Data Processing Addendum
Last updated: 2026-09-02
1. Scope and relationship of the parties
In plain terms: when Atlio Limited handles personal data on your behalf, you are the controller and we are the processor. Atlio Limited is a New Zealand company; our regional operations in the UAE are conducted through its branch, Atlio Information Technology LLC. This DPA sets out our GDPR Article 28 commitments: security, sub-processor notice, breach reporting, audit rights, and data return or deletion. A countersigned copy is available on request.
This Data Processing Addendum (“DPA”) forms part of the agreement between Atlio Limited, a company registered in New Zealand (“Atlio Limited”, acting as Data Processor), and the customer entity that has accepted Atlio Limited’s Terms of Service (acting as Data Controller) (together, the “Parties”). Atlio Limited conducts regional operations in the United Arab Emirates through its branch, Atlio Information Technology LLC (Dubai, United Arab Emirates).
This DPA applies where Atlio Limited processes personal data on behalf of the Controller in the course of providing the SearchChamp platform. SearchChamp is a product of Atlio Limited. It supplements the Terms of Service and, in the event of a conflict, this DPA takes precedence on data-protection matters. It does not apply to the processing Atlio Limited carries out as a controller in its own right, such as account registration, billing, and marketing, which is described in our Privacy Policy.
This DPA is designed to meet the requirements of Article 28 of the EU General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679), the corresponding provisions of the UK GDPR, the New Zealand Privacy Act 2020, the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021), and any other applicable data-protection laws.
2. Processing details
2.1 Subject matter and purpose
Atlio Limited processes personal data for the sole purpose of providing the SearchChamp platform services as described in the Terms of Service, including AI-assisted keyword research, content generation, site auditing, AI visibility tracking, link outreach, publishing to connected platforms, and related analytics and notifications.
2.2 Nature of processing
Collection, storage, organisation, analysis, retrieval, disclosure by transmission to the sub-processors engaged under section 5, and deletion of personal data submitted by the Controller or generated through the Controller’s use of the platform.
2.3 Types of personal data
- Account and team data: names, email addresses, and account identifiers of the Controller’s users.
- Website content and metadata submitted by the Controller for processing by AI agents.
- Integration data the Controller authorises the platform to read from connected services, such as Google Search Console, Google Analytics 4, Google Ads, and Google Tag Manager, which may contain personal data.
- Outreach contact data: names, email addresses, and domains of link-building prospects the Controller adds or instructs the platform to find, together with outreach messages and delivery signals such as bounces and replies.
- Usage and interaction data generated through use of the platform.
- IP addresses and device identifiers collected via server logs.
2.4 Categories of data subjects
- The Controller’s employees and team members who access the platform.
- End users and visitors of the Controller’s connected websites, where their data is incidentally processed during site audits, analytics reads, or AI agent tasks.
- Outreach prospects and other recipients of messages the Controller sends through the platform.
- Where the Controller uses the platform to provide services to its own clients: personnel and end users of those clients whose websites the Controller connects.
2.5 Duration of processing
Atlio Limited processes personal data for the duration of the active subscription and for such further periods as required by applicable law or as specified in our data-retention schedules (see our Privacy Policy), and in accordance with section 11 of this DPA.
3. Controller obligations
The Controller agrees to:
- Ensure that it has a lawful basis for providing personal data to Atlio Limited for processing;
- Comply with all applicable data-protection laws in relation to the personal data it submits to the Service, and ensure that its documented instructions to Atlio Limited comply with those laws;
- Provide adequate privacy notices to data subjects whose data will be processed through the Service;
- Obtain any necessary consents from data subjects before submitting their data to the Service;
- Notify Atlio Limited promptly if it receives a data-subject request relating to data processed by Atlio Limited on its behalf.
4. Processor obligations
Atlio Limited agrees to:
- Process personal data only on documented instructions from the Controller, including with regard to international transfers, unless required to do so by applicable law; in that case, Atlio Limited will inform the Controller of the legal requirement before processing, unless the law prohibits it;
- Inform the Controller without undue delay if, in its opinion, an instruction infringes the GDPR or other applicable data-protection law;
- Ensure that persons authorised to process personal data have committed to confidentiality or are under an appropriate statutory obligation of confidentiality;
- Implement and maintain appropriate technical and organisational security measures as described in section 6;
- Not engage sub-processors without prior general or specific written authorisation of the Controller, subject to section 5 of this DPA;
- Assist the Controller in responding to data-subject rights requests, taking into account the nature of the processing;
- Assist the Controller in ensuring compliance with its obligations under Articles 32 to 36 of the GDPR, including security of processing, breach notification, data protection impact assessments, and prior consultation with supervisory authorities, taking into account the nature of the processing and the information available to Atlio Limited;
- Make available to the Controller information reasonably necessary to demonstrate compliance with the obligations set out in Article 28 GDPR, and allow for and contribute to audits as described in section 10;
- Notify the Controller without undue delay after becoming aware of a personal data breach involving data processed on behalf of the Controller;
- Delete or return all personal data to the Controller at the end of the service relationship, in accordance with section 11.
