Data Processing Agreement
This Data Processing Agreement (“DPA”) forms part of the agreement between the customer (“Controller”, “you”) and LYNX Media (“Processor”, “we”, “us”) governing use of TopicalLoop. It applies where we process personal data on your behalf in connection with the Service.
1. Definitions
Terms used in this DPA have the meanings given in applicable data protection law (including the GDPR and UK GDPR). “Personal data”, “processing”, “controller”, “processor”, “data subject” and “supervisory authority” carry their statutory meanings.
2. Roles and scope
- You are the controller of personal data you submit, connect or generate through TopicalLoop (including client website data, end-user analytics and content).
- LYNX Media processes that data solely to provide, maintain and improve the Service, provide support, ensure security and comply with law, in accordance with your documented instructions.
- This DPA applies to processing activities performed while providing TopicalLoop under your subscription or trial.
3. Subject matter and duration
Processing relates to SEO operations workflows, connected integrations (such as Google Search Console and Google Analytics 4), content operations, reporting and related platform features. Processing continues for the term of your agreement and as needed for deletion, backup expiry and legal retention.
4. Nature and purpose of processing
- Ingesting and analysing website, search and analytics data you authorise
- Generating recommendations, briefs, reports and deployment workflows
- Hosting and displaying customer workspace data
- Providing support, security monitoring and service communications
5. Categories of data and data subjects
Depending on your use of TopicalLoop, this may include:
- Data subjects: your personnel, contractors, clients and website visitors whose data appears in connected sources
- Categories: contact details, account identifiers, website/content metadata, search analytics, usage logs, approval records and similar operational data
6. Controller instructions
We will process personal data only on documented instructions from you, including as necessary to provide the Service, unless required by EU/UK law (in which case we will inform you unless prohibited). You are responsible for the lawfulness of instructions and for obtaining necessary permissions from data subjects and third parties.
7. Confidentiality
We ensure that persons authorised to process personal data are bound by confidentiality obligations or statutory duties of confidentiality.
8. Security measures
We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures are designed with regard to the state of the art, costs of implementation, nature of processing and risk. Details may be provided on request.
9. Sub-processors
You authorise us to engage sub-processors to deliver the Service (for example cloud infrastructure, email delivery and monitoring). We remain responsible for sub-processor performance and will impose data protection terms substantially similar to this DPA. A list of sub-processors is available on request at hello@topicalloop.com. We will notify you of intended changes where required by law or contract.
10. International transfers
Where personal data is transferred outside the EEA/UK, we will implement appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms, unless an adequacy decision applies.
11. Assistance to the controller
Taking into account the nature of processing, we will reasonably assist you with:
- Responding to data subject requests
- Data protection impact assessments and prior consultations where applicable
- Demonstrating compliance with Articles 32–36 GDPR, to the extent applicable to the Service
12. Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting your data, and provide information reasonably required for you to meet your breach notification obligations.
13. Deletion and return
On termination or at your written request, we will delete or return personal data processed on your behalf, except where retention is required by law or permitted under backup retention schedules (typically deleted on rolling expiry).
14. Audits
Upon reasonable notice, we will make available information necessary to demonstrate compliance and allow audits mandated by applicable law, subject to confidentiality, security and minimal disruption. We may satisfy audit requests through third-party certifications or summaries where appropriate.
15. Liability and order of precedence
Liability under this DPA is subject to the limitation of liability in our Terms of Service. If this DPA conflicts with the Terms regarding processing of personal data, this DPA prevails.
16. Contact
Data protection enquiries and sub-processor list requests: hello@topicalloop.com