Skip to content

Data processing

The data-processing terms for customer information handled by Netrix.

This addendum applies when Netrix processes personal data for a customer under a Netrix service agreement. It describes the parties' roles, customer instructions, safeguards, subprocessors, incident response, international transfers, assistance, and deletion.

Draft — Revised August 27, 2026

01

When this DPA applies

This Data Processing Addendum (“DPA”) is between Netrix and the customer identified in a Netrix order or service agreement (“Customer”). It applies only when Netrix processes Customer Personal Data as a processor or service provider to provide the service.

This DPA becomes effective only when it is incorporated into a binding agreement between Netrix and Customer or signed by both parties. It forms part of that agreement. It does not apply when Netrix acts as an independent controller for its own account administration, billing, security, product analytics, or legal obligations, which are covered by the Netrix Privacy Notice.

02

Definitions

“Customer Personal Data” means personal data, personal information, or similar regulated information that Customer submits to Netrix or asks Netrix to collect and process on Customer's behalf. “Data Protection Law” means privacy and data-protection law applicable to that processing.

“Controller,” “processor,” “business,” “service provider,” “consumer,” “data subject,” “processing,” “sell,” and “share” have the meanings given by applicable Data Protection Law. “Subprocessor” means a third party Netrix engages to process Customer Personal Data for the service.

03

Roles and customer responsibility

Customer is the controller or business and Netrix is the processor or service provider for Customer Personal Data, unless the law assigns the parties different roles for a specific activity. Customer decides the purpose of processing and gives Netrix documented instructions through the agreement, product settings, connected services, support requests, and authorized user actions.

Customer is responsible for the legality of its instructions, the accuracy and minimization of Customer Personal Data, its relationships with its own clients and data subjects, required notices and consents, and the lawfulness of the websites, profiles, credentials, and data it connects.

04

Processing instructions

Netrix will process Customer Personal Data only to provide, secure, support, and troubleshoot the service; follow Customer's documented instructions; prevent fraud and abuse; and comply with applicable law. Netrix will inform Customer if we believe an instruction violates Data Protection Law, unless law prohibits notice.

Netrix will not sell Customer Personal Data, share it for cross-context behavioral advertising, retain or use it outside the direct business relationship except as permitted by law, or combine it with personal data received from another source except as needed to provide the service and permitted by Data Protection Law.

05

Details of processing

The subject matter is providing Netrix's technical SEO, local SEO, reporting, AI-assisted drafting, connection, and supported deployment features. Processing lasts for the service term plus the limited retention and deletion period described in the agreement.

Operations may include collection, recording, organization, storage, retrieval, analysis, normalization, display, transmission to customer-selected providers, generation of drafts, application of approved supported changes, public verification, export, restriction, deletion, and support access.

06

Data subjects and data categories

Data subjects may include Customer personnel; Customer's clients and their personnel; website owners, authors, and visitors whose information appears in crawled content; business-location personnel; reviewers; report recipients; and other people whose information Customer lawfully submits.

Data may include contact and account details; membership and activity records; public or authenticated website content; URLs and technical crawl data; location and profile details; review content and reviewer identifiers; local search metrics; brand notes; support communications; IP and device information; and provider identifiers. Customer should not submit sensitive personal data unless necessary, authorized, and expressly agreed in writing.

07

Confidentiality and personnel

Netrix will limit Customer Personal Data access to personnel and contractors who need it to provide or secure the service. They must be bound by confidentiality obligations and receive appropriate privacy and security guidance for their responsibilities.

Netrix remains responsible for its personnel's processing of Customer Personal Data and will remove access when it is no longer needed.

08

Security measures

Netrix will maintain reasonable administrative, technical, and organizational safeguards appropriate to the nature of Customer Personal Data and the risks of processing. Current measures include account-scoped authorization, role-based access, credential encryption, transport security, secret filtering, signed WordPress requests, provider-permission checks, restrictions on outbound fetch targets, production-change gates, logging, backups where configured, vulnerability management, and incident-response procedures.

Security evolves with the service and risk. Netrix may update safeguards as long as the overall protection of Customer Personal Data is not materially reduced during the agreement. No security program eliminates all risk.

09

Subprocessors

Customer gives general authorization for Netrix to use Subprocessors needed to provide the service. Netrix will maintain a public list or other notice of material Subprocessor categories and will require each Subprocessor to protect Customer Personal Data under written terms appropriate to the service it provides. Netrix remains responsible for its Subprocessors to the extent required by Data Protection Law.

