Data processing agreement
This DPA applies where YourReporting processes personal data on behalf of a customer ("the Agency") in the course of providing the Service. It is designed to satisfy Article 28 UK GDPR without a signature round-trip: accepting the Terms accepts this DPA. If your client requires a countersigned copy, email [email protected].
1. Roles and scope
The Agency is controller (or processor for its own clients); YourReporting is processor. The processing: retrieval of website performance data from Google properties mapped by the Agency; storage of monthly report snapshots; generation and delivery of reports to recipients configured by the Agency. Duration: the life of the account. Data subjects: visitors to the mapped websites (aggregate-level data) and report recipients. Categories: aggregated site-usage metrics, search queries, page paths; recipient names and email addresses.
2. Instructions
We process only on the Agency's documented instructions — the configuration made in the product is the instruction — unless UK law requires otherwise, in which case we inform the Agency unless prohibited.
3. Confidentiality and security
Personnel access to customer data is limited, logged, and permitted only for support the Agency has requested, or for security and legal compliance. Measures include: encryption in transit (TLS) and at rest for credentials, tenant isolation enforced and tested in code, audit logging of access to client data, and scrubbing of tokens and personal data from error telemetry.
4. Sub-processors
The Agency authorises the sub-processors listed at /legal/subprocessors. We will give at least 30 days' notice by email before adding or replacing one, during which the Agency may object on reasonable data-protection grounds; if we cannot resolve the objection, the Agency may terminate with a pro-rata refund of prepaid fees.
5. Data subject rights and assistance
Taking into account the nature of the processing, we assist the Agency with data subject requests, security, breach notification, and impact assessments, at no charge for reasonable requests.
6. Breach notification
We notify the Agency without undue delay, and in any case within 72 hours, of becoming aware of a personal data breach affecting its data, with the information Article 33(3) requires as it becomes available.
7. International transfers
Primary processing occurs in the UK/EU. Where a sub-processor processes data outside the UK/EU (see the sub-processor list), transfers rely on adequacy regulations or the ICO's International Data Transfer Agreement/Addendum as applicable.
8. Deletion and return
On account closure, or on instruction, we delete the Agency's data within 30 days, except where law requires retention. Report PDFs already delivered to the Agency's clients are outside our control and the Agency's responsibility.
9. Audit
We make available information reasonably necessary to demonstrate compliance with this DPA, and allow audits by the Agency or its appointed auditor, on 30 days' notice, at most annually, during business hours, without access to other tenants' data.