keptseo

Data Processing Addendum

Effective October 9, 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Service between Clearpath Digital LLC, 15746 CR 70, Greeley, CO 80631, USA ("KeptSEO", "Processor") and the customer ("Customer", "Controller"). It applies when KeptSEO processes personal data on the Customer's behalf that is subject to the EU General Data Protection Regulation (GDPR), the UK GDPR, or similar data protection laws.

To receive a countersigned copy, email chris@clearpathdigital.io with your company name, address and the name of the person signing.

1. Roles and scope

The Customer is the controller and KeptSEO is the processor of the personal data in Customer data (GDPR Article 28). KeptSEO processes it only to provide the service described in the Terms.

2. Processor obligations

KeptSEO will:

3. Sub-processors

The Customer gives general authorization for KeptSEO to use sub-processors. The current list is at keptseo.com/subprocessors. KeptSEO will give notice of a new sub-processor by updating that page, and by email to Customers who ask, before it processes Customer personal data. The Customer may object on reasonable data protection grounds within 30 days. If we cannot resolve the objection, the Customer may end the affected service and receive a refund of prepaid fees for the unused period. KeptSEO binds each sub-processor to data protection terms no less protective than this DPA and remains responsible for their work.

4. International transfers

KeptSEO is based in the United States. Where personal data is transferred from the European Economic Area, Switzerland or the United Kingdom to a country without an adequacy decision, the parties agree to the Standard Contractual Clauses approved by European Commission Implementing Decision (EU) 2021/914 (Module Two, controller to processor, and Module Three where it applies) and, for the UK, the International Data Transfer Addendum issued by the Information Commissioner. These are incorporated by reference. Section 1 completes Annex I and section 5 completes Annex II.

5. Security measures

More detail is on the Security page. KeptSEO may change these measures as long as the overall level of protection does not go down.

6. Personal data breaches

KeptSEO will notify the Customer without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting Customer personal data. The notice will describe the breach, the kinds of data and people affected, the likely consequences and the steps taken, as far as these are known. KeptSEO will send updates as it learns more.

7. Deletion and return

When the Customer's account ends, KeptSEO will delete Customer personal data within 30 days, except data the law requires it to keep (such as invoices). Before that, the Customer can export its data in the product or ask us for a copy. Backups expire on their normal schedule and are only restored to recover from a failure.

8. Audits

On written request, and no more than once a year unless a breach or a regulator requires it, KeptSEO will answer reasonable written questions and provide documents about its compliance with this DPA. If that is not enough, the Customer, or an independent auditor bound by confidentiality, may audit KeptSEO on 30 days' notice, during business hours, at the Customer's cost, and without disrupting the service or exposing other customers' data.

9. Liability and precedence

Each party's liability under this DPA is subject to the limits in the Terms, except where the law does not allow such limits. If this DPA conflicts with the Terms, this DPA controls on data protection matters. If the Standard Contractual Clauses conflict with this DPA, the clauses control.

Contact

Clearpath Digital LLC, 15746 CR 70, Greeley, CO 80631, USA. chris@clearpathdigital.io.