
Each local area page used to take us half a day to create and optimize.
With SEOmatic, we can create hundreds of pages in the same time, which helps our clients make the best use of their budget.
It's transformed how we deliver scalable SEO solutions.
Will Hawkins
Marketing Director, Digi-Business UK
Agents read your Search Console data, do the work, and prove what actually moved. You decide what ships.
14-Day Free Trial. $1 card check, refunded. Cancel Anytime.
Version 1.0 β September 7, 2026
This is SEOmatic's standard GDPR Article 28 DPA. It cross-references the Trust Center (sub-processors, security measures) and the Privacy Policy, so what you sign is what the product actually does.
This Data Processing Agreement ("DPA") forms part of the agreement between the customer accepting it ("Controller") and SEOmatic, operated from 1 rue Marguerin, 75014 Paris, France ("Processor"), for the SEOmatic service (the "Service"). It applies where the Processor processes personal data on the Controller's behalf within the meaning of Regulation (EU) 2016/679 ("GDPR").
Where the Controller is itself a processor for its own clients (the agency case), the Controller warrants that its instructions to SEOmatic are consistent with its own controllers' instructions, and SEOmatic acts as a sub-processor.
The Processor processes the data the Controller connects to the Service in order to provide it: reading Search Console performance data to diagnose and prioritize SEO work, generating and reviewing content and fixes with AI model providers, staging changes for the Controller's approval, publishing approved changes to the Controller's CMS, and measuring outcomes. Processing lasts for the duration of the Controller's use of the Service, plus the deletion windows in section 8.
Processed on the Controller's behalf:
The Processor processes personal data only on the Controller's documented instructions, which are: this DPA, the Service's settings and features as operated by the Controller (including the approval workflow β nothing publishes without the Controller's approval unless the Controller enables autonomous mode), and any additional written instructions agreed between the parties. The Processor informs the Controller if, in its opinion, an instruction infringes the GDPR.
The EU-sensitive routing control (Settings β Agent β Data Residency) is an instruction mechanism: enabling it instructs the Processor to route all AI processing for that workspace to Anthropic and never to China-hosted providers, enforced in code. Those Anthropic calls run on the Controller's own Anthropic API key under the Controller's own agreement with Anthropic (who bills the Controller directly); the Controller's explicit acknowledgment of this is required at enablement and recorded.
Persons authorised to process the data are bound by confidentiality. The Processor implements the technical and organisational measures published on its Trust Center (seomatic.ai/trust), which include: TLS in transit; AES-256-GCM encryption at rest for CMS credentials and OAuth tokens; API keys stored as SHA-256 hashes; role-based access control; a durable audit trail of any administrative access to customer accounts; automatic deletion and retention jobs; and an approval-gated, reversible change pipeline. Material degradations of these measures will not be applied to existing customers without notice.
The Controller grants general authorisation for the sub-processors listed on the Trust Center (seomatic.ai/trust), which states each provider's purpose and region. The Processor will update that list at least 15 days before adding or replacing a sub-processor; the Controller may object on reasonable data-protection grounds within that window, in which case the parties will seek a solution and, failing one, the Controller may terminate the affected part of the Service.
The Processor remains fully liable to the Controller for its sub-processors' performance and imposes data-protection obligations on them equivalent to this DPA.
Taking into account the nature of the processing, the Processor assists the Controller with data-subject requests (access, rectification, erasure, restriction, portability, objection) β write to contact@seomatic.ai and requests are handled within 30 days β and with the Controller's obligations under Articles 32-36 GDPR (security, breach notification, DPIAs), to the extent the information is available to the Processor.
The Processor notifies the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, with the information required by Article 33(3) GDPR as it becomes available.
On deletion of a workspace or account, or on termination, associated personal data is deleted from production systems within 30 days, with encrypted backups expiring on their rotation schedule of up to 90 days, except where retention is required by law (e.g. French accounting law for invoices). Content the Service published into the Controller's own CMS belongs to the Controller and is untouched by termination. The Controller can export its data via the in-app export and the Service's product export features before termination.
The Processor makes available the information reasonably necessary to demonstrate compliance with Article 28 GDPR β the Trust Center, this DPA, and written answers to security questionnaires β and allows for audits, including inspections, conducted by the Controller or its mandated auditor, at most once per year, on 30 days' notice, at the Controller's cost, and without access to other customers' data.
Infrastructure is hosted in the United States (Hetzner, AWS). For personal data of EU/EEA and UK data subjects, transfers to the Processor's sub-processors rely on the European Commission's Standard Contractual Clauses (Module 2 or 3, as applicable) or an applicable adequacy framework, as stated per provider on the Trust Center. Where a China-hosted AI provider would be involved, the EU-sensitive routing control (section 4) prevents that workspace's content from reaching it.
Liability under this DPA follows the liability provisions of the parties' underlying agreement. This DPA takes effect on execution, remains in force as long as the Processor processes personal data for the Controller, and is governed by French law. In case of conflict between this DPA and the underlying agreement, this DPA prevails for data-protection matters.
Email contact@seomatic.ai from your account email with your legal entity name and address. We return a countersigned copy of this version, normally within 2 business days. Custom redlines are reviewed case by case.