Skip to content
pageree← Back to home

Pageree / Legal

Data Processing Agreement

The commitments governing personal data Pageree processes for its customers.

Version September 10, 2026

Privacy PolicyTerms of UseData Processing AgreementSubprocessorsReport abuse

In effect since September 10, 2026

This is the applicable version of the Pageree legal package. It applies to accounts created or subscriptions purchased on or after that date; accounts that accepted an earlier version keep it until they accept a newer one. Viewing this page does not by itself create an agreement, start a trial, or authorize a payment.

On this page

  1. Parties and scope
  2. Instructions and confidentiality
  3. Security and incidents
  4. Rights, assistance and audits
  5. Subprocessors and transfers
  6. Return and deletion
  7. Processing details
  8. Security measures
  9. Contact

1. Parties and scope

This Data Processing Agreement (“DPA”) is between the customer identified in the accepted service agreement or order (“Customer”) and Aleksandr Shelestov PR JustOneDev, trading as Pageree (“Pageree”). It forms part of the Terms of Use when accepted with them, or when separately agreed in writing. An authorized representative must accept for an organization. The acceptance record or signed order identifies the Customer, representative, applicable document version and acceptance date.

“Customer Personal Data” means personal data processed by Pageree on the Customer’s behalf through page hosting, form capture and delivery, analytics, and requested content or asset processing. The Customer acts as controller, or as a processor with authority from its controller to appoint Pageree as a subprocessor. Pageree acts as processor or subprocessor for these activities.

Applicable data protection law includes Serbian personal-data law and, where applicable, the EU GDPR, UK GDPR and other laws governing the processing. Account administration, proportionate platform security, legal compliance and Pageree’s own business correspondence are described separately in the Privacy Policy; assigning a role here does not override the role required by law.

This DPA controls a conflict about Customer Personal Data. Applicable mandatory law and valid international-transfer terms take priority. It does not limit an individual’s statutory rights or either party’s liability where the law does not permit that limitation.

2. Instructions and confidentiality

The accepted agreement, this DPA, and the Customer’s authorized settings and requests are documented instructions. They include publishing content to the public, collecting configured form fields, retaining leads for the stated recovery period, delivering them to the selected recipient, generating analytics and returning authorized tool results to connected clients.

Pageree will process Customer Personal Data only on those instructions, including for international transfers, unless applicable law requires otherwise. Where legally permitted, Pageree will inform the Customer of that requirement before processing. Pageree will promptly flag an instruction it believes infringes applicable data protection law and may suspend that processing while the parties resolve the concern.

People authorized to access Customer Personal Data must be bound by confidentiality obligations and receive access only as needed for their work. Pageree will not sell the data, use private leads for its own advertising, or use Customer Personal Data to train its own general-purpose AI models. External AI processing is limited to the requested feature and approved provider terms; a Customer’s independently chosen AI client has its own relationship with the Customer.

The Customer must establish a lawful basis, provide accurate notices, obtain consent where required, minimize collected fields, and ensure its instructions and recipients are lawful. The standard service must not be used for children’s data, special-category or criminal-offence data, passwords, full payment-card details, or government identification numbers. A different use requires a separate written agreement and suitable controls before collection.

3. Security and personal-data incidents

Pageree will maintain technical and organizational measures appropriate to the processing risk, including the measures in section 8, and assess their effectiveness. Measures may evolve without materially reducing the protection committed to the Customer.

Pageree will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data. Pageree will provide the known nature of the breach, affected categories and approximate numbers where available, a contact point, likely consequences, and measures taken or proposed. Information may be supplied in stages as it becomes available; the initial notice will not wait for a complete investigation.

Pageree will investigate, contain and remediate the breach and reasonably assist the Customer’s assessment and legally required notifications. A processor notice is not an admission of fault. The Customer normally decides its controller notifications; Pageree remains responsible for notifications imposed directly on it by law.

4. Rights, assistance and assurance

Considering the nature of processing and information available, Pageree will reasonably assist with requests for access, correction, deletion, restriction, objection and portability; security obligations; breach assessment and notification; data protection impact assessments; and consultations with regulators.

