EN
Language · same page NLNederlands/verwerkersovereenkomst/ ENEnglish (UK)/en/data-processing-agreement/ ESEspañol/es/contrato-de-encargo-de-tratamiento/ We do not remember your choice and never redirect you automatically.
DOC.D1 · CTR-01 · data processing agreement version 1.0 · in force from 11 August 2026

Data processing agreement

If we process personal data on your behalf, these arrangements apply. They are written in ordinary language, because an agreement you do not understand does not protect you. That does not make the legal content any thinner.

See the sub-processors Read the privacy statement twelve articles and three annexes · with the annex on Jarvis
DOC.D1a · Version

Which version this is, and which law it runs under

Article 28 has the same number in two different laws, and that is the trap this page is written around. If you are established in the European Union, including Ireland, the article you can hold us to is article 28 of the GDPR. If you are established in the United Kingdom, it is article 28 of the UK GDPR, which is a separate statute with the same numbering and its own regulator, the Information Commissioner's Office. A translation that simply wrote "article 28 GDPR" for a British client would be pointing at a law that no longer governs them. Where this document says article 28, read it as the one that applies where you are.
DocumentData processing agreement TheSEO, abbreviated in this document as DPA
Document IDCTR-01
Version1.0
In force from11 August 2026
Last changed25 August 2026, this English edition only
Earlier versionsNone. This is version 1.0, the first published version; there is no version archive yet
# OPEN POINT
On acceptance it should be recorded which version you accepted, at what moment, by whom and on behalf of which organisation. While that archive does not exist, we cannot refer back to older versions. We would rather name that than write it away.

Would you like a signed copy, or does your own template have to be used? Email sales@theseo.nl. We will also sign on your paper, provided the level of protection does not drop because of it.

Figure D.01the shape of this document, before you start reading
D1aWhich version this is
D1bBetween whom this agreement applies
D1cWhat we use the data for
D1dWhich people and which data it concerns
D1eWho may reach it, and how we keep it shut
D1fWhat happens when it goes wrong
D1gWhen somebody exercises their rights
D1hThe parties we engage
D1iData outside the EEA, and out of the United Kingdom
D1jReturning, exporting and erasing
D1kChecking that we really do it
D1lGovernment requests, liability and changes
Annexes · per product, applicable only if you buy that product
D1mAnnex A: MyParcel Dashboard
D1nAnnex B: Jarvis and TheSEO Brain
D1oAnnex C: LinkLoop and bespoke work
D1pWhat still has to be done

# Twelve articles, three annexes and a list of open points. The annexes are indented because they apply only to the product above them.
# Looking for one thing? This strip is the fastest route. Reading the whole piece? You can skip it.
# The marker running down the strip is a reading position, not a status.

DOC.D1b · Parties

Between whom this agreement applies

This DPA belongs with the agreement between you as a business client and us. You are the controller, we are the processor. It applies in so far as we process personal data on your behalf. The terms mean the same here as they do in the GDPR, and as they do in the UK GDPR for a client established in the United Kingdom.

Who you are making this arrangement with

CompanyMansotti
Trading nameTheSEO, trading name of Mansotti
Company registrationDutch Chamber of Commerce (KVK) 77834453
VAT numberDutch VAT number NL003245282B11
Registered addressAlbert Plesmanring 9, 3712 DA Huis ter Heide, the Netherlands
Emailsales@theseo.nl
Telephone+31 6 29 91 97 56

The same details are on our contact page and on our invoices. We are not registered with Companies House and we do not present ourselves as established in the United Kingdom.

Order of precedence and duration

The DPA starts as soon as processing starts and runs until we have deleted or returned all personal data we process on your behalf. Where processing on your behalf is concerned and the documents contradict each other, this DPA prevails over the general terms and over the product annex. The main agreement governs the commercial arrangements.

DOC.D1c · Purpose and instructions

What we use the data for

We process the data solely to deliver the agreed function: SaaS, hosting, synchronisation, analysis, support, communication or an AI function. And we do that according to your documented instructions. Those instructions are: the main agreement, the settings you choose in the product, the support request you give us, and this DPA.

If we consider an instruction to be in breach of data protection law, we say so before carrying it out, and we may suspend that processing. If law obliges us to carry out a processing operation, we tell you in advance unless the law forbids that.

Who is responsible for what

You determine the purpose, the means, the categories, the data subjects and the retention periods for the processing where you are the controller. You warrant that there is a valid lawful basis, that you are transparent towards the people concerned, and that your instruction is sound. We do not independently set new purposes for your data.

For our own contract administration, invoicing, security, fraud prevention, legal obligations and business communication, we are the controller ourselves. Our privacy statement applies to that, not this DPA.

