Data Processing Agreement

Last updated: 2 October 2026

This Data Processing Agreement ("DPA") is between Wolf of Blog Street, Inc., a Delaware corporation, 4501 Mission Bay Drive, Ste 3A, San Diego, CA 92109, USA ("we", "us", the processor and data importer) and the SEO Toolbox member who accepts it ("you", the controller, or a processor for your client, and the data exporter). You accept it, and it forms part of your agreement with us (the Private Beta Terms, and later the Terms of Service), when you tick the box at sign-up or log-in and use SEO Toolbox. No signature is needed. If you need a countersigned copy, write to privacy@seotoolbox.ai.

1. Definitions

"GDPR" means Regulation (EU) 2016/679; "UK GDPR" means the GDPR as it applies in the United Kingdom. "Personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have their GDPR meanings. "Client Personal Data" means personal data you load into SEO Toolbox or ask it to collect: data about your clients and their websites, their Google or Microsoft data, staff seats and client portal users, and outreach contacts. "Sub-processor" means a provider we engage to process Client Personal Data.

2. The processing (Annex I)

Subject matter and durationProviding SEO Toolbox to you, for as long as your account exists and then until deletion under section 3.7.
Nature and purposeStoring, analysing, reporting on and sending the data as the tools you or your agent run require: SEO analysis, reports and client portals, and outreach from your own mailbox.
Types of personal dataNames, email addresses, roles and public pages of contacts; portal and staff users' names and emails; outreach messages and replies; Search Console, Analytics and Business Profile data, which can include search queries; any personal data in files and notes you upload.
Data subjectsYour clients and their staff; your staff; client portal users; people you contact through outreach; people whose data appears in your connected accounts.
Frequency of transferContinuous, while you use SEO Toolbox.

3. Our obligations (GDPR Article 28(3))

  1. Instructions. We process Client Personal Data only on your documented instructions, including for transfers to a third country, unless the law requires otherwise (in which case we tell you first, unless that law forbids it). Your instructions are this DPA, your agreement with us, your settings and the runs you or your agent start under your keys. We tell you if we believe an instruction breaks data protection law.
  2. Confidentiality. Everyone we authorise to process Client Personal Data is bound by confidentiality.
  3. Security. We take the measures Article 32 requires, as section 6 describes.
  4. Sub-processors. You give us general authorisation to use the sub-processors in section 7. We tell you at least 14 days before we add or replace one, by updating this page and the Privacy Policy and by email, and you may object on reasonable data protection grounds; if we cannot resolve the objection, you may end your use of SEO Toolbox. Each sub-processor is bound by data protection terms that give the same protection as this DPA, and we remain responsible for it.
  5. Data subjects' rights. Taking into account the nature of the processing, we help you, by appropriate technical and organisational measures, to answer requests from data subjects. We pass on to you any request we receive about Client Personal Data.
  6. Assistance. We help you meet your duties under Articles 32 to 36 (security, breach notification, data protection impact assessments and prior consultation), taking into account the information available to us. We notify you of a personal data breach affecting Client Personal Data without undue delay, and within 72 hours of becoming aware of it, with the information we have.
  7. Deletion or return. When your account ends, or earlier on your request, we delete Client Personal Data, as section 8 of the Privacy Policy says, unless the law requires us to keep it; you can export your results before then. During the private beta an administrator deletes an account on request within 30 days; backups roll off within 14 days after that.
  8. Information and audits. We make available the information needed to show we meet Article 28, and allow and contribute to audits by you or an auditor you appoint: on 30 days' written notice, no more than once a year unless a supervisory authority requires it or after a personal data breach, during business hours, and bound by confidentiality. We first answer with our written documentation; each party bears its own costs.

4. Your obligations

You are responsible for having a lawful basis for the Client Personal Data you load, for giving data subjects the notices the law requires, and for your instructions being lawful. You confirm you may connect the accounts and load the data you use, and that your outreach follows the laws that apply to you (for example CAN-SPAM, GDPR, PECR and CASL).

