Annex to the Terms of Service · Version 2026-09-06 · The Swedish version is the binding one and prevails in case of conflict. · Svenska
Data Processing Agreement (DPA)
Between the Customer (the agency or the directly purchasing business, "Controller") and Area81 Solutions AB, reg. no. 559099-5550, Sweden ("Processor", "Area81") · Version 2026-09-06
This agreement is an annex to the ShakeSERP Terms of Service (the "Main Agreement"). Accepting the Main Agreement includes accepting this DPA. It is drawn up under Article 28(3) of Regulation (EU) 2016/679 ("GDPR"). In case of conflict between the Main Agreement and this DPA, this DPA prevails on matters of personal-data processing. The Swedish version of this DPA is the binding one; this English text is a convenience translation.
1. Subject matter and duration
The processing concerns the personal data necessary to provide the ShakeSERP service to the Customer and the Customer's end clients. The DPA applies for the term of the Main Agreement and thereafter until all personal data has been deleted or returned under section 10.
2. Nature and purpose of the processing
The Processor processes personal data to: (a) send interview invitations and sign-in links by email; (b) store interview answers; (c) generate, review and publish articles and other content using third-party AI models; (d) build a knowledge memory isolated per end client; (e) measure aggregate website traffic, search positions, Search Console and Google Analytics data, and citations in AI answer engines; (f) produce reports, newsletters and social posts at the Customer's request; (g) handle credits, receipts and invoicing; (h) provide support.
3. Categories of data subjects and personal data
Data subjects: contact persons and staff of the Customer and of the Customer's end clients; persons mentioned in interview answers or content; newsletter recipients when the Customer has connected an email tool.
Personal data: name, work email, role, company, language; interview answers and professional opinions; sign-in data (one-time links, one-time codes, session identifiers); technical data from provider connections (e.g. Search Console property, Analytics property, WordPress endpoint) in encrypted form; aggregate, cookieless traffic statistics without IP addresses.
Sensitive data: not processed intentionally. The Customer shall not submit special categories of personal data (Article 9) or data on criminal convictions to the service.
4. Controller instructions
The Processor processes personal data only on the Customer's documented instructions. The configured functions of the service, the Main Agreement and this DPA constitute such instructions. Further instructions are given in writing to privacy@area81.se. Where Union or Swedish law requires other processing, the Processor informs the Customer before processing unless the law prohibits such information. The Processor immediately informs the Customer if, in its opinion, an instruction infringes the GDPR.
5. Confidentiality
The Processor ensures that persons authorised to process the personal data have committed themselves to confidentiality or are under a statutory obligation of confidentiality, and that authorisation is limited to what is necessary.
6. Security (Article 32)
The Processor implements the technical and organisational measures described in Annex A and keeps them current with the state of the art. Material changes that lower the level of protection require the Customer's approval.
7. Sub-processors
The Customer gives general prior authorisation for the sub-processors listed in Annex B. The Processor binds each sub-processor by written contract to obligations equivalent to this DPA and remains fully liable to the Customer for the sub-processor's performance. Planned additions or replacements are notified to the Customer at least 14 days in advance at the address the Customer has registered. Within that period the Customer may object on reasonable grounds; if no solution is found, the Customer may terminate the affected part of the service without termination fee.
8. Transfers outside the EU/EEA
Personal data is stored in the EU (Frankfurt). Some sub-processors (AI and search APIs) process data outside the EU/EEA. Such transfers rely on the Commission's Standard Contractual Clauses (2021/914), the EU–US Data Privacy Framework where the provider is certified, and supplementary measures: only the data required for each call is sent, and the provider's zero-retention / no-training options are enabled where offered. The current status per sub-processor is set out in Annex B.
9. Assistance to the Controller
Taking into account the nature of the processing, the Processor assists the Customer with: (a) responding to data-subject requests under Articles 15–22, through the export and deletion functions built into the service and manually where needed; (b) security, breach notification, data-protection impact assessments and prior consultation under Articles 32–36. Assistance materially beyond the service's built-in functions is charged at the applicable hourly rate by agreement.
10. Deletion and return
When the service for an end client ends, or when the Main Agreement terminates, the Processor deletes within 30 days all personal data, including interview answers, knowledge memory, generated content and measurement data, or returns it in a machine-readable format if the Customer so requests before deletion. Exceptions apply to data that must be retained by law (accounting records for seven years under the Swedish Bookkeeping Act) and to backups, which are deleted through normal rotation (at most 35 days) and are not used for any other processing.
