Data Processing Agreement

Last updated: 2026-09-15

Draft — not yet finalized. This document is a starting point adapted to this platform's actual behavior (credits, refunds, data handling), not a template pasted in unedited. It still needs the operator's finalized business/registration details filled in and a legal review before this is relied on as a binding agreement.

This Data Processing Agreement ("DPA") applies when you (the "Customer", acting as data controller) use SEO Analyzer to process personal data belonging to your own clients or end users (for example, running site audits or reports that include your client's data). SEO Analyzer (operated by ITTechLux — see the Legal Notice for the operator's current legal status) acts as data processor for that data, under Art. 28 GDPR.

For personal data about you (the Customer) that we process directly as controller — your own account and billing data — see the Privacy Policyinstead; this page only covers data you submit about your own clients.

1. Subject matter and duration

Processing covers any personal data contained in URLs, page content, or other input you submit for analysis on behalf of a client, for the duration of your subscription plus any retention period described in the Privacy Policy.

2. Nature and purpose

Processing is limited to what's needed to generate the reports and analysis you request — crawling, analysis (including by third-party LLM providers, see below), and report generation/storage.

3. Sub-processors

Sub-processors used to deliver the service are listed in the Privacy Policy's Sub-processors section (payment processing, LLM provider, email delivery, hosting). [PLACEHOLDER: confirm whether this DPA should list sub-processors here explicitly instead of by reference, and whether advance notice of sub-processor changes is required — standard practice for a DPA aimed at business customers.]

4. Customer obligations

You are responsible for having a lawful basis to submit your client's data for processing (e.g. your own contract or legitimate interest basis with that client), and for responding to your client's own data-subject requests — we provide the export/delete tools described in the Privacy Policy to support that.

5. Security measures

[PLACEHOLDER: describe actual security measures in production — encryption at rest for stored credentials (already implemented, see credentials-encryption.md), access controls, backup/disaster-recovery posture (see the database disaster-recovery runbook) — needs review to confirm this is accurate and complete enough for a business customer's due diligence.]

6. International transfers

[PLACEHOLDER: confirm where sub-processors (LLM provider, hosting, email) are located and what transfer mechanism applies (SCCs, adequacy decision) if any are outside the EU/EEA — needs legal review.]

7. Requesting a signed DPA

If you need a countersigned copy of this DPA for your own compliance records, contact hello@seoanalyzer.app.