For a new Subprocessor that will materially process Customer Personal Data, Netrix will provide reasonable advance notice when required by the agreement or law. Customer may object on reasonable data-protection grounds. The parties will work in good faith on a commercially reasonable alternative; if none is available, either party may end the affected feature, and Netrix will refund prepaid fees for its unused affected period.

10

International transfers

Customer authorizes processing in the United States and other countries where Netrix and authorized Subprocessors operate. When Data Protection Law requires a transfer mechanism, the applicable approved standard contractual clauses or another lawful mechanism identified in the agreement will apply.

For transfers subject to the EU General Data Protection Regulation, the parties will use the European Commission clauses applicable to controller-to-processor or processor-to-processor transfers as the roles require, with the optional selections and annex details completed from this DPA and the order. For UK transfers, the applicable UK addendum or replacement mechanism will apply.

11

Data-subject and consumer requests

If Netrix receives a request from a data subject about Customer Personal Data, Netrix will direct the person to Customer unless law requires Netrix to respond. Taking into account the nature of processing, Netrix will provide reasonable product features and assistance so Customer can respond to applicable access, correction, deletion, portability, restriction, objection, opt-out, and appeal requests.

Customer is responsible for verifying the request, deciding the response, and using available product controls. Additional work beyond standard features may be charged at agreed rates when the request is unusually burdensome and law permits the charge.

12

Assessments, consultations, and records

Taking into account the nature of processing and information available to Netrix, we will reasonably assist Customer with data-protection impact assessments, prior consultations, and records of processing when the requested information concerns the service and Customer cannot reasonably obtain it elsewhere.

Netrix will provide information reasonably needed to show compliance with our processor obligations, subject to confidentiality, security, privilege, and protections for other customers.

13

Security incidents

Netrix will notify Customer without undue delay after confirming a breach of security that leads to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data processed by Netrix (“Security Incident”). Notice will include available information about the nature, likely consequences, affected data, and steps taken or planned.

Netrix may provide information in phases as the investigation continues. Notice is not an admission of fault. Unsuccessful attempts, blocked attacks, and events that do not affect Customer Personal Data are not Security Incidents under this section. Customer is responsible for notices to regulators, data subjects, and its own clients, and Netrix will reasonably assist as required by law.

14

Audits

No more than once each year, and additionally after a material Security Incident or when a regulator requires it, Customer may request information reasonably necessary to evaluate Netrix's compliance with this DPA. Netrix may first satisfy the request with current security documentation, questionnaires, or independent reports that are available.

If that material is not reasonably sufficient, Customer may conduct a narrowly scoped audit during normal business hours with reasonable advance notice. The audit must avoid disruption, protect other customers and Netrix confidential information, and use an independent auditor that is not a competitor. Customer pays its audit costs unless the audit identifies a material breach by Netrix.

15

Return and deletion

During the agreement, Customer may use available exports and account controls to retrieve or delete Customer Personal Data. After termination and any agreed export period, Netrix will delete or anonymize Customer Personal Data within a commercially reasonable period unless law requires retention. Backup copies may remain until overwritten under the backup cycle and will stay protected and unavailable for ordinary use.

Deletion from Netrix does not alter customer-owned WordPress content, Cloudflare resources, provider records, report copies already downloaded by recipients, or other systems outside Netrix's control. Customer is responsible for disconnecting or deleting those systems. Netrix may retain limited security, billing, dispute, and legal-compliance records that are excluded from ordinary product use.

16

Government requests

If a government authority requests Customer Personal Data, Netrix will direct the authority to Customer when lawful. If Netrix must respond, we will review the request, disclose only what is legally required, and notify Customer before disclosure unless law prohibits notice.

Where permitted and reasonably appropriate, Netrix will challenge an unlawful or overbroad request and provide Customer with available information needed to seek protection.

17

Liability, precedence, and changes

The liability limits and exclusions in the service agreement apply to this DPA to the maximum extent permitted by Data Protection Law. Nothing in this DPA reduces a data subject's rights or limits liability that applicable law does not allow the parties to limit.

If this DPA conflicts with the service agreement on processing Customer Personal Data, this DPA controls. Applicable standard contractual clauses control over both where they say they do. Changes to this DPA must be in writing and agreed by both parties, except Netrix may update public provider details or make a change required by law that does not materially reduce Customer's protection.

18

Processing schedule

Subject matter: delivery of the Netrix service. Duration: the service term plus the export, retention, and deletion period. Purpose: the features Customer configures and requests. Frequency: continuous or episodic according to account use.

Data subjects and categories are described above. Customer's account owner is the point of contact for instructions. [email protected] is the point of contact for privacy requests, [email protected] is the point of contact for DPA questions, and [email protected] is the point of contact for suspected security incidents.