Data Processing Agreement

What we do with the personal data you entrust to us, what we will never do with it, and the commitments you can hold us to.

Last updated: 5 September 2026

This Data Processing Agreement governs our processing of personal data on your behalf under Article 28 of the GDPR. It forms part of your contract with us and takes effect without signature. Where you need a countersigned copy for your own records, write to legal@keupera.com.

Contents

§1 Parties, Roles and Incorporation

1.1 Parties. This Data Processing Agreement ("DPA") is concluded between the customer identified in the Keupera account ("Controller", "you") and Keupera, a sole proprietorship of Ole Nepomuk Mai, Goethestrasse 70, 10625 Berlin, Germany ("Processor", "we", "us").

1.2 Incorporation. This DPA forms an integral part of the Terms of Service and applies automatically from the moment you begin using any part of the Services that involves our processing of personal data on your behalf. No signature is required for it to take effect. Where your procurement process requires a countersigned copy, write to legal@keupera.com and we will provide one.

1.3 Roles. In respect of the processing described in Annex I, you act as controller and we act as processor within the meaning of Art. 4(7) and 4(8) GDPR. Where you are yourself a processor for your own client — for example where you operate an agency workspace — we act as sub-processor, this DPA applies with the necessary changes, and you warrant that you are authorised by your own controller to appoint us.

1.4 Separate document. Processing in which we act as controller in our own right — your account, your billing relationship, our own marketing and security — is not governed by this DPA. It is described in our Privacy Policy at /legal/privacy.

1.5 Precedence. In respect of the processing of personal data, this DPA prevails over any conflicting provision of the Terms of Service. Where the Standard Contractual Clauses incorporated under § 11 conflict with this DPA, the Standard Contractual Clauses prevail.

1.6 Term. This DPA takes effect on the earlier of your acceptance of the Terms of Service and your first use of the Services, and continues for as long as we process personal data on your behalf, together with the obligations in § 12 that survive it.

§2 Subject Matter, Duration, Nature and Purpose

2.1 Subject matter. Provision of the Keupera search and generative-engine optimisation platform, as described in the Terms of Service and the product documentation.

2.2 Duration. The term of the Terms of Service, plus the deletion and return period in § 12.

2.3 Nature of the processing. Collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure by transmission, alignment, combination, restriction, erasure and destruction — in each case by automated means and in each case only as required to provide the Services you have configured.

2.4 Purpose. Exclusively the provision of the Services to you. We do not process personal data covered by this DPA for our own purposes. In particular we do not use it to train, fine-tune or otherwise develop any artificial-intelligence or machine-learning model, and we do not sell it or disclose it for advertising.

2.5 Categories of data subject and personal data. Annex I.

§3 Processing on Documented Instructions

3.1 Instructions. We process personal data only on your documented instructions, including as regards transfers to a third country, unless required to do otherwise by Union or Member State law to which we are subject. In that case we inform you of the legal requirement before processing, unless that law prohibits such information on important grounds of public interest.

3.2 What constitutes an instruction. Your complete instructions consist of: the Terms of Service; this DPA; the product documentation; the configuration you make in the Services; and any further written instruction you give under § 3.4. By configuring the Services you instruct us in particular to:

  • crawl and analyse the Target Websites you specify, at the depth and frequency you configure
  • retrieve Search Console data from the property you connect
  • transmit content and prompts to the AI sub-processors in Annex III in order to produce the outputs you request
  • publish content to the content management systems you connect, at the times you schedule
  • transmit outbound messages through the mail server you configure
  • collect website analytics from the domains you register, using the script you deploy
  • collect and store the leads submitted through the widgets you deploy

3.3 Unlawful instructions. We inform you without delay if, in our opinion, an instruction infringes the GDPR or other Union or Member State data protection law. We may suspend performance of that instruction until it is confirmed, amended or withdrawn.

3.4 Additional instructions. Instructions beyond the standard functionality of the Services must be given in text form to legal@keupera.com. We may charge for the reasonable cost of implementing them, having told you in advance.

