VERIFY BACKLINKS · DATA PROCESSING AGREEMENT (DPA)

How we process and protect your backlink data
during verification.

This DPA outlines how backlink lists and evaluation outputs are handled using pre-index evaluation signals used to help customers review backlink quality, risk and viability before or after search engines crawl, index or evaluate those links.

This agreement governs how your backlink data is processed when you request an audit with Verify Backlinks.

Covers Backlink lists, evaluation outputs, toxic scores and disavow recommendations.
Roles You remain Controller; Verify Backlinks acts as Processor only where Personal Data is included in audit files.
Focus Clear data flows and strict limits around pre index evaluation of backlinks.
DPA
DPA snapshot
DPA summary
How your backlink data moves through our engine under this agreement.
Roles and control

You define why audits are run and remain Controller. Verify Backlinks processes data only to run audits you request. This agreement applies only where Personal Data is included in the uploaded audit files.

Data we process

Backlink URLs, anchor fields, technical metadata and the resulting evaluation outputs, including toxic scores, tiers, risk labels, spam indicators and disavow recommendations used to build reports.

How it is handled

Data flows through a pre index evaluation step, is used to generate Excel / PDF / disavow.txt, and is retained only for delivery, support, security and legal obligations as described in this DPA.

We process Customer audit files only to run audits, generate outputs, provide support, and protect the Service.
We do not Use audit files to build audiences, sell datasets, or use Customer audit data for unrelated marketing or advertising.

Data Processing Agreement

This DPA forms part of the agreement between the Customer as Controller and VerifyBacklinks as Processor for audit processing services. It is designed to satisfy GDPR Article 28 and provide globally consistent safeguards. This DPA applies only to the extent Customer audit files include Personal Data.

Effective 15 December 2025 Last updated 15 December 2025 Processor Verify Backlinks Location Amsterdam, Netherlands KvK 95435123 Contact [email protected]

This DPA applies when Verify Backlinks processes Customer Personal Data as a Processor on behalf of the Customer. Terms such as “Personal Data”, “Processing”, “Controller”, “Processor”, “Sub processor”, and “Supervisory Authority” have the meanings given in the GDPR and in similar laws where applicable.

Verify Backlinks provides a backlink evaluation and report generation service. The primary inputs are backlink URLs and related technical fields. The service is not designed for personal profile processing. This DPA applies only to the extent Personal Data is included in uploaded audit files or generated outputs, including Personal Data that may appear inside URLs, anchor fields, or support communications.

The Customer remains responsible for determining whether uploaded audit files include Personal Data and for ensuring a lawful basis to process and upload such data.

The Customer acts as Controller and determines the purposes and means of Processing. Verify Backlinks acts as Processor and processes Customer Personal Data only to provide the Service and only on documented instructions from the Customer as reflected by this DPA, the Terms of Service, and the Customer configuration and use of the Service.

Payment processing is performed via Stripe. Payment providers typically act as independent controllers for certain payment and fraud prevention data. Verify Backlinks does not store full payment card details.

Verify Backlinks does not act as Controller for Customer audit files. VerifyBacklinks does not determine the Customer purposes for running audits.

Verify Backlinks processes Customer Personal Data only for the following purposes: running audits requested by the Customer, generating outputs in Excel, PDF and disavow formats, delivering results, maintaining security, preventing abuse, maintaining service reliability, and providing support.

Verify Backlinks will inform the Customer if it believes a documented instruction violates applicable data protection law where required by law, and may suspend the relevant Processing until the instruction is clarified or corrected.

Customer audit data is never used to create advertising audiences or to build marketing datasets.

Verify Backlinks ensures that persons authorized to process Customer Personal Data are bound by confidentiality obligations and access is restricted to persons who require access for audit processing, security operations, or support delivery.

Verify Backlinks implements appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to Customer Personal Data.

  • Access controls designed around least privilege and role based permissions.
  • Secure storage and secure transport protections appropriate to the service context.
  • Security monitoring and logging to detect abuse and support incident response.
  • Change management and security review practices for service updates.
  • Availability safeguards and recovery procedures proportionate to service scope.

Detailed measures are described in Annex III. Measures may evolve as the Service improves, provided they do not materially reduce the level of protection.

Verify Backlinks will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data and will provide information reasonably required to help the Customer comply with breach notification obligations.

Notifications are sent to the Customer support contact on file or through established support channels.

