Draft — pending legal review before public launch

Data Processing Agreement

Last updated: 12 July 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Catello Z. ("Processor", "Whao") and the agency creating an account ("Controller", "you"). It reflects the requirements of Article 28 of the EU General Data Protection Regulation (GDPR) and, where applicable, the UK GDPR. You accept this DPA when you accept our Terms of Service at sign-up.

1. Subject matter and duration

The Processor processes personal data on behalf of the Controller for the purpose of providing the Whao SEO reporting service. Processing takes place for the duration of the Controller's account with Whao, and ends when the account is deleted, subject to Section 9 (Deletion).

2. Nature and purpose of processing

The Processor stores, retrieves, and displays personal data supplied or authorised by the Controller in order to: (a) let the Controller manage records of its own clients ("End Clients") inside the dashboard; (b) retrieve Google Analytics 4 and Google Search Console metrics for End Client properties the Controller has connected; and (c) render and store the reports the Controller builds from that data.

3. Categories of data and data subjects

Category of dataData subjects
End Client contact records: name, email, website, business type, countryController's End Clients (business contacts)
Encrypted Google OAuth access/refresh tokensThe individual(s) whose Google account was used to authorise access to an End Client's GA4/Search Console property
GA4 organic session counts and Search Console query/click/impression/position dataAggregate visitors to the End Client's website (not directly identified)
Free-text report notes entered by the ControllerWhatever the Controller chooses to write — may incidentally include End Client staff names

4. Processor obligations

The Processor shall:

  • Process personal data only on documented instructions from the Controller (including regarding international transfers), unless required to do otherwise by EU or Member State law;
  • Ensure persons authorised to process the data are bound by confidentiality;
  • Implement appropriate technical and organisational security measures (Section 7);
  • Respect the conditions in Section 6 for engaging sub-processors;
  • Assist the Controller in responding to data subject rights requests (Section 8);
  • Assist the Controller with its obligations under Articles 32–36 GDPR (security, breach notification, impact assessments), taking into account the nature of processing and information available to the Processor;
  • Delete or return all personal data at the end of the provision of services, per Section 9;
  • Make available to the Controller the information reasonably necessary to demonstrate compliance with this DPA, and allow for audits, including inspections, conducted by the Controller or an auditor mandated by the Controller, subject to reasonable notice and confidentiality.

5. Controller obligations

The Controller warrants that it has a valid legal basis to collect and share the personal data described in Section 3 with the Processor, including any consents or notices required towards its End Clients, and that its instructions to the Processor comply with applicable data protection law.

6. Sub-processors

The Controller provides general authorisation for the Processor to engage the following sub-processors, each bound by a data processing agreement offering an equivalent level of protection:

Sub-processorFunctionLocation
Supabase Inc.Database, authentication, file storageEU (Frankfurt, eu-central-1)
Vercel Inc.Application hosting / computeEU (Frankfurt, fra1); static assets may be edge-cached globally
Google LLCSource API for GA4 / Search Console data connected by the ControllerGlobal (Google infrastructure)

The Processor will give the Controller reasonable notice (by email or in-app notice) before adding or replacing a sub-processor that processes personal data, so the Controller can object on reasonable data-protection grounds.

7. Security measures

The Processor applies the following measures, appropriate to the risk:

  • Encryption at rest: Google OAuth access and refresh tokens are encrypted with AES-256-GCM before being written to the database.
  • Encryption in transit: all connections to the application and its APIs use HTTPS/TLS.
  • Access control: Row Level Security (RLS) policies at the database level ensure each agency can only read or write its own data — enforced independently of application code.
  • Secure OAuth flow: Google account connections use PKCE and a random state parameter to prevent interception and cross-site request forgery.
  • Least privilege: only read-only Google API scopes (analytics.readonly, webmasters.readonly) are requested — the Processor cannot modify or delete data in the Controller's connected Google properties.

8. Assistance with data subject requests

If the Processor receives a request from a data subject relating to data processed on the Controller's behalf, it will promptly forward the request to the Controller without responding to it directly, unless legally required to do so. The Processor will provide reasonable assistance to enable the Controller to respond, including through account-level tools (deleting an individual End Client record, or the entire account).

9. Deletion or return of data

On termination of the Controller's account — whether by the Controller deleting it from Settings, or by the Processor terminating it for breach — the Processor deletes all personal data associated with the account, including End Client records, connected Google OAuth tokens, reports, and uploaded logos, without undue delay. Deletion is immediate and cascades across all related records; it is not reversible. The Controller is responsible for exporting any data it wishes to retain before deleting its account.

10. Personal data breach notification

The Processor will notify the Controller without undue delay, and in any event within 72 hours of becoming aware, of any personal data breach affecting the Controller's data, providing the information reasonably available to enable the Controller to meet its own notification obligations under Articles 33–34 GDPR.

11. International transfers

Personal data is stored and processed within the EU by the Processor's primary sub-processors (Supabase, Vercel). Where processing necessarily involves a transfer outside the EEA — for example, calls to Google's APIs, or Vercel's global edge caching of static content — the Processor relies on Standard Contractual Clauses and/or the EU-U.S. Data Privacy Framework, as offered by the relevant sub-processor.

12. Liability and precedence

Liability under this DPA is subject to the limitations set out in the Terms of Service. In the event of a conflict between this DPA and the Terms of Service on data protection matters, this DPA prevails.

13. Contact

Data protection queries relating to this DPA: privacy@whao.dev.