Data Processing Agreement
Last updated: 2026-05-18
This DPA forms part of the Terms of Service between Monitelia ("Processor") and the Customer ("Controller") for processing of personal data under GDPR Art. 28.
1. Definitions
"Personal data", "data subject", "processing", "controller", "processor", "sub-processor" have the meanings given in GDPR Art. 4. "Customer Data" means data the Controller (or its end users) submits through the service.
2. Roles
- For Customer Data submitted through the service, the Customer is the Controller and Monitelia is the Processor.
- For Account Data (the Customer's own email, billing details, audit log) Monitelia is an independent Controller.
3. Subject matter + duration
Monitelia processes Customer Data to provide the SEO monitoring service described in the Terms of Service, for as long as the Customer has an active account plus a 30-day post-termination deletion window.
4. Nature, purpose, and categories
- Nature: storage, indexing, aggregation, transformation, export, transmission to sub-processors strictly to deliver service.
- Purpose: SEO crawling, rank tracking, brand monitoring, reporting.
- Categories of data subjects: the Customer's own staff (team members) and end users whose data appears in scraped web/social content the Customer chooses to monitor.
- Categories of personal data: names, email addresses, public social media handles, public posts, URLs, IP addresses (in audit log of Customer's own actions).
5. Processor obligations (GDPR Art. 28(3))
- Process only on documented instructions from the Controller (these terms and what the Controller configures in the UI).
- Ensure persons authorised to process are under appropriate confidentiality obligations.
- Implement the security measures described in Section 8.
- Engage sub-processors only on the conditions in Section 6.
- Assist the Controller with GDPR Art. 32-36 obligations.
- Assist the Controller in responding to data-subject requests (the dashboard provides export + delete; bespoke requests via
privacy@yourdomain.com). - On termination, delete or return Customer Data, except where retention is required by law.
- Make available all info necessary to demonstrate compliance and allow audits — see Section 9.
6. Sub-processors
Current list is published at the bottom of the Privacy Policy. We notify Controllers of changes by email at least 14 days before adding a new sub-processor; the Controller may object and terminate the affected service proportionate to the impact.
7. International transfers
Where personal data is transferred outside the EEA, the parties adopt the EU Standard Contractual Clauses (Module Two: controller-to-processor) by reference, with this DPA as the umbrella agreement.
8. Security measures (GDPR Art. 32)
- TLS 1.2+ for all data in transit
- Encryption at rest (provided by Supabase + Storage)
- Tenant isolation via PostgreSQL row-level security
- Bcrypt password hashing
- SHA-256 API token storage
- Audit logging of sensitive admin actions
- Principle of least privilege for staff access
- Sub-processors selected for SOC 2 / ISO 27001 compliance where available
- Point-in-time recovery + weekly application-level backups
9. Audits
The Controller (or an independent auditor under NDA) may audit compliance with this DPA up to once per year, on 30 days' notice, during business hours, at the Controller's expense, and without disrupting our operations or other customers' data.
10. Data breach notification
We will notify the Controller without undue delay (and in any case within 72 hours) of becoming aware of a personal data breach affecting Customer Data, with the information required by Art. 33(3).
11. Liability + indemnity
Each party's liability under this DPA is subject to the limits set out in the Terms of Service.
12. Term + termination
This DPA stays in effect for as long as Customer Data is processed. On termination of the service, we delete Customer Data within 30 days unless retention is legally required.
13. Order of precedence
If this DPA conflicts with the Terms of Service for processing of personal data, this DPA prevails. The SCCs (where applicable) prevail over both.
Signature (optional)
By using the service the Controller is deemed to have accepted this DPA. Enterprise customers may also request a signed copy atlegal@yourdomain.com.