Data Processing Agreement
Version 2026-10-02
This Data Processing Agreement (“DPA”) is part of the Terms of Service between the Customer (controller) and [company name], Netherlands (processor). It applies to personal data the processor handles for the Customer through AI Mention Monitor, and meets Article 28 of the General Data Protection Regulation (GDPR).
1. Subject, nature and purpose
- Purpose: providing the Service: asking questions to AI assistants, analysing and storing the answers, reports, alerts, and the integrations the Customer switches on.
- Data: whatever personal data the Customer puts into the Service (names and contact details of its users, and any personal data in brands, questions, competitors, notes or reports). When the Customer connects Google Analytics or Search Console: daily totals read from those services (visits, conversions and revenue per source and page; search clicks and impressions per query and page). These totals are not meant to contain personal data; the Customer does not put personal data into page paths or search terms that it connects. When the Customer connects a Google account: that account's email address and its access tokens (stored encrypted, deleted on disconnect, and the access then withdrawn at Google).
- Data subjects: the Customer's users, and people the Customer's monitored content may refer to.
- Duration: as long as the agreement runs, plus the deletion periods below.
2. Instructions
The processor processes the data only on the Customer's documented instructions, which are these terms and the Customer's settings and actions in the Service, unless EU or Dutch law requires otherwise; the processor then informs the Customer first, unless the law forbids it. The processor tells the Customer if it believes an instruction breaks the GDPR.
The Customer also instructs the processor to use the data to analyse, improve and extend the Service, and to make aggregated statistics from it that cannot be traced back to the Customer or to individuals. The processor keeps personal data in this to what is needed, pseudonymises it where possible, and does not use it to train AI models.
Not covered by this DPA, because it is not personal data processed on the Customer's behalf: the names and websites of companies that appear as competitors in the Customer's results. The Terms of Service set out how we may use them (contacting those companies without ever disclosing the Customer).
3. Confidentiality
Everyone at the processor with access to the data is bound to confidentiality and only gets access when needed for their work.
4. Security measures (Art. 32)
- Hosting in the EU; firewalled servers reachable only over SSH with keys; automatic security updates.
- TLS for all connections; backups encrypted before they leave the server; passwords hashed; API secrets and tokens encrypted or hashed at rest.
- Strict separation between organisations in the application, tested automatically; role-based access within an organisation.
- Audit log of important actions; monitoring and alerting; continuous database backups with a weekly restore test.
- Least-privilege credentials, with separate keys for backups and files.
5. Subprocessors
The Customer gives general authorisation for the subprocessors on the subprocessors page. The processor announces a new or replaced subprocessor at least 30 days in advance. The Customer may object on reasonable grounds within that period; if no solution is found, the Customer may end the agreement and receives a pro-rata refund of prepaid fees. The processor binds each subprocessor to the same data protection obligations and remains responsible for them.
6. Transfers outside the EU
Transfers to countries outside the EEA only take place with appropriate safeguards: an adequacy decision (such as the EU–US Data Privacy Framework) or the European Commission's standard contractual clauses.
7. Assistance
The processor helps the Customer, as far as reasonably possible, with requests from data subjects (the Service offers exports, corrections and deletion), with data protection impact assessments and with prior consultations.
8. Personal data breaches
The processor notifies the Customer without undue delay and in any case within 48 hours after becoming aware of a breach affecting the Customer's data, with the information available at that point (what happened, which data, likely consequences, measures taken), and keeps the Customer informed.
9. End of processing
When the Customer deletes its organisation, or the agreement ends, the processor deletes the Customer's data after a 30-day grace period, in which the Customer can still cancel the deletion and export its data. Backups containing the data roll off within 14 days after that. Figures synced from Google Analytics and Search Console are also deleted 30 days after the Customer disconnects them. Invoices and payment records are kept as long as tax law requires.
10. Audits
The processor makes available the information needed to show compliance with this DPA. The Customer may have an audit done by an independent auditor bound to confidentiality, at most once a year, with at least 30 days' notice and at its own cost, unless a breach gives reason for more.
11. Liability and precedence
The liability provisions of the Terms of Service apply. Where this DPA and the Terms conflict on personal data, this DPA prevails.