Data Processing Addendum
Last updated: 2026-07-02
1. Scope and relationship of the parties
In plain terms: when Atlio Information Technology handles personal data on your behalf, you are the controller and we are the processor. This DPA sets out our GDPR Article 28 commitments — security, sub-processor notice, breach reporting, audit rights, and data return or deletion. A countersigned copy is available to Agency and Enterprise customers on request.
This Data Processing Addendum (“DPA”) forms part of the agreement between Atlio Information Technology LLC (“Atlio Information Technology”, acting as Data Processor) and the customer entity that has accepted Atlio Information Technology’s Terms of Service (acting as Data Controller) (together, the “Parties”).
This DPA applies where Atlio Information Technology processes personal data on behalf of the Controller in the course of providing the SearchChamp platform. SearchChamp is a product of Atlio Information Technology. It supplements the Terms of Service and, in the event of a conflict, this DPA takes precedence on data-protection matters.
This DPA is entered into for the purpose of complying with the requirements of the EU General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679), the UK GDPR, the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021), and any other applicable data-protection laws.
2. Processing details
2.1 Subject matter and purpose
Atlio Information Technology processes personal data for the sole purpose of providing the SearchChamp platform services as described in the Terms of Service, including AI-powered keyword research, content generation, site auditing, AI visibility tracking, and related analytics.
2.2 Nature of processing
Collection, storage, analysis, retrieval, and deletion of personal data submitted by the Controller or its end users.
2.3 Types of personal data
- End-user account data: names, email addresses, and account identifiers.
- Website content and metadata submitted by the Controller for processing by AI agents.
- Usage and interaction data generated through use of the platform.
- IP addresses and device identifiers collected via server logs.
2.4 Categories of data subjects
- The Controller’s employees and team members who access the platform.
- End users of the Controller’s connected websites, where their data is incidentally processed during site audits or AI agent tasks.
2.5 Duration of processing
Atlio Information Technology processes personal data for the duration of the active subscription and for such further periods as required by applicable law or as specified in our data-retention schedules (see our Privacy Policy).
3. Controller obligations
The Controller agrees to:
- Ensure that it has a lawful basis for providing personal data to Atlio Information Technology for processing;
- Comply with all applicable data-protection laws in relation to the personal data it submits to the Service;
- Provide adequate privacy notices to data subjects whose data will be processed through the Service;
- Obtain any necessary consents from data subjects before submitting their data to the Service;
- Notify Atlio Information Technology promptly if it receives a data-subject request relating to data processed by Atlio Information Technology on its behalf.
4. Processor obligations
Atlio Information Technology agrees to:
- Process personal data only on documented instructions from the Controller, unless required to do so by applicable law;
- Ensure that persons authorised to process personal data have committed to confidentiality or are under an appropriate statutory obligation of confidentiality;
- Implement and maintain appropriate technical and organisational security measures as described in section 6;
- Not engage sub-processors without prior general or specific written authorisation of the Controller, subject to section 5 of this DPA;
- Assist the Controller in responding to data-subject rights requests, taking into account the nature of the processing;
- Assist the Controller in ensuring compliance with its obligations under Articles 32 to 36 GDPR — including security of processing, breach notification, data protection impact assessments, and prior consultation with supervisory authorities — taking into account the nature of the processing and the information available to Atlio Information Technology;
- Make available to the Controller information reasonably necessary to demonstrate compliance with the obligations set out in Article 28 GDPR;
- Notify the Controller without undue delay after becoming aware of a personal data breach involving data processed on behalf of the Controller;
- Delete or return all personal data to the Controller at the end of the service relationship, in accordance with section 11.
5. Sub-processors
The Controller provides general written authorisation for Atlio Information Technology to engage the sub-processors listed at /legal/sub-processors that process Customer Personal Data on the Controller’s behalf. Atlio Information Technology will:
- Notify the Controller at least 14 days before adding or replacing a sub-processor by updating the sub-processors page and, where the Controller has opted in to notifications, by email;
- Impose data-protection obligations on sub-processors that are at least equivalent to those set out in this DPA;
- Remain fully liable to the Controller for the performance of sub-processors’ obligations.
The Controller may object to a new sub-processor within 14 days of notice by emailing [email protected]. If the parties cannot reach agreement within 30 days, the Controller may terminate the relevant services with a prorated refund of prepaid fees.
