LocalBusinessAudit

Data Processing Agreement

Effective October 1, 2026

This agreement covers personal data that business customers, such as agencies, put into localbusinessaudit.com about their own clients, prospects and team.

It applies automatically to customers it is relevant to; no signature is needed. For a countersigned copy, contact [email protected].

1. Scope and roles

This Data Processing Agreement (“DPA”) forms part of the Master Service Agreement or, where no MSA applies, the Terms of Service, between LocalBusinessAudit (“Processor”) [To be completed: registered company name, entity type and registered address] and the customer (“Controller”).

It applies where the Processor handles personal data on the Controller's behalf and data protection law, such as the GDPR, UK GDPR or US state privacy laws, applies to that data. In that situation the customer is the controller (or a processor for its own clients) and LocalBusinessAudit is its processor (or sub-processor).

It does not cover personal data that LocalBusinessAudit handles for its own purposes, such as account, billing and security data. That is described in the Privacy Policy.

2. Details of the processing

ItemDescription
Subject matterProviding the audit service to the Controller
DurationFor as long as the Controller has an account, plus the deletion period in section 9
Nature and purposeStoring, organising, displaying and transmitting data the Controller submits, in order to run audits, show and share reports, send report emails and invitations, and deliver webhooks
Types of personal dataNames and email addresses of team members and report recipients; business contact details of the Controller's clients and prospects (business name, website, city, and the phone numbers and email addresses they publish on their website or Google listing); the content of messages the Controller sends with reports
Categories of peopleThe Controller's staff and team members; owners, staff and contacts of the Controller's clients and prospects
Special categories of dataNone. The Controller must not submit sensitive personal data

3. Processor's obligations

  • Instructions: process the personal data only on the Controller's documented instructions, which are the agreement, the Controller's use of the Service's features, and any further written instructions consistent with them. The Processor will tell the Controller if it believes an instruction breaks the law.
  • Confidentiality: ensure everyone it authorises to handle the data is bound by confidentiality.
  • Security: maintain the measures in Annex A.
  • No other use: not sell the personal data, and not use or combine it for any purpose other than providing the Service, except as the law allows a processor to do.

4. Controller's obligations

The Controller is responsible for having a lawful basis to submit the personal data, for giving any required notices to the people concerned, and for the accuracy of what it submits. The Controller is responsible for its own messages to its clients and prospects sent through the Service.

5. Sub-processors

The Controller authorises the Processor to use the following sub-processors:

Sub-processorPurposeLocation
[To be completed: hosting provider name and location]Hosting of servers and database[To be completed: hosting region]
ResendDelivery of report emails and invitationsUnited States
Google (PageSpeed Insights, Places API)Speed tests and public business listing data. Receives the website address, business name and city onlyUnited States and other Google locations
DataForSEOBacklink data and public Google reviews for paid-plan audits. Receives the website address and Google listing identifier only[To be completed: DataForSEO processing location]
OpenAIWriting the optional AI growth plan. Receives the audit findings with the business name, city and category onlyUnited States
StripeSubscription billing for the Controller's own account. Does not receive the Controller's client dataUnited States

The Processor will impose data protection obligations on each sub-processor that are no less protective than this DPA, and remains responsible for their performance. It will update this page at least 30 days before adding or replacing a sub-processor. The Controller may object on reasonable data protection grounds within that period; if the objection cannot be resolved, the Controller may end the affected service and receive a refund of fees paid for the period after termination.

6. Requests from individuals

If a person contacts the Processor to exercise their rights over data the Controller is responsible for, the Processor will pass the request to the Controller without undue delay and will not respond itself except to say so. The Processor will give reasonable help so the Controller can respond, including by deleting or exporting data on request.

7. Personal data breaches

The Processor will notify the Controller without undue delay, and where feasible within 72 hours, after becoming aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration or unauthorised disclosure of, or access to, the personal data. The notice will describe what happened, the data affected and the steps being taken, as far as known, and will be updated as more is learned.

8. Assistance and audits

The Processor will give reasonable help with data protection impact assessments and consultations with regulators that relate to the Service.

On written request, no more than once a year unless a breach has occurred or a regulator requires it, the Processor will provide the information reasonably needed to show it complies with this DPA and answer reasonable written questions. An on-site audit may take place only where that information is insufficient, on reasonable notice, during business hours, under confidentiality, and at the Controller's cost.

9. Return and deletion

During the agreement the Controller can view and remove its data in the Service. After the agreement ends, the Processor will delete the personal data within 60 days of a written request, or return an export first if asked, except where the law requires it to be kept. Backups are overwritten in the normal backup cycle.

10. International transfers

Where the personal data is transferred from the EEA, UK or Switzerland to a country without an adequacy decision, the European Commission's standard contractual clauses (Module Two, controller to processor, or Module Three, processor to processor, as applicable), together with the UK addendum where UK data is involved, are incorporated into this DPA by reference. The details in section 2 and Annex A complete their annexes. The Processor will sign a standalone copy on request.

11. Liability and priority

Each party's liability under this DPA is subject to the limits in the agreement it forms part of. If this DPA and that agreement conflict on a matter of personal data, this DPA applies; if the standard contractual clauses and this DPA conflict, the clauses apply.

12. Annex A: security measures

  • Encryption in transit: all access to the Service is over HTTPS.
  • Credentials: passwords are stored only as salted one-way hashes. Login sessions, password-reset links, email confirmations and invitations use random tokens of which only a hash is stored.
  • Access control: each workspace's data is available only to its owner and the team members they invite, with owner, admin and member roles. Staff access to administrative tools is limited to named, verified accounts.
  • Network: the database, queue and internal services are not reachable from the internet; only the web server is.
  • Abuse protection: sign-in and other sensitive actions are rate-limited. Outgoing webhooks are restricted to public HTTPS addresses and are signed.
  • Data minimisation: visitor IP addresses are stored only as a keyed hash. Card details are handled by Stripe and never reach the Processor's systems.
  • Backups: the database is backed up regularly and backups are retained for a limited period.

Related documents: Privacy Policy · Terms of Service · Refund Policy · Master Service Agreement