5. Sub-processors
The Controller provides general written authorisation for Atlio Limited to engage the sub-processors listed at /legal/sub-processors that process personal data on the Controller’s behalf. Atlio Limited will:
- Notify the Controller at least 14 days before adding or replacing a sub-processor by updating the sub-processors page and, where the Controller has opted in to notifications, by email;
- Impose data-protection obligations on sub-processors that are at least equivalent to those set out in this DPA;
- Remain fully liable to the Controller for the performance of sub-processors’ obligations.
The Controller may object to a new sub-processor within 14 days of notice by emailing legal@searchchamp.com. If the parties cannot reach agreement within 30 days, the Controller may terminate the relevant services. Termination takes effect at the end of the current billing period.
6. Security measures
Atlio Limited maintains the following technical and organisational measures:
- Encryption at rest: AWS-managed encryption is configured for the RDS database and backups and for reviewed object-storage services used for personal data processed on the Controller’s behalf.
- Encryption in transit: public web and API endpoints use HTTPS; service-to-service transport controls are applied according to the AWS service and connection path.
- Access control: role-based application access and workspace-scoped authorization checks are used. Production database network access is restricted through private administrative paths.
- Network isolation: database tiers are deployed in private subnets without direct public ingress.
- Audit logging: authentication, workspace, administrative, and service events are recorded across category-specific stores. Production CloudWatch log groups have a 90-day minimum-retention control; audit records may be retained longer.
- Vulnerability management: automated dependency vulnerability scanning, security review as part of the development process, and a responsible disclosure channel (security@searchchamp.com).
- Incident response: a documented personal-data-breach runbook supports the notification commitment in section 9, with operating evidence reviewed through the readiness programme.
A full description of security controls and their current evidence boundaries is maintained at /legal/security.
7. Data subject rights
Atlio Limited will assist the Controller in fulfilling data subject rights requests within the timeframes required by applicable law. Where a data subject contacts Atlio Limited directly, Atlio Limited will forward the request to the Controller and, where technically feasible, provide the Controller with tools to facilitate compliance, such as the in-app data export and account deletion functions.
The Controller remains the primary party responsible for responding to data subjects.
8. International data transfers
Personal data is primarily stored and processed in AWS eu-west-1 (Ireland), within the EEA. Where personal data is transferred outside the EEA or the UK, Atlio Limited relies on the following mechanisms:
- AI model providers in the United States: for transfers to Anthropic, OpenAI, and Google, Atlio Limited relies on those providers’ data processing terms, which incorporate the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, Module 3: Processor-to-Processor).
- OpenRouter-routed model hosts: certain AI tasks are routed through the OpenRouter gateway (United States) to a fixed allowlist of model hosts operating in the United States, China, and Sweden with a Finland data centre. These transfers rely on OpenRouter’s data processing terms, which incorporate the SCCs, and OpenRouter binds each model host to equivalent data-handling commitments. Every routed request is sent with training denied.
- SEO and AI-answer data: processed by DataForSEO OÜ in Estonia, inside the EU, so no third-country transfer mechanism is required.
- AWS: data is primarily stored in eu-west-1 (Ireland) within the EEA. AWS provides SCCs for any cross-region replication.
- Google integrations: where the Controller connects Google Search Console, Google Analytics 4, Google Ads, or Google Tag Manager, Atlio Limited relies on the EU SCCs and Google’s Data Processing Terms for any transfer outside the EEA or UK.
- UK transfers: the International Data Transfer Addendum issued by the UK Information Commissioner’s Office is applied to transfers subject to the UK GDPR.
- Transfers within our corporate group: Atlio Limited is registered in New Zealand, which holds a European Commission adequacy decision for personal data (Commission Implementing Decision 2013/65/EU), so transfers from the EEA to Atlio Limited in New Zealand are covered by that decision. Where personal data is handled by our UAE branch, Atlio Information Technology LLC, transfers from the EEA to the UAE are covered by SCCs pending a UAE adequacy decision.
The authoritative per-vendor list of processing regions and transfer mechanisms is maintained at /legal/sub-processors. Atlio Limited assesses the legal landscape of each destination country before transferring data and will, upon request, provide copies of applicable transfer mechanisms to the Controller.
