BuiltWith
Last Reviewed: 03 Jun 2026
At a Glance
BuiltWith's DPA addresses EU GDPR and Australian Privacy Act requirements, with SCCs, processor-only processing and strong flowdown obligations in place. The notable limitation is that on-site audits are explicitly excluded — adherence is demonstrated through documentation and information requests only.
Company & Product Details
HQ
Australia
Products
BuiltWith website technology intelligence
Product description
Technology profiling / sales intelligence service that identifies technologies used by websites and related web attributes.
What data is being processed?
Personal data processed on behalf of customers is defined through Section A of the DPA and may include customer account / contact data and any other personal data the customer submits or causes BuiltWith to process.
Document Details
Date of DPA
01 Jan 2025
Additional date information
Document states "Revision Year: 2025" without a specific day. PDF metadata creation date is 18 November 2025. Stored date of 2025-01-01 represents the revision year; the precise effective date is uncertain from the document text alone.
What jurisdictions are covered?
GDPR and Australian Privacy Act-style processor terms; international transfer clauses refer to GDPR Chapter V / SCCs.
Is the DPA incorporated into service or customer agreements?
Link
https://builtwith.com/pdf/DATA-PROCESSING-AGREEMENT-2025.pdf
Location & Transfers
Where is data held or processed?
Canada Section A of the DPA explicitly states that the Data Processing Location is Canada. Processing takes place at the business address of BuiltWith and its approved sub-processors as listed in Section A. Sub-processors (Postmark, Stripe, Braintree/PayPal, Persona, Coinbase, CoinPayments, Google, Amazon) may process data in their own locations; international transfers to countries outside Canada are governed by GDPR Chapter V and SCCs where applicable (Section A; clause 5.7).
Could there be a transfer out of the EU/UK?
Are there SCCs or other measures in place?
Security Measures
Are the technical measures contractual?
Detail of measures
Section C of the DPA sets out comprehensive organisational and technical measures: security policy and procedures, defined roles and responsibilities, access control policy (need-to-know), asset management, change management (clause 1.1); incident response plan, business continuity controls (clause 1.2); confidentiality of personnel, awareness training (clause 1.3); access control and authentication system with strong password requirements (clause 2.1); logging and monitoring of all data access (clause 2.2); server/database and workstation security (clause 2.3); network communication encrypted via HTTPS/SSL, firewalls and intrusion detection (clause 2.4); backup procedures (clause 2.5); mobile device management (clause 2.6); secure development lifecycle (clause 2.7); data deletion/disposal procedures including software overwriting and shredding (clause 2.8); physical security with all datacentres ISO/IEC 27001:2013 certified (clause 2.9).
Non Processor Data Use
Does the company process data solely as a processor?
Subprocessing
General authorization
Do all the DPA terms flow down to sub-processors?
Is data only processed on the instruction of the controller?
Rights & Responsibilities
Does the company provide assistance for the data subject's rights?
Does the contract include staff confidentiality clauses?
Are there audit rights for the data?
Is there assistance with DPIA requests?
How much notice is provided for data breaches?
Without undue delay and no later than 48 hours after becoming aware of a personal data breach. (clause 5.4(b))
What happens to the data on termination?
On termination of the processing services, BuiltWith must delete all personal data processed on behalf of the controller unless law requires storage. (clause 5.3 (b))