Data Processing Agreement (DPA)
Version 2.1 · Last updated: July 8, 2026
This is an English translation of our Dutch data processing agreement (Verwerkersovereenkomst), provided for your convenience. The Dutch original is the legally binding version. In case of any discrepancy between this translation and the Dutch original, the Dutch version prevails. Read the Dutch version.
This data processing agreement ("DPA") forms part of the agreement between Gung Ho B.V., trading as SEOwriters ("Processor"), and the customer using the service ("Controller" or "you"). The DPA governs the processing of personal data that SEOwriters carries out on your behalf in connection with the SEOwriters platform. In the event of a conflict between this DPA and the agreement, this DPA prevails for matters concerning the processing of personal data.
1. Definitions
Terms such as "personal data", "processing", "data subject", "controller", "processor", "subprocessor" and "data breach" have the meaning given to them by the General Data Protection Regulation (GDPR).
2. Subject matter, nature and purpose of the processing
SEOwriters processes personal data exclusively for the purpose of the agreed service: generating, publishing and reporting on SEO content for your website(s), including retrieving performance data from your connected sources. The nature of the processing includes collecting, storing, consulting, analyzing and deleting data. No profiling takes place and no automated decision-making with legal effect.
3. Duration
This DPA applies for as long as the agreement runs. Processing ends upon termination of the agreement, with a run-off period of a maximum of 30 days for deletion or return (see article 13).
4. Categories of personal data and data subjects
Categories of personal data:
- aggregated visitor data from your website (via Google Analytics 4);
- search and performance data (via Google Search Console);
- author and account data within your WordPress installation used for publishing;
- email addresses you link to transactional communication.
Categories of data subjects: visitors to your website and registered users of your WordPress installation.
No special categories of personal data (Art. 9 GDPR) are processed. If you nevertheless provide us with such data, you do so at your own responsibility.
5. Instructions and lawful basis
SEOwriters processes personal data solely on the basis of your written instructions, including the instructions contained in the agreement and this DPA. If SEOwriters believes an instruction conflicts with the GDPR or other legislation, it will report this. SEOwriters does not process the data for its own purposes.
You warrant that you have a lawful basis for the processing of the data you make available to us or have connected, and that you are authorized to connect the relevant Google and WordPress accounts.
6. Confidentiality
SEOwriters obliges the persons who have access to the personal data to maintain confidentiality and grants access only to employees with an operational need.
7. Security (Art. 32 GDPR)
SEOwriters takes appropriate technical and organizational measures to ensure a level of security appropriate to the risk. These measures are set out in Annex 3 and include, among other things, encryption of credentials and tokens, encryption in transit and at rest, need-based access restriction, and audit logging.
8. Subprocessors
You hereby give general authorization for the engagement of the subprocessors listed in Annex 2. SEOwriters imposes the same obligations on each subprocessor as set out in this DPA. In the event of an intended change (addition or replacement), SEOwriters will inform you at least 30 days in advance, so you can raise an objection. If you raise a reasoned objection and the parties cannot reach agreement, you may terminate the agreement for the affected component.
9. Assistance to the controller
SEOwriters provides you with reasonable assistance with:
- handling requests from data subjects (access, rectification, erasure, restriction, objection, data portability);
- fulfilling your obligations in the event of data breaches (Art. 33-34 GDPR);
- data protection impact assessments (DPIAs, Art. 35) and prior consultation (Art. 36), to the extent relevant to the service.
If SEOwriters receives a request directly from a data subject, it will refer that request to you and will not handle it independently.
10. Data breaches
SEOwriters informs you without undue delay and no later than within 48 hours after becoming aware of a data breach that (also) concerns your data, with the information you need to comply with your reporting obligation. Assessing and reporting to the Dutch Data Protection Authority and data subjects remains your responsibility as controller.
11. International transfers
SEOwriters does not transfer personal data outside the EEA unless under appropriate safeguards within the meaning of Chapter V GDPR: the European Commission's Standard Contractual Clauses and/or certification under the EU-US Data Privacy Framework. The relevant subprocessors and safeguards are listed in Annex 2.
12. Audits
At your reasonable request, SEOwriters makes available the information needed to demonstrate compliance with this DPA, and cooperates with audits, including inspections, carried out by you or an independent auditor authorized by you. Parties will agree in advance on frequency, scope and costs, with due regard for the continuity and security of the service.
13. Return and deletion after termination
After termination of the agreement, SEOwriters deletes the personal data within 30 days, or returns it to you, at your choice, unless legislation requires longer retention.
14. Liability
The liability of the parties under this DPA is governed by the liability provisions in the agreement, without prejudice to mandatory law.
15. Governing law
This DPA is governed by Dutch law. Disputes will be submitted to the competent court of the District Court of Amsterdam (rechtbank Amsterdam).
Annex 1: Details of the processing
- Subject matter: processing of personal data for the purpose of automated SEO content, publication and reporting.
- Duration: term of the agreement + a maximum of 30 days run-off.
- Nature and purpose: collecting, storing, analyzing, publishing and deleting for the purpose of the service.
- Type of personal data: see article 4.
- Categories of data subjects: see article 4.
Annex 2: Subprocessors
| Party | Service | Data location | Safeguard |
|---|---|---|---|
| Supabase | Database hosting (PostgreSQL) | EU (Frankfurt) | EU region; SCCs (US parent) |
| Google Cloud | Application hosting (Cloud Run) | EU (europe-west1, Belgium) | EU region; SCCs + DPF |
| Google (Gemini API) | AI content generation | EU / US | SCCs + DPF |
| Google (Search Console / Analytics API) | Access to your connected data | EU / US | SCCs + DPF |
| Anthropic (Claude API) | AI text generation (advisory engine) and a second, independent quality check on medical/financial/legal content (YMYL) | US | SCCs + DPF |
| Pexels (Canva Germany GmbH) | Image fallback for missing product photos | Worldwide (EU parent company) | SCCs |
| DataForSEO | Keyword and backlink enrichment (SEO data: keywords/domains, no visitor personal data) | US | SCCs |
| Vercel | Frontend hosting and CDN | US + worldwide CDN | SCCs + DPF |
| Resend | Transactional email | US | DPF + SCCs |
| Sentry | Error monitoring (anonymized) | EU region | SCCs (US parent) |
| n8n | Workflow automation | EU (own server) | No transfer outside the EEA |
| OpenAI (conditional: only once GEO monitoring is enabled for your site) | AI visibility measurement: how your content appears in AI answers | US | SCCs + DPF |
| Perplexity (conditional: only once GEO monitoring is enabled for your site) | AI visibility measurement: how your content appears in AI answers | US | SCCs + DPF |
OpenAI and Perplexity are only engaged for a site once you enable GEO monitoring (AI visibility) for that site. If GEO monitoring is off, neither party processes your data.
Annex 3: Technical and organizational measures (TOMs)
- Encryption of credentials: OAuth tokens and WordPress Application Passwords are stored encrypted with a key derived per customer (Fernet + HKDF).
- Encryption in transit and at rest: all connections via TLS; database encrypted at rest (EU-Frankfurt).
- Access management: access to production systems solely on the basis of operational need, recorded in an audit log.
- Data minimization: Google connections use read-only scopes only; no more data is processed than necessary.
- Per-customer separation: data is logically separated per customer.