Data processing agreement
Version September 2026
If you use SEOHero for your business, we process personal data on your behalf: search data from Google Search Console, the content of your website and the credentials of the systems you connect. The GDPR requires that we record how we do that. This data processing agreement is part of your agreement with Fourwrd V.O.F.; you do not need to sign or return anything. Save it as a PDF for your own records.
1. Roles and scope
For the personal data contained in the website and search data that SEOHero analyses on your behalf — Search Console queries and clicks, the content of your web pages, the details of the systems you connect — you are the controller: you decide which website we analyse and what we publish. SEOHero (Fourwrd V.O.F., Chamber of Commerce 42087615, De Nieuwe Erven 3, 5431 NV Cuijk, the Netherlands) is the processor and processes that data only on your instructions.
For your own account data (name, e-mail address, invoices, login and security logs) Fourwrd V.O.F. is itself the controller; that processing is described in the privacy policy, not in this agreement.
This agreement is an integral part of the agreement between us and applies to business customers. By accepting the terms of service you also accept this agreement. Where it conflicts with the terms, this agreement prevails for the processing of personal data.
2. Subject, nature, purpose and duration
We process personal data solely to provide SEOHero: running SEO audits of your website, retrieving and showing your Search Console and Ads data, generating, planning and publishing articles and images, sending reports, placing links within the backlink network if you join it, and answering questions in the AI assistant.
What we do with the data: store it, analyse it, send the parts a feature needs to our AI subprocessors, deliver articles to your website, make back-ups and delete the data when you do or when the agreement ends. We do not use the data for our own purposes, not for marketing and not to train AI models, and we do not sell it.
The agreement runs for as long as your subscription runs. The obligations continue to apply for as long as we still hold data for you afterwards, until the deletion described in section 12 is complete.
3. Categories of data and data subjects
- Data subjects: visitors of your website (in the search data), your staff and other users of your account and of the Google account you connect, and people who are named on the pages of your website that we crawl.
- Website data: the URLs and content of your web pages, audit results and page speed measurements.
- Search data from Google Search Console and Google Ads: search queries, clicks, impressions and positions per page and per query. Search queries can occasionally contain personal data typed by a visitor; Google does not pass on IP addresses.
- Connection data: the e-mail address of the Google account you connect and its OAuth tokens; the URL, user name and application password of your WordPress site or the URL of your webhook. Tokens and application passwords are stored encrypted.
- Content data: brand instructions, keywords, article texts and images, publication dates and the addresses at which articles were published.
- Special categories of personal data do not belong here. Do not enter medical or other sensitive data in brand instructions, article instructions or keywords; the service is not designed for that.
4. Instructions
Your instructions are this agreement, the terms of service and what you set and do in the dashboard: adding a website, connecting Search Console, turning autopilot on, publishing or deleting an article, joining the backlink network. Other instructions you give by e-mail.
We process the data only on those instructions, including for transfers outside the European Union, unless a legal obligation requires otherwise. In that case we inform you in advance, unless the law forbids it.
If we believe an instruction breaches the GDPR or other data protection rules, we tell you immediately.
5. Confidentiality
Everyone at Fourwrd V.O.F. with access to the data is bound to confidentiality. Access is granted only as far as needed for the work and withdrawn as soon as that need ends. When an administrator views a customer account, that action is logged.
6. Security
We take appropriate technical and organisational measures to protect the data against loss and unlawful processing, in proportion to the risks. They include at least:
- Encrypted connections (TLS with HSTS) for the website, the dashboard and the API.
- Passwords are stored only as scrypt hashes; session tokens only as hashes; two-step verification is available for every account.
- Google OAuth tokens and WordPress application passwords are stored encrypted (AES-256-GCM) with a key that is kept outside the database and the back-ups.
- Access based on roles, with data separated per customer account; administrator actions are logged.
- Limits on the number of login attempts and on registrations, password resets and form submissions per address.
- Protection against requests to internal addresses when we fetch customer websites (SSRF guard).
- Hosting at Hetzner in the European Union (Germany); the application is reachable only through the reverse proxy over HTTPS.
- Daily back-ups of the database, kept for 14 days, with an off-site copy in Finland (EU).
- Servers and software are kept up to date with security updates.