3.5 Territory. Processing takes place within the European Economic Area, save for the transfers identified in Annex III and governed by § 11.

§4 Confidentiality

4.1 Undertaking. We ensure that persons authorised to process personal data under this DPA have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. That obligation survives the end of their engagement.

4.2 Authorised persons. Access is restricted to those who need it to provide the Services or to support you. In our organisation this means the proprietor and, where engaged, individual contractors bound in writing to obligations no less protective than those in this DPA.

4.3 Need to know. We do not access the content of your workspace except where necessary to provide a support response you have requested, to investigate a security incident, to comply with a legal obligation, or to prevent or address a technical fault. Where we do, access is limited to what the purpose requires.

4.4 Training. Persons authorised to process are instructed on the requirements of this DPA and on our security measures before they are given access.

§5 Security of Processing

5.1 Measures. We implement the technical and organisational measures set out in Annex II, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing, as well as the risk to the rights and freedoms of natural persons.

5.2 Changes. We may change individual measures, provided the level of protection is not reduced. Annex II reflects the measures in force from time to time and is published at /legal/security.

5.3 Honesty about limits. Annex II states what we do and, expressly, what we do not yet do. We hold no ISO 27001 or SOC 2 certification and do not represent that we do. We would rather you assess us on an accurate description than on an aspirational one.

5.4 Your own measures. You remain responsible for the security of your own systems, for the strength and confidentiality of the credentials used to access the Services, for the roles you assign to your Members, and for the security of any endpoint to which you direct our outbound webhooks.

§6 Sub-processors

6.1 General authorisation. You give us general written authorisation to engage sub-processors. The sub-processors engaged at the date of this DPA are listed in Annex III and published, always current, at /legal/subprocessors.

6.2 Notice of changes. Before we add or replace a sub-processor that processes personal data covered by this DPA, we notify you at least 30 days in advance, by email to the address of the Organisation owner and by updating the published list. You may subscribe to change notices on that page.

6.3 Objection. You may object to a proposed sub-processor within 30 days of notice, on reasonable grounds relating to data protection, by writing to legal@keupera.com. We will discuss the objection with you in good faith and will seek a reasonable accommodation, such as an alternative provider or a change of configuration. If none is available, you may terminate the affected Services without penalty and we will refund prepaid fees for the unused period on a pro-rata basis.

6.4 Emergency replacement. Where a sub-processor must be replaced at short notice to preserve the security or availability of the Services, we may do so immediately and will notify you as soon as possible, with reasons. Your right of objection under § 6.3 then applies retrospectively.

6.5 Flow-down. We engage each sub-processor under a written contract imposing data protection obligations that are materially the same as those imposed on us by this DPA, in particular the obligation to implement appropriate technical and organisational measures.

6.6 Our liability. Where a sub-processor fails to fulfil its data protection obligations, we remain fully liable to you for the performance of that sub-processor's obligations.

6.7 Not sub-processors. Providers you select and connect yourself — in particular the mail server through which outbound messages are sent, the content management systems you connect, and any third-party AI client you connect to our MCP server or ChatGPT app — are your suppliers, not our sub-processors. We have no contractual relationship with them and no control over them.

§7 Assistance to the Controller

7.1 Data subject rights. Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures, insofar as this is possible, in fulfilling your obligation to respond to requests to exercise the rights in Chapter III GDPR. The Services themselves provide much of this assistance: you can export, correct and delete records directly, and delete an entire workspace.

7.2 Requests received by us. If a data subject contacts us directly in relation to personal data we process on your behalf, we will not respond substantively. We will confirm receipt, forward the request to you without undue delay and in any event within 5 working days, and assist you as § 7.1 provides.

7.3 Assistance with Articles 32 to 36. We assist you in ensuring compliance with the obligations in Arts. 32 to 36 GDPR, taking into account the nature of the processing and the information available to us. This includes providing the information you need for a data protection impact assessment and, where required, for prior consultation with a supervisory authority.

