Legal

Data Processing Addendum

Version 1.0 · effective 2026-07-23

SEOverts Data Processing Addendum

Effective date: July 24, 2026 Version: 1.0

This Data Processing Addendum ("DPA") forms part of, and is incorporated into, the SEOverts Terms of Service / Master Subscription Agreement (the "Agreement") between Meerkat 9000 LLC, a South Carolina limited liability company ("Processor," "SEOverts," "we," "us"), and the customer that has accepted the Agreement ("Controller," "Customer," "you"). This DPA governs the Processor's processing of Personal Data on the Controller's behalf in connection with the SEOverts Service, an SEO intelligence and ads monitoring platform.

By accepting the Agreement, the Controller enters into this DPA on behalf of itself and, to the extent required by applicable Data Protection Laws, in the name and on behalf of its authorized affiliates.

1. Definitions

Capitalized terms not defined here have the meanings in the Agreement.

  • "Controller," "Processor," "Data Subject," "Personal Data," "Processing," "Special Categories of Personal Data," and "Personal Data Breach" have the meanings given in the GDPR; where US state privacy laws apply, the equivalent terms ("business," "service provider," "consumer," "personal information," "process") apply correspondingly.
  • "Data Protection Laws" means all laws and regulations applicable to the Processing of Personal Data under the Agreement, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and applicable US state privacy laws.
  • "SCCs" means the Standard Contractual Clauses approved by the European Commission in its Implementing Decision (EU) 2021/914.
  • "UK IDTA" means the UK International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner.
  • "Sub-processor" means any third party engaged by the Processor to Process Personal Data on the Controller's behalf.
  • "Connected Account Data" means data retrieved from the Controller's connected third-party accounts (for example, Google Search Console, Google Analytics 4, Google Business Profile, PageSpeed Insights, Meta Ads, Google Ads, and TikTok Ads) via the Controller's OAuth authorizations.

2. Roles and Scope

2.1 As between the parties and with respect to Connected Account Data and any other Personal Data Processed by the Processor under the Agreement, the Controller is the controller (or business) and the Processor is the processor (or service provider). Where the Controller is itself a processor for a third party (for example, an agency managing a client's Websites), the Processor acts as a sub-processor, and references to the Controller's instructions include that third party's instructions as relayed by the Controller.

2.2 This DPA applies to the extent the Processor Processes Personal Data on the Controller's behalf in providing the Service.

2.3 Organizations and Websites. The Controller's tenant within the Service is its Organization, and Processing is organized per Website connected within that Organization. The Controller represents that it has the authority to connect each Website and each third-party account it authorizes, and this DPA covers Personal Data Processed for all Websites within the Controller's Organization.

3. Nature, Purpose, Duration, and Subject Matter of Processing

3.1 Subject matter and nature: the Processor Processes Personal Data to provide, secure, and support the Service, including retrieving, hosting, analyzing, and displaying SEO and advertising analytics data for the Controller's connected Websites (keyword rank tracking, site audits, backlink and competitor analysis, GEO/AEO/Local SEO insights, and ads monitoring and optimization for Meta Ads, Google Ads, and TikTok Ads) and sending transactional communications on the Controller's behalf. Ads budget recommendations generated by the Service are advisory only and are applied solely after the Controller's explicit approval, always within the Controller's user-set hard monthly budget cap per Website.

3.2 Purpose: to perform the Processor's obligations under the Agreement and on the Controller's documented instructions.

3.3 Duration: for the term of the Agreement and until deletion or return of Personal Data under Section 11.

3.4 The categories of Data Subjects and types of Personal Data are described in Annex I.

3.5 Limited Use. The Processor's use of information received from Google APIs (including Search Console, GA4, and Business Profile data) adheres to the Google API Services User Data Policy, including the Limited Use requirements: such data is used only to provide user-facing features of the Service, is never sold or transferred to third parties (except as necessary to provide the Service, with consent, or as required by law), is never used for advertising, and is never used to train generalized AI/ML models. Data received from Meta and TikTok platform APIs is Processed subject to those platforms' applicable data terms, which flow down to the Controller's use of the Service.

4. Processor Obligations

The Processor will:

4.1 Process only on documented instructions. Process Personal Data only on the Controller's documented instructions (including the Agreement and this DPA), and as needed to provide the Service, unless required by law (in which case the Processor will, where lawful, inform the Controller). The Processor will inform the Controller if, in its opinion, an instruction infringes Data Protection Laws.

4.2 Confidentiality. Ensure that persons authorized to Process Personal Data are bound by appropriate confidentiality obligations.

4.3 Security. Implement and maintain appropriate technical and organizational measures as described in Annex II, taking into account the state of the art, costs, and the nature, scope, context, and purposes of Processing and the risks to Data Subjects.

