Snack SEO — Data Processing Agreement #

Effective date: 18 August 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service or other written agreement (the "Agreement") between:

(1) Snack Prompt Corp, a Texas corporation, of 604 Canyon Creek Trail, Fort Worth, TX 76112, United States ("Processor", "Snack Prompt", "we", "us"); and

(2) the Customer identified in the Agreement ("Controller", "Customer", "you"),

each a "Party" and together the "Parties", and governs our processing of Personal Data contained in Client Data on your behalf in connection with Snack SEO.

How to execute this DPA. This DPA takes effect automatically and forms part of the Agreement for every Customer whose use of the Service involves our processing of Personal Data on their behalf — no signature is required. If your compliance programme requires a countersigned copy, email hello@snackseo.com with the subject line "DPA Countersignature Request", stating your full legal entity name, registered address, the account email, and (if applicable) your EEA/UK representative and DPO contact details, and we will return a signed copy. Signature blocks are provided at Annex D.


Table of contents #

  1. Definitions
  2. Roles of the Parties and scope
  3. Customer instructions and Customer obligations
  4. Our processing obligations
  5. Confidentiality of personnel
  6. Security measures
  7. Sub-processors
  8. Assistance with data subject rights
  9. Assistance with DPIAs, consultation and security obligations
  10. Personal data breaches
  11. International transfers
  12. Audits and information rights
  13. Deletion and return of Personal Data
  14. Google user data — specific commitments
  15. AI processing — specific commitments
  16. Crawled data — allocation of responsibility
  17. California, other US states, Brazil and Canada
  18. Liability, term and general

1. Definitions #


2. Roles of the Parties and scope #

2.1 Roles. In respect of Customer Personal Data, you are the Controller and we are the Processor. Where you are yourself a processor acting for your own client (for example, where you are an agency), you act as that client's processor and we act as your sub-processor; you warrant that you have your client's authority to appoint us and to agree this DPA on terms that satisfy your obligations to them.

2.2 Our controller processing is outside this DPA. We act as an independent Controller in respect of Account Data — data about you and your Authorised Users as our customer, and telemetry about use of the Service — as described in our Privacy Policy. That processing is governed by the Privacy Policy, not by this DPA.

2.3 Order of precedence. In the event of a conflict, the order of precedence is: (1) the SCCs and UK Addendum in Annex C; (2) this DPA; (3) the Terms of Service; (4) the Privacy Policy.

2.4 Duration. This DPA applies from the effective date of the Agreement until we have deleted or returned all Customer Personal Data in accordance with section 13.


3. Customer instructions and Customer obligations #

3.1 Documented instructions. We will process Customer Personal Data only on your documented instructions, which comprise: (a) the Agreement and this DPA; (b) your configuration and use of the Service through its interfaces and APIs (including the domains you add, the accounts you connect, the crawls you configure, the prompts you run and the reports you generate); and (c) any further written instruction you give that we agree to in writing. Processing necessary to comply with EU or Member State law to which we are subject is also permitted; we will inform you of that legal requirement before processing unless the law prohibits it on important grounds of public interest.

3.2 Unlawful instructions. We will immediately inform you if, in our opinion, an instruction infringes Applicable Data Protection Law, and may suspend performance of that instruction until it is amended or confirmed.

3.3 Your warranties and responsibilities. You represent, warrant and undertake that:

(a) you have a lawful basis for all processing you instruct, and have given all notices and obtained all consents required by Applicable Data Protection Law;
(b) you have the right and authority to transfer Customer Personal Data to us and to authorise our processing, including in respect of every domain you add, every account you connect and every end client whose data you place in the Service;
(c) your instructions comply with Applicable Data Protection Law and do not cause us to breach it;
(d) you have implemented appropriate technical and organisational measures in your own systems and workspace configuration, including correct configuration of workspaces, projects, roles and permissions;
(e) you will not submit to the Service any special-category data under Article 9 GDPR, criminal-conviction data under Article 10 GDPR, "sensitive personal information" under the CCPA/CPRA, payment-card data subject to PCI-DSS, or data subject to HIPAA, GLBA, FERPA or comparable sector-specific regimes, unless we have expressly agreed in a signed writing to receive it; and
(f) you are responsible for the accuracy, quality and legality of Customer Personal Data and the means by which you acquired it.

3.4 Data minimisation. You should submit only the Personal Data necessary for the purposes for which you use the Service. The Service is designed to work with website, ranking and search-performance data; it is not designed as a repository for records about identified individuals.


