Data Processing Addendum (DPA)
Version: 2026-06-19 · Effective: 21 June 2026
This DPA forms part of our Terms of Service and governs our role as processor of personal data on your behalf when you use the Service.
1. Scope
You are the controller of personal data you submit (e.g. team member emails, customer site visitors via GA4/GSC). We are the processor.
2. Instructions
We process personal data only to deliver the Service as described in our Privacy Policy and Terms. We don't use your data for any other purpose without your consent.
3. Sub-processors (with locations)
| Sub-processor | Purpose | Location |
|---|---|---|
| Microsoft (Graph) | Transactional email + Bing API | EU / US |
| GSC, GBP, GA4, PSI APIs | EU / US | |
| Payfast | Payment processing | South Africa |
| Cloudflare | TLS / DDoS / CDN | Global edge |
| Elitehost | Application hosting | South Africa |
| SerpApi | Competitor search-result scraping, keyword-rank tracking | US |
| OpenPageRank (Domcop) | Competitor domain-authority scoring | US |
| Anthropic (Claude) | AI-visibility citation checks (see §3a) | US |
| OpenAI (ChatGPT) | AI-visibility citation checks (see §3a) | US |
| Google (Gemini) | AI-visibility citation checks (see §3a) | US |
| Perplexity | AI-visibility citation checks (see §3a) | US |
| Wikimedia Foundation | Brand-entity verification (public Wikipedia/Wikidata API, read-only) | US |
Adding a new sub-processor: we'll email controllers 30 days before going live. You may object, in which case we'll work with you to find an alternative (or you may terminate).
3a. LLM providers & data retention
The four LLM providers above receive only your tracked search queries and your own site's domain/brand name — never your customers' personal data, invoices, or account credentials — for the sole purpose of checking whether your brand is cited in AI-generated answers. We send API traffic to each provider's standard API tier (not their free consumer chat products), which each provider's own current terms state is not used to train their models. We have not signed a separate enterprise zero-retention agreement with any of the four providers as of this version of this document; if you need that level of contractual assurance, contact [email protected] before enabling AI-visibility tracking on your account.
4. Security measures
HTTPS, AES-256 at rest for secrets, password hashing (Argon2), 2FA, IP allowlisting on the Payfast webhook, append-only audit log enforced at the database level, signed handshake for the WP plugin.
5. Sub-processor transfers (POPIA / GDPR)
International transfers to Microsoft, Google, and Cloudflare are covered by Standard Contractual Clauses and equivalent legal safeguards.
6. Breach notification
If we discover a personal data breach affecting your data, we will notify you without undue delay (target: 72 hours), with detail of scope, impact, and our response.
7. Data subject requests
If a data subject contacts us directly, we'll route the request to you within 5 business days. You're responsible for the response.
8. Return / deletion on termination
On account closure you have 30 days to export. After that we delete personal data within 90 days, except where law requires longer retention (e.g. invoices).
9. Contact
For DPA queries: [email protected].