SearchVIU
All versions: v1
Version: v1.0 Effective date: 4 August 2026 Provider: searchVIU GmbH ("searchVIU", "we", "us", "our") Canonical location: /dpa on the platform of the Service used — this version: /dpa/v1
This Data Processing Agreement ("DPA") forms part of the searchVIU GmbH Master Service Terms & Service Level Agreement published at /terms (the "Master Terms") and the applicable Product Schedule, or of any other written or electronic agreement that incorporates this DPA (together, the "Agreement"). It governs the processing of personal data by searchVIU on behalf of the Customer in connection with the Service, as required by Article 28(3) GDPR.
The Customer enters into this DPA on its own behalf and, where applicable, on behalf of those of its affiliates that are authorised to use the Service under the Agreement and that have not entered into a separate arrangement with searchVIU. For the purposes of this DPA only, references to "Customer" include such affiliates.
| Role | Party |
|---|---|
| Processor | searchVIU GmbH, Gebrüder-Wright-Straße 58, 53125 Bonn, Germany. Commercial register: Amtsgericht Bonn, HRB 25557. VAT ID: DE312038967. |
| Controller | the Customer identified in the Order Form or in the Account ("Customer"). |
Contact for all data protection matters under this DPA: info@searchviu.com.
This DPA takes effect on the earlier of (a) acceptance of the Master Terms or of this DPA by the Customer, (b) signature by both parties, or (c) the commencement of processing of personal data by searchVIU on behalf of the Customer.
Where the Customer accepts this DPA during sign-up or in the Service, the acceptance is recorded together with the DPA version, the version of the sub-processor list then in force (Annex C), and a timestamp. Each published version of this DPA is preserved and remains individually identifiable, so that it can always be determined which wording applied to a Customer and when.
This DPA is versioned independently of the Master Terms and the Product Schedules: a new version of this DPA does not require a new version of those documents, and vice versa.
searchVIU may publish revised versions of this DPA. For material changes, searchVIU will give reasonable prior notice (as a rule, at least 30 days) before the new version takes effect and may require renewed acceptance. Changes that are required by applicable law, or that are non-material (such as corrections, clarifications, or updates to Annex B that do not reduce the level of security), take effect on publication. Changes to the list of sub-processors are handled under Section 9 and do not constitute a change to this DPA.
This DPA governs the processing of personal data and prevails over the Master Terms, the applicable Product Schedule and any Order Form in matters of data protection. All other provisions of those documents remain unaffected.
Individually negotiated agreements prevail. Where the parties have entered into a separately signed data processing agreement, or a master service agreement (MSA) or equivalent individually negotiated written contract containing data protection provisions, that document prevails over this DPA to the extent of any conflict. This DPA then applies only to matters that the signed document does not address.
In case of conflict, the following order of precedence applies:
Note the relationship between items 2 and 4: the data protection provisions of an MSA rank above this DPA, while the MSA in all other respects ranks below it. An MSA that is silent on data protection therefore does not displace this DPA. Section 13 of the Master Terms sets out the same order of precedence; the two lists are maintained identically.
The terms "personal data", "processing", "controller", "processor", "sub-processor", "data subject", "personal data breach" and "supervisory authority" have the meaning given in Article 4 GDPR.
Capitalised terms not defined here have the meaning given in the Master Terms.
The Customer is the controller and searchVIU is the processor in respect of Customer Personal Data. Where the Customer itself acts as a processor on behalf of a third party controller, searchVIU acts as a sub-processor and this DPA applies accordingly; in that case the Customer warrants that it is authorised by the relevant controller to enter into this DPA on that controller's behalf and to issue the instructions set out in it.
Each party is responsible for compliance with its own obligations under Data Protection Law.
Data searchVIU processes as controller. Personal data that searchVIU processes in its own right — in particular account, authentication, usage, billing and support data relating to the Customer's users, and searchVIU's own business and marketing data — is not Customer Personal Data and is not subject to this DPA. That processing is described in the Privacy Statement for the applicable Service, which is linked from the sign-up form and from the Service.
The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex A. The parties may amend Annex A by written agreement where necessary to reflect changes in the Service or in Data Protection Law.
searchVIU shall process Customer Personal Data only on the documented instructions of the Customer, including with regard to transfers to a third country or an international organisation, unless required to do otherwise by Union or Member State law to which searchVIU is subject. In such a case, searchVIU shall inform the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
The Agreement, this DPA, the applicable Order Form, and the Customer's configuration and use of the features and functionality of the Service constitute the Customer's complete and documented instructions. Additional or changed instructions must be given in writing (email is sufficient); searchVIU may charge for the reasonable cost of implementing instructions that go beyond the functionality of the Service and beyond searchVIU's statutory obligations.
searchVIU shall inform the Customer without undue delay if, in its opinion, an instruction infringes Data Protection Law, and may suspend execution of that instruction until it is confirmed or withdrawn. searchVIU shall inform the Customer without undue delay if it determines that it can no longer meet its obligations under this DPA or under Data Protection Law.
searchVIU shall not use Customer Personal Data for its own purposes, shall not sell or share it, and shall not combine it with personal data received from or on behalf of other parties, except where necessary to provide, secure, operate and maintain the Service in accordance with the Agreement.