4. Our processing obligations #

We will:

4.1 process Customer Personal Data only as set out in section 3.1, and only for the purposes described in Annex A;

4.2 not sell or share Customer Personal Data (as those terms are defined in the CCPA/CPRA), not retain, use or disclose it for any purpose other than performing the Service and the purposes permitted by section 4.3, not retain, use or disclose it outside the direct business relationship between us, and not combine it with personal information obtained from other sources except as permitted by CCPA regulations;

4.3 be permitted to process Customer Personal Data to (a) provide, secure, maintain, troubleshoot and support the Service; (b) detect, prevent and investigate security incidents, fraud and abuse; (c) comply with legal obligations; and (d) create aggregated and de-identified data as permitted by section 5.4 of the Terms of Service, provided that such data does not identify you, your end clients or any Data Subject and we do not attempt to re-identify it;

4.4 not use Customer Personal Data to train, fine-tune or improve any generalised artificial intelligence or machine-learning model, and require our AI Sub-processors to do the same (see section 15);

4.5 maintain a record of processing activities carried out on your behalf as required by Article 30(2) GDPR;

4.6 cooperate on request with the Supervisory Authority in the performance of its tasks; and

4.7 where required, and having assessed that Article 27 GDPR applies to our processing, appoint and publish the details of a representative in the Union and in the United Kingdom, and notify you of that appointment.


5. Confidentiality of personnel #

We ensure that persons authorised to process Customer Personal Data are bound by a duty of confidentiality (contractual or statutory) that survives the end of their engagement, are subject to background screening appropriate to the role and permitted by law, receive data protection and security training, and have access only on a need-to-know, least-privilege basis, which is reviewed periodically and revoked promptly on role change or departure.


6. Security measures #

6.1 We implement and maintain the technical and organisational measures set out in Annex B, which are designed to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, in accordance with Article 32 GDPR.

6.2 We may update those measures from time to time, provided that we do not materially reduce the overall level of security. The current version is always the one published with this DPA.

6.3 You are responsible for assessing whether the measures in Annex B meet your own requirements, and for the security of everything within your control, including your credentials, your endpoint devices, your workspace configuration and the systems from which you access the Service.


7. Sub-processors #

7.1 General authorisation. You give us a general written authorisation to engage Sub-processors to process Customer Personal Data, subject to this section.

7.2 Current list. The Sub-processors engaged as at the effective date are listed at https://snackseo.com/legal/subprocessors (Sub-processors), which forms part of this DPA and identifies each Sub-processor's name, service, processing location and transfer safeguard.

7.3 Obligations we impose. We will impose on each Sub-processor, by written contract, data protection obligations no less protective than those in this DPA, in particular in relation to security, confidentiality, purpose limitation, assistance and international transfers. We remain fully liable to you for the performance of each Sub-processor's obligations.

7.4 Notice of changes and right to object. We will give you at least 30 days' prior notice of the addition or replacement of a Sub-processor, by email to your account address and/or by updating the Sub-processors page (you may subscribe to change notifications there). You may object on reasonable, documented data-protection grounds within 30 days of the notice by emailing hello@snackseo.com. We will work with you in good faith to find a commercially reasonable alternative or workaround. If we cannot, you may terminate the affected part of the Service by written notice and receive a pro-rata refund of prepaid fees for the unused remainder of the term, and that is your sole and exclusive remedy.

7.5 Emergency changes. Where a change is required urgently to protect the security or availability of the Service, we may make it immediately and notify you as soon as practicable; your objection right under 7.4 then applies retrospectively.


8. Assistance with data subject rights #

8.1 Self-service. The Service provides functionality that enables you to access, correct, export and delete Customer Personal Data yourself. You should use it in the first instance to respond to Data Subject requests.

8.2 Our assistance. Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, insofar as this is possible, to fulfil your obligation to respond to requests to exercise rights of access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and rights relating to automated decision-making.

8.3 Requests received by us. If we receive a request from a Data Subject relating to Customer Personal Data, we will not respond to it substantively (other than to acknowledge receipt and to direct the individual to you), and will forward it to you without undue delay and in any event within 5 business days, unless we are legally required to respond.

8.4 Cost. Assistance under this section is provided at no charge for a reasonable volume of requests. Where assistance requires significant engineering effort beyond standard functionality, we may charge our reasonable costs, having first given you an estimate and obtained your approval.


