Data Processing Addendum
Effective July 8, 2026
This Data Processing Addendum ("DPA") forms part of your agreement with VerifiedDR. We act as the Processor. You act as the Controller when you accept our Terms of Service . This DPA applies when you process personal data for a business, agency or client. It applies to business use with no signature. Email us for a signed copy at contact@verifieddr.com.
1. Subject Matter And Duration
We process personal data to provide the VerifiedDR service: website visibility monitoring, reports, alerts, link exchanges, and the API, for the duration of your use of the service, plus the deletion window described in section 7.
2. Nature And Purpose Of Processing
Hosting, storage, transmission, analysis, and display of the data you submit to the service; sending the emails and webhook notifications you configure; and processing payments.
3. Categories Of Data And Data Subjects
Data subjects: your team members who hold accounts, and contacts whose details you submit (for example link exchange recipients). Data categories: names, email addresses, account identifiers, OAuth tokens for integrations you connect, usage data, billing records, and the content of messages you send through the service. Website metrics (DR, TrueDR, backlinks, traffic) relate to websites, not identified persons.
4. Our Obligations
We process data under your settings and our agreement. Each person with access must keep it private. We help with data requests and GDPR Articles 32–36 where we can. We tell you when we learn of a breach that affects your data.
5. Security
Technical and organizational measures include encryption in transit (TLS) for all traffic, encryption at rest with our infrastructure providers, role-gated admin access, hashed credentials, scoped API tokens, per-route rate limiting, and rolling encrypted backups. Payment card data is handled entirely by Stripe and never touches our systems.
6. Subprocessors
You allow us to use subprocessors for hosting, storage, payments, analytics, email, sign-in and abuse limits. Ask for the current list at contact@verifieddr.com. Each subprocessor must meet data duties equal to this DPA. We stay liable for their work. Ask us to notify you before a change. You may object by email on sound data grounds. You may end the affected service when we cannot resolve the issue.
7. Deletion And Return
You can export your data at any time from settings (JSON) and delete your account there too, which erases personal data from production immediately and from rolling backups within weeks. Records we must keep under law (payment records held by Stripe) stay until the statutory period ends.
8. International Transfers
Where a subprocessor processes personal data outside the EEA, the transfer is covered by the EU-U.S. Data Privacy Framework or the European Commission's Standard Contractual Clauses. To the extent a transfer from you to us requires them, the SCCs (Module 2, Controller to Processor) are incorporated into this DPA by reference.
9. Audit
We make available the information reasonably necessary to demonstrate compliance with this DPA, this page, our privacy policy, and security documentation on request to contact@verifieddr.com.