Data processing agreement

Effective August 2, 2026

You already have this

This agreement forms part of the terms of service and applies automatically to every customer of the hosted service - there is nothing to sign and nothing to request. It is the written contract required by Article 28 of the GDPR (and its UK equivalent) for the personal data we process on your behalf.

If your procurement process needs a countersigned copy, or your own paper instead of ours, email privacy@dispatchseo.com and we will sort it out.

Who is who

For personal data contained in the websites, repositories and Search Console properties you connect - your own site visitors' search queries, anything personal in the content we process for you - you are the controller and Neo Zino is the processor, acting on your instructions.

For your own account data - your email, your billing details, your use of the product - we are the controller in our own right, and our privacy policy governs it rather than this agreement.

What we process, and why

Subject matter and duration: providing the DispatchSEO hosted service, for as long as your account is open.

Nature and purpose: storing, organising, analysing and transmitting the data needed to research keywords, generate content drafts, deliver them to your repository, and track search performance.

Types of personal data: identifiers and contact details of your account users; search queries and performance statistics from your Search Console properties; repository and site metadata; and whatever personal data happens to appear in content or site material you connect.

Categories of data subjects: your personnel who use the service, and visitors to your websites insofar as their search behaviour appears in aggregated Search Console statistics. We do not need or want special-category data, and the service is not built to handle it.

Our obligations

We process only on your documented instructions, which are these terms and your use of the product's features, including for international transfers - unless the law requires otherwise, in which case we will tell you first unless that law forbids it. If we think an instruction breaches data protection law, we will say so.

Confidentiality. Anyone authorised to process the data is bound by a duty of confidentiality.

Security. We maintain the technical and organisational measures required by Article 32, described in the Security section of our privacy policy - encryption in transit and of stored credentials, default-deny database access, and hashed authentication secrets.

Subprocessors. You give general authorisation for us to engage the subprocessors listed at /subprocessors. We impose the same data-protection obligations on each of them and remain fully liable to you for their performance. We will give at least 30 days' notice before adding or replacing one; if you reasonably object on data-protection grounds and we cannot resolve it, you may terminate and we will refund the unused portion of your period.

Helping you with data subjects.Taking into account the nature of the processing, we will help you respond to requests to access, correct, delete, restrict, port or object - largely through the product's own controls, which let you reach and delete this data yourself. If a data subject contacts us directly, we will redirect them to you rather than answer for you.

Breaches and assessments. We will notify you without undue delay after becoming aware of a personal data breach affecting your data, with the detail you need for your own notification duties, and will give reasonable assistance with data protection impact assessments and prior consultations.

Return or deletion. On termination we delete your data as described in the privacy policy - deleting your account erases your projects and their history immediately - unless the law requires us to keep something. You can export your data from the product before you go, and we will help if you ask.

Information and audits.We will make available the information needed to show we comply with this agreement, and allow and contribute to audits by you or an auditor you appoint, on reasonable notice, no more than once a year unless a breach or a regulator makes another one necessary, at your cost and without disrupting the service or exposing another customer's data.

International transfers

We are established in Israel, which the European Commission recognises as providing an adequate level of protection, so transfers from the EEA to us need no additional safeguard. Where a subprocessor is outside the EEA or the UK, the transfer is covered by the European Commission's Standard Contractual Clauses (or the UK Addendum or International Data Transfer Agreement, as applicable), which are incorporated into this agreement by reference and prevail over anything inconsistent with them. The subprocessors page names the mechanism for each.

Liability

Liability under this agreement is subject to the limitations in the terms of service, except where data protection law does not permit that - nothing here limits either party's liability to a data subject or a supervisory authority.

Back to dispatchseo.com