Data Processing Addendum
This Data Processing Addendum ("DPA") forms part of the Terms of Service between Clearpath Digital LLC, 15746 CR 70, Greeley, CO 80631, USA ("KeptSEO", "Processor") and the customer ("Customer", "Controller"). It applies when KeptSEO processes personal data on the Customer's behalf that is subject to the EU General Data Protection Regulation (GDPR), the UK GDPR, or similar data protection laws.
To receive a countersigned copy, email chris@clearpathdigital.io with your company name, address and the name of the person signing.
1. Roles and scope
The Customer is the controller and KeptSEO is the processor of the personal data in Customer data (GDPR Article 28). KeptSEO processes it only to provide the service described in the Terms.
- Subject matter and duration: providing KeptSEO for the life of the Customer's account, plus the deletion period in section 7.
- Nature and purpose: importing, storing, analyzing and displaying search performance data, and running the Customer's account.
- Data subjects: the Customer's users and team members, and any people whose data appears in connected sources.
- Personal data: names, email addresses, Google account IDs, profile pictures, IP addresses and user agents in request logs, and any personal data contained in the Customer's search data (for example, in search queries).
- Special categories: none intended.
2. Processor obligations
KeptSEO will:
- process personal data only on the Customer's documented instructions (the Terms, this DPA and the Customer's use of the product), unless the law requires otherwise, and tell the Customer if it believes an instruction breaks the law;
- make sure people allowed to process the data are bound by confidentiality;
- apply the security measures in section 5;
- help the Customer, as far as reasonably possible, respond to requests from data subjects;
- help the Customer meet its duties on security, breach notification, impact assessments and prior consultation, given the nature of the processing and the information KeptSEO has;
- make available the information needed to show compliance with this DPA.
3. Sub-processors
The Customer gives general authorization for KeptSEO to use sub-processors. The current list is at keptseo.com/subprocessors. KeptSEO will give notice of a new sub-processor by updating that page, and by email to Customers who ask, before it processes Customer personal data. The Customer may object on reasonable data protection grounds within 30 days. If we cannot resolve the objection, the Customer may end the affected service and receive a refund of prepaid fees for the unused period. KeptSEO binds each sub-processor to data protection terms no less protective than this DPA and remains responsible for their work.
4. International transfers
KeptSEO is based in the United States. Where personal data is transferred from the European Economic Area, Switzerland or the United Kingdom to a country without an adequacy decision, the parties agree to the Standard Contractual Clauses approved by European Commission Implementing Decision (EU) 2021/914 (Module Two, controller to processor, and Module Three where it applies) and, for the UK, the International Data Transfer Addendum issued by the Information Commissioner. These are incorporated by reference. Section 1 completes Annex I and section 5 completes Annex II.
5. Security measures
- Encryption in transit (TLS) and at rest on Cloudflare's platform.
- OAuth refresh tokens encrypted with AES-256-GCM, never sent to browsers and never written to logs.
- Read-only access to Google Search Console.
- Access to each property re-checked against the permissions Google reports, and removed when Google no longer grants it.
- Workspace isolation: one workspace cannot read another's notes, saved views or settings.
- Protected session cookies, and administrative access limited to the people who run the service.
- Point-in-time recovery for the account database and a documented restore procedure.
More detail is on the Security page. KeptSEO may change these measures as long as the overall level of protection does not go down.
6. Personal data breaches
KeptSEO will notify the Customer without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting Customer personal data. The notice will describe the breach, the kinds of data and people affected, the likely consequences and the steps taken, as far as these are known. KeptSEO will send updates as it learns more.
7. Deletion and return
When the Customer's account ends, KeptSEO will delete Customer personal data within 30 days, except data the law requires it to keep (such as invoices). Before that, the Customer can export its data in the product or ask us for a copy. Backups expire on their normal schedule and are only restored to recover from a failure.
8. Audits
On written request, and no more than once a year unless a breach or a regulator requires it, KeptSEO will answer reasonable written questions and provide documents about its compliance with this DPA. If that is not enough, the Customer, or an independent auditor bound by confidentiality, may audit KeptSEO on 30 days' notice, during business hours, at the Customer's cost, and without disrupting the service or exposing other customers' data.
9. Liability and precedence
Each party's liability under this DPA is subject to the limits in the Terms, except where the law does not allow such limits. If this DPA conflicts with the Terms, this DPA controls on data protection matters. If the Standard Contractual Clauses conflict with this DPA, the clauses control.
Contact
Clearpath Digital LLC, 15746 CR 70, Greeley, CO 80631, USA. chris@clearpathdigital.io.