Data Processing Agreement

Last updated September 18, 2026. This page is provided in English only. A legal agreement is the one document we will not machine-translate, because you would be signing a version neither of us can rely on.

This agreement forms part of our terms of service and binds NebulaSEO automatically for every customer whose use of the service involves personal data protected by the GDPR, the UK GDPR, or the CCPA, from the moment you have an account. You do not need to sign anything for it to apply. If the two documents ever disagree about personal data, this one wins.

Who is who

You are the controller of your clients’ data. NebulaSEO is your processor: we process personal data only on your documented instructions, including for any international transfer — this agreement, your dashboard settings, and your written requests are those instructions. If an instruction looks to us like it would break data-protection law, we will tell you before acting on it. Everyone we allow to touch personal data, employee or contractor, is bound to confidentiality by contract or by law. The people this data is about: your clients’ owners, staff and contact people, reviewers as Google or Yelp publish them, and your clients’ customers where a connected tool such as Jobber sends them to us. Where it concerns our processing, we will also help you with data-protection impact assessments and any consultation with a supervisory authority. Where your client is a business whose own customers leave reviews, you remain the controller of that too.

What we process, and why

Business listing details, review text and reviewer display names as Google publishes them, search-position data, the contact details you enter for a client, and the content our AI drafts for you. We process it to provide the service you are paying for and for nothing else. We do not sell it, we do not use your clients’ data to train models, and we do not use one customer’s data to serve another.

How long we keep it

For as long as the location is active on your account. Delete a location and its data goes with it. Close the account and everything goes, at your choice returned to you first via the dashboard export — except billing and tax records the law requires us to keep (see the privacy policy), which we keep only as long as that law requires and nothing else. Backups roll off within 30 days. You can export your data at any time from the dashboard without asking us. The export is a fixed set of collections, listed on the export screen; websites built in our hosted builder are hosted rather than portable and are not in it, and very large collections are capped at 5,000 rows each.

Your clients’ rights

If someone asks you to access, correct or delete their data, tell us at privacy@nebulaseo.com and we will help you answer within the time the law gives you. We will not respond to your client directly, because they are your client and not ours.

Security, and what happens if it goes wrong

Data is encrypted in transit and at rest. Access is limited to the people who need it. Sign-in is through Google, and multi-factor authentication is available on every account. If there is a breach affecting your data we will tell you without undue delay and within 72 hours of becoming aware, with what we know and what we are doing.

Where the data lives

The United States. If you are in the EU, that is an international transfer covered by the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, Module Two, controller to processor), which are incorporated into this agreement by reference. If you are in the UK, the UK Addendum to those clauses is incorporated too. They apply automatically; email us any time for a countersigned copy for your records.

Subprocessors

The other companies that touch your data, what each one does, and where they are. Each of them is bound by a written contract that imposes data-protection obligations at least as protective as this agreement, and we remain fully responsible to you for their work as if it were our own. You authorise the list below generally. We will email your account owner — and any address you subscribe by writing to privacy@nebulaseo.com with the subject “subprocessor updates” — at least 30 days before we add or replace one. If you object on data-protection grounds and we cannot resolve it, you can leave and we will refund the unused part of the month.

CompanyWhereWhat it does for you
VercelUnited StatesHosting, edge network, file storage for uploaded images
StripeUnited States / IrelandCard payments, subscriptions, agency payouts
GoogleUnited StatesBusiness Profile, Places, sign-in, Search Console, Analytics, and picture generation (the prompt a customer types)
MetaUnited StatesFacebook Pages and Instagram: the posts and images a customer chooses to publish there, and the Page and account tokens that allow it
Unsplash, Pexels, PixabayCanada / United States / GermanyFree stock photos: the search terms a customer types into the photo picker
AnthropicUnited StatesGenerates post drafts, review replies and review insights; answers dashboard-assistant and sales-chat conversations (the message text plus a snapshot of the account); summarises call transcripts for the voice agent and call tracking
TelnyxUnited StatesPhone numbers, call tracking, the voice agent
ResendUnited StatesTransactional and agency-branded email delivery
SentryUnited StatesError monitoring
UpstashUnited StatesRate limiting and short-lived cache
CloudflareUnited StatesDNS for customer domains
DataForSEOCyprusSearch-position data for the rank grid, and AI-visibility checks that send the business name and city in the query
PerplexityUnited StatesAI-visibility checks, on a manual click only
PlaidUnited StatesBank connection for referral payouts
AppleUnited StatesPush notifications to the iPhone app
Google (Firebase Cloud Messaging)United StatesPush notifications to the Android app
YelpUnited StatesReview data, where a location is connected
Jobber, Housecall ProCanada / United StatesJob data, only if the customer connects them

For California

We are your service provider under the CCPA. We do not sell or share personal information, we do not retain, use, or disclose it for any purpose other than providing the service described here or as the CCPA otherwise permits, we do not use it outside our direct relationship with you, and we do not combine it with personal information we receive from anyone else except as the CCPA allows. We certify that we understand these restrictions and will comply with them. If we ever determine we can no longer comply, we will tell you promptly, and you may take the reasonable and appropriate steps the CCPA gives you to stop and remedy any unauthorized use.

Checking our work

On request, we will give you the information you reasonably need to confirm we are keeping these promises, including a summary of our security measures. If that is not enough, you may audit us or appoint an independent auditor to do it: once a year unless a breach or a regulator gives you cause, on 30 days’ notice, during business hours, under confidentiality, at your cost. We will allow for and contribute to it, as Article 28(3)(h) GDPR requires.

Signing it

Email privacy@nebulaseo.com and we will send this as a countersigned PDF, with the Standard Contractual Clauses attached, usually the same day. You do not need to be a customer yet to ask.

See also our privacy policy and terms of service.

La lettre NebulaSEO
Faites-vous trouver dans le pack local
Des notes sur le classement local, envoyées quand il y a quelque chose à dire
Nous utiliserons votre e-mail uniquement pour cela. Vous pouvez vous désabonner à tout moment. Confidentialité