GDPR Data Processing Agreement
Controller to Processor terms with UK GDPR Article 28 style protections.
1. Definitions
- Controller: the client who determines purposes and means of processing.
- Processor: Business Opt, processing personal data on behalf of the Controller.
- Personal Data, Processing, and Data Subject: as defined in UK GDPR.
- UK GDPR: the UK General Data Protection Regulation and applicable data protection laws.
2. Subject matter and duration
Subject matter: delivery of Local SEO, ads, and website services that require processing of personal data.
3. Nature and purpose
Processing is limited to what is necessary to provide the services, including communications, reporting, account access, optimisation actions, and technical support.
4. Types of personal data and data subjects
- Client staff and representatives
- Client customers and leads where applicable
- Website visitors where applicable
- Contact details such as name, email, and phone
- Customer enquiry content submitted via forms
- Analytics identifiers where applicable
5. Processor obligations
- Process personal data only on documented instructions from the Controller.
- Ensure personnel are bound by confidentiality.
- Implement appropriate technical and organisational measures to protect personal data.
- Assist the Controller with data subject requests and compliance duties where applicable.
6. Security measures
- Role based access controls and least privilege.
- Secure credential handling and access revocation on request.
- Encryption in transit where supported by providers.
- Incident response procedures.
7. Return or deletion
At the end of services, and on the Controller’s written request, we will delete or return personal data processed on the Controller’s behalf, unless we are required by law to retain it.