9. Assistance with DPIAs, consultation and security obligations #

Taking into account the nature of processing and the information available to us, we will provide reasonable assistance to you in relation to your obligations under Articles 32 to 36 GDPR (and equivalent provisions of other Applicable Data Protection Law), including security of processing, notification of Personal Data Breaches, data protection impact assessments and prior consultation with a Supervisory Authority. Our assistance will ordinarily consist of making available this DPA, Annex B, the Sub-processors page, our security documentation, and answers to a reasonable security questionnaire.


10. Personal data breaches #

10.1 Notification. We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. Notification will be sent by email to the security or administrative contact on your account, so please keep it current.

10.2 Content. So far as the information is available to us, the notification will describe (a) the nature of the breach, including the categories and approximate number of Data Subjects and records concerned; (b) the likely consequences; (c) the measures taken or proposed to address it and mitigate its effects; and (d) a contact point for further information. Where we cannot provide all the information at once, we will provide it in phases without undue further delay.

10.3 Cooperation and remediation. We will take reasonable steps to contain, investigate and remediate the breach, will preserve relevant evidence, and will provide reasonable cooperation and information to enable you to meet your own notification obligations to Supervisory Authorities and Data Subjects.

10.4 No admission. Our notification is not an acknowledgement of fault or liability.

10.5 Your obligations. You are responsible for notifying Supervisory Authorities and Data Subjects where required in respect of Customer Personal Data. You will not make any public statement identifying us in connection with a breach without our prior written consent, except where legally required, in which case you will give us as much prior notice as is practicable.


11. International transfers #

11.1 Locations. Customer Personal Data is processed in the European Union (Germany) and the United States, and by Sub-processors in the locations identified on the Sub-processors page.

11.2 EEA transfers — SCCs. Where our processing involves a transfer of Customer Personal Data from the EEA to a country not benefiting from an adequacy decision, the SCCs are incorporated into this DPA by reference and apply, completed as set out in Annex C. Module Two (controller to processor) applies where you are a Controller; Module Three (processor to processor) applies where you are a processor acting for your own controller.

11.3 UK transfers. For transfers subject to the UK GDPR, the UK Addendum is incorporated by reference and applies to the SCCs, completed as set out in Annex C.

11.4 Swiss transfers. For transfers subject to the Swiss FADP, the SCCs apply with the adaptations recognised by the Swiss Federal Data Protection and Information Commissioner: references to the GDPR are read as references to the FADP, the FDPIC is the competent authority, and the SCCs also protect the data of legal entities until the FADP is amended to remove that protection.

11.5 Onward transfers. We will only make an onward transfer of Customer Personal Data to a Sub-processor in a third country where an appropriate safeguard under Chapter V GDPR is in place.

11.6 Transfer impact and government access. We assess the laws and practices of destination countries, and apply supplementary measures where appropriate, including encryption in transit and at rest, strict access controls and data minimisation. If we receive a legally binding request from a public authority for Customer Personal Data, we will (unless legally prohibited) notify you promptly, challenge the request where there are reasonable grounds to consider it unlawful, and disclose only the minimum amount of data lawfully required. We will keep a record of such requests and make it available to you and, on request, to the competent Supervisory Authority. As at the effective date, we have not received any such request.


12. Audits and information rights #

12.1 Information. We will make available to you all information reasonably necessary to demonstrate compliance with Article 28 GDPR, including this DPA, Annex B, the Sub-processors page, and, where we hold them, third-party audit reports or certifications for our infrastructure Sub-processors (for example, SOC 2 or ISO 27001 reports held by Supabase, Hetzner or Cloudflare), subject to confidentiality.

12.2 Questionnaires. We will respond to a reasonable security and data-protection questionnaire once in any 12-month period at no charge.

12.3 Audits. You (or an independent auditor you appoint who is not a competitor of ours and who signs a confidentiality agreement) may audit our compliance with this DPA:

(a) not more than once in any 12-month period, unless required by a Supervisory Authority or following a Personal Data Breach affecting your Customer Personal Data;
(b) on at least 30 days' prior written notice;
(c) during our normal business hours;
(d) in a manner that does not disrupt our business, does not compromise the confidentiality or security of other customers' data, and does not require us to disclose commercially sensitive information or provide direct access to production systems containing other customers' data; and
(e) at your cost, save that we will bear our own reasonable internal costs of a first annual audit.

