Data Processing Agreement
Version 1.0 · Last updated 18 July 2026
This Data Processing Agreement (“DPA”) applies where you use SeoWrite on behalf of an organisation and, in doing so, instruct SeoWrite to process personal data. It forms part of, and is incorporated by reference into, our Terms of Service (the “Agreement”). If you use SeoWrite for your own personal purposes, SeoWrite is a controller of your data under our Privacy Policy and this DPA does not apply to you.
1. Parties and scope
This DPA is between:
- DEVITGROUP LTD (“SeoWrite”, “Processor”), a company registered in England & Wales (Company No. 12709920), 71-75 Shelton Street, London WC2H 9JQ (ICO registration ZC078036); and
- the customer identified in the Agreement, acting on behalf of an organisation (“Customer”, “Controller”).
The individual who accepts the Agreement on the Customer’s behalf represents and warrants that they are duly authorised to bind the Customer to the Agreement and this DPA. The “Customer” is the organisation identified in the account details or order; where no organisation is identified, it is the organisation on whose behalf that individual accepts the Agreement.
This DPA takes effect on the Customer’s acceptance of the Agreement (electronic acceptance is sufficient) and remains in force for the duration of the Agreement. Capitalised terms used but not defined here have the meanings given in the Agreement. In the event of conflict between this DPA and the Agreement in relation to the processing of personal data, this DPA prevails.
2. Roles
The Customer is the Controller and SeoWrite is the Processor with respect to the personal data described in Annex 1. Each party complies with its own obligations under UK GDPR (Data Protection Act 2018) and EU GDPR (“Data Protection Law”).
SeoWrite acts as an independent controller — not as the Customer’s processor — of account registration, authentication, billing and website-analytics data, as described in its Privacy Policy. This DPA applies to personal data processed within the Services on the Customer’s behalf.
3. Processor obligations (Art. 28(3))
SeoWrite shall:
- (a) Instructions. Process personal data only on the Customer’s documented instructions (this DPA, the Agreement, and the Customer’s configuration and use of the Services), unless required by law (in which case SeoWrite informs the Customer unless legally prohibited).
- (b) Confidentiality. Ensure personnel authorised to process the data are bound by confidentiality.
- (c) Security. Implement the technical and organisational measures in Annex 3 (Art. 32).
- (d) Sub-processors. The Customer gives general authorisation to the sub-processors listed at seowrite.ai/legal/sub-processors (Annex 2). SeoWrite will give at least 30 days’ notice (by email to the account’s registered email address) of any new or replacement sub-processor; the Customer may object on reasonable data-protection grounds, and if no resolution is reached may terminate the affected Services, in which case SeoWrite refunds any prepaid fees covering the period after termination. SeoWrite imposes materially equivalent obligations on each sub-processor and remains liable for their acts and omissions.
- (e) Data-subject rights. Taking into account the nature of processing, assist the Customer by appropriate technical and organisational measures to respond to data-subject requests (Art. 12–22).
- (f) Assistance. Assist the Customer with Art. 32–36 (security, breach notification, DPIAs, prior consultation), taking into account the nature of processing and the information available. Assistance under (e) and (f) is provided at no additional charge to the extent reasonable and proportionate; SeoWrite may charge reasonable, pre-notified costs for materially excessive or repetitive requests.
- (g) Return / deletion. The Customer may export and retrieve its content via the Services at any time during the term (return). On termination or closure of the Customer’s account: (i) SeoWrite automatically deletes the account identity and anonymises billing records, retaining only personal data whose retention is required by law (e.g. tax and accounting records — Art. 17(3)(b)); and (ii) SeoWrite automatically deletes the Customer’s remaining projects, content and generated images on account closure, and in any event within 30 days of closure, whether or not a request is received, unless and to the extent retention is required by law. Deletion is effected from SeoWrite’s live systems; any residual copies in encrypted backups expire within SeoWrite’s standard backup-retention cycle and are not restored save for disaster recovery of the Services.
- (h) Audit. Make available information necessary to demonstrate compliance and allow audits on 30 days’ notice, once per year, at the Customer’s cost (or via SeoWrite’s compliance documentation / sub-processor reports where sufficient). The once-per-year limit does not apply to audits required by a supervisory authority or following a personal-data breach affecting Customer data.
- (i) Infringing instructions. Immediately inform the Customer if, in SeoWrite’s opinion, an instruction from the Customer infringes UK GDPR, EU GDPR or other applicable data-protection provisions.
