Data Processing Agreement

The Data Processing Agreement (DPA) that governs Misar AI Technology Pvt Ltd's processing of Personal Data on your behalf when you use the hosted MisarSEO Service.

Last updated: July 21, 2026

This Data Processing Agreement ("DPA") forms part of, and is incorporated by reference into, the Terms and Conditions between Misar AI Technology Private Limited ("Company", "we", "us", "MisarSEO" — the Processor) and the customer that has agreed to those Terms ("Customer", "you" — the Controller) in respect of the hosted MisarSEO Service. It applies whenever, in performing the Service, we process Personal Data on your behalf.

If you require a countersigned copy of this DPA, or you need to execute a DPA on a different form (for example, your own template), contact us at privacy@misar.io.

1. Definitions

Terms defined in the EU General Data Protection Regulation ("GDPR"), the UK GDPR read together with the UK Data Protection Act 2018 ("UK GDPR"), India's Digital Personal Data Protection Act, 2023 ("DPDP Act"), and comparable laws (together, "Data Protection Laws") have the same meaning in this DPA. "Personal Data" means any Personal Data processed by Company on Customer's behalf under the Terms.

2. Roles of the parties

  • Customer is the Controller (or, where Customer is itself a processor acting on behalf of a further Controller, the relevant Processor) of the Personal Data submitted to the Service.
  • Company is the Processor of that Personal Data.
  • Company only processes Personal Data on documented instructions from Customer. Customer's use of the Service — including the configuration choices Customer makes in the Service — constitutes such documented instructions.

3. Details of processing

  • Subject matter: provision of the hosted MisarSEO Service (keyword research, crawl audits, rank tracking, AI brand-visibility, GSC integration, and related features described in the Terms).
  • Duration: for the duration of Customer's use of the Service, plus the post-termination retention windows described in Company's Privacy Policy (Data Retention section).
  • Nature and purpose: hosting, storing, transmitting, indexing, analyzing, and otherwise processing Personal Data as necessary to deliver the Service, to secure it, to bill for it, and to comply with law.
  • Categories of data subjects: Customer's authorized users of the Service and any individuals whose Personal Data Customer chooses to submit to the Service.
  • Categories of Personal Data: account and profile information, authentication and session data, usage/analytics data, billing identifiers, and any Personal Data contained in URLs, projects, keyword lists, crawl data, or other content Customer submits.

4. Sub-processors

Customer generally authorizes Company to engage sub-processors to assist with the provision of the Service, subject to the safeguards in this Section. The current list of sub-processors is maintained on the Sub-processor Register. Company will:

  1. impose data-protection obligations on each sub-processor that are, in substance, no less protective than those imposed on Company under this DPA; and
  2. remain liable to Customer for the acts and omissions of its sub-processors that cause Company to breach this DPA.

Company will update the Sub-processor Register when it adds, removes, or materially changes the role of a sub-processor. If Customer has a reasonable, documented data-protection objection to a new sub-processor, Customer may raise that objection to privacy@misar.io, and the parties will work in good faith to find a resolution; where no resolution is reached, Customer's sole remedy is to terminate the affected part of the Service in accordance with the Terms.

5. Cross-border transfers

Where Company (or one of its sub-processors) transfers Personal Data across a border in the course of providing the Service, that transfer is made in reliance on an appropriate transfer mechanism, as described in the "cross-border transfer safeguards" section of the Sub-processor Register. In particular:

  • For transfers of Personal Data originating in the European Economic Area, the parties incorporate by reference the European Commission's Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), including Module 3 (processor-to-processor) where Customer is itself a processor and Company acts as its sub-processor, and Module 2 (controller-to-processor) where Customer is a controller. The optional Docking Clause (Clause 7) applies. The Independent Supervisory Authority under Clause 13 is the supervisory authority of the EEA member state where the Controller is established. The governing law under Clause 17 (Option 1) and the choice of forum under Clause 18(b) are those of the Republic of Ireland unless the parties agree otherwise in writing. The Annexes to the SCCs are set out in Annex A below.
  • For transfers of Personal Data originating in the United Kingdom, the parties incorporate by reference the UK Information Commissioner's Office International Data Transfer Agreement ("IDTA") or, where the parties are already relying on the EU SCCs above, the UK International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (Version B1.0) (the "UK Addendum"). Table 4 of the UK Addendum is completed by reference to Annex A of this DPA.
  • For transfers of Personal Data originating in Switzerland, the parties rely on the EU SCCs as amended for Switzerland in accordance with the guidance of the Swiss Federal Data Protection and Information Commissioner (FDPIC).