If Pageree receives a request concerning Customer Personal Data, it will route it to the Customer or act under the Customer’s documented instructions, unless law requires otherwise. The Customer instructs Pageree to operate the documented, email-verified lead access and erasure flow. It searches matching leads across that Customer’s account; it does not search other customers or delete copies already delivered elsewhere. Requests outside that flow are handled through [email protected].

Pageree will make information reasonably necessary to demonstrate compliance with this DPA available to the Customer and allow and contribute to audits, including inspections, by the Customer or its qualified independent auditor. The parties will agree reasonable notice, confidentiality, scope and security arrangements. Those arrangements must not prevent an urgent justified audit, a regulator’s powers, or an audit needed to investigate a breach or credible noncompliance. Evidence about third parties will be shared subject to lawful confidentiality restrictions.

If exceptional assistance has an additional cost, Pageree will explain and agree it in advance where lawful. Fees or commercial disputes must not delay legally required assistance or notices.

5. Subprocessors and international processing

The Customer gives general written authorization for the applicable subprocessors identified in the Subprocessor Register. Pageree will impose written data-protection obligations providing the protection required for the delegated processing and remains responsible to the Customer for its subprocessors’ performance as required by law.

Pageree will give at least 30 days’ advance notice to the Customer’s account contact before adding or replacing a subprocessor that will handle its Customer Personal Data. The Customer may raise a reasoned data-protection objection during that period. The parties will seek a reasonable solution; if none is available, the affected processing will not start for that Customer, and either party may end the affected service with a refund of unused prepaid fees for it. An urgent legal or security need may require stopping an existing service sooner, but does not authorize bypassing applicable notice or objection rights.

Processing may involve Serbia, EU infrastructure, global edge services and the countries of applicable providers. Hosting in the EU does not establish EU-only processing. Before a restricted transfer, the parties will ensure an applicable lawful transfer mechanism and any necessary assessment or supplementary measures are in place. Where required, they will execute the applicable EU standard contractual clauses, UK transfer addendum or other legally recognized terms with completed annexes. This DPA alone is not a completed transfer agreement or a claim of adequacy for Serbia.

A CRM, mailbox or independent agent chosen directly by the Customer is normally its recipient, not a Pageree-appointed subprocessor merely because Pageree sends data there on instruction. Pageree will document the destination and necessary transit providers. The Customer must assess the recipient and any applicable transfers.

6. Return, retention and deletion

Lead payloads, delivery metadata and attached consent evidence expire 30 days after capture, including delivered leads. Earlier verified erasure may shorten this period. The Customer should retrieve any records it lawfully needs before expiry; later cancellation does not restart the clock.

At the end of the processing service, Pageree will, at the Customer’s choice, return available Customer Personal Data or delete it, and delete remaining copies unless applicable law requires retention. An export request must be made before normal expiry or deletion; it does not authorize indefinite retention. Active-system deletion is due within 30 days of the closure or valid deletion instruction, subject to an earlier applicable deadline. Pageree will confirm completion on request.

Isolated backup copies expire through the approved rotation within a further 30 days after active-system deletion. They are protected from ordinary use; recovery must reapply deletion instructions before restored systems return to service. Active deletion and backup rotation can therefore take up to 60 days in total. If a binding instruction or applicable law requires earlier complete deletion, the parties must arrange it or cease the affected processing.

Any legally required retained subset will be restricted to that legal purpose, identified and periodically reviewed. Routine backup or legal-retention exceptions must not keep an entire account indefinitely. Independent recipient copies remain the responsibility of those recipients and the Customer.

7. Processing details

Subject matter and purpose
Operate Customer landing pages, capture and deliver inquiries, provide page analytics, process requested content and assets, and support and secure those activities.
Nature and frequency
Collection, transmission, storage, validation, retrieval, aggregation, publication on instruction, export and erasure. Processing occurs continuously while the Customer enables the relevant features.
Duration
The service period and the category-specific expiry and return/deletion periods. The retention schedule forms part of these instructions.
People concerned
Landing-page visitors and prospective customers, Customer personnel and contacts, and people lawfully included in Customer-provided content.
Data categories
Configured contact and inquiry fields; consent wording, choices and policy references; delivery and request metadata; page and session identifiers, URLs, referrers, device/browser and interaction data; Customer content, prompts and assets. Restricted data described in section 2 is excluded.
Customer contact
The authorized account owner or the privacy contact recorded in the accepted order. The Customer must keep this contact current.
Pageree contact
[email protected]; legal notices to [email protected].