The Customer is responsible for the lawfulness of the collection of Customer Personal Data and of its transfer to searchVIU, for having a valid legal basis, and for providing any required information to data subjects. This includes ensuring that the Customer holds the necessary rights and permissions for any website, data source or content it connects to or submits to the Service (see Section 5 of the Master Terms).
The Service is not designed for the processing of special categories of personal data under Article 9 GDPR or of personal data relating to criminal convictions and offences under Article 10 GDPR. The Customer shall not submit such data to the Service, and shall not connect data sources whose primary purpose is to supply such data, unless the parties have agreed otherwise in writing and have implemented the additional safeguards required.
The Customer is responsible for its own notification obligations towards supervisory authorities and data subjects under Articles 33 and 34 GDPR.
General authorisation. The Customer grants searchVIU general authorisation to engage sub-processors for the provision of the Service, in accordance with Article 28(2) GDPR. By accepting this DPA, the Customer authorises the sub-processors listed at the time of acceptance in the sub-processor list referred to in Annex C. That list carries a version identifier, and the version in force at the time of acceptance is recorded together with the acceptance (Section 2), so that it can always be determined which sub-processors the Customer authorised.
Fixed and configurable sub-processors. The sub-processor list distinguishes fixed infrastructure sub-processors, which are always engaged, from configurable sub-processors, which are engaged only where the corresponding feature, data source or workflow node is used in the Customer's setup.
Exclusion on request. The Customer may request that individual configurable sub-processors be excluded for its projects, and searchVIU will implement such exclusions. Where an exclusion would prevent a function the Customer uses from operating, searchVIU will inform the Customer of the impact so that the Customer can decide how to proceed. Fixed infrastructure sub-processors cannot be excluded without terminating the affected Service.
Notice of changes. searchVIU maintains the sub-processor list as a versioned record and will notify the Customer at least 30 days in advance of any intended addition or replacement of a sub-processor, before that sub-processor begins processing Customer Personal Data. Notice is given by email from info@searchviu.com to the contact person designated by the Customer under Section 5 of the Master Terms. The Customer is responsible for keeping that contact up to date.
Objection. The Customer may object to an intended change on reasonable data protection grounds within 30 days of the notice. The parties will then work together in good faith for up to 30 days to find a workable solution, which may include excluding the sub-processor for the Customer's projects or using an alternative. Where no solution is found and the sub-processor is essential to the affected Service, either party may terminate the affected Service on written notice, without penalty; fees already incurred remain payable and searchVIU will refund prepaid fees for the unused remainder of the term on a pro-rata basis.
Flow-down and liability. searchVIU shall impose on each sub-processor, by contract, data protection obligations that are materially the same as those set out in this DPA, including as regards security and international transfers. searchVIU remains fully liable to the Customer for the performance of each sub-processor's obligations.
Where a Service uses AI or machine learning models — including large language models operated by third parties — those providers are engaged as sub-processors and are identified as such in the sub-processor list.
AI functionality that processes Customer Personal Data appears in the Service in two forms, which differ in how the Customer can control them:
The Customer remains responsible for deciding what content it submits to AI-based functionality and for any decisions it takes on the basis of the output.
searchVIU shall ensure that persons authorised to process Customer Personal Data — including its managing director and any contractors — have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that this obligation survives the end of their engagement.
Access to Customer Personal Data is limited to those who need it to provide the Service, on a least-privilege and need-to-know basis, and is reviewed periodically.
Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing, as well as the risks to the rights and freedoms of natural persons, searchVIU shall implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR. The measures in place are described in Annex B.
searchVIU may update these measures over time, provided the level of security is not materially reduced.
searchVIU shall notify the Customer without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting Customer Personal Data.
The notification shall include, to the extent then available: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed to address the breach, and a contact point for further information. Where the information is not available at once, it will be provided in phases without further undue delay.
searchVIU shall take reasonable steps to contain and remedy the breach and shall keep the Customer informed of material developments. searchVIU shall document all personal data breaches and the remedial action taken.
Unsuccessful attempts and events that do not compromise the security of Customer Personal Data — such as failed log-in attempts, port scans, or blocked network attacks — are not personal data breaches and are not individually notifiable.
A notification under this Section is not an acknowledgement of fault or liability.
Taking into account the nature of the processing, searchVIU shall assist the Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Customer's obligation to respond to requests by data subjects under Chapter III GDPR (Articles 12 to 23).
