Data Processing Addendum (DPA)

Version: 2026-06-19 · Effective: 21 June 2026

This DPA forms part of our Terms of Service and governs our role as processor of personal data on your behalf when you use the Service.

1. Scope

You are the controller of personal data you submit (e.g. team member emails, customer site visitors via GA4/GSC). We are the processor.

2. Instructions

We process personal data only to deliver the Service as described in our Privacy Policy and Terms. We don't use your data for any other purpose without your consent.

3. Sub-processors (with locations)

Sub-processorPurposeLocation
Microsoft (Graph)Transactional email + Bing APIEU / US
GoogleGSC, GBP, GA4, PSI APIsEU / US
PayfastPayment processingSouth Africa
CloudflareTLS / DDoS / CDNGlobal edge
ElitehostApplication hostingSouth Africa
SerpApiCompetitor search-result scraping, keyword-rank trackingUS
OpenPageRank (Domcop)Competitor domain-authority scoringUS
Anthropic (Claude)AI-visibility citation checks (see §3a)US
OpenAI (ChatGPT)AI-visibility citation checks (see §3a)US
Google (Gemini)AI-visibility citation checks (see §3a)US
PerplexityAI-visibility citation checks (see §3a)US
Wikimedia FoundationBrand-entity verification (public Wikipedia/Wikidata API, read-only)US

Adding a new sub-processor: we'll email controllers 30 days before going live. You may object, in which case we'll work with you to find an alternative (or you may terminate).

3a. LLM providers & data retention

The four LLM providers above receive only your tracked search queries and your own site's domain/brand name — never your customers' personal data, invoices, or account credentials — for the sole purpose of checking whether your brand is cited in AI-generated answers. We send API traffic to each provider's standard API tier (not their free consumer chat products), which each provider's own current terms state is not used to train their models. We have not signed a separate enterprise zero-retention agreement with any of the four providers as of this version of this document; if you need that level of contractual assurance, contact [email protected] before enabling AI-visibility tracking on your account.

4. Security measures

HTTPS, AES-256 at rest for secrets, password hashing (Argon2), 2FA, IP allowlisting on the Payfast webhook, append-only audit log enforced at the database level, signed handshake for the WP plugin.

5. Sub-processor transfers (POPIA / GDPR)

International transfers to Microsoft, Google, and Cloudflare are covered by Standard Contractual Clauses and equivalent legal safeguards.

6. Breach notification

If we discover a personal data breach affecting your data, we will notify you without undue delay (target: 72 hours), with detail of scope, impact, and our response.

7. Data subject requests

If a data subject contacts us directly, we'll route the request to you within 5 business days. You're responsible for the response.

8. Return / deletion on termination

On account closure you have 30 days to export. After that we delete personal data within 90 days, except where law requires longer retention (e.g. invoices).

9. Contact

For DPA queries: [email protected].

← Back to home