SEOmise

Legal

Data processing agreement

Version 1.0

This data processing agreement ("DPA") forms part of the terms of service between SEOMISE LTD ("we", the processor) and the customer that accepts it for its workspace ("you", the controller). It applies where we process personal data on your behalf in providing the service, and is written to meet Article 28 of the GDPR and the UK GDPR.

1. Subject matter and duration

We process personal data contained in the content you add to your workspace (websites, search and analytics data, Google Business Profile data including reviews, backlink and project data) for as long as you use the service and until it is deleted in line with section 9.

2. Nature and purpose

Storing, analysing and displaying that data to provide the features you use: site audits, rankings, local SEO, link management, reports and AI-assisted drafts that a person approves.

3. Types of data and data subjects

Names, e-mail addresses and opinions of reviewers; names and contact details of your team; visitor data where you connect analytics or visitor tracking (IP addresses are masked according to the platform setting). No special category data is needed for the service; do not add it.

4. Your instructions

We process personal data only on your documented instructions, which are this DPA and your use of the service, unless the law requires otherwise; we will tell you if we believe an instruction breaks data protection law.

5. Confidentiality and security

Everyone authorised to process the data is bound by confidentiality. We apply the technical and organisational measures described on our security page and trust centre, including encryption in transit and of secrets at rest, role-based access, two-step sign-in for staff, a tamper-evident audit log, backups and access reviews.

6. Sub-processors

You authorise the sub-processors listed on our sub-processors page. We impose the same data protection obligations on each and remain responsible for them. We will update that page before adding or replacing a sub-processor, and you may object on reasonable grounds.

Sub-processorPurposeLocation
BrevoSending service e-mail: invitations, password resets, alerts and reportsEuropean Union

7. International transfers

Where personal data is transferred outside the UK or EEA, the transfer is covered by an adequacy decision or the European Commission's standard contractual clauses (with the UK addendum where needed).

8. Assistance, breaches and audits

We help you answer data subject requests (the service has self-service export, correction and deletion), carry out impact assessments and meet your security obligations. We notify you without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting your data, with the information you need to notify your supervisory authority within 72 hours. We make available the information needed to demonstrate compliance and allow for audits, which may be met by our latest security documentation.

9. Deletion and return

You can export your workspace's data at any time. When you delete your workspace, its data is deleted after the cooling-off period, and from backups as they expire, except where the law requires us to keep it (such as invoices).

10. Contact

Data protection questions: privacy@seomise.com.

This is the standard agreement offered with the service. If your organisation needs its own terms, contact us.

Workspace owners accept this agreement for their workspace, and download a signed copy, from Account → Privacy in the app.