Legal
Last updated: April 13, 2026
All capitalised terms not otherwise defined in this DPA have the meanings given to them in the Thriven Terms of Service. In addition:
The Customer is the Controller and Thriven is the Processor for the purposes of applicable data protection law. Thriven processes Personal Data only on documented instructions from the Customer, unless required to do so by applicable law.
| Element | Details |
|---|---|
| Subject matter | Processing of personal data to provide the Thriven AI SEO platform (SEO audits, content briefs, analytics) |
| Duration | For the term of the subscription and 30 days thereafter (for data export), unless a longer retention period is required by law |
| Nature of processing | Collection, storage, analysis, AI-assisted content generation, transmission to sub-processors, deletion |
| Purpose | Enabling the Controller's authorised users to access and use the Thriven platform features |
| Types of personal data | Names, email addresses, IP addresses, usage/session data contained in URLs or content submitted by the Controller |
| Categories of data subjects | The Controller's employees, contractors, and end-users whose data appears in submitted content |
Thriven shall process Personal Data only on documented instructions from the Controller (which include the Terms of Service and this DPA). If Thriven is required by applicable law to process Personal Data other than as instructed, it will inform the Controller unless prohibited by law.
Thriven ensures that persons authorised to process Personal Data are subject to appropriate confidentiality obligations (whether by contract or statute).
Thriven implements and maintains appropriate technical and organisational measures to protect Personal Data, including:
Thriven has the Controller’s general authorisation to engage sub-processors, subject to the requirements in Section 5. Thriven remains fully liable to the Controller for the performance of sub-processors’ obligations under this DPA.
Taking into account the nature of the processing, Thriven will assist the Controller by appropriate technical and organisational measures to respond to requests from Data Subjects exercising their rights under applicable data protection law (access, rectification, erasure, portability, restriction, objection).
Thriven will assist the Controller in ensuring compliance with its obligations relating to security, breach notification, data protection impact assessments (DPIAs), and prior consultation with Supervisory Authorities.
At the choice of the Controller, Thriven shall delete or return all Personal Data to the Controller upon termination of the service, and delete existing copies unless applicable law requires storage.
Thriven shall make available to the Controller all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits and inspections conducted by the Controller or a mandated third-party auditor, subject to reasonable notice (minimum 30 days) and appropriate confidentiality undertakings. Audits are limited to once per calendar year unless a Security Incident occurs.
The Controller grants Thriven general authorisation to engage the following sub-processors. Thriven will impose data protection obligations on sub-processors equivalent to those in this DPA.
| Sub-processor | Role | Location | DPA / Safeguards |
|---|---|---|---|
| Vercel, Inc. | Application hosting and CDN | USA | SCCs + Vercel DPA |
| Neon, Inc. | PostgreSQL database hosting | USA (AWS us-east-1) | SCCs + Neon DPA |
| Stripe, Inc. | Payment processing | USA | SCCs + Stripe DPA |
| OpenAI, L.L.C. | AI content generation (no training on customer data) | USA | SCCs + OpenAI DPA |
| Resend / Postmark | Transactional email delivery | USA | SCCs + Provider DPA |
Thriven will notify the Controller at least 30 days in advance of adding or replacing a sub-processor by updating this page and sending an email notification to the primary account contact. If the Controller has reasonable objections to a new sub-processor, it may notify Thriven within 14 days of the notice. Thriven will use reasonable efforts to address the concern. If the parties cannot agree, the Controller may terminate the affected subscription with a pro-rata refund for the unused period.
Where Thriven transfers Personal Data outside the EEA, the UK, or another territory with an adequacy decision, such transfer is subject to:
The SCC Module 2 (Controller to Processor) applies to transfers of Personal Data from the Controller (in the EEA/UK) to Thriven (where Thriven operates from a non-adequate country). These SCCs are incorporated into this DPA by reference.
In the event of a Security Incident, Thriven shall:
The Controller represents and warrants that:
This DPA is effective from the date the Controller first accesses the Service and remains in effect for the duration of the Terms of Service. Termination of the Terms of Service automatically terminates this DPA. Thriven’s obligations regarding deletion/return of Personal Data under Section 4.7 survive termination.
Each party’s liability under this DPA is subject to the limitations of liability set out in the Terms of Service. Nothing in this DPA limits either party’s liability to Data Subjects or Supervisory Authorities under applicable data protection law.
This DPA is governed by the same law as the Terms of Service. Where SCCs apply, they are governed by the law of the EU member state where the lead Supervisory Authority is located, or as otherwise specified in the SCCs.
By accepting the Thriven Terms of Service, the Customer acknowledges and agrees to the terms of this DPA without the need for a separate signature. If your organisation requires a countersigned DPA, please email legal@thriven.ai.
Physical infrastructure is hosted by Vercel (on AWS). Physical security controls are the responsibility of the cloud provider. Thriven staff do not have physical access to production servers.