Roles & scope
This Data Processing Addendum (DPA) supplements the Terms of Service between the customer (the Controller) and SearchDaddy, Inc. (the Processor). For personal data the Processor processes on the Controller's behalf in providing the Service, the Controller is the controller (or "business") and the Processor is the processor (or "service provider"). Each party will comply with applicable data-protection laws.
Signing entityUntil SearchDaddy, Inc. is incorporated, the Processor under this DPA is the operator, doing business as SearchDaddy, Inc. (sole proprietorship). On incorporation, this DPA will be assigned to the corporate entity. A DPA should not be executed with customers under an "Inc." name before that entity legally exists.
Details of processing
The subject matter, duration, nature, and purpose of processing, and the categories of data subjects and personal data, are set out in Annex I. The Processor processes personal data only to provide the Service and on the Controller's documented instructions, including those in the Terms and this DPA, unless required to act otherwise by law (in which case it will inform the Controller where lawful).
Processor obligations
- Instructions. Process only on the Controller's documented instructions and notify the Controller if an instruction appears to infringe applicable law.
- Confidentiality. Ensure personnel authorized to process personal data are bound by confidentiality.
- Security. Implement and maintain the technical and organizational measures in Annex II.
- Assistance. Taking into account the nature of processing, assist the Controller with data-subject requests and with security, breach-notification, and impact-assessment obligations.
- Records. Make available information reasonably necessary to demonstrate compliance with this DPA.
Sub-processors
The Controller authorizes the Processor to engage the sub-processors listed below to process personal data. The Processor imposes data-protection obligations on each sub-processor substantially as protective as those in this DPA and remains responsible for their performance. The Processor will give the Controller advance notice of any intended addition or replacement of a sub-processor and an opportunity to object on reasonable data-protection grounds.
| Sub-processor | Function | Location |
|---|---|---|
| Stripe | Payment processing | United States |
| Postmark | Transactional email | United States |
| Sentry | Error monitoring | United States |
| OpenAI | AI-engine queries (ChatGPT) | United States |
| Anthropic | AI-engine queries (Claude) | United States |
| AI-engine queries (Gemini / AI Overviews) | United States | |
| Perplexity | AI-engine queries | United States |
| SerpApi / DataForSEO | Search & AI-Overview data | United States |
| [Hosting / cloud provider] | Infrastructure hosting | [confirm] |
Data-subject requests
If the Processor receives a request from a data subject to exercise rights under applicable law in relation to the Controller's personal data, it will, where lawful, forward the request to the Controller without undue delay and not respond directly except on the Controller's instruction. The Processor will assist the Controller in responding, taking into account the nature of processing.
Security measures
The Processor maintains appropriate technical and organizational measures designed to protect personal data against unauthorized or unlawful processing and accidental loss, destruction, or damage, as described in Annex II. The Processor may update these measures provided the level of protection is not materially decreased.
Breach notification
The Processor will notify the Controller without undue delay after becoming aware of a personal-data breach affecting the Controller's personal data, and will provide information reasonably available to help the Controller meet its own notification obligations. Notification is not an acknowledgment of fault.
International transfers
Where processing involves transferring personal data across borders to a country without an adequacy decision, the parties will rely on an appropriate transfer mechanism, such as the Standard Contractual Clauses, which are incorporated by reference where applicable. [Confirm the governing transfer mechanism with counsel before relying on this section for EU/UK data.]
Audits
The Processor will make available information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates, on reasonable prior notice, no more than once per year except as required by a supervisory authority or following a breach, subject to confidentiality and without disrupting operations. The Processor may satisfy audit requests by providing then-current third-party reports where available.
Return & deletion
On termination of the Service, the Processor will, at the Controller's choice, delete or return the Controller's personal data and delete existing copies, unless retention is required by law. The Controller may export Customer Data for a limited period after termination as described in the Terms.
California terms
To the extent the CCPA/CPRA applies, the Processor is a "service provider." The Processor will not sell or share the Controller's personal information; will not retain, use, or disclose it for any purpose other than performing the Service or as otherwise permitted by the CCPA; will not combine it with personal information from other sources except as permitted; and certifies it understands and will comply with these restrictions. The Controller may take reasonable steps to remediate unauthorized use.
Liability & precedence
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms. In case of conflict between this DPA and the Terms regarding the processing of personal data, this DPA controls; the Standard Contractual Clauses, where incorporated, control over both for the data they govern.
Annexes
Annex I — Details of processing
- Subject matter: provision of AI visibility monitoring, scoring, audits, and remediation services.
- Duration: the term of the Service plus any limited post-termination export and deletion period.
- Nature & purpose: hosting, querying AI engines, analysis, scoring, reporting, and support.
- Categories of data subjects: the Controller's authorized users and personnel; owner-operators named as part of a business identity.
- Categories of personal data: contact and account data (name, business name, email, phone); usage and device data; communications. The Service is not designed to process special categories of data, and the Controller should not submit them.
Annex II — Technical & organizational measures
- encryption of personal data in transit, and at rest where supported by the infrastructure;
- role-based access controls and the principle of least privilege;
- authentication controls and scoped session cookies at the SearchDaddy, Inc. domain;
- logging, error monitoring, and alerting;
- use of reputable infrastructure and sub-processors with their own security programs;
- backup and recovery practices; and
- confidentiality obligations on personnel and contractors.
See the Security page for the current overview. Measures evolve as the Service matures.