12.4 Where the SCCs apply, this section 12 is agreed to satisfy Clause 8.9 of the SCCs.


13. Deletion and return of Personal Data #

13.1 During the term, you may export Customer Personal Data at any time using the Service's export functionality.

13.2 On expiry or termination of the Agreement, and at your choice, we will delete or return Customer Personal Data. Unless you instruct otherwise in writing within 30 days of termination, we will delete it: from live production systems within 30 days, and from encrypted backups within a further 60 days as those backups age out on their normal rotation. Data in backups pending deletion remains subject to this DPA and is not actively processed.

13.3 We may retain Customer Personal Data to the extent required by EU, Member State, UK or US law, in which case we will continue to protect it under this DPA, restrict processing to the purpose requiring retention, and delete it when the requirement lapses.

13.4 On written request made within 30 days of termination, we will provide written certification that deletion has been completed.


14. Google user data — specific commitments #

Where you connect a Google Search Console, Google Analytics or Google Business Profile account, we additionally commit that:

14.1 Our use and transfer of information received from Google APIs to any other application adheres to the Google API Services User Data Policy, including the Limited Use requirements, as set out in full in section 5 of the Privacy Policy.

14.2 We access only the scopes described in section 4 of the Privacy Policy, request read-only scopes where the relevant API offers one, and use the data solely to provide the user-facing SEO reporting, analysis and recommendation features of the Service.

14.3 We do not use Google user data for advertising, do not sell or share it, and do not use it to train or improve generalised AI or ML models.

14.4 Human access to Google user data is limited to the cases permitted by the Limited Use requirements (your affirmative consent; security investigation; legal compliance; or aggregated and anonymised data used for internal operations).

14.5 OAuth tokens are stored encrypted and are deleted within 7 days of disconnection or revocation; retrieved report data is deleted in accordance with section 4.4 of the Privacy Policy or sooner on your request.

14.6 You may revoke our access at any time through the Service, through https://myaccount.google.com/permissions, or by emailing hello@snackseo.com.


15. AI processing — specific commitments #

15.1 Where you use an AI feature, Customer Personal Data contained in your Input or context may be transmitted to the AI Sub-processors identified on the Sub-processors page (OpenAI, Anthropic, Google, OpenRouter, Perplexity).

15.2 We contract with those providers on API / enterprise terms under which inputs and outputs are not used to train their models. Providers may retain inputs and outputs for a limited period for abuse monitoring, typically no more than 30 days, after which they are deleted. Where a provider offers zero-retention processing for a given endpoint, we will prefer it where technically feasible.

15.3 We do not train our own models on Customer Personal Data.

15.4 You control what goes into a prompt. Prompts you configure — including AI-search visibility monitoring prompts — are transmitted to third-party AI providers. You must not place Personal Data in a prompt unless you have a lawful basis for doing so and have accounted for the transfer in your own records and notices.

15.5 AI features do not perform automated decision-making producing legal or similarly significant effects concerning Data Subjects. You must not configure or use them to do so.

15.6 If you require that no Customer Personal Data be processed by AI Sub-processors, contact hello@snackseo.com; we will tell you which features must be disabled to achieve that, and you may disable them.


16. Crawled data — allocation of responsibility #

16.1 When we crawl a domain at your instruction, we may collect Personal Data that appears on its pages (for example, author names, staff directories, testimonials or contact details).

16.2 You are the Controller of that data. You warrant that you own or are authorised to act for each domain you add, and that the crawling and processing you instruct is lawful, including in respect of any Personal Data on those pages.

16.3 We process crawled Personal Data solely to provide the audit, content and analysis features of the Service, retain crawl artefacts for the period stated in section 12 of the Privacy Policy, and do not use crawled Personal Data for any purpose of our own other than the creation of aggregated and de-identified data as permitted by section 4.3.

16.4 If a Data Subject contacts us about Personal Data collected from a crawled site, we will handle the request under section 8.3.


17. California, other US states, Brazil and Canada #

17.1 CCPA/CPRA. For personal information subject to the CCPA/CPRA, you are a "business" and we are a "service provider". We certify that we understand and will comply with the restrictions in section 4.2: we will not sell or share the personal information, will not retain, use or disclose it for any purpose other than the business purposes specified in the Agreement (including retaining, using or disclosing it for a commercial purpose other than providing the Service), will not retain, use or disclose it outside the direct business relationship between us, and will not combine it with personal information received from another source except as permitted by the CCPA. We will notify you if we determine we can no longer meet these obligations, and you may take reasonable and appropriate steps to stop and remediate unauthorised use. We will provide the same level of privacy protection as the CCPA requires of you, and will cooperate with your reasonable measures to ensure our use is consistent with your obligations.

