Data Processing Agreement
Version 1.0 · Last updated 9 September 2026
This Data Processing Agreement (“DPA”) applies where you use SeoWrite on behalf of an organisation and, in doing so, instruct SeoWrite to process personal data. It forms part of, and is incorporated by reference into, our Terms of Service (the “Agreement”). If you use SeoWrite for your own personal purposes, SeoWrite is a controller of your data under our Privacy Policy and this DPA does not apply to you.
1. Parties and scope
This DPA is between:
- DEVITGROUP LTD (“SeoWrite”, “Processor”), a company registered in England & Wales (Company No. 12709920), 71-75 Shelton Street, London WC2H 9JQ (ICO registration ZC078036); and
- the customer identified in the Agreement, acting on behalf of an organisation (“Customer”, “Controller”).
The individual who accepts the Agreement on the Customer’s behalf represents and warrants that they are duly authorised to bind the Customer to the Agreement and this DPA. The “Customer” is the organisation identified in the account details or order; where no organisation is identified, it is the organisation on whose behalf that individual accepts the Agreement.
This DPA takes effect on the Customer’s acceptance of the Agreement (electronic acceptance is sufficient) and remains in force for the duration of the Agreement. Capitalised terms used but not defined here have the meanings given in the Agreement. In the event of conflict between this DPA and the Agreement in relation to the processing of personal data, this DPA prevails.
2. Roles
The Customer is the Controller and SeoWrite is the Processor with respect to the personal data described in Annex 1. Each party complies with its own obligations under UK GDPR (Data Protection Act 2018) and EU GDPR (“Data Protection Law”).
SeoWrite acts as an independent controller — not as the Customer’s processor — of account registration, authentication, billing and website-analytics data, as described in its Privacy Policy. This DPA applies to personal data processed within the Services on the Customer’s behalf.
3. Processor obligations (Art. 28(3))
SeoWrite shall:
- (a) Instructions. Process personal data only on the Customer’s documented instructions (this DPA, the Agreement, and the Customer’s configuration and use of the Services), unless required by law (in which case SeoWrite informs the Customer unless legally prohibited).
- (b) Confidentiality. Ensure personnel authorised to process the data are bound by confidentiality.
- (c) Security. Implement the technical and organisational measures in Annex 3 (Art. 32).
- (d) Sub-processors. The Customer gives general authorisation to the sub-processors listed at seowrite.ai/legal/sub-processors (Annex 2). SeoWrite will give at least 30 days’ notice (by email to the account’s registered email address) of any new or replacement sub-processor; the Customer may object on reasonable data-protection grounds, and if no resolution is reached may terminate the affected Services, in which case SeoWrite refunds any prepaid fees covering the period after termination. SeoWrite imposes materially equivalent obligations on each sub-processor that processes personal data, and remains liable for their acts and omissions. Exception, stated openly: Annex 2 identifies the entries with which SeoWrite holds no Art. 28 terms because personal data is removed or redacted from the text by an automated step before it leaves SeoWrite's systems, and the request is refused rather than sent if that step cannot run. The technical control, not a contract, is the safeguard, and SeoWrite remains liable to the Customer for it. If that control is ever removed or bypassed for such an entry, SeoWrite will obtain Art. 28 terms and give notice under this clause before any personal data is sent.
- (e) Data-subject rights. Taking into account the nature of processing, assist the Customer by appropriate technical and organisational measures to respond to data-subject requests (Art. 12–22).
- (f) Assistance. Assist the Customer with Art. 32–36 (security, breach notification, DPIAs, prior consultation), taking into account the nature of processing and the information available. Assistance under (e) and (f) is provided at no additional charge to the extent reasonable and proportionate; SeoWrite may charge reasonable, pre-notified costs for materially excessive or repetitive requests.
- (g) Return / deletion. The Customer may export and retrieve its content via the Services at any time during the term (return). On termination or closure of the Customer’s account: (i) SeoWrite automatically deletes the account identity and anonymises billing records, retaining only personal data whose retention is required by law (e.g. tax and accounting records — Art. 17(3)(b)); and (ii) SeoWrite automatically deletes the Customer’s remaining projects, content and generated images on account closure, and in any event within 30 days of closure, whether or not a request is received, unless and to the extent retention is required by law. Deletion is effected from SeoWrite’s live systems; any residual copies in encrypted backups expire within SeoWrite’s standard backup-retention cycle and are not restored save for disaster recovery of the Services.
- (h) Audit. Make available information necessary to demonstrate compliance and allow audits on 30 days’ notice, once per year, at the Customer’s cost (or via SeoWrite’s compliance documentation / sub-processor reports where sufficient). The once-per-year limit does not apply to audits required by a supervisory authority or following a personal-data breach affecting Customer data.
- (i) Infringing instructions. Immediately inform the Customer if, in SeoWrite’s opinion, an instruction from the Customer infringes UK GDPR, EU GDPR or other applicable data-protection provisions.
