1Parties and scope
This Data Processing Agreement ("DPA") forms part of the agreement between Good Venture Labs Inc. ("Processor", "Actium") and the customer identified in the order form ("Controller", "Customer") for use of the Service (the "Agreement"). It applies where Actium processes Personal Data on behalf of the Customer.
If there is a conflict between this DPA and the Agreement on data protection matters, this DPA prevails.
2Definitions
Terms such as "Personal Data", "Processing", "Controller", "Processor", "Data Subject", and "Supervisory Authority" have the meanings given in Data Protection Laws, meaning the EU GDPR, the UK GDPR and Data Protection Act 2018, the CCPA/CPRA, PIPEDA, and other applicable privacy laws. "Sub-processor" means any third party engaged by Actium to process Personal Data.
3Roles and instructions
3.1The Customer is the Controller and Actium is the Processor of Customer Personal Data processed through the Service.
3.2Actium will process Personal Data only on the Customer's documented instructions (including as set out in the Agreement and this DPA), unless required otherwise by law, in which case Actium will inform the Customer (unless legally prohibited).
3.3Actium will inform the Customer if, in its opinion, an instruction infringes Data Protection Laws.
4Details of processing (Annex 1)
The subject matter, duration, nature, purpose, types of Personal Data, and categories of Data Subjects are set out in Annex 1 below.
5Confidentiality
Actium ensures that personnel authorised to process Personal Data are bound by confidentiality obligations and are trained on their responsibilities.
6Security
Actium will implement appropriate technical and organisational measures to protect Personal Data, as described in Annex 2, taking into account the state of the art, costs, and the risks to Data Subjects.
7Sub-processors
7.1The Customer provides general authorisation for Actium to engage Sub-processors listed in Annex 3.
7.2Actium will impose data protection obligations on Sub-processors that are no less protective than this DPA and remains liable for their performance.
7.3Actium will give the Customer at least 30 days' notice of any intended addition or replacement of a Sub-processor (via email or our sub-processor notification list), during which the Customer may object on reasonable data-protection grounds. If the Customer objects on reasonable data-protection grounds, the parties will work in good faith to address the concern; if it cannot be resolved, the Customer may suspend or terminate the affected part of the Service by written notice.
8Data subject rights
Taking into account the nature of the processing, Actium will assist the Customer by appropriate measures to respond to Data Subject requests to exercise their rights. If Actium receives such a request directly, it will refer the Data Subject to the Customer (unless prohibited).
9Assistance to the Controller
Actium will provide reasonable assistance to the Customer with data protection impact assessments, prior consultations with Supervisory Authorities, and security/breach obligations, taking into account the information available to Actium.
10Personal data breach
Actium will notify the Customer without undue delay (and in any case within 72 hours where feasible) after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide information reasonably required for the Customer to meet its notification obligations.
11International transfers
11.1Actium will not transfer Personal Data outside the UK/EEA except where appropriate safeguards are in place.
11.2Where Personal Data originating in the EEA is transferred to a country without an adequacy decision, the EU Standard Contractual Clauses (Module Two: Controller-to-Processor) are incorporated by reference and completed using the information in the Annexes.
11.3For transfers subject to UK law, the UK International Data Transfer Addendum to the SCCs applies.
11.4For transfers of Personal Data originating in Switzerland, the SCCs apply as amended by the Swiss Federal Data Protection and Information Commissioner, with references to the EU GDPR understood as references to the Swiss FADP where applicable.
12CCPA/CPRA service provider terms
Where Actium processes Personal Information of California residents on the Customer's behalf, Actium acts as a service provider. Actium will not (a) sell or share such Personal Information; (b) retain, use, or disclose it for any purpose other than performing the Service or as permitted by the CCPA; or (c) combine it with data from other sources except as permitted. Actium certifies it understands and will comply with these restrictions.
