OwnMoat

Data Processing Agreement

OwnMoat, Inc.

Last updated: July 19, 2026

This Data Processing Agreement ("DPA") forms part of the agreement between OwnMoat, Inc., a Delaware corporation ("OwnMoat," the "Processor"), and the customer accepting it (the "Customer," the "Controller"), and applies where OwnMoat processes Personal Data on the Customer's behalf in providing the Service. Capitalized terms not defined here have the meanings in the Terms of Service or, for data-protection terms ("Personal Data," "processing," "data subject," "supervisory authority"), the meanings in applicable Data Protection Law.

"Data Protection Law" means all laws applicable to the processing of Personal Data under this DPA, including the EU/UK General Data Protection Regulation ("GDPR"), the California Consumer Privacy Act ("CCPA"), and India's Digital Personal Data Protection Act 2023, as applicable.

1. Scope and roles

The Customer is the Controller and OwnMoat is the Processor of Personal Data processed through the Service. Each party will comply with Data Protection Law applicable to it. The details of processing are set out in Annex 1.

2. Processing on instructions

OwnMoat will process Personal Data only on the Customer's documented instructions — which are: the Terms, this DPA, the Customer's configuration of the Service (including which Google properties and websites the Customer connects), and the Customer's use of Service features — unless required to process otherwise by law, in which case OwnMoat will inform the Customer unless legally prohibited. OwnMoat will promptly inform the Customer if, in its opinion, an instruction infringes Data Protection Law.

3. Confidentiality

OwnMoat ensures that persons authorized to process Personal Data are bound by confidentiality obligations. Consistent with the Google API Services User Data Policy (Limited Use), human access to Google user data is restricted as described in the Privacy Policy.

4. Security

OwnMoat implements appropriate technical and organizational measures to protect Personal Data, as described in Annex 2, taking into account the state of the art, costs, and the nature and risks of processing. OwnMoat may update these measures provided the overall level of protection is not reduced.

5. Subprocessors

The Customer generally authorizes OwnMoat to engage the subprocessors listed in the Privacy Policy (Section 5), which constitutes the current subprocessor list. OwnMoat will provide at least 14 days' notice (by email or in-Service notice) before adding or replacing a subprocessor. If the Customer reasonably objects on data-protection grounds and the parties cannot resolve the objection, the Customer may terminate the affected portion of the Service and receive a pro-rata refund of prepaid unused fees. OwnMoat imposes data-protection obligations on subprocessors no less protective than this DPA and remains responsible for their performance.

6. Data subject requests

Taking into account the nature of processing, OwnMoat will assist the Customer by appropriate technical and organizational measures in fulfilling the Customer's obligation to respond to data-subject requests (access, rectification, erasure, restriction, portability, objection). If a data subject contacts OwnMoat directly, OwnMoat will promptly forward the request to the Customer and will not respond substantively except as required by law.

7. Assistance

OwnMoat will provide reasonable assistance to the Customer with data-protection impact assessments, consultations with supervisory authorities, and security-of-processing obligations under Data Protection Law, taking into account the nature of processing and information available to OwnMoat.

8. Personal data breach

OwnMoat will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data breach affecting Customer Personal Data, and will provide information reasonably required for the Customer to meet its breach-notification obligations, updating the Customer as further information becomes available. Notification is not an acknowledgement of fault.

9. International transfers

The Customer acknowledges that OwnMoat processes data in the United States and other locations where it or its subprocessors operate. For transfers of Personal Data from the EEA, UK, or Switzerland to countries without an adequacy decision, the parties incorporate by reference the European Commission's Standard Contractual Clauses (Module 2: Controller-to-Processor), with the Customer as data exporter and OwnMoat as data importer, and the UK Addendum where applicable; the details in Annexes 1 and 2 serve as the appendices to those clauses. In case of conflict, the Standard Contractual Clauses prevail.

10. Audit

OwnMoat will make available information reasonably necessary to demonstrate compliance with this DPA, including summaries of third-party audits or certifications of its infrastructure providers where available. No more than once annually and on 30 days' notice, the Customer may conduct a reasonable audit (by written questionnaire, or where legally required, an inspection during business hours that does not compromise other customers' data or OwnMoat's security), at the Customer's expense.

11. Return and deletion

Upon termination of the Service, or upon the Customer's request (including disconnecting a Google property), OwnMoat will delete the relevant Customer Personal Data within 30 days, and purge it from backups within 90 days, except where retention is required by law. Upon written request made before deletion, OwnMoat will export the Customer's analysis data in a machine-readable format.

12. CCPA

To the extent the CCPA applies, OwnMoat acts as a "service provider": it will not sell or share Personal Data, will not retain, use, or disclose it outside the direct business relationship with the Customer or for any purpose other than providing the Service, and certifies that it understands these restrictions.

13. Liability and order of precedence

Each party's liability under this DPA is subject to the limitations of liability in the Terms of Service, except where Data Protection Law does not permit such limitation. In case of conflict between this DPA and the Terms, this DPA prevails with respect to processing of Personal Data.


Annex 1 — Details of processing

Subject matter and nature: Analysis of the Customer's website search performance and AI-search visibility; generation of reports, briefings, and recommendations; as configured by the Customer in the Service.

Duration: The term of the Service, plus the deletion periods in Section 11.

Categories of data subjects: The Customer's users and personnel who use the Service; visitors to the Customer's websites only to the extent their data appears in aggregated analytics the Customer connects.

Categories of Personal Data: Account data of the Customer's users (name, email); Google Search Console and Google Analytics data of the Customer's connected properties (search queries, aggregated traffic and behavior metrics — which may in limited cases contain personal data such as query strings); publicly available website content of the Customer's registered sites; Service usage logs.

Special categories: None intended or required; the Customer agrees not to use the Service to process special-category data.

Annex 2 — Technical and organizational measures