This Addendum applies where you (the "Customer", data controller) use DatA+ ("Processor") to process personal data on your behalf, such as your clients' Search Console and Analytics data.
Customer is the controller and DatA+ is the processor of the personal data processed to provide the service. DatA+ processes personal data only on the Customer's documented instructions, which include using the service as intended.
DatA+ keeps personal data confidential, encrypts credentials at rest, uses read-only access to Google data, and restricts access to what is needed to run the service.
The Customer authorizes the subprocessors listed in our Privacy Policy (Google, Neon, Vercel, Google Gemini, Anthropic, Resend, Lemon Squeezy). We will give notice before adding a new subprocessor and impose equivalent data-protection obligations on each.
DatA+ will assist the Customer, taking into account the nature of processing, in responding to data subject requests and in meeting security, breach-notification, and impact-assessment obligations. Self-serve export and deletion tools are provided in the app.
DatA+ will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's data.
On termination, or on request, DatA+ will delete the Customer's personal data, except where retention is required by law.
Where personal data is transferred outside the EEA or UK, the parties rely on the Standard Contractual Clauses or another lawful transfer mechanism.
DatA+ will make available information reasonably necessary to demonstrate compliance with this Addendum.