7.4 Personal data breach. We notify you of a personal data breach affecting personal data processed on your behalf without undue delay and in any event within 48 hours of becoming aware of it. The notification will describe, as far as is then known, the nature of the breach including the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed; and a contact point. Where the information cannot be provided at once, it will be supplied in phases without further undue delay.

7.5 No delay for investigation. We will not delay notification under § 7.4 in order to complete our investigation. Notifying you is your right, not our discretion.

7.6 Cost. Assistance under this section is provided at no charge, save where a request is manifestly unfounded or excessive, or where it requires engineering work materially beyond the standard functionality of the Services, in which case we will agree a reasonable charge with you in advance.

§8 Your Obligations as Controller

The Services depend on you doing the following. We set them out expressly, because several of them cannot be performed by us on your behalf.

8.1 Lawful basis. You must have a lawful basis under Art. 6 GDPR — and, where applicable, Art. 9 — for all personal data you submit to the Services or instruct us to collect.

8.2 Transparency. You must provide your own data subjects with the information required by Arts. 13 and 14 GDPR, including the fact that we act as your processor.

8.3 Consent for the analytics script. Our website analytics script contains no consent mechanism and begins collecting when the page loads. You must obtain valid consent under Art. 5(3) of the ePrivacy Directive and § 25 TDDDG, or the equivalent rule in the relevant jurisdiction, before the script is loaded, and configure your site accordingly.

8.4 Lead capture. Where you deploy the embeddable audit widget with lead capture, you must present your own privacy notice at the point of capture and must have a lawful basis for the collection and for any subsequent contact. The consent timestamp we record is evidence of the time of submission only. It is not evidence of valid consent, and must not be presented as such.

8.5 Outreach. You must have a lawful basis for contacting the recipients of any message sent through the Services, and must comply with § 7 UWG, the CAN-SPAM Act and every equivalent law. You are the sender and the controller of those communications.

8.6 Connected accounts. You must be entitled to grant the access you grant, and to authorise the actions you configure.

8.7 Prohibited content. You must not submit special categories of personal data under Art. 9 GDPR, personal data relating to criminal convictions and offences under Art. 10 GDPR, or personal data of children, unless we have agreed in writing in advance and have implemented the additional measures that such data requires.

8.8 Retention configuration. Where the Services offer a retention setting — for example the analytics retention period — you are responsible for setting it in accordance with your own retention policy.

8.9 Accuracy of instructions. You are responsible for the lawfulness of your instructions and for the accuracy, quality and legality of the personal data you provide.

§9 Audit and Demonstration of Compliance

9.1 Information. We make available to you all information necessary to demonstrate compliance with Art. 28 GDPR and with this DPA. That information comprises this DPA and its Annexes, the security description at /legal/security, the sub-processor list at /legal/subprocessors, our Privacy Policy, and — on request — the certifications and audit reports our sub-processors make available to us.

9.2 Requests for further information. You may request further information relevant to our compliance once in any twelve-month period, and additionally following a personal data breach affecting your data, or where a supervisory authority requires it. We respond within 30 days.

9.3 On-site audit. Where the information provided under §§ 9.1 and 9.2 is genuinely insufficient to demonstrate compliance, you may audit us, including by inspection. Such an audit requires at least 30 days' written notice, must take place during ordinary business hours, must not unreasonably disrupt our operations, is limited to the processing carried out for you, and is conducted subject to confidentiality. Access to systems and data of other customers is excluded.

9.4 Auditors. You may appoint an independent third-party auditor, provided that auditor is not a competitor of ours and enters into a confidentiality undertaking with us. We may object, on reasonable grounds, to a particular auditor, and you will then appoint another.

9.5 Cost. Audits under § 9.3 are at your cost, including our reasonable costs of participation, save where the audit reveals a material breach of this DPA by us, in which case we bear our own costs.

