This Data Processing Addendum (“DPA”) supplements the Terms of Service when Consultwise LLC processes personal data on a Customer’s behalf. It becomes binding when incorporated into an executed order or agreement.
Important: This online copy describes the standard DPA framework. Customers requiring a signed DPA, security exhibit, subprocessor list, or transfer terms should contact [email protected].
1. Roles and instructions
Customer is the controller/business and appoints Consultwise LLC as processor/service provider for Customer Personal Data. We process data only on documented instructions, including the agreement and configured use of the Service, unless law requires otherwise. Customer is responsible for lawful instructions, notices, consents, and the accuracy and legality of data.
2. Processing details
| Subject matter | Providing hosted SEO, analytics, content, integration, reporting, and workflow services. |
|---|---|
| Duration | For the agreement term and limited retention/deletion period. |
| Nature and purpose | Hosting, organizing, analyzing, generating, transmitting, securing, supporting, and deleting data as Customer directs. |
| Data subjects | Customer users, personnel, clients, prospects, website visitors, contacts, and people represented in Customer content. |
| Data types | Identifiers, contact and account data, online identifiers, analytics/search data, website and CMS content, communications, business data, and other data submitted by Customer. |
3. Confidentiality and security
We ensure personnel authorized to process Customer Personal Data are bound by confidentiality. We maintain proportionate technical and organizational measures designed to protect confidentiality, integrity, availability, and resilience, including access controls, credential encryption, logging, recovery practices, vulnerability management, and vendor oversight.
4. Subprocessors
Customer authorizes subprocessors needed to deliver the Service, including infrastructure, hosting, database, email, payment, AI, analytics, support, and connected-platform providers. We remain responsible for their obligations to the extent required by applicable law and will impose appropriate data-protection terms. Customers may request the current list and notice process at the contact below.
5. Assistance and incidents
Taking into account the nature of processing, we will reasonably assist Customer with data-subject requests, security obligations, impact assessments, and regulator consultations. We will notify Customer without undue delay after confirming a personal-data breach affecting Customer Personal Data and provide available information needed for Customer’s obligations.
6. Return, deletion, and audits
At termination or written request, we will delete or return Customer Personal Data as required by the agreement, unless law requires retention. Copies may remain temporarily in protected backups. We will provide information reasonably necessary to demonstrate compliance and, where that is insufficient, allow a proportionate audit subject to confidentiality, security, scope, scheduling, and cost protections.
7. International transfers
For restricted transfers, the parties will use an applicable lawful mechanism, which may include the European Commission Standard Contractual Clauses and the UK International Data Transfer Addendum. The controller-to-processor module applies where appropriate; Customer is data exporter and Consultwise LLC is data importer unless the transfer context requires otherwise.
8. Priority and contact
If this DPA conflicts with the agreement on personal-data processing, this DPA controls. Other terms remain unchanged. Contact [email protected] to request execution or supporting documentation.