Where searchVIU receives a request directly from a data subject relating to Customer Personal Data, it shall not respond to the substance of the request unless legally required or authorised by the Customer, and shall forward the request to the Customer without undue delay.
Where the Service provides self-service functionality for access, export, correction or deletion, the Customer shall use that functionality in the first instance. searchVIU may charge for reasonable additional effort that goes beyond that functionality.
Taking into account the nature of the processing and the information available to it, searchVIU shall provide the Customer with reasonable assistance in complying with its obligations under Articles 32 to 36 GDPR, including in relation to security of processing, breach notification, data protection impact assessments and prior consultation with supervisory authorities. searchVIU may charge for reasonable effort in connection with Articles 35 and 36.
searchVIU maintains a record of processing activities carried out on behalf of the Customer in accordance with Article 30(2) GDPR.
searchVIU shall make available to the Customer all information reasonably necessary to demonstrate compliance with Article 28 GDPR and this DPA. In the first instance, searchVIU may satisfy this obligation by providing current certifications, third-party audit reports (such as ISO 27001 or SOC 2), penetration test summaries, or a completed security questionnaire.
Where the Customer cannot reasonably establish compliance from that information, searchVIU shall allow for and contribute to audits, including inspections, conducted by the Customer or by an independent auditor mandated by the Customer and not being a competitor of searchVIU. Such audits shall be:
searchVIU may charge for its reasonable effort in supporting audits, questionnaires and assessments that go beyond providing the standard information referred to above.
Audits of infrastructure operated by sub-processors are satisfied by the certifications and audit reports of those sub-processors.
Upon termination or expiry of the Agreement, searchVIU shall, at the Customer's choice, delete or return Customer Personal Data, and delete existing copies, unless Union or Member State law requires further storage.
The Customer's choice must be communicated within 30 days of termination. Absent a choice, searchVIU will delete the data. Deletion takes place within 30 days of termination or of the Customer's request. Residual copies contained in backups are deleted in the ordinary course of the backup cycle, within no more than 90 days, and remain subject to this DPA until deleted.
Deletion of a Customer project in the Service automatically removes the associated datasets, storage, service accounts and scheduled jobs.
Where searchVIU is required to retain data to comply with statutory retention obligations, it shall restrict processing of that data to the purpose of the retention obligation, and the confidentiality obligations of this DPA and of the Agreement continue to apply.
Place of processing. The core infrastructure of the Service — the application, its databases, object storage and the data warehouse — is operated exclusively within the European Union, and Customer Personal Data is stored exclusively within the European Union.
The Service runs on Google Cloud Platform. At the effective date of this version, the regions used are europe-west1 (Belgium) and europe-west4 (Netherlands); BigQuery datasets are held in the EU multi-region, which Google limits to data centres located within the European Union and which excludes the United Kingdom and Switzerland. searchVIU may change the regions it uses within the European Union without amending this DPA. Any change that would result in Customer Personal Data being stored outside the European Union is a material change and is subject to Section 2 and, where a sub-processor is involved, to Section 9.
No restricted transfer between the parties. searchVIU is established in Germany. Where the Customer is established in the EEA, the United Kingdom or Switzerland, the provision of the Service does not involve a transfer of Customer Personal Data by the Customer to a third country.
Sub-processors outside the European Union. Some functions of the Service are provided with the help of sub-processors established or operating outside the European Union — in particular market-data, search-data and AI providers. The Service is designed so that those functions receive only the data they need to perform their task, such as keywords, domains, brand terms, public URLs and prompts, and not Customer Personal Data.
Where a sub-processor nevertheless processes Customer Personal Data outside the EEA — because the Customer configures a function that way, or because personal data appears incidentally in publicly available content retrieved on the Customer's instruction — searchVIU ensures that the transfer takes place only on the basis of a valid transfer mechanism under Chapter V GDPR: an adequacy decision (including, where applicable, certification under the EU-U.S. Data Privacy Framework), or the EU SCCs (Module Three, processor to processor) concluded by searchVIU with the sub-processor, together with any supplementary measures required following a transfer impact assessment. The applicable mechanism for each sub-processor is indicated in the sub-processor list referred to in Annex C.
Customers outside the EEA. Where the Customer is established outside the EEA, the United Kingdom or Switzerland and Chapter V GDPR applies to the disclosure of Customer Personal Data by searchVIU to the Customer, the EU SCCs apply as set out in Annex D.
Government access requests. Where searchVIU receives a legally binding request from a public authority for disclosure of Customer Personal Data, it shall — unless legally prohibited — notify the Customer without undue delay, challenge the request where there are reasonable grounds to do so, and disclose only the minimum amount of data legally required. searchVIU maintains a record of such requests.
