On this page
Data processing agreement
Effective Sep 1, 2026 · v2.0This DPA forms part of the terms of service and applies when Serplyze processes personal data on your behalf, for example personal data that appears in search queries or in the list of users you invite.
01Roles
You are the controller and we are the processor for personal data within your Search Console data and team account data. We process it only on your documented instructions, which are these terms, the DPA and your use of the product.
02Details of processing
03Our obligations
- Ensure staff with access are bound by confidentiality.
- Apply the security measures in section 5.
- Help you answer data subject requests and impact assessments.
- Notify you of a personal data breach without undue delay, and within 48 hours of becoming aware of it.
04Subprocessors
You authorise the following categories of subprocessor. We give at least 30 days’ notice of a new one, and you may object on reasonable grounds.
05Security measures
- Encryption in transit (TLS 1.2 or later) and at rest (AES-256).
- Google OAuth tokens encrypted separately and never shown in the product.
- Least-privilege staff access with logged, time-limited production sessions.
- Daily encrypted backups kept for 35 days, restored and tested quarterly.
06Deletion and audits
At the end of the agreement we delete personal data within 30 days, unless the law requires otherwise. Once a year, on 30 days’ notice, you may request information needed to show compliance with this DPA.