Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Redbit S.r.l.s. ("Processor", "we") and the Customer ("Controller", "you"). It applies where, in providing SerpTune, we process personal data on your behalf. Where our roles differ, the Privacy Policy governs data for which we are the controller.
1. Roles & subject-matter
For personal data contained in the pages you submit and for which you are the controller ("Customer Personal Data"), you are the controller and we are the processor. Subject-matter: producing the comparative SEO analyses you request. Duration: for as long as you use the Service. Nature & purpose: fetching, cleaning, and AI-analysing the submitted page content to generate your report. Categories of data subjects and data: as determined by the pages you submit.
2. Processor obligations
- Instructions: we process Customer Personal Data only on your documented instructions (including as set out in the Terms and this DPA), unless required otherwise by EU/Member-State law, in which case we inform you unless the law prohibits it.
- Confidentiality: persons authorised to process the data are bound by confidentiality.
- Security: we implement appropriate technical and organisational measures (Annex A).
- Assistance: taking into account the nature of processing, we assist you with data-subject requests and with your obligations under Articles 32–36 GDPR.
- Breach: we notify you without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data.
- Deletion/return: on termination we delete Customer Personal Data (raw HTML within 48 hours, derived records on account closure), unless storage is legally required.
- Audits: we make available information necessary to demonstrate compliance and allow for audits, subject to reasonable confidentiality and notice.
3. Sub-processors
You provide general authorisation for us to engage the sub-processors listed in the Privacy Policy (currently Anthropic, LangChain/LangSmith, our search-results provider, Cloudflare, IONOS, and our transactional-email system). We impose data-protection terms on each sub-processor equivalent to those in this DPA and remain liable for their performance. We will give notice of intended additions or replacements and allow you to object on reasonable data-protection grounds.
4. International transfers
Where processing involves a transfer outside the EEA/UK, it is governed by the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable), with supplementary measures. See the Privacy Policy for details.
5. Liability & precedence
Liability under this DPA is subject to the limitations in the Terms. In case of conflict on data-protection matters, this DPA prevails over the Terms; on all other matters, the Terms prevail.
Annex A — Technical & organisational measures
Encryption in transit (TLS/HSTS); hashed credentials (Argon2id); CSRF protection; rate limiting and login lockout; bot protection; least-privilege access controls; audit logging; short retention of raw fetched content (48h); EU-hosted infrastructure; and reputable sub-processors under data-protection terms.
Signature
By accepting the Terms of Service or using the Service to process Customer Personal Data, you enter into this DPA. A countersigned copy for your records is available on request via [email protected].