9.6 Proportionality. We are a very small organisation. We take these obligations seriously and will meet them fully; we ask in return that audit requests be proportionate to the risk of the processing actually carried out for you.

9.7 Supervisory authorities. Nothing in this section limits the powers of a supervisory authority. We cooperate with supervisory authorities in the performance of their tasks, as Art. 31 GDPR requires.

§10 Records of Processing

10.1 Our record. We maintain a record of all categories of processing carried out on behalf of controllers, as required by Art. 30(2) GDPR, containing the name and contact details of each controller, the categories of processing, the transfers to third countries and their safeguards, and a general description of the measures in Annex II.

10.2 Availability. We make that record available to a supervisory authority on request, and to you insofar as it concerns the processing carried out for you.

10.3 Data protection officer. We have not appointed a data protection officer; the threshold in § 38(1) sentence 1 BDSG is not met. Our contact point for all matters under this DPA is legal@keupera.com. Should an appointment become necessary, we will notify you and publish the contact details.

§11 International Transfers

11.1 Principal locations. The primary database, file storage and application backend are located in the European Union (Ireland). The analytics store, crawler and MCP server are located in Germany. Product analytics is hosted in the European Union.

11.2 Transfers outside the EEA. The sub-processors marked accordingly in Annex III process personal data outside the European Economic Area, principally in the United States.

11.3 Standard Contractual Clauses. For those transfers, the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914 are hereby incorporated into this DPA by reference and form an integral part of it:

  • Module Two (controller to processor) where you act as controller
  • Module Three (processor to processor) where you act as processor for your own controller
  • Clause 7 (docking) applies. Clause 9, Option 2 (general written authorisation) applies, with the notice period in § 6.2. Clause 11(a), the optional independent dispute resolution body, does not apply. Clause 17: the governing law is the law of the Federal Republic of Germany. Clause 18(b): the competent courts are those of Berlin, Germany.
  • Annex I.A, I.B and Annex II of the Standard Contractual Clauses are populated by Annex I and Annex II of this DPA respectively; Annex III of the Standard Contractual Clauses is populated by Annex III of this DPA.

11.4 The EU–US Data Privacy Framework. Several of our sub-processors are certified under the Framework, and its adequacy decision remains in force. We do not rely on the Framework as our sole basis for any transfer, because an appeal against the judgment upholding the adequacy decision is pending before the Court of Justice. The Standard Contractual Clauses stand independently of that outcome.

11.5 Transfer impact assessment. We have carried out and documented an assessment of the transfers in Annex III, covering the legal regime of the destination country, the practical likelihood of access by public authorities, and the supplementary technical and organisational measures applied. A summary is available on request.

11.6 United Kingdom and Switzerland. Where the UK GDPR applies, the International Data Transfer Addendum issued by the Information Commissioner applies to the Standard Contractual Clauses. Where the Swiss FADP applies, references to the GDPR are read as references to the FADP and the competent authority is the Federal Data Protection and Information Commissioner.

11.7 Requests from public authorities. If we receive a legally binding request from a public authority for personal data processed on your behalf, we will notify you before responding unless prohibited from doing so, will challenge the request where there is a reasonable basis to do so, and will disclose only the minimum permissible. We will maintain and, on request, provide a record of such requests to the extent the law allows.

§12 Deletion and Return

12.1 Your choice. On termination of the Services, and at your choice, we delete or return all personal data processed on your behalf, and delete existing copies, unless Union or Member State law requires storage.

12.2 Export first. Export tools are available throughout the term and during the transitional period under the switching provisions of the Terms of Service. We recommend exporting before termination.

12.3 Default and deadline. If you give no instruction, we delete the personal data within 30 days of the end of the transitional period following termination.

12.4 Backups. Personal data removed from live systems persists in encrypted backups until those backups age out on their ordinary rotation cycle, after which it is overwritten. Backups are not selectively edited. Data in backups remains subject to this DPA until it is overwritten, and a restored backup is re-processed to remove data that was deleted in the interim.