4.4 Assistance (Data Subject requests). Taking into account the nature of the Processing, provide reasonable assistance (including by appropriate technical and organizational measures, and the Service's export/erasure features) to enable the Controller to respond to Data Subject requests to exercise their rights.

4.5 Assistance (compliance). Provide reasonable assistance to the Controller with data-protection impact assessments, prior consultations with supervisory authorities, and security obligations, taking into account the information available to the Processor.

4.6 Personal Data Breach. Notify the Controller without undue delay after becoming aware of a Personal Data Breach affecting the Controller's Personal Data, and provide information reasonably available to assist the Controller in meeting its breach-notification obligations. Notifications will be sent to the Controller's designated contact.

4.7 Records. Maintain records of its Processing activities as required by Article 30(2) of the GDPR.

5. Sub-processors

5.1 General authorization. The Controller grants the Processor general authorization to engage Sub-processors to Process Personal Data, subject to this Section. The Processor's current Sub-processors are listed in Annex III and in the public Sub-processor List.

5.2 Obligations flow-down. The Processor will impose data-protection obligations on each Sub-processor that are no less protective than those in this DPA and will remain liable to the Controller for its Sub-processors' performance.

5.3 Change notice and objection. The Processor will provide notice of the addition or replacement of a Sub-processor (for example, by updating the Sub-processor List and offering a subscription to updates). The Controller may object on reasonable data-protection grounds within thirty (30) days of notice. The parties will work in good faith to resolve the objection; if they cannot, the Controller may, as its sole remedy, terminate the affected portion of the Service.

6. International Data Transfers

6.1 The Processor will not transfer Personal Data outside the EEA, the UK, or Switzerland except in accordance with this Section and Data Protection Laws.

6.2 SCCs. Where the Processor Processes EEA-originating Personal Data in a country without an adequacy decision, the SCCs are incorporated into this DPA by reference and apply, with Module Two (Controller-to-Processor) (or Module Three (Processor-to-Processor) where the Controller is itself a processor). The Annexes to the SCCs are populated by Annex I, Annex II, and Annex III of this DPA. In the SCCs: the Controller is the "data exporter" and the Processor is the "data importer"; the optional docking clause applies; the supervisory authority and the governing-law/forum options are completed in accordance with Section 6.5.

6.3 UK transfers. For UK-originating Personal Data, the UK IDTA (or the UK Addendum to the SCCs) is incorporated by reference and amends the SCCs as required for UK law.

6.4 Swiss transfers. For Swiss-originating Personal Data, the SCCs apply with amendments to refer to the Swiss FADP and the Swiss Federal Data Protection and Information Commissioner.

6.5 To the extent the SCCs offer options, the parties select: clause 7 (docking): included; clause 9: Option 2 (general written authorization), with the change-notice period in Section 5.3; clause 11 (independent dispute resolution): not selected; clause 17 governing law: Ireland (or, for UK/Swiss, as required by the IDTA/Swiss amendments); clause 18 forum: the courts of Ireland (or as required). Where the parties' Agreement otherwise specifies governing law, that choice applies only to the extent permitted by the SCCs.

7. Controller Obligations

7.1 The Controller will: (a) comply with Data Protection Laws as a controller; (b) establish and document a lawful basis for the Processing it instructs; (c) provide all required notices to and obtain all required consents from Data Subjects (including visitors to and customers of its connected Websites, where their Personal Data appears in Connected Account Data); (d) ensure it has the authority to connect each Website and third-party account it authorizes; and (e) ensure its instructions are lawful. The Controller is responsible for the accuracy, quality, and legality of the Personal Data and the means by which it acquired it, and for its own compliance with the terms of the third-party platforms it connects.

8. Special Categories of Data

8.1 The Service is not designed to Process Special Categories of Personal Data. The analytics and advertising data the Service retrieves is predominantly aggregate or pseudonymous; the Controller will not submit or configure the Service to retrieve Special Categories of Personal Data except where strictly necessary and lawful, and is solely responsible for any additional safeguards required, including a valid Article 9 condition where applicable.

9. Audit Rights

9.1 The Processor will make available to the Controller information reasonably necessary to demonstrate compliance with this DPA and Article 28 of the GDPR, and will allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates. To minimize disruption, the Processor may satisfy audit requests by providing existing reports, certifications, or summaries of its security measures. Any on-site audit will be on reasonable prior written notice, no more than once per year (absent a Personal Data Breach or regulator requirement), during business hours, subject to confidentiality, and at the Controller's expense.

10. Liability

10.1 Each party's liability under or in connection with this DPA is subject to the exclusions and limitations of liability set out in the Agreement (including the limitation-of-liability section). Nothing in this DPA limits liability that cannot be limited under Data Protection Laws, including liability to Data Subjects under the SCCs.