6. Security measures
Atlio Information Technology maintains the following technical and organisational measures:
- Encryption at rest: AES-256 encryption for all database storage, backups, and object storage, using AWS-managed encryption keys (KMS for databases and backups; SSE-S3 for object storage).
- Encryption in transit: TLS 1.3 for all data transmitted between clients, servers, and third-party services.
- Access control: role-based access control (RBAC) with least-privilege principles. Production database access is restricted to authorised engineers and reachable only via a bastion host inside the private VPC; administrative access requires MFA and is logged.
- Network isolation: all production resources are deployed inside a private VPC with no direct public internet access to database tiers.
- Audit logging: data-mutation, authentication, PII-access, and administrative actions are logged with actor, timestamp, resource, and IP address. Logs are retained for 30 days and cannot be deleted by standard operational roles.
- Vulnerability management: automated dependency vulnerability scanning, security review as part of the development process, and a responsible disclosure channel ([email protected]).
- Incident response: defined escalation paths, with notification to affected Controllers without undue delay and in any event within 72 hours of becoming aware of a personal data breach (see section 9).
A full description of security controls is maintained at /legal/security.
7. Data subject rights
Atlio Information Technology will assist the Controller in fulfilling data subject rights requests within the timeframes required by applicable law. Where a data subject contacts Atlio Information Technology directly, Atlio Information Technology will forward the request to the Controller and, where technically feasible, provide the Controller with tools to facilitate compliance (such as data export and deletion functions within the platform).
The Controller remains the primary party responsible for responding to data subjects.
8. International data transfers
Where personal data is transferred outside the EEA or UK, Atlio Information Technology relies on the following mechanisms:
- Standard Contractual Clauses (SCCs): for transfers to AI providers in the United States, Atlio Information Technology relies on those providers’ data processing terms, which incorporate the EU SCCs (Commission Implementing Decision (EU) 2021/914, Module 3: Processor-to-Processor). UK addendums are used for UK transfers.
- AWS: data is primarily stored in eu-west-1 (Ireland) within the EEA. AWS provides SCCs for any cross-region replication.
- Google: where the Controller connects Google Search Console, Analytics 4, or Ads, Atlio Information Technology relies on the EU SCCs and Google’s Data Processing Terms for any transfer outside the EEA or UK.
- UAE transfers: Atlio Information Technology’s headquarters are in the UAE. Transfers from the EEA to Atlio Information Technology in the UAE are covered by SCCs pending a UAE adequacy decision.
Upon request, Atlio Information Technology will provide copies of applicable transfer mechanisms to the Controller.
9. Personal data breach notification
Atlio Information Technology will notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Controller data. The notification will include, to the extent available:
- A description of the nature of the breach, including the categories and approximate number of data subjects and records affected;
- The name and contact details of the data protection point of contact;
- A description of the likely consequences of the breach;
- A description of the measures taken or proposed to address the breach.
Where information is not immediately available, Atlio Information Technology may provide it in phases. The Controller is responsible for any notifications to supervisory authorities and data subjects required by applicable law.
10. Audit rights
Atlio Information Technology will provide the Controller with all information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Controller or a mandated auditor.
Audit requests must be submitted with at least 30 days’ notice, conducted during normal business hours, and limited in scope to matters relevant to this DPA. The Controller bears the cost of any audit it initiates. Atlio Information Technology may satisfy audit requests by providing relevant, up-to-date security documentation — such as completed security questionnaires and available third-party attestations covering its sub-processors — in lieu of an on-site audit.
11. Deletion and return of data
Upon termination of the service relationship or upon written request, Atlio Information Technology will, at the Controller’s election:
- Return all personal data to the Controller in a structured, machine-readable format (JSON or CSV); or
- Securely delete all personal data and certify deletion in writing within 30 days.
Atlio Information Technology may retain personal data for longer periods where required by applicable law, in which case it will isolate and protect the data from further processing.
12. Liability
Each party’s liability under this DPA is subject to the limitations and exclusions set out in the Terms of Service. Nothing in this DPA limits a party’s liability to data subjects or supervisory authorities under applicable data-protection law.
13. Contact and execution
This DPA takes effect upon acceptance of the Terms of Service. For customers requiring a countersigned DPA, please contact:
Atlio Information Technology LLCDubai, United Arab Emirates
Email: [email protected]