9. Personal data breach notification
Atlio Limited will notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Controller data. The notification will include, to the extent available:
- A description of the nature of the breach, including the categories and approximate number of data subjects and records affected;
- The name and contact details of the data protection point of contact;
- A description of the likely consequences of the breach;
- A description of the measures taken or proposed to address the breach.
Where information is not immediately available, Atlio Limited may provide it in phases. The Controller is responsible for any notifications to supervisory authorities and data subjects required by applicable law.
10. Audit rights
Atlio Limited will provide the Controller with all information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Controller or a mandated auditor.
Audit requests must be submitted with at least 30 days’ notice, conducted during normal business hours, and limited in scope to matters relevant to this DPA. The Controller bears the cost of any audit it initiates. Atlio Limited may satisfy audit requests by providing relevant, up-to-date security documentation, such as completed security questionnaires and available third-party attestations covering its sub-processors, in lieu of an on-site audit.
11. Deletion and return of data
Upon termination of the service relationship or upon written request, Atlio Limited will, at the Controller’s election:
- Return all personal data to the Controller in a structured, machine-readable format (JSON or CSV); or
- Securely delete all personal data and certify deletion in writing within 30 days.
If the Controller makes no election, personal data is deleted under the default schedule in the Privacy Policy: the account is closed no later than 90 days after cancellation and its data is then deleted within 30 days of closure. The Controller may also export its data at any time, including after cancellation, using the in-app export.
Atlio Limited may retain personal data for longer periods where required by applicable law, in which case it will isolate and protect the data from further processing.
12. Liability
Each party’s liability under this DPA is subject to the limitations and exclusions set out in the Terms of Service. Nothing in this DPA limits a party’s liability to data subjects or supervisory authorities under applicable data-protection law.
13. Contact and execution
This DPA takes effect upon acceptance of the Terms of Service. For customers requiring a countersigned DPA, please contact:
Atlio Limited (New Zealand)UAE branch: Atlio Information Technology LLC, Dubai, United Arab Emirates
Email: legal@searchchamp.com
Data processing addendum: common questions
A GDPR Article 28 agreement that forms part of the contract between Atlio Limited, a company registered in New Zealand, and the customer entity that has accepted the Terms of Service. Where SearchChamp processes personal data on your behalf, you act as the data controller and Atlio Limited acts as the data processor, and this DPA sets out the security, sub-processor, breach-notification, audit, and data-return commitments that apply. On data-protection matters it takes precedence over the Terms of Service.
The DPA applies where Atlio Limited processes personal data on your behalf in the course of providing the SearchChamp platform, for example the data of your team members, your website visitors, or your outreach contacts. It does not cover the processing Atlio Limited carries out as a controller in its own right, such as account registration, billing, and marketing, which is described in the Privacy Policy.
The DPA takes effect automatically when the Terms of Service are accepted. If your organisation requires a countersigned copy, email legal@searchchamp.com and one will be provided on request.
Data is primarily stored in AWS eu-west-1 (Ireland), within the EEA. AI model providers such as Anthropic, OpenAI, and Google process data in the United States under data processing terms that incorporate the EU Standard Contractual Clauses, and requests routed through the OpenRouter gateway may be served by model hosts in the United States, China, or Sweden. SEO and AI-answer data is processed by a provider in Estonia, inside the EU. Atlio Limited is registered in New Zealand, which holds a European Commission adequacy decision for personal data; where data is handled by its UAE branch, transfers from the EEA are covered by SCCs. The authoritative per-vendor list of regions and transfer mechanisms is maintained at /legal/sub-processors.
At your election, Atlio Limited will return all personal data in a structured, machine-readable format (JSON or CSV) or securely delete it and certify deletion in writing within 30 days. If you make no election, data is deleted under the default schedule in the Privacy Policy: the account is closed no later than 90 days after cancellation and its data is deleted within 30 days of closure, subject to legal retention requirements. You can also export your data yourself at any time using the in-app export.
Atlio Limited notifies the affected controller without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting controller data. The notification describes the nature of the breach, the point of contact, the likely consequences, and the measures taken or proposed, and may be provided in phases where information is not immediately available.
The current list, with purposes, regions, and transfer mechanisms, is maintained at /legal/sub-processors. Atlio Limited gives at least 14 days' notice before adding or replacing a sub-processor, by updating that page and, where you have opted in to notifications, by email. You may object within 14 days of notice by emailing legal@searchchamp.com; if no agreement is reached within 30 days, you may terminate the affected services effective at the end of the current billing period.
Yes. Atlio Limited will provide the information reasonably necessary to demonstrate compliance with the DPA and will allow for and contribute to audits conducted by you or a mandated auditor. Requests require at least 30 days' notice, run during normal business hours, and are limited in scope to the DPA; audit requests may be satisfied with relevant, up-to-date security documentation in lieu of an on-site audit.