11. Deletion or Return of Personal Data

11.1 Upon termination or expiry of the Agreement, and at the Controller's choice, the Processor will delete or return the Personal Data it Processes on the Controller's behalf and delete existing copies, except to the extent retention is required by law. The Service's export and erasure features and the Processor's time-bound retention/erasure practices implement this Section. OAuth tokens for connected accounts are deleted upon disconnection of the relevant integration.

12. Order of Precedence

12.1 In the event of a conflict between this DPA and the Agreement regarding the Processing of Personal Data, this DPA prevails. In the event of a conflict between this DPA and the SCCs, the SCCs prevail with respect to the transfers they govern.


Annex I: Description of Processing

A. List of Parties

  • Data exporter / Controller: the Customer that accepted the Agreement; contact: the Organization owner/administrator and billing contact on file. Activities: operating one or more Websites and using the Service for SEO intelligence and ads monitoring. Role: controller.
  • Data importer / Processor: Meerkat 9000 LLC, [Address], South Carolina, USA; contact: privacy@getseoverts.com / dpo@getseoverts.com. Activities: providing the SEOverts Service. Role: processor.

B. Description of Transfer / Processing

  • Categories of Data Subjects: the Controller's members and authorized users; and, to the extent present in Connected Account Data, visitors to and customers of the Controller's connected Websites (for example, individuals reflected in GA4 analytics, Google Business Profile reviews, or ads audience metrics).
  • Categories of Personal Data: account data of members and authorized users (name, email address, role); OAuth tokens and account identifiers for connected third-party accounts; Connected Account Data, including website analytics data (largely aggregate or pseudonymous), search performance data, business-profile data (which may include reviewer names and review content), and advertising performance and audience metrics; SEO data associated with the Controller's Websites (keyword rankings, backlinks, site-audit results, competitor data); and billing contact details.
  • Special categories: none intended; see Section 8.
  • Frequency of Processing: continuous, for the duration of the Agreement.
  • Nature and purpose: retrieval, hosting, storage, analysis, display, and support of SEO and advertising analytics data; generating recommendations (applied only after explicit Controller approval and within the Controller's budget caps); sending transactional communications; security and abuse prevention.
  • Retention: for the term and per Section 11 and the Processor's retention practices. OAuth tokens are encrypted at rest and deleted upon disconnection of the relevant integration. Google user data is Processed subject to the Limited Use requirements described in Section 3.5.
  • Sub-processors: see Annex III.

C. Competent Supervisory Authority: determined in accordance with the SCCs and the Controller's establishment (for EEA transfers) and the ICO (for UK) / FDPIC (for Switzerland).

Annex II: Technical and Organizational Security Measures

The Processor maintains measures designed to ensure a level of security appropriate to the risk, including:

  • Access control & least privilege: role-based access; organization-scoped authorization with per-Website scoping; tenant isolation enforced in the application and reinforced by database row-level security; default-deny access.
  • Authentication: managed identity provider; hashed credentials; session and CSRF protections; OAuth connections established only with the Controller's explicit authorization.
  • Encryption: encryption of data in transit (TLS); encryption at rest at the infrastructure layer; OAuth tokens additionally encrypted at rest with AES-256-GCM and deleted on disconnect.
  • Network & application security: edge protections and content-security policies; strict origin/CORS validation; rate limiting and abuse controls; bot protection on sensitive flows.
  • Secrets management: secrets kept out of client bundles and source control; environment-validated configuration.
  • Logging & monitoring: centralized error monitoring (PII-scrubbed), audit logging of sensitive actions (identifiers only), and health/readiness probes.
  • Data minimization & retention: collection limited to the analytics and advertising data needed to provide the Service; time-bound retention and erasure practices; Google user data handled under Limited Use (Section 3.5).
  • Resilience & backups: managed, redundant infrastructure with backup and recovery capabilities.
  • Personnel: confidentiality obligations; access on a need-to-know basis.
  • Vendor management: Sub-processors bound by equivalent obligations (Section 5).
  • Incident response: breach detection and a process to notify the Controller without undue delay (Section 4.6).

Annex III: Authorized Sub-processors

The Processor's current Sub-processors are maintained in the public Sub-processor List. As of the effective date, they include:

Sub-processorPurposeLocation
SupabaseDatabase, authentication, storageUnited States
StripePayments and subscription billingUnited States
CloudflareHosting, CDN, edge computeGlobal
ResendTransactional emailUnited States
UpstashQueues and rate limitingUnited States
SentryError monitoringUnited States
DataForSEOSEO data provider (SERP, keyword, and backlink data)United States
Google APIsSearch Console, GA4, Business Profile, PageSpeed, Google Ads integrationsUnited States / Global
Meta APIsMeta Ads integrationUnited States / Global
TikTok APIsTikTok Ads integrationUnited States / Global

Changes are communicated as described in Section 5.3 and the Sub-processor List.