Legal

GDPR Compliance

Last updated: June 2026

Our Commitment

LocalSites.Dev is committed to protecting the privacy and rights of individuals in the European Economic Area (EEA) and the United Kingdom. This page explains how we comply with the General Data Protection Regulation (GDPR) and outlines the specific rights available to you under that regulation.

Our Role Under GDPR

When we are the data controller

We act as the data controller when we collect and process your personal data for our own purposes, such as:

  • Managing your LocalSites.Dev account
  • Processing your subscription payments
  • Sending you service-related communications
  • Analyzing platform usage to improve the Service

When we are the data processor

When you use LocalSites.Dev to build a website that collects information from your own visitors (for example, through a contact form), you are the data controller and we act as the data processor. In that role, we process visitor data strictly on your behalf and according to your instructions.

Legal Bases for Processing

We process personal data under the following legal bases:

  • Contract performance: Processing necessary to provide the Service you subscribed to (account management, website hosting, payment processing).
  • Legitimate interest: Processing necessary for our legitimate business interests, such as improving the platform, preventing fraud, and ensuring security. We balance these interests against your rights and freedoms.
  • Consent: Where required, such as for analytics cookies and marketing communications. You can withdraw consent at any time.
  • Legal obligation: Processing required to comply with applicable laws, such as tax record-keeping and responding to lawful government requests.

Your Rights Under GDPR

If you are in the EEA or UK, you have the following rights regarding your personal data:

  • Right of access: You can request a copy of the personal data we hold about you, along with information about how we use it.
  • Right to rectification: You can ask us to correct any inaccurate or incomplete data. You can also update most information directly from your admin dashboard.
  • Right to erasure: You can ask us to delete your personal data. We will comply unless we have a legal obligation to retain it (such as billing records).
  • Right to restrict processing: You can ask us to limit how we use your data while a dispute or request is being resolved.
  • Right to data portability: You can request your data in a structured, commonly used, machine-readable format (JSON or CSV).
  • Right to object: You can object to processing based on legitimate interest. We will stop processing unless we have compelling grounds that override your rights.
  • Right to withdraw consent: Where processing is based on consent, you can withdraw it at any time. This does not affect the lawfulness of processing done before withdrawal.
  • Right to lodge a complaint: You have the right to file a complaint with your local data protection authority if you believe your rights have been violated.

Exercising Your Rights

To exercise any of these rights, email privacy@localsites.dev with the subject line “GDPR Request.” We will verify your identity and respond within 30 days. If your request is complex, we may extend this by an additional 60 days with notice.

There is no fee for exercising your rights. However, if requests are manifestly unfounded or excessive, we may charge a reasonable administrative fee or decline the request.

International Data Transfers

LocalSites.Dev is based in the United States. If you are in the EEA or UK, your data is transferred to and processed in the United States. We protect these transfers through:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Ensuring our sub-processors (such as Railway for hosting and Stripe for payments) maintain adequate safeguards for international transfers
  • Implementing technical and organizational measures to protect data during and after transfer

Sub-Processors

We use the following sub-processors to deliver the Service:

  • Railway (United States) — Application and database hosting
  • Stripe (United States) — Payment processing
  • MiniMax — AI content generation
  • Google Analytics (United States) — Website analytics

We will notify you if we add or change sub-processors that handle personal data. You may object to a new sub-processor by contacting us within 30 days of notification.

Data Protection Officer

For GDPR-related inquiries, you can reach our data protection contact at dpo@localsites.dev.

Data Processing Agreement

If you need a Data Processing Agreement (DPA) for your records, contact legal@localsites.dev and we will provide one. Agency-tier customers receive a DPA as part of their onboarding.