Data Processing Addendum
Effective: 4 September 2026
1. About this Addendum
This Data Processing Addendum (“DPA”) forms part of the agreement between Bee Bizzi Ltd, trading as SEO Toolz (“SEO Toolz”, “we”, “us”), and the customer that has agreed to our Terms of Service (“Customer”, “you”). It applies where we process personal data on your behalf in the course of providing the Service. Where this DPA conflicts with the Terms of Service on the subject of data protection, this DPA prevails.
2. Roles of the parties
For personal data processed under this DPA, the Customer acts as the Controller and SEO Toolz acts as the Processor. Where the Customer is itself a processor acting on behalf of a third party (for example, an agency acting for its own client), SEO Toolz acts as a sub-processor and the Customer is responsible for the instructions it passes on.
3. Scope and purpose of processing
SEO Toolz processes personal data only to provide and support the Service: SEO analytics and reporting, competitor and gap analysis, rank tracking, site crawling, AI-powered recommendations and content generation, the client portal, lead capture, and related platform functionality. We process personal data in accordance with your documented instructions, which are given through your configuration and use of the Service and through this DPA, unless required otherwise by applicable law.
4. Categories of data and data subjects
Depending on how you use the Service, the personal data processed may include:
- Account and team-member details (name, email address, authentication data);
- Client-portal user details you invite (name, email address);
- Contact details submitted through lead-capture forms and the chatbot on sites you connect;
- Data returned by connected third-party accounts you authorise (e.g. Google Search Console, Google Business Profile);
- Usage and audit records generated by your use of the Service.
Data subjects may include your staff, your clients’ staff, portal users, and individuals who submit their details through forms on websites you connect to the Service.
5. Security measures
SEO Toolz maintains technical and organisational measures appropriate to the risk, including:
- Encryption of data in transit (TLS) and at rest (AES-256, provided by our infrastructure providers);
- Application-layer encryption of third-party API credentials that customers store in the Service;
- Multi-factor authentication (TOTP) available on all accounts and enforced once enabled;
- Passwords stored only as salted hashes;
- Role-based access controls and least-privilege administrative access;
- Row-level security isolating each account’s data;
- Audit logging of account activity.
6. Sub-processors
You authorise SEO Toolz to engage sub-processors to provide parts of the Service (for example, hosting, database, email delivery, payment processing, AI model providers, and SEO data). Our current sub-processors and the purpose of each are available on request and are summarised in our Privacy Policy. We will give at least 30 days’ notice of the addition or replacement of a sub-processor that processes customer personal data, and you may object on reasonable data-protection grounds. Each sub-processor is bound by terms no less protective than this DPA for the processing it performs.
7. International transfers
Our primary database and authentication are hosted within the EU. Some sub-processors operate in the United States or elsewhere. Where personal data is transferred outside the UK or EEA, SEO Toolz relies on the transfer mechanisms and contractual safeguards offered by the relevant provider (such as Standard Contractual Clauses and the UK Addendum) to support a lawful transfer.
8. Personal data breaches
SEO Toolz will notify you without undue delay after becoming aware of a personal data breach affecting your customer data, and will provide the information reasonably needed for you to meet your own notification obligations. We will take reasonable steps to contain and remediate the breach.
9. Assistance to the Controller
Taking into account the nature of the processing, SEO Toolz will provide reasonable assistance to help you respond to data-subject requests for access, rectification, erasure, restriction, portability, and objection, and to help you meet obligations relating to security, breach notification, and data-protection impact assessments. Where a data subject contacts SEO Toolz directly about Customer data, we will refer them to you.
10. Return and deletion of data
On termination of your account, or on your written request, SEO Toolz will delete the personal data it processes on your behalf — including projects, crawl data, reports, portal users, and stored integrations — except where retention is required by law. A one-way, non-reversible hash of the account email address may be retained solely to enforce one free trial per email. Backups age out on our providers’ standard cycles.
11. Audits
SEO Toolz will make available the information reasonably necessary to demonstrate compliance with this DPA, in the first instance through documentation and completed security questionnaires. Further audit steps may be agreed where reasonably justified, on reasonable notice and no more than once per year unless required by a supervisory authority.
12. Requesting a countersigned copy
If your organisation requires a signed copy of this DPA, or a copy on your own paper, email hello@seotoolz.app and we will arrange it.
13. Contact
Questions about this DPA or our data-processing practices? Email hello@seotoolz.app.