4. Customer (Controller) obligations
The Customer:
- warrants that its instructions to SeoWrite, and its collection and provision of personal data to the Services, comply with Data Protection Law (including having a lawful basis and giving data subjects any required notices);
- is responsible for the accuracy, quality and lawfulness of the personal data it submits in prompts, keywords, brand-voice inputs and content;
- shall not submit special-category data (Art. 9), criminal-offence data (Art. 10) or data relating to children (see Annex 1).
5. AI processing — no model training
- SeoWrite does not use Customer personal data, prompts, or generated content to train any AI model.
- Web-research grounding (optional, off by default). Where the Customer enables it, a search query is sent to Tavily. Tavily’s standard terms permit it to use query text to improve its services, so this is the one outbound step SeoWrite cannot promise is excluded from model training. It is also the step that carries the least: only a constructed search query is sent, never the raw prompt or generated content, and personal data is removed from it beforehand (clause 3(d) exception, Annex 2). Customers who want no query text used this way should leave web-research grounding disabled.
- SeoWrite’s AI sub-processors (Anthropic, OpenAI) process personal data via their commercial APIs. Under those providers’ commercial API terms as at the Last-updated date of this DPA: customer data submitted via API is not used to train their models; API inputs and outputs are subject to limited retention — not retained by default, with retention of up to approximately 30 days for certain models or for abuse monitoring — in each case subject to legal and trust-and-safety exceptions (flagged content may be retained longer); and Zero-Data-Retention arrangements are available subject to provider eligibility (certain models are not ZDR-eligible). SeoWrite will notify Customers under clause 3(d) if a provider materially changes these terms.
- Generated content is retained only as the Customer’s content record and deleted under clause 3(g).
6. International transfers
- The Customer→SeoWrite transfer is to the UK, which benefits from an EU adequacy decision — no additional safeguards are required for EU/EEA Customers.
- Where SeoWrite transfers data to a sub-processor outside the UK/EEA, the transfer relies on the mechanism stated for that sub-processor at seowrite.ai/legal/sub-processors (Annex 2) — the EU-US Data Privacy Framework (incl. UK Extension), and/or EU Standard Contractual Clauses with the UK Addendum, and/or the UK IDTA.
- Where the Customer is established outside the UK/EEA and requires SCCs/IDTA on the Customer leg, the module in Annex 4 applies on request.
7. Breach notification
SeoWrite notifies the Customer without undue delay, and in any event within 72 hours of becoming aware, of a personal-data breach affecting Customer data, with the information the Customer reasonably needs to meet its Art. 33/34 duties.
8. Liability, term, governing law
- Liability is subject to the limitations in the Agreement. Nothing in this DPA or the Agreement excludes or limits either party’s liability to data subjects under Article 82 GDPR / UK GDPR, or any liability that cannot lawfully be excluded or limited.
- This DPA terminates with the Agreement; clauses that by nature survive (confidentiality, deletion, audit) survive termination.
- Governed by the laws of England & Wales; the courts of England & Wales have jurisdiction (subject to data subjects’ statutory rights).
9. Notices & data-protection contact
- Notices to SeoWrite under this DPA — including requests for data-subject-request assistance (clause 3(e)), deletion requests (clause 3(g)) and breach-related matters — go to [email protected].
- SeoWrite gives notices under this DPA to the Customer account’s registered email address.
EU representative (Article 27)
SeoWrite is established in the UK and has appointed an EU/EEA representative under Article 27 of the EU GDPR. The representative (DataRep) and its full contact details — including the list of EU/EEA postal addresses — are set out in our Privacy Policy.
Annex 1 — Details of processing (Art. 28(3))
| Subject-matter | Generation, storage and delivery of SEO/marketing content on the Customer’s instruction. |
|---|---|
| Duration | Term of the Customer’s subscription plus the retention windows in clause 3(g). |
| Nature & purpose | AI text/image generation, keyword research, plagiarism checking, publishing and content delivery. |
| Types of personal data | Any personal data the Customer includes in prompts, keywords, brand-voice inputs or generated content (e.g. names, contact details). |
| Categories of data subjects | Determined by the Customer — typically the Customer’s staff, clients, or individuals referenced in the Customer’s content. |
| Special-category data | Not requested or required; the Customer must not submit special-category data. |
Annex 2 — Sub-processors
SeoWrite’s current sub-processors, the data each processes, their location and transfer mechanism are published, and kept up to date, at seowrite.ai/legal/sub-processors. SeoWrite gives at least 30 days’ notice of any change to that list under clause 3(d).
Annex 3 — Technical & organisational measures (Art. 32)
EU/UK data residency (Hetzner Nuremberg; object-storage buckets EU-pinned); encryption in transit (TLS) and at rest; role-based access control on a need-to-know basis; secrets management; access-log retention; and encrypted offsite backups.
Annex 4 — Optional Customer-leg SCCs / UK IDTA (on request)
For Customers established outside the UK/EEA that require transfer safeguards on the Customer→SeoWrite leg: EU Standard Contractual Clauses (Decision 2021/914) Module 2 (Controller→Processor) and the UK IDTA (v B1.0), incorporated by reference and completed with the details in Annex 1. For personal data exported by SeoWrite back to a Customer established outside the UK/EEA, EU SCCs Module 4 (Processor→Controller) and/or the UK Addendum apply as appropriate. Available from [email protected] on request.