Where an onward transfer is made to a country covered by an adequacy decision (for example, EU–UK or EU–Switzerland adequacy), that adequacy decision is the transfer basis and no SCCs are required.

6. Security

Company will implement and maintain appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access — including the measures described in the "How We Protect Information" section of the Privacy Policy (encryption in transit and at rest, access controls, secure sub-processor selection, logging, and backup). Company will regularly review these measures.

7. Data-subject requests

Company will make available to Customer, insofar as is reasonably possible using the Service, the functionality needed for Customer to respond to data-subject requests (for example, self-serve data export and account deletion, as described in the Privacy Policy). Where a data subject contacts Company directly with a request that Company reasonably identifies as relating to Customer's use of the Service, Company will, without undue delay, forward that request to Customer and will not respond to the request itself (other than to acknowledge receipt and redirect the data subject to Customer) unless Company is required to do so by law.

8. Personal-data breach notification

Company will notify Customer without undue delay after becoming aware of a Personal Data breach affecting Customer's Personal Data, and will provide Customer with the information Customer reasonably needs to comply with its own breach-notification obligations under Data Protection Laws.

9. Audits

Company will make available to Customer such information as is reasonably necessary to demonstrate compliance with this DPA. Where Customer reasonably requires an audit or inspection, the parties agree to conduct that audit through the following process, in this order of preference: (a) Company will first provide, on request, the most recent third-party security or compliance reports it holds and its written responses to Customer's due-diligence questionnaire; (b) if (a) is not sufficient to satisfy Customer's audit obligation, the parties will agree in writing on the scope, timing, and controls of a further audit, which will be conducted no more than once per year (unless required more often by a supervisory authority or following a Personal Data breach), during normal business hours, subject to appropriate confidentiality obligations, and at Customer's cost.

10. Return and deletion

On termination of Customer's subscription, or on Customer's earlier written request, Company will delete or return Personal Data in accordance with the retention periods and deletion mechanics described in the "Data Retention" section of the Privacy Policy. Company may retain Personal Data to the extent required by applicable law, in which case the terms of this DPA continue to apply to that retained data.

11. Order of precedence

In the event of a conflict between this DPA and the Terms, this DPA controls solely with respect to the processing of Personal Data. In the event of a conflict between this DPA and the incorporated Standard Contractual Clauses or UK IDTA/Addendum, the SCCs or UK IDTA/Addendum control.

12. Contact

Questions about this DPA, or requests for a countersigned copy, can be sent to privacy@misar.io (privacy queries) or legal@misar.io (contract execution).


Annex A — SCC / UK Addendum details

A.1 List of parties.

  • Data exporter: the Customer that has entered into the Terms with Company, as identified in Customer's account profile.
  • Data importer: Misar AI Technology Private Limited, No. 472/7, Koramangala VI Bk, Balaji Arcade, Bengaluru, Karnataka 560095, India. Contact: privacy@misar.io.

A.2 Description of transfer. As set out in Section 3 (Details of processing) above.

A.3 Competent supervisory authority (SCC Clause 13). As set out in Section 5 above.

A.4 Technical and organizational measures (SCC Annex II). As set out in Section 6 above and the "How We Protect Information" section of the Privacy Policy.

A.5 Sub-processors (SCC Annex III / UK Addendum Table 3). The sub-processors listed on the Sub-processor Register, which is updated from time to time in accordance with Section 4 above.

A.6 UK Addendum — Table 4 (Which Parties may end the Addendum as set out in Section 19). Either party.