17.2 Other US state laws. Where Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana or comparable state privacy law applies, this DPA constitutes the required contract between controller and processor, and we will comply with the corresponding processor duties, including duties of confidentiality, deletion or return of data, demonstration of compliance, cooperation with assessments, and engagement of sub-processors under a written contract.

17.3 LGPD. Where the LGPD applies, you are the controlador and we are the operador. We will process Personal Data only on your instructions, adopt security measures under Article 46, assist with data subject rights under Articles 18 and 19, and notify you of security incidents so that you can notify the ANPD and affected individuals under Article 48.

17.4 PIPEDA. Where PIPEDA applies, we act as your service provider. We will use Personal Data only for the purposes for which it was transferred to us, apply comparable protections, and cooperate with your accountability obligations. You acknowledge that Personal Data processed outside Canada may be accessible to the courts, law enforcement and national security authorities of the jurisdiction in which it is processed, and that you are responsible for informing individuals of that fact.


18. Liability, term and general #

18.1 Liability. Each Party's liability under or in connection with this DPA is subject to the exclusions and limitations of liability in the Agreement (including section 17 of the Terms of Service), except to the extent that Applicable Data Protection Law, or the SCCs, provide otherwise in respect of claims by Data Subjects or Supervisory Authorities.

18.2 Term. This DPA takes effect on the effective date of the Agreement and continues until we have deleted or returned all Customer Personal Data under section 13. Provisions that by their nature should survive do so.

18.3 Changes. We may update this DPA where necessary to reflect changes in Applicable Data Protection Law, in the Service, or in our Sub-processors, provided the update does not materially reduce the protections it gives you. We will give at least 30 days' notice of material changes.

18.4 Governing law. This DPA is governed by the law stated in the Agreement (the State of Texas, United States), except that the SCCs are governed by the law stated in Annex C, and nothing in this section deprives a Data Subject of the protection of mandatory provisions of Applicable Data Protection Law.

18.5 Severability. If any provision is held invalid, the remainder continues in force.


Annex A — Details of processing #

(This Annex also serves as Annex I to the SCCs.)

A.1 List of parties #

Data exporter: the Customer identified in the Agreement, acting as Controller (or as processor for its own controller). Contact details: as recorded in the Customer's account. Activities relevant to the transfer: receipt of SEO and AI-search visibility services. Role: Controller (Module Two) or Processor (Module Three).

Data importer: Snack Prompt Corp, 604 Canyon Creek Trail, Fort Worth, TX 76112, United States. Contact: hello@snackseo.com. Activities relevant to the transfer: provision of the Snack SEO platform. Role: Processor (Module Two) or Sub-processor (Module Three).

A.2 Categories of Data Subjects #

A.3 Categories of Personal Data #

Special categories of data: none are requested or intended. The Customer must not submit them (section 3.3(e)). If special-category data is nevertheless present in crawled or uploaded content, it is processed only incidentally, under the same security measures as all other Customer Personal Data, and the Customer remains responsible for the lawfulness of that processing.

A.4 Frequency of the transfer #

Continuous, for the duration of the Agreement.

A.5 Nature and purpose of the processing #

Collection, retrieval, recording, organisation, structuring, storage, adaptation, analysis, enrichment, generation of derived metrics and AI outputs, retrieval, consultation, use, disclosure to Sub-processors, restriction, erasure and destruction — in each case for the purpose of providing the Snack SEO platform to the Customer, namely: site crawling and technical auditing; keyword and content research; rank tracking; competitor analysis; retrieval and reporting of connected Google property data; AI-assisted content generation and recommendations; AI-search visibility monitoring; dashboards, reporting and exports; account administration, support, security and abuse prevention.

A.6 Duration of processing #

For the term of the Agreement, plus the retention and deletion periods set out in section 13 of this DPA and section 12 of the Privacy Policy.

A.7 Sub-processors #

As listed at Sub-processors, which forms part of this Annex. The nature, subject matter and duration of each Sub-processor's processing is as stated on that page.

A.8 Competent Supervisory Authority (Annex I.C to the SCCs) #

The Supervisory Authority of the EEA Member State in which the data exporter is established; or, where the exporter is not established in the EEA but has appointed an Article 27 representative, the authority of the Member State in which that representative is established; or, where neither applies, the Supervisory Authority of the Member State in which the Data Subjects whose data is transferred are located. For UK transfers, the Information Commissioner's Office. For Swiss transfers, the FDPIC.