DOC.D1d · What we process

Which people and which data it concerns

Who it can be about

  • your staff, users and contacts;
  • your customers, prospects, suppliers or business partners;
  • recipients of shipments and people communicating about a delivery or a claim;
  • people about whom you lawfully process business content in Jarvis or in an engagement.

Which data that can be

  • identification, contact, organisation and account data;
  • usage, session, authorisation, audit and security data;
  • business content, documents, instructions, prompts and their output;
  • data listed in a product specific annex below.

What may not go in

Special category data, criminal offence data, data about children and full payment card details do not belong here. They are prohibited, unless they are expressly permitted in a signed engagement annex and the additional measures and the data protection impact assessment have been completed. So do not put them in a field, a document or a prompt merely because it happens to be possible.

How long and how often

Processing is ongoing or happens on request, for the duration of your subscription or your engagement. After that the agreed export, deletion and backup periods follow. They are set out further down and per product in the annex.

DOC.D1e · Access and security

Who may reach it, and how we keep it shut

Access to your data goes only to whoever needs that access, and that person is bound to confidentiality by contract or by law. Access hangs on a role, is reviewed periodically, and is withdrawn in good time on a change of duties or on leaving. If support looks into your data, that is temporary, aimed at the question you asked, and logged where appropriate.

Beyond that we take appropriate measures as article 32 requires, matched to the risk. The current baseline includes, where fitting:

  • encrypted transport and encrypted or otherwise appropriate storage of secrets;
  • strong authentication, two step verification for administrators, and the fewest possible rights per role;
  • separation between organisations, server side authorisation and tests demonstrating that one client cannot reach another;
  • secure development, review, test, change and rollback procedures;
  • signed webhooks that do not execute twice, input validation and rate limits;
  • logging without unnecessary content, timely alerting and incident triage;
  • vulnerability management, dependency checking and a reporting point for anyone who finds something;
  • backups, restore tests, continuity planning and secure deletion;
  • supplier assessment and separation of production, staging and test;
  • periodic reviews of risks, access rights and recovery.

These measures may move with the state of the art, as long as the level of protection does not materially drop because of it. If you ask, we give a current description and the evidence that goes with it, without weakening the security of other clients.

DOC.D1f · Breaches

What happens when it goes wrong

If there is a personal data breach involving data we process on your behalf, and it is confirmed, we report it without undue delay as soon as there are sufficient grounds. Internally we aim to do that within 24 hours of confirmation. That is a target we set ourselves, not a guarantee we sell you.

That report states, in so far as we already know it:

  • what happened, which systems it affects, which categories of data and roughly how many;
  • what the likely consequences are;
  • what we have already done and what we propose;
  • who you can turn to and when you get the next update.

An early report is sometimes incomplete. We consider that less bad than a late report, so we add to it as soon as we know more. We record the incident and give you reasonable help with your own notification and information duties. You decide whether a report goes to the supervisory authority or to the people concerned, unless we are legally obliged to do so ourselves.

If the incident is caused by a failure on our side, that support is included. If the support is exceptionally extensive because of something in your own environment, we may charge reasonable costs for it, but only if we told you in advance.

The order, in one picture

The paragraphs above describe roles that take turns: first us, then you. Read as running text it is easy to lose track of where the decision sits and which clock starts where. So the same arrangement is set out below once more, but as a lane. Left the role, middle the step, right the deadline with its origin beside it, so you can see which deadline we set ourselves and which one comes from the law.

FIG.01: The notification chain after a data breachsix steps, two roles
breach-chain-d1f.mdfrom confirmation to decision
us 1. The incident is confirmedThe clock only starts at a confirmed breach of personal data that we process on your behalf. A suspicion we are still looking into is not worth a report, because a report that turns out not to be an incident costs you a response you never needed to make. starting pointconfirmation, not the first suspicion
us 2. We report it to youWithout undue delay, as soon as there are sufficient grounds. Internally we aim to do that within 24 hours of confirmation. That aim is stated in the first paragraph of this article and it is exactly what it says: a target we set ourselves, not a deadline we sell you. 24 hours, a targetour own standard, from article D1f above
us 3. What that report containsWhat happened and which systems it affects, which categories of data and roughly how many, the likely consequences, what we have already done and what we propose, who you can turn to and when the next update comes. If we do not yet know part of it, the report still goes out and we add to it. six componentsincomplete is allowed, late is not

