SEO Actions
Data Processing Agreement
Last updated: August 15, 2026
Effective date: August 15, 2026
1. Parties, effectiveness, and incorporation
This Data Processing Agreement (“DPA”) forms part of the Terms, order, or agreement between the customer identified in the account or order (“Customer”) and the person or entity operating SEO Actions and identified as provider in the order, invoice, or receipt (“SEO Actions”). It applies when SEO Actions processes Customer Data for Customer and lasts while that processing continues.
Customer enters this DPA for itself and, where applicable, authorized affiliates. Electronic acceptance of the Terms or use of the Service incorporates this DPA unless the parties sign a different one.
2. Definitions and roles
“Customer Data” means personal data SEO Actions processes for Customer through the Service. “Data Protection Laws” means applicable law, including Mexico's LFPDPPP, GDPR/UK GDPR, and CCPA/CPRA where relevant. Controller, processor, business, service provider, process, and data subject have their meanings under applicable law.
Customer is controller and SEO Actions is processor. If Customer is itself a processor, SEO Actions is a subprocessor. Each party independently controls data processed for its own account, billing, security, or business-relationship purposes.
3. Instructions and Customer duties
SEO Actions will process Customer Data only to provide, secure, support, and maintain the Service under the agreement, settings, requests, and other documented instructions, unless law requires otherwise. Where permitted, we will disclose that legal requirement first and notify Customer if an instruction appears unlawful.
Customer warrants that its instructions, collection, and transfers are lawful; required notices and consents exist; connected accounts are authorized; and data is minimized. The Service is not designed for sensitive, children's, health, full payment-card, biometric, or criminal data; processing it requires written agreement and additional safeguards.
4. Confidentiality and authorized personnel
SEO Actions limits access to personnel and contractors who need it for their duties. Those persons are bound by confidentiality commitments or equivalent legal duties and receive appropriate security and privacy instructions.
5. Security
SEO Actions will maintain appropriate technical and organizational measures considering state of the art, cost, nature, scope, context, purposes, and risk. Current measures appear in Annex B. Implementation may evolve without materially reducing the Service's overall protection.
6. Subprocessors
Customer gives general authorization to use the subprocessors in Annex C and others needed for enabled features. SEO Actions will impose substantially equivalent protection duties and remain responsible for their performance to the extent required by law.
We will provide notice of material changes through the Service, this page, email, or a list available on request. Customer may object on reasonable data-protection grounds within 10 days. The parties will seek a reasonable alternative; if none exists, Customer may stop using and terminate the affected feature without future penalty.
7. Data-subject rights and compliance
Considering the nature of processing, SEO Actions will reasonably assist with access, correction, cancellation, objection, deletion, restriction, and portability requests. If we directly receive a request concerning Customer Data, we will refer it to Customer unless legally prohibited.
We will also provide reasonable information and assistance for impact assessments, authority consultations, and security duties. Assistance beyond standard features may be charged at reasonable rates unless caused by SEO Actions' breach.
8. Personal Data Incidents
SEO Actions will notify Customer without undue delay after confirming a Customer Data breach. As available, notice will describe nature, approximate categories and volume, likely consequences, measures taken, and contact point. Information may be provided in phases. Notice is not an admission of fault.
Customer determines whether notice to individuals or authorities is required unless law directly assigns that duty to SEO Actions.
9. Return and deletion
During the term, Customer may use available export features. After Service termination and upon Customer's request or choice, SEO Actions will delete or return data within a reasonable period unless law requires retention. Backups are isolated and expire in ordinary cycles; while retained, they remain protected and unused for other purposes.
10. Information and audits
SEO Actions will provide information reasonably needed to demonstrate compliance. Available questionnaires, reports, or independent evidence will be used first. If insufficient, Customer may request one audit per 12 months with 30 days' notice, during business hours, by an independent auditor under confidentiality, without accessing other customers' data or harming security or operations.
Customer bears reasonable costs unless the audit finds SEO Actions materially noncompliant. Additional audits are allowed when required by a competent authority or after a material incident.
11. International transfers
Where an EEA Customer Data transfer to a non-adequate country needs safeguards, the Standard Contractual Clauses in Decision (EU) 2021/914 are incorporated by reference: Module Two (controller-to-processor) or Module Three (processor-to-subprocessor), as applicable. Ireland law and courts apply where an option is required; the competent authority is determined under Clause 13. This DPA's Annexes complete the SCC Annexes, and the SCCs control any conflict.
For the UK, the current international data-transfer addendum issued by the UK authority applies where relevant. For Mexico and other jurisdictions, the parties will use the applicable lawful mechanism and reasonable supplementary measures.
12. CCPA/CPRA
For personal information subject to CCPA/CPRA, SEO Actions acts as service provider or contractor. It will not sell or share the information, retain, use, or disclose it outside the agreement's specified business purposes, combine it except as legally permitted, or use it for cross-context behavioral advertising. Customer may take reasonable steps to verify compliance and stop unauthorized use. SEO Actions will notify Customer if it can no longer comply.
13. Liability, conflict, and termination
Liability under this DPA is subject to the main agreement's exclusions and limits unless applicable law or the SCCs prohibit that limit. If terms conflict, this DPA controls processing matters; the SCCs control within their scope. Duties intended to survive continue after termination.
Annex A — Processing details
- Subject and purpose: provide, secure, support, and maintain SEO Actions features configured by Customer.
- Duration: Service term plus limited export, backup, blocking, or legally required retention.
- Operations: collection, access, organization, storage, analysis, generation, transformation, transmission, retrieval, instructed publication, export, deletion, and anonymization.
- Data subjects: users, personnel, customers, prospects, visitors, authors, contacts, and others whose data Customer includes.
- Data: identifiers, contact, professional profile, usage, device, content, communications, web data, protected connection credentials/tokens, and authorized analytics or publishing data.
- Sensitive data: not intended. Only by written agreement, demonstrated need, and additional safeguards.
- Frequency: continuous or on demand, based on Customer use and automations.
Annex B — Technical and organizational measures
- Need-based access management, authentication, and least-privilege permissions.
- Secret and token protection; encryption in transit and at rest where infrastructure provides it.
- Logical account/project separation and server-side controls for sensitive operations.
- Logging, monitoring, vulnerability management, updates, and incident response.
- Backup, recovery, and continuity proportionate to the Service and infrastructure provider.
- Development review, testing, change control, and data minimization in logs and analytics.
- Contractual vendor assessment, personnel confidentiality, and deletion or anonymization when no longer needed.
Annex C — Current subprocessors
Depending on configuration and used features: Clerk (identity/authentication), Convex (database/storage), Vercel (hosting, network, storage, analytics, workflows, and AI infrastructure), Sentry (errors/observability), Resend (email), model providers selected through AI Gateway (inference), Apify (extraction/audits), and DataForSEO (SEO metrics). Customer-selected integrations receive data as instructed recipients and their own terms also apply.
Privacy contact
DPA-related requests: support@seoactions.com.