Verify Backlinks may engage sub processors strictly to support hosting, storage, monitoring, security, communications, and payment operations necessary to provide the Service. Sub processors are bound by written obligations that provide a level of protection for Customer Personal Data that is at least as protective as this DPA.

Verify Backlinks operates the audit evaluation engine within controlled environments. Sub processors do not receive any right to use Customer audit files for their own purposes and may process Customer Personal Data only to provide contracted services to Verify Backlinks.

A current named list of sub processors is available on request by contacting [email protected]. Verify Backlinks will provide advance notice of material changes to sub processors where required by applicable law or contract.

Customer Personal Data may be processed in countries outside the Customer jurisdiction depending on infrastructure, sub processors, and support operations. Where EU, EEA, or UK transfer rules apply, Verify Backlinks uses appropriate safeguards such as Standard Contractual Clauses or other lawful transfer mechanisms.

Verify Backlinks maintains contractual controls and security measures intended to protect Customer Personal Data during cross border processing.

Verify Backlinks provides reasonable assistance to help the Customer respond to data subject requests and to support DPIAs and consultations where required, taking into account the nature of Processing and information available.

If a request is made directly to Verify Backlinks, Verify Backlinks will, where legally permitted, direct the requester to the Customer.

Upon termination of the Service or upon Customer request where feasible, VerifyBacklinks will delete or return Customer Personal Data, unless retention is required by applicable law or required for security, fraud prevention, dispute handling, and accounting obligations. Deletion timelines may depend on backups and operational constraints.

If the Customer requests deletion of a specific audit dataset, the Customer should provide sufficient identifiers such as order reference or report filename.

Upon reasonable written request, Verify Backlinks will provide information necessary to demonstrate compliance with this DPA, including security summaries and sub processor information.

Any audit request must protect the confidentiality and security of Verify Backlinks systems and other customers data. Where an on site audit is required by law, it will be subject to reasonable notice, scope limitations, scheduling constraints, and confidentiality obligations.

  • Reasonable notice and scheduling.
  • Scope limited to systems relevant to the Service.
  • Confidentiality obligations and protection of other customers data.
  • Customer bearing audit costs unless applicable law requires otherwise.

This DPA applies for as long as Verify Backlinks processes Customer Personal Data. If there is a conflict between this DPA and other terms regarding Processing, this DPA governs to the extent of that conflict.

Contact for DPA and privacy matters: [email protected]
Verify Backlinks — Amsterdam, the Netherlands · KvK 95435123

If you need a current sub processor list or a signed copy for procurement, contact us.

Annexes

Standard DPA schedules (download-friendly)

Annex I — Details of Processing

ItemDetails
Subject matterPre-index and post-index backlink audit processing and report generation.
DurationFor the term of the Service and as necessary for delivery, support, security, dispute handling and legal obligations, subject to retention limits.
Nature and purposeProcessing uploaded backlink lists to evaluate links and generate Excel / PDF / disavow outputs requested by the Customer.
Types of Personal DataPotentially: URLs that may include identifiers, anchor text fields that may include identifiers, contact details if included in Inputs, log data (IP and timestamps), support communications.
Categories of data subjectsCustomer staff and users, support contacts, and potentially third parties referenced within URLs or anchors contained in Customer uploads.

Customer remains responsible for the lawfulness of uploaded data and documented instructions.

Annex II — Sub processor categories

CategoryPurpose
Cloud hosting / compute / storageOperate the Service, run audits, store files as required for processing, generate outputs, and deliver reports.
Monitoring / logging / securityMaintain service reliability, detect abuse, perform incident response, and protect systems.
Email delivery and support toolingRespond to support requests and send operational notifications.
Payments (Stripe)Payment processing and transaction status for audits, subject to Stripe terms and policies.

A current named sub processor list is available on request at [email protected].

Annex III — Technical and Organizational Measures (TOMs)

Control areaMeasures (high level)
Access controlLeast privilege principles, role based access, restricted administrative tooling, access review where feasible.
ConfidentialityConfidentiality obligations for staff and contractors with access, controlled support workflows.
IntegrityChange management, testing practices, audit trails or logging for sensitive actions where applicable.
AvailabilityOperational monitoring, recovery procedures proportionate to service scope, incident response workflows.
Incident managementBreach detection and escalation, Customer notification without undue delay, post incident review and remediation.

Measures may evolve to improve security and reliability, without materially reducing protection.