and responsibilities, access control policy (need-to-know), asset management, change management (clause 1.1); incident response plan, business continuity controls (clause 1.2); confidentiality of personnel, awareness training (clause 1.3); access control and authentication system with strong password requirements (clause 2.1); logging and monitoring of all data access (clause 2.2); server/database and workstation security (clause 2.3); network communication encrypted via HTTPS/SSL, firewalls and intrusion detection (clause 2.4); backup procedures (clause 2.5); mobile device management (clause 2.6); secure development lifecycle (clause 2.7); data deletion/disposal procedures including software overwriting and shredding (clause 2.8); physical security with all datacentres ISO/IEC 27001:2013 certified (clause 2.9).

Non Processor Data Use

Does the company process data solely as a processor?

Yes
The DPA restricts BuiltWith to acting solely as a processor on the controller's documented instructions. Clause 5.1(a) limits processing to documented instructions from the controller. Clause 5.2 limits processing to the specific purposes set out in Section A (BuiltWith Pro SaaS Tool Access Credentials). No language granting BuiltWith independent controller rights or rights to use personal data for its own purposes was found in the document. The DPA does not address this topic explicitly beyond the purpose limitation, so the default of Yes applies (clauses 5.1, 5.2).

Subprocessing

General authorization

General
General authorisation is granted for the engagement of sub-processors listed in Section A; the sub-processor list is also maintained at https://builtwith.com/privacy (clause 5.6(a)). Sub-processors must be bound by a contract imposing the same DPA obligations (clause 5.6(b)). A copy of the sub-processor agreement is available to the controller on request (clause 5.6(c)). BuiltWith remains fully responsible for sub-processor performance and must notify the controller of any sub-processor failure (clause 5.6(d)).

Do all the DPA terms flow down to sub-processors?

Yes
BuiltWith must engage sub-processors by a contract imposing the same obligations as under this DPA, and must ensure the sub-processor complies with those obligations (clause 5.6(b)). BuiltWith remains fully responsible to the controller for the performance of the sub-processor and must notify the controller of any failure by the sub-processor to fulfil its obligations (clause 5.6(d)).

Is data only processed on the instruction of the controller?

Yes
Personal data may be processed only on documented instructions from the data controller as specified in Section A. Subsequent instructions must also be documented. BuiltWith must immediately inform the controller if it believes any instruction infringes applicable data protection law (clause 5.1(a),(b)).

Rights & Responsibilities

Does the company provide assistance for the data subject's rights?

Yes
BuiltWith must notify the controller of data subject requests and assist with rights responses. (clause 6.1(a))

Does the contract include staff confidentiality clauses?

Yes
Clause 5.4(d) requires that persons authorised to process personal data must have committed to confidentiality or be under a statutory obligation of confidentiality. Section C, clause 1.3(a) also requires that all employees understand their responsibilities and obligations related to personal data processing, communicated during pre-employment and/or induction.

Are there audit rights for the data?

Structured
Section A explicitly states that on-premise audits are not available ("On-premise audits: No"). BuiltWith must make available all information necessary to demonstrate compliance with this DPA and allow for and contribute to reviews of data files and documentation or audits of the processing activities, particularly if there are indications of non-compliance (clause 5.5(c)). Both parties must make such information available to the competent supervisory authority on request (clause 5.5(d)).

Is there assistance with DPIA requests?

Yes
the DPA expressly includes assistance with DPIAs and prior supervisory consultation obligations.

How much notice is provided for data breaches?

Without undue delay and no later than 48 hours after becoming aware of a personal data breach. (clause 5.4(b))

What happens to the data on termination?

On termination of the processing services, BuiltWith must delete all personal data processed on behalf of the controller unless law requires storage. (clause 5.3 (b))