Annex B — Technical and organisational security measures #

(This Annex also serves as Annex II to the SCCs.)

1. Pseudonymisation and encryption. TLS 1.2 or higher for all data in transit, including between application and database and to all Sub-processor APIs. AES-256 encryption at rest for databases, object storage and backups. OAuth tokens, API keys and other secrets are encrypted at rest with a separately managed key and are never written to application logs. Passwords are stored only as salted hashes produced by a modern memory-hard algorithm.

2. Confidentiality. Multi-tenant isolation enforced at the database layer by row-level security policies keyed to workspace membership, in addition to application-layer authorisation checks. Role-based access control within each workspace. Least-privilege, named-account access for personnel, with mandatory multi-factor authentication; production data access restricted to a small number of engineers, logged, and reviewed periodically. Confidentiality undertakings for all personnel and contractors. Physical security of servers is provided by our infrastructure Sub-processors (Hetzner, Supabase, Cloudflare) in certified data centres with 24/7 monitoring, controlled access and environmental protections.

3. Integrity. Change control and peer code review for all production changes; separated development, staging and production environments; input validation and output encoding; audit logging of privileged and security-relevant actions; version-controlled infrastructure configuration; automated dependency and vulnerability scanning.

4. Availability and resilience. Encrypted automated backups with point-in-time recovery, retained within the same regional footprint as the primary data; redundant infrastructure and managed database failover; DDoS protection and WAF at the edge (Cloudflare); uptime and error-rate monitoring with alerting.

5. Restoration. Documented backup restoration procedures, with restoration tested periodically. Recovery objectives are set to restore service and data within commercially reasonable timeframes appropriate to the platform.

6. Testing and evaluation. Regular review of the effectiveness of security measures; dependency and container vulnerability scanning; static analysis in the build pipeline; periodic access reviews; security review of each Sub-processor before onboarding and on material change.

7. Identification and authorisation of users. Email-and-password authentication with hashing as above; support for multi-factor authentication and, on eligible plans, single sign-on; session and refresh token rotation and revocation; account lockout and anomaly detection on repeated failed sign-ins; workspace administrators can revoke user access immediately.

8. Data minimisation and quality. We request read-only API scopes where available; we retrieve only the data needed for the features in use; retention periods are defined per data type (Privacy Policy section 12); the Service provides deletion and export functionality.

9. Accountability. Records of processing under Article 30(2); documented incident response plan with defined roles and a 48-hour customer notification commitment; data protection and security training for personnel; written contracts with all Sub-processors imposing equivalent obligations.

10. Measures for transfers. Encryption in transit and at rest; SCCs and the UK Addendum with all relevant Sub-processors; transfer impact assessment; policy of challenging unlawful government access requests and disclosing only the minimum lawfully required.

These measures are described at a level of detail appropriate for an early-stage platform and will be updated as the Service and our certifications evolve. We do not currently hold an ISO 27001 or SOC 2 certification of our own; our core infrastructure Sub-processors do hold such certifications for the infrastructure they provide.


Annex C — Standard Contractual Clauses and UK Addendum #

C.1 Incorporation #

The SCCs (Implementing Decision (EU) 2021/914) are incorporated into this DPA by reference and take effect in respect of any transfer of Customer Personal Data from the EEA to a country without an adequacy decision.

C.2 Modules and options #

C.3 UK Addendum #

For transfers subject to the UK GDPR, the UK International Data Transfer Addendum (version B1.0) applies to the SCCs, completed as follows:

C.4 Switzerland #

For transfers subject to the Swiss FADP, the SCCs apply with the adaptations set out in section 11.4.

C.5 Conflict #

In the event of a conflict between the SCCs or the UK Addendum and any other part of this DPA or the Agreement, the SCCs and the UK Addendum prevail.


Annex D — Signature blocks #

This DPA is effective without signature. Where a countersigned copy is required, the Parties may execute below (electronic signature accepted).

Snack Prompt Corp

Name: ______________________________
Title: ______________________________
Date: ______________________________
Signature: __________________________

Customer

Legal entity name: ______________________________
Registered address: ______________________________
Account email: ______________________________
EEA/UK representative (if any): ______________________________
Data protection contact: ______________________________
Name: ______________________________
Title: ______________________________
Date: ______________________________
Signature: __________________________


See also our Terms of Service, Privacy Policy, Sub-processors and Acceptable Use Policy. Questions: hello@snackseo.com.