11. Personal-data breaches
The Processor notifies the Customer without undue delay, and at the latest within 48 hours, after becoming aware of a personal-data breach concerning the Customer's data. The notification contains the information listed in Article 33(3) to the extent available and is supplemented as more becomes known. The Processor documents breaches and the measures taken.
12. Audits
The Processor makes available to the Customer all information necessary to demonstrate compliance with Article 28. At most once per twelve-month period, on at least 30 days' notice, the Customer may audit, itself or through an independent auditor bound by confidentiality. Audits take place during office hours, may not cover other customers' data, and are at the Customer's cost. Current third-party reports and the security description at shakeserp.com/security may be used to satisfy the audit right.
13. Liability
The limitations of liability in the Main Agreement apply to this DPA, except for liability that under Article 82 GDPR cannot be limited between the parties.
14. Governing law and disputes
Swedish law. Disputes are resolved under the dispute-resolution clause of the Main Agreement.
Annex A – Technical and organisational measures
- Data location. Database, application and background jobs run in the EU (Frankfurt). Backups are stored in the same region.
- Encryption. TLS 1.2+ for all traffic. Stored secrets (WordPress keys, Google refresh tokens, email-tool API keys) are encrypted with AES (Fernet) with key rotation. Passwords are stored hashed (bcrypt).
- Tenant isolation. Each end client is its own tenant. Every access path in the application checks tenant membership; the knowledge memory is scoped per end client and deleted in cascade. Foreign identifiers are answered with "not found".
- Access control. Role-based access in the agency dashboard (owner/admin/member) and in the client portal (owner/editor/viewer). Platform functions require two-factor authentication. Passwordless sign-in for end clients through short-lived one-time links and one-time codes.
- Publishing. Calls to the end client's website are signed with HMAC-SHA256 and protected against replay; outbound calls validate the target address against internal networks (SSRF protection).
- Measurement. Traffic statistics are collected in aggregate, without cookies, IP addresses or fingerprinting.
- Logging and traceability. Administrative actions are written to an audit log; error monitoring without personal data in clear text.
- Continuity. Daily backups, a documented restore drill, health checks on every deployment and the ability to roll back to a previous version.
- Development. Code review, automated tests of tenant isolation and money paths before every deployment, dependencies kept current, responsible vulnerability disclosure (security.txt).
- Personnel. Confidentiality undertaking, need-based authorisation, revocation on departure.
Annex B – Sub-processors
| Sub-processor | Purpose | Location | Transfer basis |
|---|---|---|---|
| Supabase Inc. | Database (PostgreSQL) | EU, Frankfurt | Within the EU |
| Render Services Inc. | Application hosting, background jobs, Redis, backups | EU, Frankfurt | Within the EU (US support under SCCs) |
| Brevo (Sendinblue SAS) | Email delivery; newsletters when the Customer chose Brevo | EU, France | Within the EU |
| Stripe Payments Europe Ltd | Payments, receipts | EU, Ireland | Within the EU |
| Anthropic PBC | AI generation of questions, articles and content | USA | SCCs, zero retention via API |
| OpenAI OpCo LLC | Speech-to-text, text-to-speech, citation checks | USA | SCCs, no training on API data |
| Voyage AI | Text embeddings for the knowledge memory | USA | SCCs |
| Google LLC | Search Console and Analytics (read-only, only when connected), sign-in with Google, Gemini citation checks | EU/USA | SCCs, Data Privacy Framework |
| Microsoft Ireland Operations Ltd | Sign-in with Microsoft 365 (identity only) | EU | Within the EU |
| SerpApi LLC | Search positions (queries only, no personal data) | USA | SCCs |
| Perplexity AI Inc. | Citation checks (questions only) | USA | SCCs |
| Ideogram AI | Image generation (prompt only) | Canada | Adequacy decision |
| Pexels GmbH | Stock photos (no personal data) | EU | Within the EU |
| Sentry (Functional Software Inc.) | Error monitoring | EU region | Within the EU, SCCs |
| Creatomate B.V. / Bannerbear Pte Ltd | Video and image templates, only when the feature is enabled | EU / Singapore | Within the EU / SCCs |
Current list and change history: shakeserp.com/security.
Data-protection contact: privacy@area81.se · Area81 Solutions AB, Sweden