This Data Processing Agreement ("DPA") applies where AutomateSEO processes personal data on your behalf. It satisfies Article 28(3) of the UK GDPR and the EU GDPR and is incorporated into the Terms of Service.
You do not need to sign this. It takes effect automatically when you use the Service. If your procurement process requires a countersigned copy, email privacy@automateseo.app with your entity details and we will return a signed PDF, normally within 2 business days.
Parties
- Processor: Darran Goulding, a sole trader established in the United Kingdom, trading as Digital Visibility and as AutomateSEO, of 235 Peniel Green Road, Llansamlet, Swansea, Wales, SA7 9BA, United Kingdom ("we", "us").
- Controller: the customer entity that holds the AutomateSEO account ("you").
1. Scope and roles
1.1 In relation to Customer Personal Data (defined in 1.3), you are the controller and we are the processor. Where you are yourself a processor acting for another controller — for example an agency running the platform for a client — we are a sub-processor, and you confirm you have authority to appoint us and to give the instructions in this DPA.
1.2 In relation to data about your own account — your administrator names, billing contacts, login records and usage telemetry — we act as an independent controller for the purposes set out in our Privacy Policy. This DPA does not apply to that data.
1.3 "Customer Personal Data" means personal data contained in Customer Content or Generated Content that we process on your behalf, including personal data in your business profile, author and spokesperson records, uploaded images and voice samples, content briefs, pages and sitemaps crawled from sites you connect, contact records, and anything present in content generated in your account.
1.4 Terms not defined here have the meaning given in the Terms of Service or in UK/EU GDPR. "Data Protection Law" means the UK GDPR, the Data Protection Act 2018, the EU GDPR (2016/679), and the Privacy and Electronic Communications Regulations, in each case as amended or replaced.
2. Your obligations as controller
2.1 You warrant that:
- you have a lawful basis for the processing you instruct;
- you have provided all required privacy notices to the individuals concerned;
- where the data includes a person's image, likeness or voice for avatar or spokesperson features, you hold that person's explicit, documented and informed consent covering AI-generated reproduction of their likeness or voice;
- your instructions do not require us to breach Data Protection Law.
2.2 You are responsible for the accuracy, quality and legality of Customer Personal Data and for the means by which you acquired it.
2.3 You must not submit special category data (Article 9) or criminal offence data (Article 10) to the Service except for likeness and voice data used for the video features, which the Service is designed to handle. The Service is not designed for and must not be used to process health records, financial account data, or data about children.
3. Our obligations as processor
We will:
3.1 Process only on your documented instructions. Your use of the Service, its settings and this DPA constitute your documented instructions. We will not process Customer Personal Data for any other purpose. If we are required by UK or EU law to process for another purpose, we will tell you first unless the law prohibits it.
3.2 Tell you if an instruction is unlawful. We will notify you if, in our opinion, an instruction infringes Data Protection Law, and may suspend that processing until it is resolved.
3.3 Never sell Customer Personal Data, never use it for our own purposes, never use it to train our own AI models, and never use it for advertising or profiling.
3.4 Ensure confidentiality. Everyone we authorise to process Customer Personal Data is bound by a written confidentiality obligation that survives the end of their engagement, and is trained on their data protection responsibilities.
3.5 Apply the security measures in Annex 3, meeting Article 32.
3.6 Assist you with:
- responding to data subject requests (Article 28(3)(e)) — see section 6;
- data protection impact assessments and prior consultation (Articles 35 and 36);
- security, breach notification and communication obligations (Articles 32 to 36);
taking into account the nature of the processing and the information available to us. Reasonable assistance is included at no charge; assistance that is disproportionate or repeated may be charged at our then-current professional services rate, notified in advance.
3.7 Notify you of a personal data breach affecting Customer Personal Data without undue delay and in any event within 48 hours of becoming aware of it, with the information in Article 33(3) to the extent available, and updates as the investigation progresses. We will not delay notification to complete the investigation.
3.8 Delete or return Customer Personal Data at the end of the Service, per section 8.
3.9 Make available the information needed to demonstrate compliance and allow audits, per section 7.
4. Sub-processors
4.1 General authorisation. You give us general written authorisation to appoint sub-processors. Our current sub-processors are listed at automateseo.app/subprocessors, which forms Annex 2 of this DPA.
