Data Processing Agreement
OwnMoat, Inc.
Last updated: July 19, 2026
This Data Processing Agreement ("DPA") forms part of the agreement between OwnMoat, Inc., a Delaware corporation ("OwnMoat," the "Processor"), and the customer accepting it (the "Customer," the "Controller"), and applies where OwnMoat processes Personal Data on the Customer's behalf in providing the Service. Capitalized terms not defined here have the meanings in the Terms of Service or, for data-protection terms ("Personal Data," "processing," "data subject," "supervisory authority"), the meanings in applicable Data Protection Law.
"Data Protection Law" means all laws applicable to the processing of Personal Data under this DPA, including the EU/UK General Data Protection Regulation ("GDPR"), the California Consumer Privacy Act ("CCPA"), and India's Digital Personal Data Protection Act 2023, as applicable.
1. Scope and roles
The Customer is the Controller and OwnMoat is the Processor of Personal Data processed through the Service. Each party will comply with Data Protection Law applicable to it. The details of processing are set out in Annex 1.
2. Processing on instructions
OwnMoat will process Personal Data only on the Customer's documented instructions — which are: the Terms, this DPA, the Customer's configuration of the Service (including which Google properties and websites the Customer connects), and the Customer's use of Service features — unless required to process otherwise by law, in which case OwnMoat will inform the Customer unless legally prohibited. OwnMoat will promptly inform the Customer if, in its opinion, an instruction infringes Data Protection Law.
3. Confidentiality
OwnMoat ensures that persons authorized to process Personal Data are bound by confidentiality obligations. Consistent with the Google API Services User Data Policy (Limited Use), human access to Google user data is restricted as described in the Privacy Policy.
4. Security
OwnMoat implements appropriate technical and organizational measures to protect Personal Data, as described in Annex 2, taking into account the state of the art, costs, and the nature and risks of processing. OwnMoat may update these measures provided the overall level of protection is not reduced.
5. Subprocessors
The Customer generally authorizes OwnMoat to engage the subprocessors listed in the Privacy Policy (Section 5), which constitutes the current subprocessor list. OwnMoat will provide at least 14 days' notice (by email or in-Service notice) before adding or replacing a subprocessor. If the Customer reasonably objects on data-protection grounds and the parties cannot resolve the objection, the Customer may terminate the affected portion of the Service and receive a pro-rata refund of prepaid unused fees. OwnMoat imposes data-protection obligations on subprocessors no less protective than this DPA and remains responsible for their performance.
6. Data subject requests
Taking into account the nature of processing, OwnMoat will assist the Customer by appropriate technical and organizational measures in fulfilling the Customer's obligation to respond to data-subject requests (access, rectification, erasure, restriction, portability, objection). If a data subject contacts OwnMoat directly, OwnMoat will promptly forward the request to the Customer and will not respond substantively except as required by law.
7. Assistance
OwnMoat will provide reasonable assistance to the Customer with data-protection impact assessments, consultations with supervisory authorities, and security-of-processing obligations under Data Protection Law, taking into account the nature of processing and information available to OwnMoat.
8. Personal data breach
OwnMoat will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data breach affecting Customer Personal Data, and will provide information reasonably required for the Customer to meet its breach-notification obligations, updating the Customer as further information becomes available. Notification is not an acknowledgement of fault.
9. International transfers
The Customer acknowledges that OwnMoat processes data in the United States and other locations where it or its subprocessors operate. For transfers of Personal Data from the EEA, UK, or Switzerland to countries without an adequacy decision, the parties incorporate by reference the European Commission's Standard Contractual Clauses (Module 2: Controller-to-Processor), with the Customer as data exporter and OwnMoat as data importer, and the UK Addendum where applicable; the details in Annexes 1 and 2 serve as the appendices to those clauses. In case of conflict, the Standard Contractual Clauses prevail.
10. Audit
OwnMoat will make available information reasonably necessary to demonstrate compliance with this DPA, including summaries of third-party audits or certifications of its infrastructure providers where available. No more than once annually and on 30 days' notice, the Customer may conduct a reasonable audit (by written questionnaire, or where legally required, an inspection during business hours that does not compromise other customers' data or OwnMoat's security), at the Customer's expense.
11. Return and deletion
Upon termination of the Service, or upon the Customer's request (including disconnecting a Google property), OwnMoat will delete the relevant Customer Personal Data within 30 days, and purge it from backups within 90 days, except where retention is required by law. Upon written request made before deletion, OwnMoat will export the Customer's analysis data in a machine-readable format.
12. CCPA
To the extent the CCPA applies, OwnMoat acts as a "service provider": it will not sell or share Personal Data, will not retain, use, or disclose it outside the direct business relationship with the Customer or for any purpose other than providing the Service, and certifies that it understands these restrictions.
13. Liability and order of precedence
Each party's liability under this DPA is subject to the limitations of liability in the Terms of Service, except where Data Protection Law does not permit such limitation. In case of conflict between this DPA and the Terms, this DPA prevails with respect to processing of Personal Data.
Annex 1 — Details of processing
Subject matter and nature: Analysis of the Customer's website search performance and AI-search visibility; generation of reports, briefings, and recommendations; as configured by the Customer in the Service.
Duration: The term of the Service, plus the deletion periods in Section 11.
Categories of data subjects: The Customer's users and personnel who use the Service; visitors to the Customer's websites only to the extent their data appears in aggregated analytics the Customer connects.
Categories of Personal Data: Account data of the Customer's users (name, email); Google Search Console and Google Analytics data of the Customer's connected properties (search queries, aggregated traffic and behavior metrics — which may in limited cases contain personal data such as query strings); publicly available website content of the Customer's registered sites; Service usage logs.
Special categories: None intended or required; the Customer agrees not to use the Service to process special-category data.
Annex 2 — Technical and organizational measures
- Encryption of data in transit (TLS 1.2+) and at rest (provider-managed encryption on databases and backups)
- Read-only, minimally scoped OAuth access to Google user data; tokens stored encrypted; revocable by the Customer at any time
- Role-based access control; production access limited to authorized personnel; authentication via managed identity provider
- Secrets management with rotation; no credentials in source control
- Isolation of customer data by organization identifier enforced at the application layer, with automated cross-tenant access tests
- Logging and monitoring of production systems; error tracking and alerting
- Hosted on SOC 2-audited infrastructure providers (Railway, Supabase, Cloudflare)
- Backup and recovery procedures; rolling backup purge within 90 days
- Vendor management: subprocessors bound by data-protection terms; API-based AI providers used under terms prohibiting training on Customer data
- Personnel confidentiality obligations; principle of least privilege