← Sitefetti

SITEFETTI · 2026-09-25-processing-release-v7

Customer data-processing addendum

Operator and contact

FORUM TRADE, podjetje za trgovino, zastopništvo in posredniško dejavnost, Miloš Verić s.p.
Šerkova ulica 13, 1000 Ljubljana, Slovenia

hello@sitefetti.com

Parties and roles

The subscription customer is controller of personal data collected through its website. FORUM TRADE is processor for those records. FORUM TRADE is separately controller for its own account administration, billing and service-security purposes.

Scope, duration and data

Processing covers hosting, display, editing, export, requested communications, security and backup during the service and agreed exit period. Individuals include staff, visitors, enquirers and shoppers. Data may include names, contact and business details, messages, supplied photographs, proposals and orders. Standard forms do not collect card numbers. The service is not intended for sensitive identity documents or special-category data.

Documented instructions

Authorised Workspace actions and documented support requests are instructions. Processing follows those instructions unless law requires otherwise; the customer is informed where permitted. Sitefetti informs the customer of instructions it considers unlawful. Website contacts are not added to Sitefetti marketing. Personal data is sent to AI only when necessary for an authorised operation.

Confidentiality and security

Access is restricted to authorised people with confidentiality duties. Measures include tenant access checks, protected credentials, TLS and separately stored encrypted backups. The customer controls its users and supplies lawful content and notices. No guarantee of absolute security is given.

Assistance and incidents

Sitefetti assists with data-subject requests and, taking account of the processing and available information, security obligations, impact assessments and prior consultation. It notifies the customer without undue delay after becoming aware of a breach affecting their data, supplies available scope and mitigation information and supplements it as the investigation progresses.

Subprocessors and transfers

Authorised subprocessors are Render Services, Inc. (application hosting, primary region Frankfurt); Supabase Pte. Ltd. (database and website images, primary region Ireland); OpenAI Ireland Ltd. (requested text and image generation, Global project processing); Plus Five Five, Inc., trading as Resend (email addresses and message content, United States); and Cloudflare, Inc. (encrypted R2 backups, EU bucket jurisdiction). Each receives only the data needed for its function and is bound by data-protection obligations appropriate to that processing. Sitefetti remains responsible for its subprocessors’ obligations. EU primary storage does not exclude support or further processing outside the EU. Transfers use an applicable adequacy decision or standard contractual clauses and the required supplementary safeguards. Contact hello@sitefetti.com for relevant safeguard information. Stripe Payments Europe, Limited, and where applicable Stripe Technology Europe, Limited, process payments in their applicable controller or processor roles. Better Stack, Inc. receives availability and backup-result signals and operator contact details, not customer archives. The latter services are not authorised to use customer website contacts for marketing.

Changes to subprocessors

The customer generally authorises the listed subprocessors for their stated functions. Before Sitefetti appoints an additional or replacement subprocessor, it emails the verified account contact with the provider, purpose, location and safeguards at least seven days before that provider receives customer data. A reasoned data-protection objection can be sent to hello@sitefetti.com. Sitefetti and the customer seek an alternative; if none resolves the objection, the affected processing is suspended or the customer may terminate that affected service with a refund for its unused prepaid period. Upstream provider notices are reviewed when received and passed on promptly. A shorter upstream notice is not a silent waiver of safeguards: if sufficient protection or time for objection cannot be maintained, the affected processing must be paused. Notices and their delivery are recorded; publication of a changed webpage alone is not notice.

Return and deletion

After the paid service ends, the customer has 30 days to export supported records. On a verified instruction to return data, support supplies the Workspace JSON and separately arranges the customer-owned images needed for a usable export; image links alone are not a complete image archive. On a verified deletion instruction, support checks the affected tenant, shared media and provider-held copies, records legal or dispute exceptions, and carries out and documents the approved scope. Cancellation alone is not deletion. Scheduled retention deletion is preceded by a seven-day warning to a verified email. Active paid services are excluded. The seven newest verified daily backup copies rotate after a successful new copy; unsuccessful backups can delay rotation. Deleted-data restrictions must be reapplied before any restoration becomes available. This procedure requires manual support and does not claim automatic erasure or removal of statutory payment records.

Evidence and audit

Provide relevant compliance information and allow and contribute to audits, including inspections, by the customer or its mandated auditor. Agree a secure method and reasonable arrangements protecting other tenants and secrets without removing the audit right or a competent authority's powers. Current exports and deletion manifests do not prove that all provider-held data has been exported or erased.

Contact and completion

Send documented instructions, objections and incident reports to hello@sitefetti.com with the account or website reference, without passwords or API keys. The order identifies the contracting customer. This addendum applies to personal data processed on that customer’s behalf. The version presented and accepted at purchase is stored with the order and supplied with the purchase confirmation. Later document updates do not silently replace that historical record. Return and deletion are supported procedures requiring review, not a promise of instantaneous automatic erasure.