Data Processing Agreement
Last updated: December 20, 2025
1. Introduction
This Data Processing Agreement ("DPA") forms part of the Terms of Service between BeforeQuery ("Processor") and the Customer ("Controller") and governs the processing of personal data by BeforeQuery on behalf of the Customer in connection with the Services.
2. Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person
- "Processing" means any operation performed on personal data
- "Data Subject" means the individual to whom personal data relates
- "Sub-processor" means any third party engaged by BeforeQuery to process personal data
3. Scope and Purpose
BeforeQuery processes personal data solely for the purpose of providing the Services, which includes:
- Website crawling and analysis
- SEO issue detection and reporting
- GEO analysis for AI visibility
- Account management and authentication
- Customer support
4. Data Categories
Personal data processed may include:
- Contact information (name, email)
- Account credentials
- Website content and URLs
- Usage data and analytics
- Communication records
5. Processor Obligations
BeforeQuery agrees to:
- Process personal data only on documented instructions from the Controller
- Ensure personnel are bound by confidentiality obligations
- Implement appropriate technical and organizational security measures
- Assist the Controller with data subject requests
- Delete or return personal data upon termination
- Make available information necessary for compliance audits
6. Security Measures
BeforeQuery implements the following security measures:
- Encryption of data in transit (TLS 1.3) and at rest (AES-256)
- Access controls and authentication
- Regular security assessments and penetration testing
- Incident response procedures
- Employee security training
- Physical security at data centers
7. Sub-processors
BeforeQuery uses the following sub-processors:
| Provider | Purpose | Location |
|---|---|---|
| AWS | Cloud infrastructure | US/EU |
| Stripe | Payment processing | US |
| SendGrid | Email delivery | US |
We will notify customers of any changes to sub-processors with at least 30 days notice.
8. International Transfers
Where personal data is transferred outside the EEA, BeforeQuery ensures appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission.
9. Data Subject Rights
BeforeQuery will assist the Controller in responding to data subject requests, including rights of access, rectification, erasure, portability, and objection to processing.
10. Data Breach Notification
BeforeQuery will notify the Controller without undue delay (and in any event within 72 hours) upon becoming aware of a personal data breach that affects Controller data.
11. Term and Termination
This DPA remains in effect for the duration of the Services agreement. Upon termination, BeforeQuery will delete or return all personal data within 30 days, unless retention is required by law.
12. Contact
For DPA inquiries or to request a signed copy:
Email: dpa@beforequery.com
Data Protection Officer: dpo@beforequery.com
Request a Signed DPA
Enterprise customers can request a countersigned DPA for their records.
Request DPA