01Introduction#
This Data Processing Addendum ("DPA") forms part of the Terms of Service between you ("Customer") and Mori Digital Group LLC ("Processor", "NarraSEO", or "we") and applies when we process Customer Personal Data on your behalf in providing the Service. Capitalized terms not defined here have the meaning in the Terms or in applicable data protection law.
This DPA includes Article 28 GDPR (and UK GDPR) processor terms and California CPRA/CCPA service provider terms.
02Roles and subject matter#
Customer is the controller (or business) for Customer Personal Data submitted to the Service. NarraSEO is the processor (or service provider) for that data. Mori Digital Group LLC remains controller for account administration, billing, and security data as described in the Privacy Policy.
Subject matter: hosting, processing, and generating outputs from Customer content and related workspace data as needed to provide NarraSEO features Customer enables.
03Duration#
This DPA lasts for the term of the Agreement and until Customer Personal Data is deleted or returned in accordance with the deletion section, including backup rotation.
04Nature and purpose#
Processing is automated and manual as needed for support and security. Purpose is limited to providing, securing, and improving the Service for Customer, including AI-assisted features through subprocessors, storage, retrieval, publishing Customer directs, and related operations. We do not process Customer Personal Data for our own marketing of third-party products, and we do not train cross-customer models on Customer content.
05Categories of data#
Data subjects
Customer's personnel, end users, and individuals whose information appears in content Customer submits (for example authors, customers, or sources referenced in drafts).
Personal data
Identity and contact data in accounts; content, prompts, documents, attachments, embeddings, integration metadata Customer connects; and usage metadata tied to those workloads. Customer must not submit prohibited sensitive categories described in the Terms.
06Processor obligations#
NarraSEO will:
- Process Customer Personal Data only on documented instructions from Customer (including the Agreement and product configuration), unless required by law.
- Ensure persons authorized to process Customer Personal Data are bound by confidentiality.
- Implement the security measures in the Security annex.
- Engage subprocessors only under the Subprocessor annex and flow down equivalent data protection obligations.
- Assist Customer with data subject requests, DPIAs, and consultations with supervisory authorities, taking into account the nature of processing and information available to us.
- Delete or return Customer Personal Data at the end of the provision of services, subject to the backup caveat below.
- Make available information necessary to demonstrate compliance and allow audits as described in Audit and information.
- Promptly inform Customer if, in our opinion, an instruction infringes applicable data protection law.
07Confidentiality#
We will keep Customer Personal Data confidential and limit access to personnel and subprocessors who need it to perform the Service, support, or security functions.
08Security annex#
Technical and organizational measures include access controls appropriate to a multi-tenant product, encrypted storage of secrets, hashed API credentials, TLS for ordinary web and API traffic, optional multi-factor authentication for users, and MFA for privileged internal access.
09Subprocessor annex#
Customer authorizes NarraSEO to engage the subprocessors listed below. This list is intended to match the Privacy Policy subprocessor table.
| Vendor | Purpose | Status |
|---|---|---|
| Supabase | Database, authentication, storage, vault secrets | Always active |
| Stripe | Payments, subscriptions, customer portal | Always active |
| Vercel | Application hosting and edge delivery | Always active |
| Resend | Account, billing, and lifecycle email | Always active |
| Anthropic | AI generation and chat workloads | Active when configured |
| OpenAI | AI generation, embeddings, and image generation | Active when configured |
| Google Gemini | AI generation workloads | Active when configured |
| Perplexity | Research and retrieval-assisted generation | Active when configured |
| xAI | AI generation workloads | Active when configured |
| DataForSEO | Keyword and SERP research data | Active when configured |
| Firecrawl | Site crawling and page extraction | Active when configured |
| Tavily | Web research retrieval | Active when configured |
| PageSpeed Insights | Page performance signals | Active when configured |
| YouTube Data API | Video metadata for supported workflows | Active when configured |
| Pexels | Stock imagery | Active when configured |
| Unsplash | Stock imagery | Active when configured |
| Google OAuth APIs | GSC and GA connections you authorize | Active when you connect |
| Shopify, Wix, BigCommerce | Commerce publishing OAuth when configured | Active when configured |
| Cloudflare Turnstile | Bot protection on auth surfaces | Always active |
| Reditus | Affiliate attribution | Active when enabled |
| Sentry | Error monitoring | Active when enabled |
| Google Analytics | Site and product usage analytics | Active when enabled |
We will update the public list when the subprocessors that process Customer Personal Data change. Notice is provided by updating this page and the Privacy Policy. If you object to a new subprocessor on reasonable data-protection grounds within 15 days of the listing update, contact privacy@narraseo.com and we will discuss alternatives in good faith, which may include terminating the affected feature or the Agreement.
10Assistance with requests#
We will assist with data subject requests through privacy@narraseo.com, consistent with the Privacy Policy timelines (30 days GDPR / UK GDPR; 45 days CPRA), taking into account the nature of processing.
11Breach notification#
We will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to help Customer meet its own notification obligations.
12Audit and information#
Upon written request no more than once per twelve months (unless required by a supervisory authority or following a confirmed breach), we will provide written information reasonably necessary to demonstrate compliance with this DPA. On-site audits are not available as a default right. If an on-site audit is legally required and cannot be satisfied by documentation, the parties will agree on scope, timing, and confidentiality, and Customer will bear reasonable costs unless the audit reveals a material breach by NarraSEO.
13Deletion or return#
Upon termination or Customer's request through the product deletion flow, we will delete Customer Personal Data after the grace period described in the Privacy Policy, except where retention is required by law. Encrypted backups age out on a separate cycle.
Return of data is available to the extent the product already allows export of documents and related content. Additional return formats may be arranged through support where reasonably feasible.
14International transfers#
Primary Customer Personal Data for the Service is processed in the United States. Where NarraSEO transfers Customer Personal Data from the EEA, UK, or Switzerland to a third country lacking an adequacy decision, the parties rely on the European Commission Standard Contractual Clauses (Module 2 controller to processor, and Module 3 processor to processor where applicable) and the UK International Data Transfer Addendum (or successor), completed with the information in this DPA, the Privacy Policy, and the Agreement. On request, we will provide the SCC / addendum package then in use.
15CCPA service provider terms#
For California Consumer Privacy Act / CPRA purposes, NarraSEO is a service provider / contractor. We will not sell or share Customer Personal Data, retain, use, or disclose it for any purpose other than the business purposes specified in the Agreement (including this DPA), or combine it with personal information from other sources except as permitted for service providers under the CPRA. We certify that we understand these restrictions. Customer may take reasonable and appropriate steps to ensure we use Customer Personal Data consistent with Customer's CPRA obligations, and may remediate unauthorized use upon notice.
16Miscellaneous#
If there is a conflict between this DPA and the Terms regarding processing of Customer Personal Data, this DPA controls. This DPA is governed by the same law and dispute terms as the Terms, except where data protection law requires otherwise. Liability remains subject to the limitations in the Terms except where such limitations are prohibited for data protection claims.
17Contact#
Privacy and DPA notices: privacy@narraseo.com. Account support: support@narraseo.com.
Mori Digital Group LLC
418 Broadway STE 11054
Albany, NY 12207