4.2 Notice of changes. We will give 30 days' notice before adding or replacing a sub-processor, by updating that page and emailing customers on the subprocessor notification list. Email privacy@automateseo.app to join that list.
4.3 Objection. You may object on reasonable, documented data protection grounds within the notice period. We will work in good faith to offer an alternative. If we cannot, you may terminate the affected part of the Service without penalty and receive a pro-rata refund of prepaid, unused amounts.
4.4 Flow-down and liability. Each sub-processor is engaged under a written contract imposing obligations no less protective than this DPA. We remain fully liable to you for the acts and omissions of our sub-processors.
4.5 Emergency appointments. We may appoint a sub-processor immediately where necessary to address an urgent security or availability issue, notifying you as soon as practicable afterwards.
5. International transfers
5.1 We may transfer Customer Personal Data outside the UK and EEA only where an appropriate safeguard under Chapter V is in place. Current safeguards are identified per sub-processor in Annex 2.
5.2 Where the EU Standard Contractual Clauses (Decision 2021/914) apply, they are incorporated into this DPA by reference and take precedence over it in the event of conflict:
- Module Two (controller to processor) applies where you are a controller; Module Three (processor to processor) applies where you are a processor.
- Clause 7 (docking) applies. Clause 9 uses Option 2 (general written authorisation) with the 30-day notice period in section 4.2. Clause 11 optional independent dispute resolution does not apply. Clause 17 selects Irish law. Clause 18(b) selects the courts of Ireland.
- Annex I.A parties, I.B description of transfer, and II technical and organisational measures are Annexes 1 and 3 of this DPA. The competent supervisory authority under Annex I.C is the authority of your EU establishment or, failing that, the Irish Data Protection Commission.
5.3 Where UK transfers occur, the UK International Data Transfer Addendum (version B1.0) applies to those SCCs. Tables 1 to 3 are populated by this DPA and its Annexes; in Table 4, neither party may end the Addendum as set out in section 19.
5.4 We have carried out transfer risk assessments for each destination and will provide them on request.
6. Data subject requests
6.1 The Service gives you self-serve tools to access, correct, export and delete Customer Personal Data. In most cases you can satisfy a request yourself without our involvement.
6.2 If we receive a request directly from an individual relating to Customer Personal Data, we will not respond substantively. We will redirect them to you and inform you within 5 business days, unless we are legally required to respond.
6.3 Where the self-serve tools are not enough, we will assist you promptly.
7. Audit
7.1 On request, and no more than once in any 12-month period unless required by a supervisory authority or following a personal data breach, we will provide the information reasonably necessary to demonstrate compliance with this DPA — including our security documentation, a completed security questionnaire, and any third-party assessment reports we hold.
7.2 Where that is genuinely insufficient to meet a regulatory obligation, you may audit us, or appoint an independent auditor who is not a competitor of ours, subject to: 30 days' written notice; a scope agreed in advance; conduct during UK business hours; no unreasonable disruption; the auditor signing a confidentiality agreement; and no access to other customers' data, our source code, or facilities operated by our sub-processors.
7.3 You bear the cost of an audit under 7.2, unless it identifies a material breach of this DPA by us, in which case we bear our own costs and yours.
8. Deletion and return
8.1 On termination, or at your request at any time, we will delete Customer Personal Data within 30 days, except where retention is required by law.
8.2 Before deletion, and for 30 days after termination, you may export your data using the in-app export function. On request we will provide an export in a structured, commonly used, machine-readable format.
8.3 Data in encrypted backups is purged on a rolling 90-day cycle. Until purged, backup copies remain subject to this DPA and are not restored into production except as part of a disaster recovery event, after which any deleted records are re-deleted.
8.4 We will certify deletion in writing on request.
9. Liability, term and general
9.1 Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except that nothing limits liability that cannot lawfully be limited, including liability to data subjects under Article 82 or to a supervisory authority.
