Check my visibility

Legal · DPA

Data Processing Addendum

This Addendum governs SearchDaddy, Inc.'s processing of personal data on behalf of business customers. It forms part of the Terms of Service and is intended for customers whose vendors require a signed DPA.

Version
1.0
Effective
23 Jun 2026
Role
Processor
Status
Draft · pending review

Roles & scope

This Data Processing Addendum (DPA) supplements the Terms of Service between the customer (the Controller) and SearchDaddy, Inc. (the Processor). For personal data the Processor processes on the Controller's behalf in providing the Service, the Controller is the controller (or "business") and the Processor is the processor (or "service provider"). Each party will comply with applicable data-protection laws.

Signing entityUntil SearchDaddy, Inc. is incorporated, the Processor under this DPA is the operator, doing business as SearchDaddy, Inc. (sole proprietorship). On incorporation, this DPA will be assigned to the corporate entity. A DPA should not be executed with customers under an "Inc." name before that entity legally exists.

Details of processing

The subject matter, duration, nature, and purpose of processing, and the categories of data subjects and personal data, are set out in Annex I. The Processor processes personal data only to provide the Service and on the Controller's documented instructions, including those in the Terms and this DPA, unless required to act otherwise by law (in which case it will inform the Controller where lawful).

Processor obligations

  • Instructions. Process only on the Controller's documented instructions and notify the Controller if an instruction appears to infringe applicable law.
  • Confidentiality. Ensure personnel authorized to process personal data are bound by confidentiality.
  • Security. Implement and maintain the technical and organizational measures in Annex II.
  • Assistance. Taking into account the nature of processing, assist the Controller with data-subject requests and with security, breach-notification, and impact-assessment obligations.
  • Records. Make available information reasonably necessary to demonstrate compliance with this DPA.

Sub-processors

The Controller authorizes the Processor to engage the sub-processors listed below to process personal data. The Processor imposes data-protection obligations on each sub-processor substantially as protective as those in this DPA and remains responsible for their performance. The Processor will give the Controller advance notice of any intended addition or replacement of a sub-processor and an opportunity to object on reasonable data-protection grounds.

Sub-processorFunctionLocation
StripePayment processingUnited States
PostmarkTransactional emailUnited States
SentryError monitoringUnited States
OpenAIAI-engine queries (ChatGPT)United States
AnthropicAI-engine queries (Claude)United States
GoogleAI-engine queries (Gemini / AI Overviews)United States
PerplexityAI-engine queriesUnited States
SerpApi / DataForSEOSearch & AI-Overview dataUnited States
[Hosting / cloud provider]Infrastructure hosting[confirm]

Data-subject requests

If the Processor receives a request from a data subject to exercise rights under applicable law in relation to the Controller's personal data, it will, where lawful, forward the request to the Controller without undue delay and not respond directly except on the Controller's instruction. The Processor will assist the Controller in responding, taking into account the nature of processing.

Security measures

The Processor maintains appropriate technical and organizational measures designed to protect personal data against unauthorized or unlawful processing and accidental loss, destruction, or damage, as described in Annex II. The Processor may update these measures provided the level of protection is not materially decreased.

Breach notification

The Processor will notify the Controller without undue delay after becoming aware of a personal-data breach affecting the Controller's personal data, and will provide information reasonably available to help the Controller meet its own notification obligations. Notification is not an acknowledgment of fault.

International transfers

Where processing involves transferring personal data across borders to a country without an adequacy decision, the parties will rely on an appropriate transfer mechanism, such as the Standard Contractual Clauses, which are incorporated by reference where applicable. [Confirm the governing transfer mechanism with counsel before relying on this section for EU/UK data.]

Audits

The Processor will make available information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates, on reasonable prior notice, no more than once per year except as required by a supervisory authority or following a breach, subject to confidentiality and without disrupting operations. The Processor may satisfy audit requests by providing then-current third-party reports where available.

Return & deletion

On termination of the Service, the Processor will, at the Controller's choice, delete or return the Controller's personal data and delete existing copies, unless retention is required by law. The Controller may export Customer Data for a limited period after termination as described in the Terms.

California terms

To the extent the CCPA/CPRA applies, the Processor is a "service provider." The Processor will not sell or share the Controller's personal information; will not retain, use, or disclose it for any purpose other than performing the Service or as otherwise permitted by the CCPA; will not combine it with personal information from other sources except as permitted; and certifies it understands and will comply with these restrictions. The Controller may take reasonable steps to remediate unauthorized use.

Liability & precedence

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms. In case of conflict between this DPA and the Terms regarding the processing of personal data, this DPA controls; the Standard Contractual Clauses, where incorporated, control over both for the data they govern.

Annexes

Annex I — Details of processing

  • Subject matter: provision of AI visibility monitoring, scoring, audits, and remediation services.
  • Duration: the term of the Service plus any limited post-termination export and deletion period.
  • Nature & purpose: hosting, querying AI engines, analysis, scoring, reporting, and support.
  • Categories of data subjects: the Controller's authorized users and personnel; owner-operators named as part of a business identity.
  • Categories of personal data: contact and account data (name, business name, email, phone); usage and device data; communications. The Service is not designed to process special categories of data, and the Controller should not submit them.

Annex II — Technical & organizational measures

  • encryption of personal data in transit, and at rest where supported by the infrastructure;
  • role-based access controls and the principle of least privilege;
  • authentication controls and scoped session cookies at the SearchDaddy, Inc. domain;
  • logging, error monitoring, and alerting;
  • use of reputable infrastructure and sub-processors with their own security programs;
  • backup and recovery practices; and
  • confidentiality obligations on personnel and contractors.

See the Security page for the current overview. Measures evolve as the Service matures.

↑ Back to top · Version 1.0 · Effective 23 Jun 2026