This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Aries Vincent Digital Solutions (“ArvaSEO”, the “Processor”) and the customer that accepts them (“Customer”, the “Controller”). It applies automatically, with no need to sign it separately. If you need a signed copy for your records, email privacy@arvaseo.com.
1. Definitions
“Data Protection Laws” means all laws on personal data that apply to the processing, including the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, the Philippine Data Privacy Act of 2012 and its implementing rules (“DPA 2012”), and the California Consumer Privacy Act as amended (“CCPA”). “Customer Personal Data” means personal data in Customer Data (as defined in the Terms) that ArvaSEO processes on Customer’s behalf. “Controller”, “processor”, “data subject”, “personal data breach”, “processing” and “supervisory authority” have the meanings given in the GDPR (and their equivalents under other Data Protection Laws, including “personal information controller” and “personal information processor” under the DPA 2012, and “business” and “service provider” under the CCPA).
2. Roles and instructions
- Customer is the controller of Customer Personal Data and ArvaSEO is its processor. Customer is responsible for having a lawful basis for the processing and for giving data subjects any required notice.
- ArvaSEO processes Customer Personal Data only on Customer’s documented instructions, which are these Terms, this DPA and Customer’s use and configuration of the Service, unless the law requires otherwise (in which case ArvaSEO will tell Customer first, unless the law forbids it).
- ArvaSEO will tell Customer if it believes an instruction breaks Data Protection Laws.
- The details of the processing are in Annex 1.
3. ArvaSEO’s obligations
- Confidentiality. Everyone at ArvaSEO who can access Customer Personal Data is bound by confidentiality, and access is limited to those who need it to provide, secure or support the Service.
- Security. ArvaSEO maintains the technical and organisational measures in Annex 2, appropriate to the risk, as required by Article 32 GDPR and Section 20 of the DPA 2012. ArvaSEO may improve them over time but won’t reduce their overall level of protection.
- Assistance. Taking into account the nature of the processing, ArvaSEO helps Customer respond to data subjects exercising their rights, mostly through the Service’s own features (correcting, exporting and deleting data), and otherwise on request. If ArvaSEO receives a request directly, it will refer the person to Customer. ArvaSEO also provides reasonable information to help with data protection impact assessments and consultations with authorities.
- Breach notification. ArvaSEO will notify Customer without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data, with the information Customer needs to meet its own obligations (including notifying authorities within 72 hours where required), and will take reasonable steps to contain and remedy it.
- Records. ArvaSEO keeps the records of processing required of processors.
4. Subprocessors
- Customer authorises ArvaSEO to use the subprocessors listed on the subprocessors page.
- ArvaSEO imposes data protection obligations on each subprocessor that are at least as protective as this DPA, and remains responsible for their performance.
- ArvaSEO will announce a new subprocessor on that page, and by email to workspace owners who ask to be told, at least 30 days before it starts processing Customer Personal Data. Customer may object on reasonable data protection grounds within that time; if we can’t resolve the objection, Customer may end the affected part of the Service and receive a pro-rated refund of prepaid fees for it.
5. International transfers
- Where Customer Personal Data is transferred from the EEA to a country without an adequacy decision, the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 apply and are incorporated by reference: Module 2 (controller to processor) and, for onward transfers to subprocessors, Module 3, with Clause 7 included, option 2 of Clause 9 (general authorisation, 30 days’ notice), the optional wording in Clause 11 omitted, Clause 17 option 1 (the law of Ireland), Clause 18 (the courts of Ireland), and Annexes I and II as set out in this DPA.
- For transfers from the UK, the International Data Transfer Addendum issued by the UK Information Commissioner applies together with those clauses; for Switzerland, the clauses apply with references to the GDPR read as references to the Swiss FADP.
- If any of these mechanisms is replaced or invalidated, the parties will work together to put an appropriate alternative in place.