4. Customer (Controller) obligations
The Customer:
- warrants that its instructions to SeoWrite, and its collection and provision of personal data to the Services, comply with Data Protection Law (including having a lawful basis and giving data subjects any required notices);
- is responsible for the accuracy, quality and lawfulness of the personal data it submits in prompts, keywords, brand-voice inputs and content;
- shall not submit special-category data (Art. 9), criminal-offence data (Art. 10) or data relating to children (see Annex 1).
5. AI processing — no model training
- SeoWrite does not use Customer personal data, prompts, or generated content to train any AI model.
- SeoWrite’s AI sub-processors (Anthropic, OpenAI) process personal data via their commercial APIs. Under those providers’ commercial API terms as at the Last-updated date of this DPA: customer data submitted via API is not used to train their models; API inputs and outputs are retained for approximately 30 days by default, subject to legal and trust-and-safety exceptions (flagged content may be retained longer); and Zero-Data-Retention arrangements are available subject to provider eligibility (certain newer models are not ZDR-eligible). SeoWrite will notify Customers under clause 3(d) if a provider materially changes these terms.
- Generated content is retained only as the Customer’s content record and deleted under clause 3(g).
6. International transfers
- The Customer→SeoWrite transfer is to the UK, which benefits from an EU adequacy decision — no additional safeguards are required for EU/EEA Customers.
- Where SeoWrite transfers data to a sub-processor outside the UK/EEA, the transfer relies on the mechanism stated for that sub-processor at seowrite.ai/legal/sub-processors (Annex 2) — the EU-US Data Privacy Framework (incl. UK Extension), and/or EU Standard Contractual Clauses with the UK Addendum, and/or the UK IDTA.
- Where the Customer is established outside the UK/EEA and requires SCCs/IDTA on the Customer leg, the module in Annex 4 applies on request.
7. Breach notification
SeoWrite notifies the Customer without undue delay, and in any event within 72 hours of becoming aware, of a personal-data breach affecting Customer data, with the information the Customer reasonably needs to meet its Art. 33/34 duties.
8. Liability, term, governing law
- Liability is subject to the limitations in the Agreement. Nothing in this DPA or the Agreement excludes or limits either party’s liability to data subjects under Article 82 GDPR / UK GDPR, or any liability that cannot lawfully be excluded or limited.
- This DPA terminates with the Agreement; clauses that by nature survive (confidentiality, deletion, audit) survive termination.
- Governed by the laws of England & Wales; the courts of England & Wales have jurisdiction (subject to data subjects’ statutory rights).
9. Notices & data-protection contact
- Notices to SeoWrite under this DPA — including requests for data-subject-request assistance (clause 3(e)), deletion requests (clause 3(g)) and breach-related matters — go to [email protected].
- SeoWrite gives notices under this DPA to the Customer account’s registered email address.
Annex 1 — Details of processing (Art. 28(3))
| Subject-matter | Generation, storage and delivery of SEO/marketing content on the Customer’s instruction. |
|---|---|
| Duration | Term of the Customer’s subscription plus the retention windows in clause 3(g). |
| Nature & purpose | AI text/image generation, keyword research, plagiarism checking, publishing and content delivery. |
| Types of personal data | Any personal data the Customer includes in prompts, keywords, brand-voice inputs or generated content (e.g. names, contact details). |
| Categories of data subjects | Determined by the Customer — typically the Customer’s staff, clients, or individuals referenced in the Customer’s content. |
| Special-category data | Not requested or required; the Customer must not submit special-category data. |
Annex 2 — Sub-processors
SeoWrite’s current sub-processors, the data each processes, their location and transfer mechanism are published, and kept up to date, at seowrite.ai/legal/sub-processors. SeoWrite gives at least 30 days’ notice of any change to that list under clause 3(d).
Annex 3 — Technical & organisational measures (Art. 32)
EU/UK data residency (Hetzner Nuremberg; object-storage buckets EU-pinned); encryption in transit (TLS) and at rest; role-based access control on a need-to-know basis; secrets management; access-log retention; and encrypted offsite backups.
Annex 4 — Optional Customer-leg SCCs / UK IDTA (on request)
For Customers established outside the UK/EEA that require transfer safeguards on the Customer→SeoWrite leg: EU Standard Contractual Clauses (Decision 2021/914) Module 2 (Controller→Processor) and the UK IDTA (v B1.0), incorporated by reference and completed with the details in Annex 1. For personal data exported by SeoWrite back to a Customer established outside the UK/EEA, EU SCCs Module 4 (Processor→Controller) and/or the UK Addendum apply as appropriate. Available from [email protected] on request.