Legal
Data Processing Addendum
Last updated: May 19, 2026
This Data Processing Addendum ("DPA") applies where OnlyAEO processes personal data on behalf of a client in the course of providing services, and forms part of the Service Agreement between the client ("Controller") and [CONFIRM: Legal entity name] ("Processor"). It reflects requirements under the GDPR, UK GDPR, and similar laws.
To execute this DPA for your engagement, contact tejas@onlyaeo.com.
1. Definitions
"Personal Data", "Processing", "Controller", "Processor", "Data Subject", and "Subprocessor" have the meanings given in applicable data protection law.
2. Roles
The client is the Controller. OnlyAEO is the Processor. OnlyAEO processes Personal Data only on the client's documented instructions, including as set out in the Service Agreement.
3. Scope of processing
- Subject matter. Delivery of AEO services.
- Duration. The term of the Service Agreement.
- Nature and purpose. Auditing AI visibility, producing and publishing content, distribution, and reporting.
- Types of personal data. Business contact details and any personal data contained in materials the client provides.
- Categories of data subjects. The client's personnel and contacts.
[CONFIRM: adjust to match actual data handled].
4. Processor obligations
OnlyAEO will:
- Process Personal Data only on documented instructions.
- Ensure personnel are bound by confidentiality.
- Implement appropriate technical and organizational security measures.
- Assist the Controller with data-subject requests and with security, breach, and impact-assessment obligations.
- At the Controller's choice, delete or return Personal Data at the end of the engagement, subject to legal retention requirements.
5. Subprocessors
The Controller authorizes OnlyAEO to engage Subprocessors listed on our Subprocessors page. OnlyAEO will impose data-protection terms on each Subprocessor no less protective than this DPA and remains responsible for their performance. We will give notice of intended changes to Subprocessors so the Controller can object.
6. International transfers
Where Personal Data is transferred across borders, the parties will rely on an appropriate transfer mechanism, such as the Standard Contractual Clauses, which are incorporated by reference where applicable.
7. Security incidents
OnlyAEO will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, and will provide reasonable information to help the Controller meet its notification obligations.
8. Audits
OnlyAEO will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for audits as required by applicable law, subject to reasonable confidentiality and scheduling terms.
9. Liability and conflict
Liability under this DPA is subject to the limitations in the Service Agreement. If this DPA conflicts with the Service Agreement on data protection, this DPA controls.
10. Contact
Data protection contact: tejas@onlyaeo.com.
Get in touch
Questions about this page or your data with OnlyAEO? Email tejas@onlyaeo.com. We respond within a few working days.
See also our Privacy Policy, Terms of Service, and Cookie Notice.