Legal

Data Processing

Last updated 13 July 2026 · Apefo Ltd

This page summarises the data-protection roles for a Seoryx pilot. For a paid pilot a fuller signed Data Processing Agreement can be put in place and prevails on conflict.

At a glance

  • For pilot data drawn from your connected SEO and analytics sources, you are the controller and Seoryx acts as your processor on documented instructions.
  • For our own business-contact records and site and security logs, Seoryx is an independent controller, as described in our Privacy Notice.
  • We process pilot data only to run the pilot, apply appropriate technical and organisational measures, and engage subprocessors under appropriate terms.
  • Our verified subprocessors are Cloudflare, Google (Google Analytics, only with your consent), Mailgun (operated by Sinch), our hosting provider (YNVAR) and WordPress.org; the main list lives in the Privacy Notice, and a current list is available on request.
  • International transfers rely on recognised safeguards; EU-region processing is preferred where available.
  • To put a signed DPA in place, email hello@seoryx.app with the subject line “DPA”.

Controller and processor roles

Data-protection law distinguishes the party that decides why and how personal data is processed (the controller) from the party that processes that data on the controller’s behalf (the processor). A Seoryx pilot involves both roles, and it is worth being precise about which applies to which data.

You are the controller of your pilot data
The SEO and analytics data you connect for a pilot — including any end-user or visitor data contained within it — remains yours. You decide the purposes and the scope, and you are the controller of that data. Seoryx does not determine why that data exists or repurpose it for its own ends.
Seoryx is your processor for that pilot data
When we ingest your connected SEO and analytics signals to produce a decision, an evidence-backed work order and a before/after verification window, we act as your processor. We handle that pilot data on your documented instructions and for the purpose of running the pilot you have asked us to run.
Seoryx is an independent controller for its own records
Separately, we are an independent controller for the personal data we need to run our own business — for example, the business-contact details of the people we correspond with, and the site and security logs generated when our systems are used. That processing is governed by our Privacy Notice, not by your instructions.

A human operator on your side approves every decision before it becomes a work order. Seoryx does not publish or change any website by itself, and a verification window measures change against a locked baseline rather than proving cause.

Our commitments as processor

When acting as your processor for pilot data, our commitments are as follows. A signed DPA sets these out in full; the summary below reflects our current practice.

  • Documented instructions. We process pilot data only on your documented instructions and for the purpose of the pilot, unless we are required to do otherwise by law — in which case we will tell you where we are permitted to.
  • Appropriate technical and organisational measures. We apply measures appropriate to the risk, as described on our Security page. We do not currently hold formal certifications such as SOC 2 or ISO 27001, and we do not claim to.
  • Subprocessors under appropriate terms. We engage subprocessors only under appropriate terms and remain responsible to you for their processing. The main list is published in our Privacy Notice, and a current list is available on request.
  • Assistance with your obligations. Taking account of the nature of the processing and the information available to us, we will assist you in responding to data-subject requests and in meeting your security, breach-notification and related obligations.
  • Deletion or return. At the end of the pilot, or earlier on your request, we will delete or return your pilot data, subject to routine backups and any retention required by law until those cycles expire.
  • Scoped access and anonymised samples. We support scoped access to only what a pilot needs, and we can work from anonymised or representative samples where that is sufficient for the task.

Subprocessors

We use a small number of subprocessors to deliver a pilot and to run this site. The full table — with each provider’s role and purpose — is maintained in our Privacy Notice; a current list is available on request. The verified providers are:

  • Cloudflare, Inc. — authoritative DNS for seoryx.app, and Cloudflare Turnstile anti-bot protection on the pilot form. Turnstile may set a cookie on its own domain to run the challenge.
  • Google (Google Ireland Ltd / Google LLC) — Google Analytics 4 for aggregate usage of this website, loaded via Google Site Kit. Analytics storage is denied by default for every visitor; GA4 sets cookies only where you accept, and before that runs in cookieless Consent Mode. This subprocessor relates to this website, not to pilot data.
  • Mailgun (operated by Sinch) — transactional email delivery, EU region, using the sending domain email.seoryx.app.
  • Our hosting provider (YNVAR) — website and server hosting on EU-based infrastructure.
  • WordPress.org — occasional core front-end static assets (for example, emoji), only when such assets are used.

International transfers

Where personal data is transferred outside the United Kingdom, we rely on the safeguards recognised under the applicable UK data-protection framework — for example, UK adequacy regulations where they apply, or the ICO’s International Data Transfer Agreement (IDTA) or the EU Standard Contractual Clauses with the UK Addendum where they do not. Where a provider offers EU-region processing, we prefer it: our email delivery and our hosting are on EU-based infrastructure.

Getting a signed DPA

For a paid pilot we can put a fuller, signed Data Processing Agreement in place. Where its terms conflict with this summary, the signed DPA prevails. To request one, email hello@seoryx.app with the subject line “DPA”, and tell us the entity name and the data sources in scope so we can tailor it to your pilot.

This notice describes our current processing practices under the applicable UK data-protection framework, which includes the UK GDPR, the Data Protection Act 2018 and the Data (Use and Access) Act 2025. It is a summary.

Version 1.0 Effective 13 July 2026 Last material change 13 July 2026 Document owner Apefo Ltd