Skip to content
SearchDone

Legal

Data processing and subprocessors

Who touches your data on our behalf, what they do with it, and where. Written for the person at your organisation who has to sign this off.

In build

Provisional. SearchDone is pre-launch and processes no customer data. This list reflects the intended architecture and must be confirmed, with executed data processing agreements in place, before any customer data is processed.

Last reviewed 27 August 2026

Roles

For your account and contact details, No Fear Tech Ltd is the controller. For the website and search performance data we process to provide the service, we act as processor on your instructions, and you are the controller.

A data processing agreement is available to customers on request. Once the service accepts customer data, one will be offered as standard rather than only when asked.

Intended subprocessors

PurposeWhat it handlesRegion
Application hostingServing the application; request logsTo be confirmed — EEA or UK preferred
Database and authenticationAccount records, site configuration, findings, encrypted integration tokensTo be confirmed — EEA or UK preferred
Background job executionOrchestration of crawls, analysis and scheduled workTo be confirmed
AI model providerPage content and finding context sent for analysis, explanation and draftingMay be outside the UK and EEA; safeguard to be named here
ObservabilityModel call traces and cost attributionTo be confirmed
Transactional emailEmail address and message content for service emailTo be confirmed

Each row will name the actual company, the safeguard relied upon for any transfer outside the UK or EEA, and a link to that provider's own terms. A subprocessor list with unnamed providers is not good enough to launch with, and this one will not be.

What is sent to AI providers

This is the question most worth asking, so it gets a direct answer. To analyse and explain findings we may send page content, page metadata, search queries and performance figures, and your business context. We do not send account credentials, integration tokens, or payment details.

We will only use providers who contractually do not train their models on customer data, and that commitment will be stated per provider on this page.

What never leaves

  • Integration tokens and CMS credentials, which are encrypted at rest and never sent to a model.
  • Passwords, which are not stored in recoverable form.
  • Payment details, which are handled by the payment provider.

Changes to this list

We will notify account holders before adding or replacing a subprocessor, with enough notice to object. Changes will be dated on this page.

Related

See the privacy notice for retention periods and your rights, the security page for controls, and the terms for the contractual position.