6. Deletion and return
Customer can export its data from the Service at any time while its account is active and, on request, during the 30 days after it ends. ArvaSEO then deletes Customer Personal Data within 30 days, and it leaves backups within a further 30 days, unless the law requires ArvaSEO to keep it. On request, ArvaSEO will confirm the deletion in writing.
7. Information and audits
ArvaSEO will make available the information reasonably necessary to demonstrate compliance with this DPA, including written answers to security questionnaires. If that isn’t sufficient, or a supervisory authority requires it, Customer may audit ArvaSEO’s relevant processing once a year (and after a personal data breach), on 30 days’ written notice, during business hours, without disrupting the Service or compromising other customers’ data, under confidentiality, and at Customer’s own cost.
8. CCPA service provider terms
Where the CCPA applies, ArvaSEO is Customer’s service provider. ArvaSEO will not sell or share Customer Personal Data; will not retain, use or disclose it for any purpose other than providing the Service to Customer (the business purposes in Annex 1), or outside its direct business relationship with Customer; will not combine it with personal information from other sources except as the CCPA permits; will comply with the CCPA and give it the same level of protection the CCPA requires; and will tell Customer if it can no longer meet these obligations. Customer may take reasonable steps to stop and remediate any unauthorised use.
9. Philippine Data Privacy Act
Where the DPA 2012 applies, Customer is the personal information controller and ArvaSEO the personal information processor, and this DPA is their outsourcing agreement under Section 44 of the implementing rules. ArvaSEO will process Customer Personal Data only for the purposes in Annex 1, implement the security measures required by the DPA 2012 and the issuances of the National Privacy Commission, help Customer meet its obligations, and notify Customer of personal data breaches as set out in section 3.
10. General
- This DPA lasts as long as ArvaSEO processes Customer Personal Data.
- Each party’s liability under this DPA is subject to the limits in the Terms, except where Data Protection Laws don’t allow it.
- If this DPA and the Terms conflict on data protection, this DPA wins. If this DPA and the Standard Contractual Clauses conflict, the Clauses win.
Annex 1: Details of the processing
| Subject matter and duration | Providing the ArvaSEO Service to Customer, for the term of the Terms plus the deletion period in section 6. |
|---|---|
| Nature and purpose | Hosting, storing, organising, displaying and transmitting Customer Data so Customer can run SEO work: audits, keyword and rank tracking, analytics from connected Google accounts, tasks, client reports and their scheduled emails, client portal access, prospect audits and support. |
| Categories of data subjects | Customer’s team members and client portal users; Customer’s clients and their staff; people who receive Customer’s reports; prospects Customer records; individuals whose information appears on audited web pages or in connected Google data. |
| Types of personal data | Names, business email addresses, job roles, company names, logos, notes Customer writes, sign-in and activity records, and any personal data contained in website content or Google data Customer brings in. ArvaSEO isn’t designed for special categories of data, and Customer should not add them. |
| Frequency | Continuous, for as long as Customer uses the Service. |
| Subprocessors | As listed on the subprocessors page. |
Annex 2: Security measures
- Encryption: HTTPS (TLS) for all traffic; Google OAuth tokens and customers’ AI keys encrypted at rest; passwords stored only as salted hashes; encrypted backups.
- Access control: customer data is separated by workspace, with roles and permissions inside each workspace; staff access is limited to those who need it, requires two-step verification, can be restricted to approved networks, and every staff view and change is recorded in an append-only audit log.
- Application security: protection against cross-site request forgery, rate limiting, and outgoing requests restricted to public internet addresses (the crawler can’t reach private networks).
- Availability: daily encrypted backups kept for 30 days, and monitoring and error tracking.
- Vendor management: subprocessors chosen for their security practices and bound by written data protection terms.
- Incident response: a process to investigate, contain and notify personal data breaches.
- Data minimisation: Google access is read-only and limited to what features need; AI requests send only what the user asks about; search data providers receive no personal data.