Liability towards data subjects is governed by Article 82 GDPR.
As between the parties, liability under this DPA is subject to the limitation of liability agreed in the Agreement (Section 12 of the Master Terms, or the corresponding provision of any MSA), to the extent that such limitation is permitted by applicable law. Nothing in this DPA limits liability that cannot be limited by law, including liability for intent and gross negligence and for injury to life, body or health.
This DPA applies for as long as searchVIU processes Customer Personal Data on behalf of the Customer, and in any event for the term of the Agreement. Provisions that by their nature are intended to survive — in particular Sections 11, 17 and 19 — continue to apply after termination.
This DPA is governed by the laws of Germany, without regard to conflict-of-law provisions. The place of jurisdiction, to the extent permitted by law, is Bonn, Germany. This is without prejudice to the governing law and jurisdiction provisions of any Standard Contractual Clauses agreed between the parties, which prevail for matters falling within their scope.
If any provision of this DPA is held to be invalid or unenforceable, the remaining provisions remain in full force. The invalid provision shall be replaced by a valid provision that comes closest to the commercial and data protection purpose of the original.
The authoritative version of this DPA is the English version published at /dpa. searchVIU may make a German translation available on request, for convenience only. In the event of any discrepancy, the English version prevails.
This does not apply to a German-language data processing agreement that has been signed by both parties; such a document is a separately signed agreement within the meaning of Section 3 and prevails accordingly.
Subject matter. The provision of the Service to the Customer under the Agreement.
Duration. The term of the Agreement, plus the deletion and backup periods set out in Section 17.
Nature and purpose. Provision of SEO monitoring and data warehousing, AI workflow execution, and/or AI brand and visibility monitoring, as described in the applicable Product Schedule and Order Form.
Processing operations. Collection, recording, organisation, structuring, storage, adaptation, retrieval, analysis, use, disclosure by transmission to authorised sub-processors, restriction, erasure and destruction.
Frequency. Continuous, for the duration of the Agreement.
Categories of data subjects and types of personal data, per Service used:
Special categories of personal data: none. See Section 8.
Competent supervisory authority: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen (LDI NRW), Düsseldorf, Germany — as the authority of searchVIU's place of establishment. Where the EU SCCs apply under Annex D, the competent supervisory authority is determined in accordance with Clause 13 of those clauses.
This Annex describes the measures in place at the effective date. searchVIU may update the measures, provided the level of security is not materially reduced. The current version is always the one published at /dpa.
The Service runs entirely on Google Cloud Platform in European Union regions. searchVIU operates no data centres of its own. Physical and environmental security is provided by Google Cloud and is covered by Google's certifications (including ISO/IEC 27001, 27017, 27018 and SOC 2). Each production application and the staging environment run in separate Google Cloud projects.
Each Customer's data is stored in dedicated projects, datasets and storage buckets with project-scoped service accounts. There is no shared dataset and no cross-Customer data access.
searchVIU is currently undergoing ISO/IEC 27001:2022 and SOC 2 audits. Certification has not yet been issued. The current status, and any reports once available, are provided on request. This Annex will be updated when certification is issued.
The current list of sub-processors engaged by searchVIU, including their role, the processing they carry out, their location and the applicable transfer mechanism, is maintained at:
That list forms part of this DPA. It distinguishes fixed infrastructure sub-processors from configurable sub-processors, and carries a version identifier and a last-updated date, both shown on that page. The version in force when the Customer accepted this DPA is recorded with the acceptance record (Section 2), so that it can always be determined which sub-processors were authorised at that point. Changes are handled in accordance with Section 9.
This Annex applies only where Section 18 provides that the EU SCCs apply — that is, where the Customer is established outside the EEA, the United Kingdom and Switzerland, and Chapter V GDPR applies to the disclosure of Customer Personal Data by searchVIU to the Customer.
In that case the EU SCCs are incorporated into this DPA by reference and completed as follows:
Where personal data protected by the UK GDPR is transferred, the EU SCCs apply as modified by the UK International Data Transfer Addendum issued by the Information Commissioner's Office. Where personal data protected by the Swiss FADP is transferred, references in the EU SCCs to the GDPR, the Union and Member States, and to competent supervisory authorities and courts, are read as references to the Swiss FADP, Switzerland and the competent Swiss authorities and courts.
Acceptance of this DPA constitutes signature of the EU SCCs and their annexes by both parties for the purposes of Clause 1 of the EU SCCs.
Where the EU SCCs conflict with any other provision of this DPA or of the Agreement, the EU SCCs prevail.
searchVIU GmbH Gebrüder-Wright-Straße 58, 53125 Bonn, Germany Email: info@searchviu.com · Phone: +49 (0)228 50469090 Master Terms: /terms · Sub-processors: /subprocessors Privacy Statement: linked from the sign-up form and from the Service.