7. Subprocessors
You give us general authorisation to engage subprocessors. With every subprocessor we have an agreement that imposes at least the same obligations as this agreement imposes on us. If a subprocessor fails to meet those obligations, we remain responsible towards you, within the limits of the liability section. This is the current list; the privacy policy describes per feature exactly which data each AI provider receives.
| Party | Purpose | Location and transfer basis |
|---|---|---|
| Hetzner Online GmbH | Hosting of the application and database, daily back-ups | Germany and Finland (EU) |
| Mollie B.V. | Payments and direct-debit mandates | Netherlands (EU) |
| Resend | Transactional e-mail (verification, invoices, reports) | United States (EU-US Data Privacy Framework) |
| Anthropic, PBC | AI text generation: articles, quality check, keyword research, reports, onboarding e-mails, assistant | United States (Data Privacy Framework where certified, otherwise EU Standard Contractual Clauses) |
| OpenAI | AI images for articles (receives only title and keyword) | United States (EU Standard Contractual Clauses) |
| Google (Google Ireland Ltd. / Google LLC) | Search Console and Ads data (only when you connect them), Google sign-in, PageSpeed Insights (page speed of your homepage) | Ireland and United States (EU-US Data Privacy Framework) |
8. Changes to subprocessors
If we add or replace a subprocessor, we inform you in advance by e-mail or in the dashboard. If you have a reasoned objection, let us know within fourteen days. If we cannot find a solution together, you may terminate your subscription as of the date the change takes effect.
9. Transfers outside the EU
Your data is stored within the European Union. Some subprocessors are established in the United States (Resend, Anthropic, OpenAI and Google for parts of their processing). Transfers to them take place on the basis of the EU-US Data Privacy Framework where the provider is certified, and otherwise on the basis of the Standard Contractual Clauses of the European Commission. We send each provider only the data its function needs, as described in the privacy policy.
10. Data breaches
If we discover a personal data breach, we inform you without undue delay and in any case within 48 hours after establishing the breach. We provide the information you need to meet your own notification obligations: what happened, which categories of data and data subjects are affected, the likely consequences and the measures we have taken or propose. What is not yet known, we add as soon as we know it.
Notifying the supervisory authority and informing data subjects is your responsibility as controller; we support you in doing so.
11. Rights of data subjects
If you receive a request from a data subject for access, rectification, erasure or portability, you can handle most of it yourself in the dashboard (for example by editing or deleting an article). Where that is not possible, we help you within a reasonable period so that you can answer within the statutory period.
If such a request reaches us directly, we do not handle it ourselves but refer the data subject to you and let you know that the request was received.
12. Return and deletion of data
You can copy your articles from the dashboard at any time; on request we provide an export of your data. When you delete a website or your account, the associated data is deleted immediately from our active systems. It disappears from the back-ups when those expire under the regular schedule (14 days); until then it remains there and is no longer used.
Data we are legally required to keep, such as invoices under the tax retention obligation, is retained. That data falls outside this deletion.
13. Assistance with your own obligations
Taking into account the nature of the processing and the information available to us, we assist you in meeting your obligations regarding security, data breaches, a data protection impact assessment (DPIA) and any prior consultation of the supervisory authority.
If that assistance goes beyond what reasonably belongs to the service, we agree with you in advance whether and which costs we charge.
14. Audits and information
On request we provide the information you need to demonstrate that we meet our obligations. If you want an audit carried out, we cooperate, provided it is announced in advance, takes place at most once a year, is carried out by an independent auditor bound to confidentiality and does not unnecessarily disrupt our operations. The costs are for your account, unless the audit reveals a material shortcoming on our part.
15. Your responsibilities
- You have a valid legal basis for the processing of the personal data of your website visitors, staff and users.
- You inform your website visitors about the processing, for example in your own privacy policy, and you meet your own obligations for the AI-generated articles you publish (see the terms of service).
- Your instructions to us comply with the GDPR.
- You do not enter special categories of personal data in instructions, keywords or articles.
16. Liability
The liability provisions of the terms of service also apply to this agreement, as far as mandatory law does not prevent this.
If you process data without a valid legal basis, or use the service for special categories of personal data, you indemnify us against the consequences.
17. Changes and governing law
We may amend this agreement when laws or regulations require it or when the service changes. Material changes are announced at least thirty days in advance.
This agreement is governed by Dutch law, like the terms of service. Questions about this agreement: contact@fourwrd.nl.