12ACustomer obligations and warranties
The Customer warrants that: (a) it has provided all required notices and obtained all consents or established a lawful basis necessary for Actium to process Customer Personal Data as contemplated; (b) its instructions are lawful; and (c) Customer Data does not infringe third-party rights. The Customer is responsible for the accuracy of, and its rights in, Customer Personal Data.
12BAI processing and model training
Where the Service uses AI/ML, Actium will process Customer Personal Data only to provide the Service and on the Customer's instructions. Actium will not use Customer Personal Data to train, fine-tune, or improve generally available foundation models, and will not share Customer Personal Data with third-party AI providers except as Sub-processors bound by this DPA and as necessary to provide the Service. Actium may use aggregated and de-identified data, which cannot reasonably be used to identify any individual, to maintain and improve the Service; the Customer may opt out by contacting privacy@goactium.com.
Integration Data. The Customer is responsible for ensuring it has the right to authorise each integration and that its end-users and clients have consented to data processing via these services. The Processor acts as a processor for such data on the Customer’s documented instructions (to provide and support the Service). The Customer remains the controller of all data submitted or accessed through integrations.
13Audits
Actium will make available information necessary to demonstrate compliance with Article 28 GDPR and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor, subject to reasonable confidentiality and frequency limits. Actium may satisfy this through up-to-date third-party certifications or reports (e.g. SOC 2 Type II) where available.
14Return and deletion
On termination of the Service, Actium will, at the Customer's choice, return or delete Customer Personal Data within 30 days, and delete existing copies unless retention is required by law.
15Liability and term
Each party's liability under this DPA is subject to the limitations of liability in the Agreement. This DPA remains in force for as long as Actium processes Customer Personal Data.
A1Details of processing
- Subject matter: Provision of the Actium Service.
- Duration: For the term of the Agreement and any retention period.
- Nature and purpose: Hosting, storage, and processing of Customer Data to provide the Service.
- Categories of Data Subjects: The Customer's authorised users and employees, and the end users and contacts whose personal data the Customer submits to the Service.
- Types of Personal Data: Names, email addresses, account identifiers, contact details, and usage data. The Service is not intended to process special categories of Personal Data. When the Customer authorises integration with third-party services (Google Analytics, Google Search Console, Ahrefs, Dropbox, Shopify, Unipile), the Service receives and processes personal data returned by those services’ APIs, which may include website visitor analytics, customer contact data, website audit metrics, and social media content. This data is stored in the Processor’s database and may be processed by AI agents to provide auditing, strategy, and content recommendations.
A2Technical and organisational security measures
Encryption in transit (TLS) and at rest; role-based access control and least-privilege access; network segmentation; logging and monitoring; vulnerability management and patching; a secure software development lifecycle; encrypted backups and disaster recovery; vendor security management; mandatory security-awareness training; a documented incident response plan; and physical security controls at our hosting providers.
A3Approved sub-processors
| Sub-processor | Service provided | Location | Safeguard for transfers |
|---|---|---|---|
| Ahrefs, Inc. | SEO auditing, competitive analysis, backlink data | United States | SCCs + UK Addendum |
| Amazon Web Services, Inc. | Cloud hosting & storage | United States / Canada | SCCs + UK Addendum |
| Dropbox, Inc. | Cloud storage and file access | United States / Canada | SCCs + UK Addendum |
| Google LLC | Analytics, Search Console, Drive API, OAuth | United States | SCCs + UK Addendum |
| Intercom, Inc. | Customer support | United States | SCCs + UK Addendum |
| PostHog, Inc. | Product analytics | United States | SCCs + UK Addendum |
| SendGrid (Twilio Inc.) | Transactional email | United States | SCCs + UK Addendum |
| Shopify, Inc. | E-commerce data and integration | United States / Canada | SCCs + UK Addendum |
| Stripe, Inc. | Payment processing | United States | SCCs + UK Addendum |
| Unipile, Inc. | Social media aggregation and monitoring | United States | SCCs + UK Addendum |