Legal
Data processing and subprocessors
Who touches your data on our behalf, what they do with it, and where. Written for the person at your organisation who has to sign this off.
Provisional. SearchDone is pre-launch and processes no customer data. This list reflects the intended architecture and must be confirmed, with executed data processing agreements in place, before any customer data is processed.
Last reviewed 27 August 2026
Roles
For your account and contact details, No Fear Tech Ltd is the controller. For the website and search performance data we process to provide the service, we act as processor on your instructions, and you are the controller.
A data processing agreement is available to customers on request. Once the service accepts customer data, one will be offered as standard rather than only when asked.
Intended subprocessors
| Purpose | What it handles | Region |
|---|---|---|
| Application hosting | Serving the application; request logs | To be confirmed — EEA or UK preferred |
| Database and authentication | Account records, site configuration, findings, encrypted integration tokens | To be confirmed — EEA or UK preferred |
| Background job execution | Orchestration of crawls, analysis and scheduled work | To be confirmed |
| AI model provider | Page content and finding context sent for analysis, explanation and drafting | May be outside the UK and EEA; safeguard to be named here |
| Observability | Model call traces and cost attribution | To be confirmed |
| Transactional email | Email address and message content for service email | To be confirmed |
Each row will name the actual company, the safeguard relied upon for any transfer outside the UK or EEA, and a link to that provider's own terms. A subprocessor list with unnamed providers is not good enough to launch with, and this one will not be.
What is sent to AI providers
This is the question most worth asking, so it gets a direct answer. To analyse and explain findings we may send page content, page metadata, search queries and performance figures, and your business context. We do not send account credentials, integration tokens, or payment details.
We will only use providers who contractually do not train their models on customer data, and that commitment will be stated per provider on this page.
What never leaves
- Integration tokens and CMS credentials, which are encrypted at rest and never sent to a model.
- Passwords, which are not stored in recoverable form.
- Payment details, which are handled by the payment provider.
Changes to this list
We will notify account holders before adding or replacing a subprocessor, with enough notice to object. Changes will be dated on this page.
Related
See the privacy notice for retention periods and your rights, the security page for controls, and the terms for the contractual position.