12.5 Statutory retention. Where Union or German law requires us to retain data — in particular under § 257 HGB and § 147 AO — we retain only what the obligation requires, restrict processing of it to that purpose, and delete it when the period ends.

12.6 Confirmation. We confirm deletion in text form on request.

§13 Liability and General Provisions

13.1 Liability. Liability under this DPA is governed by Art. 82 GDPR and, in respect of contractual claims between the parties, by the liability provisions of the Terms of Service. Nothing in this DPA limits a data subject's rights under Art. 82 GDPR or the powers of a supervisory authority.

13.2 Changes to this DPA. We may amend this DPA where required by a change in applicable data protection law, in the decisions of a supervisory authority or court, or in the composition of the Services. We give at least 30 days' notice in text form. Where an amendment materially reduces the protection afforded to you, you may terminate the affected Services with effect from the date it would take effect.

13.3 Severability. If a provision of this DPA is or becomes invalid, the remainder is unaffected, and the invalid provision is replaced by a valid provision that comes closest to its purpose and to the requirements of Art. 28 GDPR.

13.4 Governing law and jurisdiction. German law applies. The place of jurisdiction is Berlin, subject to the mandatory rules applicable to consumers and to Clause 18 of the Standard Contractual Clauses.

13.5 Contact. All notices under this DPA are to be sent to legal@keupera.com.

Annex I — Description of the Processing

A. List of parties

Data exporter / controller: the customer identified in the Keupera account, at the address held in the account. Contact: the Organisation owner's email address. Activities: use of the Keupera platform for search and generative-engine optimisation. Role: controller, or processor where acting for its own client.

Data importer / processor: Keupera, Ole Nepomuk Mai, Goethestrasse 70, 10625 Berlin, Germany. Contact: legal@keupera.com. Activities: provision of the Keupera platform. Role: processor, or sub-processor as the case may be.

B. Categories of data subject

  • Your Members and users of your Organisation
  • Your own clients, where you use the agency workspace
  • Visitors to the websites on which you deploy our analytics or bot-tracking script
  • Persons who submit a form to an audit widget you have embedded
  • Owners of and contacts at third-party websites identified through backlink and outreach research
  • Recipients of outbound messages you send through the Services
  • Any identifiable person named in content you create, upload or generate
  • Searchers whose queries appear, in aggregated form, in Search Console data

C. Categories of personal data

  • Identity and contact data: names, email addresses, telephone numbers, company names, job roles
  • Account and access data: user identifiers, roles, website assignments, activity timestamps
  • Client relationship data in the agency workspace: contact details, commercial notes, revenue figures, deal status
  • Online identifiers: pseudonymous visitor identifiers, session identifiers, guest tokens
  • Device and connection data: user-agent strings, browser, operating system, device type, country, city, referring page — and, in uploaded server log files, raw IP addresses
  • Content data: articles, analyses, comments, team messages, notes, images, prompts and model outputs
  • Search performance data retrieved from a connected Search Console property
  • Credentials for connected systems, held in encrypted form

D. Special categories. None is intended, requested or permitted. See § 8.7.

E. Frequency. Continuous, for the duration of the Services.

F. Nature and purpose. As set out in § 2.

G. Retention. For the duration of the Services and the deletion period in § 12, subject to any shorter retention you configure and to the statutory periods in § 12.5. The analytics store applies your plan's retention setting, with an absolute ceiling of two years.

H. Sub-processor processing. Each sub-processor in Annex III processes for the duration of its engagement, for the purpose stated against its entry.

Annex II — Technical and Organisational Measures

These are the measures in force. The current version is published at /legal/security.

