Data processing agreement

YourReporting Ltd · Last updated: 10 August 2026 · Incorporated into the Terms of Service · [SOLICITOR REVIEW REQUIRED]

This DPA applies where YourReporting processes personal data on behalf of a customer ("the Agency") in the course of providing the Service. It is designed to satisfy Article 28 UK GDPR without a signature round-trip: accepting the Terms accepts this DPA. If your client requires a countersigned copy, email [email protected].

1. Roles and scope

The Agency is controller (or processor for its own clients); YourReporting is processor. The processing: retrieval of website performance data from Google properties mapped by the Agency; storage of monthly report snapshots; generation and delivery of reports to recipients configured by the Agency. Duration: the life of the account. Data subjects: visitors to the mapped websites (aggregate-level data) and report recipients. Categories: aggregated site-usage metrics, search queries, page paths; recipient names and email addresses.

2. Instructions

We process only on the Agency's documented instructions — the configuration made in the product is the instruction — unless UK law requires otherwise, in which case we inform the Agency unless prohibited.

3. Confidentiality and security

Personnel access to customer data is limited, logged, and permitted only for support the Agency has requested, or for security and legal compliance. Measures include: encryption in transit (TLS) and at rest for credentials, tenant isolation enforced and tested in code, audit logging of access to client data, and scrubbing of tokens and personal data from error telemetry.

4. Sub-processors

The Agency authorises the sub-processors listed at /legal/subprocessors. We will give at least 30 days' notice by email before adding or replacing one, during which the Agency may object on reasonable data-protection grounds; if we cannot resolve the objection, the Agency may terminate with a pro-rata refund of prepaid fees.

5. Data subject rights and assistance

Taking into account the nature of the processing, we assist the Agency with data subject requests, security, breach notification, and impact assessments, at no charge for reasonable requests.

6. Breach notification

We notify the Agency without undue delay, and in any case within 72 hours, of becoming aware of a personal data breach affecting its data, with the information Article 33(3) requires as it becomes available.

7. International transfers

Primary processing occurs in the UK/EU. Where a sub-processor processes data outside the UK/EU (see the sub-processor list), transfers rely on adequacy regulations or the ICO's International Data Transfer Agreement/Addendum as applicable.

8. Deletion and return

On account closure, or on instruction, we delete the Agency's data within 30 days, except where law requires retention. Report PDFs already delivered to the Agency's clients are outside our control and the Agency's responsibility.

9. Audit

We make available information reasonably necessary to demonstrate compliance with this DPA, and allow audits by the Agency or its appointed auditor, on 30 days' notice, at most annually, during business hours, without access to other tenants' data.