Here the decision passes to you, because you are the controller

you 4. You assess and you decideYou determine whether a report goes to the supervisory authority and whether the people concerned are informed. We do not handle that ourselves, unless we are legally obliged to. We do supply the information you need for that decision and give you reasonable help with your own notification and information duties. your decisionour part is the information, not the choice
you 5. Reporting to the supervisory authorityThe GDPR gives you a deadline for this: without undue delay and, where feasible, not later than 72 hours after having become aware of the breach. Reporting is not required where the breach is unlikely to result in a risk to the rights and freedoms of natural persons. If it takes longer than 72 hours, the notification has to be accompanied by reasons for the delay. 72 hours, statutoryGDPR article 33(1)
you 6. Informing the people concernedWhere the breach is likely to result in a high risk to the rights and freedoms of natural persons, you inform those people without undue delay. The law puts no hour count on that; what it says is that it happens without unnecessary delay. without undue delayGDPR article 34(1), no hour count

# The 24 hours in step 2 is a target we set ourselves and it is stated in article D1f above. It is not a statutory deadline and not a guarantee.
# The deadlines in steps 5 and 6 come from the regulation itself: Regulation (EU) 2016/679, article 33 and article 34. Checked on 25 August 2026.
# If you are a controller under the UK regime rather than the EU one, the equivalent provisions of the UK GDPR apply to steps 5 and 6 instead; check your own position with your adviser.
# What the lane does not replace: in the event of a contradiction the text of the articles above governs, not this diagram.

DOC.D1g · Rights and assessments

When somebody exercises their rights

If we receive a request directly that concerns your data, we forward it to you as quickly as possible and do not act on it ourselves, unless the law obliges us to. We support you with what the technology allows: searching, exporting, correcting, restricting and deleting. You remain responsible for establishing identity, for the substantive decision and for a timely response.

Impact assessments and prior consultation

If you have to carry out a data protection impact assessment, make a balancing test or consult the supervisory authority in advance, we supply the information we reasonably have available. We also point out product specific risks that we know of.

If you intend to process something that is likely to result in a high risk, tell us before you switch it on. We may block that processing until we have agreed appropriate measures together. That is not obstruction, that is the reason this arrangement exists.

DOC.D1h · Sub-processors

The parties we engage

You give general written authorisation for the sub-processors listed in our public register at that moment. You will find that register at theseo.nl/en/sub-processors/. It states per party which service they deliver, which data goes there and where that happens.

What we take on with that:

  • we choose sub-processors on privacy and security, not only on price or convenience;
  • we impose the same data protection obligations on them as we have towards you;
  • we remain responsible for their obligations in so far as the law prescribes;
  • if a new or replacement sub-processor is going to process material client data, we give notice at least 30 days in advance.

Within that period you can object with reasons on concrete privacy grounds. We then look for a reasonable solution together, for instance a different configuration or an alternative. If we cannot agree, you may end only the part it affects, and do so before the new sub-processor is taken into use.

If a sub-processor has to be replaced urgently for security or business continuity reasons, that may go faster. We then inform you as soon as possible.

DOC.D1i · Transfers

Data outside the EEA, and out of the United Kingdom

We permit processing outside the European Economic Area only with a valid transfer basis: an adequacy decision, or the applicable standard contractual clauses, with additional measures where those are needed. The sub-processor register states the known locations and mechanisms.

If you ask, we provide the relevant information about a transfer or an available copy of the safeguard. We may redact confidential parts of it, because those concern third parties and security.

# OPEN POINT, AND IT IS SPECIFIC TO A CLIENT IN THE UNITED KINGDOM
The paragraph above describes the European route out of the EEA. If you are established in the United Kingdom, your own transfer assessment starts at a different border: our chain sits largely inside the EEA, which for you is already a transfer abroad, and the United Kingdom has its own instrument for that with its own paperwork. Which instrument fits this chain, and what it means for a route running from the United Kingdom into the European Union, is a question for a lawyer and is not filled in here on instinct. If you are a UK client and you need this settled before signing, say so and we will settle it with legal advice before we start processing, rather than after.
DOC.D1j · Ending

Returning, exporting and erasing

While the agreement is running, you can export your data yourself using the functions the product has for it. When the agreement ends, a standard export stays available for 30 days, or you can request one within that period, unless the product annex provides otherwise. After that we delete or anonymise the production data.

Backups disappear through rotation. We aim for that to happen no later than 35 days after removal from production, and in the meantime we use those backups only to restore. Data we are legally required to keep is set aside, used in a limited way and deleted when the period expires. If you want confirmation that deletion has happened, you can request it.

DOC.D1k · Demonstrability

Checking that we really do it

We make available the information you reasonably need to demonstrate that article 28 is complied with. We start with what already exists: current policy, completed questionnaires, test results and available assurance reports. If that is reasonably insufficient, you may have an audit carried out at most once a year, and additionally after a material incident.

  • with at least 30 days notice in advance, except where the law requires haste;
  • during office hours and without unreasonable disruption;
  • by an independent expert bound to confidentiality;
  • limited to systems and data that are relevant to you;
  • without access to data, secrets or security details of others.