Pseudonymisation and encryption

  • TLS for all data in transit, on every public endpoint
  • Encryption at rest at the infrastructure layer for the database, file storage and analytics store
  • AES-256-GCM encryption, under a dedicated key held only in the server environment, for credentials of connected accounts: OAuth tokens, content-management credentials and mail server passwords
  • API keys stored only as SHA-256 hashes; account passwords stored only as salted hashes by the authentication provider
  • Visitor IP addresses hashed before entering the analytics store; the raw address is not persisted there

Confidentiality — access control

  • Row-level security in the database isolates each Organisation's records at the data layer
  • A four-tier role model restricts Members to assigned websites and permitted actions
  • Columns holding credentials are unreachable from the browser: they carry no client-side grant and are read only by server-side code
  • Tables holding operational and abuse-prevention data have no client-side grant at all
  • Internal services authenticate to one another with dedicated shared secrets
  • The analytics database and queue are not exposed to the public internet; host firewalling restricts inbound traffic

Integrity

  • Authenticated encryption (GCM) for credentials, so tampering is detected rather than silently decrypted
  • Signature verification on inbound billing webhooks
  • Structured application and function logging, with secrets excluded from logs

Availability and resilience

  • Managed, replicated database infrastructure with provider-operated backups
  • Job queues with automatic retry and stale-job recovery
  • Scheduled maintenance jobs that enforce retention and clean up expired records

Restoration

  • Point-in-time restore capability provided by the database platform
  • Restored data is re-processed to remove records deleted in the interim

Data minimisation and storage limitation

  • Automated retention jobs enforcing the periods described in our Privacy Policy
  • Per-plan retention configuration for the analytics store, with an absolute two-year ceiling
  • Cascading deletion of a workspace and its dependent records

Governance

  • A named single point of contact for security and data protection: security@keupera.com and legal@keupera.com
  • Documented sub-processor list with a 30-day change-notification commitment
  • A record of processing under Art. 30(2) GDPR
  • Written confidentiality undertakings from any contractor engaged

What we do not yet have. We state this deliberately, so that you can assess us accurately:

  • No ISO 27001, SOC 2 or comparable certification
  • No independent third-party penetration test
  • No formal, tested incident-response exercise programme
  • No formal, tested backup-restoration exercise programme
  • No 24/7 security monitoring or on-call rotation

We are working on these, and this Annex is updated as each is put in place. If any of them is a precondition for your use of the Services, please tell us before you contract rather than afterwards.

Annex III — Sub-processors

The authoritative and always-current list, including the legal entity, address, purpose and transfer mechanism for each sub-processor, is published at /legal/subprocessors. It is incorporated into this DPA by reference and forms Annex III.

Summary at the date of this DPA.

Infrastructure (European Union): Supabase, Inc. (database, authentication, storage, serverless functions; data hosted in AWS eu-west-1, Ireland); Hetzner Online GmbH, Germany (analytics store, crawler, MCP server); PostHog, Inc. (product analytics, EU Cloud region).

Infrastructure (United States): Netlify, Inc. (application hosting and content delivery).

Commerce: Polar Software, Inc., United States (merchant of record; payment, subscription and invoicing data).

Artificial intelligence: OpenAI, L.L.C., United States (all text generation and analysis); BFL GmbH, Germany (image generation).

Search and web data: Bright Data Ltd., Israel (search-engine result and backlink data); browserless.io, Inc., United States (page screenshots).

Communications: Plus Five Five, Inc. (Resend), United States (transactional email sent by us); Mailgun Technologies, Inc., United States (contact and partner form delivery from our website).

Connected platforms: Google Ireland Limited (sign-in and the Search Console API, where you connect a property).

Analytics and attribution on our own websites: Visitor Analytics GmbH (TWIPLA), Germany; Simple Analytics B.V., Netherlands; ZASolution (Affonso), Germany; Artia International S.R.L. (ip-api), Romania.

Content: Contentful GmbH, Germany (our own blog and resource library; no customer data).

Transfer mechanism. Entities established outside the European Economic Area process on the basis of the Standard Contractual Clauses incorporated under § 11, save for Bright Data Ltd., which is covered by the European Commission's adequacy decision for Israel.