Data Processing
Last updated: July 6, 2026
Purpose of This Page
This page explains how Uncited Brands handles data in the course of client engagements, separate from how we handle personal information collected through this website (covered in our Privacy Policy). It is written for clients and prospective clients who need to understand our data practices for their own compliance review, and it is not itself a signed legal agreement.
If your organization requires a formal, signed Data Processing Agreement as part of onboarding us as a vendor, we’re glad to put one in place. Contact hello@uncitedbrands.com and we’ll send our standard DPA for review.
Roles and Responsibilities
In most engagements, the data we work with is business and marketing data: your website content, product and pricing information, competitor names, buyer question sets, and citation and ranking data from public AI answer engines and search results. This is generally not personal data about identifiable individuals.
Where an engagement does involve personal data, such as if you grant us access to your analytics platform, CRM, or review management tool that contains customer names or contact details, you act as the data controller (or business, under CCPA terminology) for that data, and we act as a processor (or service provider), handling it only to perform the services you’ve asked for and only according to your instructions.
Categories of Data We May Process
Depending on the scope of your engagement, this can include: content and structured data from your website, product and company information you provide directly, third-party citation, review, and ranking data pulled from public sources, and, where you grant access, data from your own analytics, Search Console, CRM, or review platforms. We do not require or request sensitive personal data such as health, financial account, or government ID information to perform AEO work, and we ask that access be scoped to what the engagement actually needs.
Sub-processors and Tools We Use
We rely on a small set of third-party tools to run the business and deliver engagements, including our website hosting provider, any project management or communication tools we use to coordinate with you, and, where applicable, email delivery services. We select vendors with reasonable security practices and only share the data with them that’s needed to provide their service to us. A current list of sub-processors is available on request.
Security Measures
We limit access to client systems and data to the team members actually working on your engagement, use unique credentials rather than shared logins wherever the platform allows it, and remove our access promptly at the end of an engagement unless you ask us to retain it for ongoing work.
International Transfers
Uncited Brands and our hosting infrastructure are based in the United States. If your organization is based outside the United States and applicable law requires a specific transfer mechanism (such as Standard Contractual Clauses under GDPR) before we can process data on your behalf, let us know during onboarding and we will put the appropriate mechanism in place as part of a signed DPA.
Data Subject Requests
If we receive a request from one of your customers or employees to access, correct, or delete their data, and that data is part of your systems rather than ours, we will forward the request to you promptly so you can respond as the controller. We will assist you in fulfilling such requests where our systems hold relevant data on your behalf.
Retention and Deletion
At the end of an engagement, we remove our direct access to your systems and delete locally stored copies of client data we no longer need for accounting, legal, or agreed reference purposes, typically within 90 days of the engagement ending, unless you ask us to delete it sooner or a signed DPA specifies a different timeline.
Contact
Questions about our data processing practices, or requests for our standard Data Processing Agreement, can be sent to hello@uncitedbrands.com.