Data Processing Agreement (DPA)
GDPR art. 28 · Livada Edge SEO · Last updated: 20 June 2026 · French law. The French version (DPA) prevails in case of discrepancy.
This agreement (“DPA”) governs the processing of personal data carried out by Livada on the Customer's behalf under the Livada Edge SEO service. It supplements the Terms of Sale and prevails over them for personal data. It is deemed concluded upon subscription to the Edge service.
Between: the Customer (“the Controller”) — when acting on behalf of its own clients (agency/reseller), it stands surety for their compliance with this DPA and warrants holding their mandate;
and: Florin Livada, sole trader, Castellane 04120, [email protected] (“the Processor” / “Livada”).
Article 1 — Purpose
Define the conditions under which Livada processes, on the Controller's behalf, the personal data necessary to provide the Livada Edge SEO service.
Article 2 — Duration
The DPA applies throughout the Edge subscription and until deletion/return of the data (art. 9).
Article 3 — Nature and purpose of processing
Nature: reverse-proxy relay of the Controller's site(s) traffic and server-side injection of optimisation signals (SEO/AEO). Purpose: provide the Edge service (visibility optimisation). Livada acts only on the Controller's documented instructions (these terms + the configuration via the console).
Article 4 — Categories of data and persons
Data (in transit only): connection and navigation data of visitors — connection IP address, user-agent, requested URL/resource, HTTP headers, returned page content. Livada does not build profiles, does not resell, and does not retain this data beyond the necessary technical transit. Persons: visitors of the Controller's site(s). The Controller undertakes not to route sensitive data (art. 9 GDPR) not provided for by the service.
Article 5 — Livada's obligations (processor) — art. 28.3 GDPR
Livada undertakes to:
- (a) process only on the Controller's documented instructions (including transfers), save legal obligation;
- (b) ensure confidentiality (authorised persons bound by confidentiality);
- (c) implement appropriate technical and organisational measures (art. 32): encryption in transit (HTTPS/TLS), no storage of visitor data, access control, security logging, anti-SSRF/anti-spoofing protections on the worker side, multi-tenant isolation;
- (d) comply with the conditions for engaging further processors (art. 6);
- (e) assist the Controller in responding to data-subject rights requests (art. 12-23), as far as possible given the “transit” nature of the processing;
- (f) assist the Controller in ensuring security, breach notification, impact assessment (art. 32-36);
- (g) at the end of the service, delete or return the data and delete copies (configuration records and logs tied to the account are deleted), save legal retention obligation;
- (h) make available the information needed to demonstrate compliance with art. 28 and allow audits (art. 7).
Article 6 — Engaging further processors (general authorisation)
The Controller authorises Livada to use the sub-processors listed in Annex 1. Livada informs the Controller of any change (addition/replacement), allowing it to object on legitimate grounds. Livada imposes equivalent obligations on sub-processors by contract (back-to-back) and remains responsible for their performance.
Article 7 — Audit
The Controller may, at its own cost, after reasonable notice and respecting confidentiality/security, verify compliance with this DPA (questionnaire, documentation, or on-site audit limited to the Edge scope), at most once a year save incident.
Article 8 — Data breach
Livada notifies the Controller without undue delay after becoming aware of a breach affecting the data processed on its behalf, with the relevant information, so that the Controller can meet its notification obligation to the CNIL (72 h, art. 33) and, where applicable, to the persons (art. 34).
Article 9 — Fate of data at the end of the contract
At the end of the service (termination/expiry), Livada deletes the data and configurations tied to the account (KV records, account-linked database rows) or returns them at the Controller's choice, and deletes existing copies, save legal retention obligation.
Article 10 — Transfers outside the EU
EU hosting/edge is preferred. Where a sub-processor (notably Cloudflare, a company established in the United States) carries out a transfer outside the EU/EEA, it is framed by a valid mechanism under Chapter V of the GDPR: EU-US Data Privacy Framework adequacy decision (10/07/2023, confirmed by the EU General Court on 03/09/2025, Latombe case) where the importer is certified, and/or Standard Contractual Clauses of the Commission (art. 46) with supplementary measures.
Verified on 20/06/2026: the DPF adequacy decision remains in force but is subject to a pending appeal before the CJEU (case C-703/25 P); the Standard Contractual Clauses serve as a fallback basis in case of invalidation, which is why this DPA does not rely on the DPF alone. The Controller acknowledges being informed of these transfers and mechanisms.
Article 11 — Liability & governing law
Each party is liable for damage caused by processing where it has failed to meet its GDPR obligations (art. 82). French law; jurisdiction per the Terms of Sale.
Annex 1 — Authorised sub-processors
| Sub-processor | Role | Location / transfer |
|---|---|---|
| Cloudflare, Inc. | Reverse-proxy / edge / CDN infrastructure | US — SCC + supplementary measures and/or EU-US DPF; EU edge preferred |
| Lemon Squeezy (Merchant of Record) | Payment / invoicing | US — Chapter V mechanism applicable |
| Brevo (Sendinblue) | Transactional emails (onboarding/notifications) | EU (France) |
Last updated: 20 June 2026 · Questions: [email protected]