8. Technical and organizational measures

  • HTTPS for public traffic; controlled provider and database access; protection of stored data and backup copies appropriate to their sensitivity.
  • Account-scoped access controls, password hashing, expiring authentication tokens, access revocation and limited operator access.
  • Customer pages isolated from application cookies; signed form forwarding, validation, size limits and shared abuse controls.
  • Durable lead storage before delivery, bounded delivery attempts, expiry checks, and operator pauses for publishing, intake and delivery.
  • Email verification for automated lead access/erasure, single-use confirmation credentials, explicit erasure confirmation and exclusion of privacy-request content from monitoring.
  • Provider review, confidentiality, incident and rights-request procedures, deletion records, backup recovery checks and periodic access reviews.

These are contractual operating requirements, not a certification or a representation that a named third-party audit has been completed. Production deployment and operational evidence must support them before this DPA is activated for customer processing.

9. Operator and contact

Aleksandr Shelestov PR JustOneDev
Jurija Gagarina 231, Novi Beograd, 11070 Belgrade, Serbia
PIB (tax identification number): 113504102
Registered with Serbian Business Registers Agency (APR), Register of Entrepreneurs
Business registration number (matični broj): 66872807
  • General: [email protected]
  • Support and billing: [email protected]
  • Privacy requests: [email protected]
  • Legal notices: [email protected]
  • Content reports: [email protected]

Useful pages for your next customer.

Explore all resources ↗

Guides 41

  • Create a landing page with Claude
  • Create a landing page with ChatGPT
  • Turn Claude Design into a lead-capture page
  • Create a campaign landing page with Claude Cowork
  • Build and publish a landing page with Claude Code
  • Build and publish a landing page with Codex
  • Build a landing page with Cursor and receive enquiries
  • Build and publish a landing page with Gemini CLI
  • Create a landing page with GitHub Copilot in VS Code
  • Build and publish a landing page with OpenCode
See all guides ↗

Templates 31

  • Waitlist landing page template
  • SaaS demo landing page template
  • Mobile app landing page template for launch
  • Product launch landing page template
  • Lead magnet landing page template
  • Newsletter signup landing page template
  • Webinar registration landing page template
  • Workshop landing page template for applications
  • Event RSVP landing page template
  • Consultation landing page template
See all templates ↗

Integrations 10

  • Send landing-page leads to Google Sheets
  • Send landing-page enquiries to HubSpot
  • Send landing-page quote requests to Pipedrive
  • Save landing-page enquiries in Airtable
  • Connect a landing-page signup form to Mailchimp
  • Connect a landing-page signup form to Kit
  • Send landing-page form submissions to Zapier
  • Send landing-page leads into a Make scenario
  • Trigger an n8n workflow from a landing-page form
  • Add Calendly booking to an AI-built landing page
See all integrations ↗

Prompts 4

  • Landing-page prompts for Claude and ChatGPT
  • AI prompts for landing-page copy that explains your offer
  • A SaaS landing-page prompt with a worked example
  • A small-business landing-page prompt for enquiries
See all prompts ↗

Comparisons 10

  • Carrd alternatives for a business landing page
  • Unbounce alternatives for small-business landing pages
  • Leadpages alternatives for founders using AI assistants
  • Framer alternatives for a focused lead-generation page
  • Lovable alternatives when you only need a landing page
  • Bolt alternatives for a simple business landing page
  • Wix alternatives for a single campaign landing page
  • PageSumo alternatives for publishing pages from Claude
  • ChatGPT Sites or Pageree for a business landing page?
  • AI landing page builders: a documented comparison
See all comparisons ↗

Free tools 4

  • Free landing-page prompt generator
  • Free landing-page conversion rate calculator
  • Free landing-page headline generator
  • Interactive landing-page launch checklist
See all free tools ↗
pageree

The landing-page toolkit
for your AI agent.

SuperpowersHow it worksPricingDocsPrivacy PolicyTerms of UseSupportLog in

© 2026 Pageree

Built for your next customer.Back to top ↑