9.2 This DPA takes effect when you first use the Service and continues for as long as we process Customer Personal Data.
9.3 If a signed Master Service Agreement or a negotiated DPA is in place with you, that document prevails over this one.
9.4 This DPA is governed by the law of England and Wales, except that the SCCs are governed as stated in section 5.2. If any part conflicts with Data Protection Law, Data Protection Law prevails and the rest continues in force.
9.5 We may update this DPA to reflect changes in law, regulator guidance or approved codes of conduct, on 30 days' notice, provided the update does not materially reduce the protections it gives you.
Annex 1 — Description of processing
Subject matter. Provision of the AutomateSEO AI content generation, optimisation and publishing platform.
Duration. For the term of the Terms of Service, plus the deletion periods in section 8.
Nature and purpose of processing. Collection, storage, organisation, structuring, retrieval, use, transmission to AI providers for content generation, transmission to platforms you connect for publishing, analysis for SEO and performance reporting, erasure.
Categories of data subject.
- Your personnel, authors and named contacts
- Spokespersons and presenters whose likeness or voice you upload
- Individuals identified in content you generate or in briefs you supply
- Individuals identified in pages, sitemaps or feeds on sites you connect
- Where you use the platform for a client: that client's personnel and contacts
Categories of personal data.
- Identifiers: names, email addresses, telephone numbers, business addresses
- Professional information: job titles, biographies, credentials, author profiles
- Online identifiers: profile URLs, social handles, account and page identifiers
- Images and audio: photographs, spokesperson likenesses, voice samples
- Authentication data: OAuth tokens and API credentials for platforms you connect (encrypted)
- Any personal data you choose to include in content, prompts or briefs
Special category data. Facial images and voice samples processed for avatar and spokesperson video may constitute biometric data. Processed only on your instruction, only to deliver that feature, and only where you have obtained explicit consent from the individual. No other special category data may be submitted.
Frequency. Continuous, for as long as you use the Service.
Retention. As set out in section 8 and in the retention table in the Privacy Policy.
Annex 2 — Sub-processors
The current list of sub-processors, including each one's legal entity, location, purpose, data categories and international transfer safeguard, is maintained at:
That page is incorporated into this DPA and is updated in accordance with section 4.
Annex 3 — Technical and organisational measures (Article 32)
The measures below are the Article 32 measures for the purposes of this DPA and Annex II of the SCCs. Our full Security Statement describes them in more detail.
Encryption. TLS 1.2 or higher for all data in transit. Encryption at rest for the database, object storage and backups. Third-party credentials and OAuth tokens additionally encrypted at the application layer with AES-256-GCM using keys held outside the database.
Access control. Row-level security isolating each customer's data at the database level. Role-based access control in the application. Least-privilege service credentials. Administrative access limited to named personnel, on a business-need basis, with multi-factor authentication required. Access reviewed on a regular basis and revoked promptly when no longer needed.
Pseudonymisation and minimisation. Only the data necessary to fulfil a request is sent to AI providers. Credentials are never included in prompts. Logs exclude secrets and are retained for a limited period.
Resilience. Managed, replicated database hosting with automated backups. Content delivery and compute distributed across a global edge network with DDoS protection. Job state persisted so that generation and publishing work can be retried without data loss.
Restoration. Automated daily backups with point-in-time recovery. Restoration procedures tested periodically.
Testing and assurance. Security review of changes before release. Dependency vulnerability monitoring. Application security auditing, with the most recent full audit completed in July 2026. Rate limiting and abuse detection on authentication and generation endpoints.
Input and transfer control. Authenticated, authorised API endpoints with webhook signature or shared-secret verification on machine-to-machine callbacks. Output sanitisation on all rendered content to prevent injection into customer sessions or published sites.
Incident management. Documented incident response process, with notification to controllers within 48 hours of becoming aware of a personal data breach.
Personnel. Confidentiality obligations for everyone with access. Data protection and security awareness training. Access removed on the day an engagement ends.
Sub-processor governance. Written agreements with Article 28 terms, transfer safeguards, and pre-engagement security assessment for every sub-processor.
To request a countersigned copy of this DPA, email privacy@automateseo.app with your legal entity name, registered address and signatory details.