You bear the reasonable costs of such an audit yourself, unless a material failure on our side is established in it. In that case we bear the reasonable costs of checking whether it has been put right.

For the avoidance of doubt: we hold no certification and we display no certification logo. We do not lean on the name of a standard here either, because naming a standard is not a mark and not evidence. What we do record is in this agreement itself: which measures apply, who may reach the data, how an audit runs and which sub-processors we use. If a supplier or a competitor tells you we hold a certification against any standard, that is not true and it did not come from us.

DOC.D1l · Other

Government requests, liability and changes

Requests from government

If we receive a request from a government body, we test whether that body is competent, how far the request reaches and whether it is proportionate. We disclose as little as possible and inform you before disclosure, in so far as that is permitted. Where appropriate we object to an unauthorised or excessive request.

Liability

The liability arrangement from the main agreement also applies to this DPA, in so far as the law allows. Nothing in it limits the rights of data subjects or the powers of supervisory authorities, and nothing excludes liability where the law forbids that. Each of us is responsible for our own role, our own instructions and our own failures.

Contact and changes

Privacy questions go to sales@theseo.nl with privacy in the subject line. Changes to this DPA follow the procedure from the main agreement. A change that materially lowers the level of protection is not made silently.

DOC.D1m · Annex A

Annex A: MyParcel Dashboard

PurposeSynchronising and displaying shipments. Alongside that: exceptions, returns, claims, analysis, notifications, branding and support
Data subjectsUsers of the client, customers and recipients of the shop, and contacts in claims
DataAccount and role, shop, API key, barcode, order reference, name and email address of the recipient, country, status and time, note, return or delay, claim, amount, and the notification, open and click status
SourcesThe client, the MyParcel API, the user, the email provider, and Stripe for the subscription status
OperationsRetrieving, storing, structuring, searching, displaying, analysing, exporting, emailing and deleting
Standard periodsShipments 18 months. Email events and general logs 90 days. Claims at most 5 years after closure. On contract end 30 days of export, plus the backup cycle
Particular riskAPI keys, access between organisations, recipient details, email tracking, claims and historical exports

We store MyParcel API keys encrypted or in appropriate secret storage. If a key is still sitting in readable text in an old field, that is a reason to hold back a release until it has been migrated and cleaned up. If an administrator has to look into a client environment temporarily, that comes with a reason, a limited duration, visible context and an audit log.

The dashboard is a separate product. There is no relationship with, and no endorsement by, MyParcel B.V.

DOC.D1n · Annex B

Annex B: Jarvis and TheSEO Brain

PurposeOrganisation memory, processing of documents and tasks, agents, insights, connections and support
Data subjectsUsers, team members and people appearing in business content that has been lawfully entered
DataProfile and role, organisation, content and documents, prompts and output, tasks, agent settings, logs and integration credentials
OperationsReceiving, storing, searching, structuring, generating, summarising, exporting and deleting
Standard periodsFor the duration of the contract. Production at the latest 30 days after the end. Backup cycle at the latest 35 days after that. Security evidence according to the incident period
Particular riskSensitive business knowledge, prompt injection, transfer to models, connector permissions and access between organisations

Agents get as few tool permissions as possible, and a sensitive action requires a confirmation. Content that comes from outside is treated as untrusted input: it may not override system instructions and may not request secrets. We do not silently use client content for generic model training.

Anyone who wants to hold this annex against the product itself will find an explanation of what annex B arranges for Jarvis in the trust centre. The text above is the leading one; that page explains it.

DOC.D1o · Annex C

Annex C: LinkLoop and bespoke work

For LinkLoop and for bespoke engagements, the order confirmation states who the data subjects are, which data categories are involved, which sources they come from, what is and is not made public, how long we keep it and which sub-processors take part.

We do not switch on public publication of user content without a separate assessment of moderation, a notice and action procedure, privacy and rights. That is a decision taken in advance and not something that can be left on by accident.

DOC.D1p · Open points

What still has to be done

This page is on noindex until the move to the new platform. These are the points that have to be settled first:

  • The version archive, so that an older version with a start and end date stays available on request.
  • The record on acceptance: which document, which version, which moment, which person and which organisation.
  • The missing details in the sub-processor register, including the start date per supplier and the transfer safeguard per supplier.
  • The transfer route out of the United Kingdom and the instrument that belongs to it, for a client established there.

While those points are open, this text is the arrangement in force as soon as you accept it, but the file around it is not yet complete. We would rather write that down than leave it out.

Version 1.0 · in force from 11 August 2026 · English edition published on 25 August 2026

Section · Next stepreachable 24/7
Book a call