5. Aggregated statistics and public data

We may create aggregated, de-identified statistics from use of the service and use them to run and improve SEO Toolbox, for research, and to publish industry studies. A statistic combines at least 10 accounts and 50 sites; no member, client, site, person or business-identifying search query can be identified in it, and no raw data leaves our platform. Google user data is used only as Google's Limited Use rules allow. One member's specific results are never shown to another member, and we never sell these statistics. Members contribute by default and can opt out, as section 3.10 of the Privacy Policy says.

Public data our providers return for runs (search results, keyword and backlink data) is stored and reused to run the service. It holds no member identifiers.

6. Security measures (Annex II)

7. Sub-processors (Annex III)

Sub-processorPurpose
Hetzner Online GmbH (Germany)Hosting of our servers, database and files
CloudflareNetwork, DNS, TLS, custom domains for client portals
Google (Google Workspace)Sending our emails, including portal invitations
Google (Search Console, Analytics, BigQuery, Business Profile, Gmail APIs)Your own Google data, when you connect it; sending outreach from Gmail
Microsoft (Graph)Sending outreach from Outlook and reading replies, when you connect it
AnthropicLanguage model used by several tools (summaries, report narration, topic and intent analysis, outreach drafts)
Microsoft (Azure OpenAI)Classifying backlinks in Backlink Audit
OpenAI, Google (Gemini, paid tier), PerplexityAI Visibility: asking AI engines your prompts
DataForSEO, SerperSearch results, keyword, backlink and AI Overview data for the keywords, domains and URLs of your runs
Firecrawl, Scrapfly, Steel, Driver; Webshare and DataImpulse (proxies)Fetching public web pages our own crawler cannot reach

Every AI provider in this list processes data under API terms that do not allow it to train on that data. The Privacy Policy (section 9) says what data each provider receives.

8. International transfers

  1. EU and EEA. For Client Personal Data transferred from the EU or EEA to us in the United States, the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914, Module 2 (controller to processor), are incorporated into this DPA by reference, with you as data exporter and us as data importer. Where you are a processor for your client, Module 3 (processor to processor) applies instead, in the same way. In them: Clause 7 (docking clause) applies; Clause 9(a): Option 2, general written authorisation, with 14 days' notice as section 3.4 says; the optional wording of Clause 11(a) does not apply; Clause 13: the supervisory authority of the EU Member State where you are established, or, if you are not established in the EU, of the Member State where your representative is or where the data subjects are; Clause 17: Option 2, the law of the EU Member State where you are established, or, where that law does not allow third-party beneficiary rights or you are not established in the EU, the law of Ireland; Clause 18: the courts of that same Member State. Annex I is section 2 (with the parties as above), Annex II is section 6 and Annex III is section 7.
  2. United Kingdom. For transfers from the UK, the International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the UK Information Commissioner (version B1.0, in force 21 March 2022) is incorporated by reference. Table 1: the parties above; Table 2: the clauses and options in point 1; Table 3: the annexes in point 1; Table 4: neither party may end the Addendum under its Section 19.
  3. Switzerland. For transfers from Switzerland, the clauses in point 1 apply with the Swiss Federal Data Protection and Information Commissioner as supervisory authority and references to the GDPR read as references to the Swiss Federal Act on Data Protection.
  4. Onward transfers. Our transfers to sub-processors outside the EU, EEA, UK and Switzerland rely on the same clauses or the EU-US Data Privacy Framework.

9. Liability and precedence

Each party's liability under this DPA is subject to the limits in your agreement with us, except where the Standard Contractual Clauses do not allow a limit. If this DPA conflicts with your agreement with us, this DPA prevails for Client Personal Data; if it conflicts with the Standard Contractual Clauses, the clauses prevail.

10. Term and changes

This DPA applies for as long as we process Client Personal Data for you. We may update it to reflect changes in law or in our sub-processors, as section 3.4 says; a change never lowers the protection of Client Personal Data.

Contact: privacy@seotoolbox.ai · Wolf of Blog Street, Inc., 4501 Mission Bay Drive, Ste 3A, San Diego, CA 92109, USA