Legal

Data Processing Agreement

Last updated: April 13, 2026

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Thriven (“Processor”) and the Customer (“Controller”). It governs the processing of personal data carried out by Thriven on behalf of the Customer in connection with the Thriven AI SEO platform. This DPA reflects the requirements of Regulation (EU) 2016/679 (GDPR) and, where applicable, the UK GDPR and other applicable data protection laws.

1. Definitions

All capitalised terms not otherwise defined in this DPA have the meanings given to them in the Thriven Terms of Service. In addition:

  • "Controller" means the Customer, who determines the purposes and means of processing Personal Data.
  • "Processor" means Thriven, who processes Personal Data on behalf of the Controller.
  • "Personal Data", "Processing", "Data Subject", "Supervisory Authority" have the meanings given in the GDPR.
  • "Sub-processor" means any third party appointed by Thriven to process Personal Data on behalf of the Controller.
  • "Security Incident" means any accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.
  • "SCCs" means the Standard Contractual Clauses for the transfer of personal data to third countries adopted by the European Commission.

2. Roles of the Parties

The Customer is the Controller and Thriven is the Processor for the purposes of applicable data protection law. Thriven processes Personal Data only on documented instructions from the Customer, unless required to do so by applicable law.

3. Description of Processing

ElementDetails
Subject matterProcessing of personal data to provide the Thriven AI SEO platform (SEO audits, content briefs, analytics)
DurationFor the term of the subscription and 30 days thereafter (for data export), unless a longer retention period is required by law
Nature of processingCollection, storage, analysis, AI-assisted content generation, transmission to sub-processors, deletion
PurposeEnabling the Controller's authorised users to access and use the Thriven platform features
Types of personal dataNames, email addresses, IP addresses, usage/session data contained in URLs or content submitted by the Controller
Categories of data subjectsThe Controller's employees, contractors, and end-users whose data appears in submitted content

4. Processor Obligations

4.1 Instructions

Thriven shall process Personal Data only on documented instructions from the Controller (which include the Terms of Service and this DPA). If Thriven is required by applicable law to process Personal Data other than as instructed, it will inform the Controller unless prohibited by law.

4.2 Confidentiality

Thriven ensures that persons authorised to process Personal Data are subject to appropriate confidentiality obligations (whether by contract or statute).

4.3 Security

Thriven implements and maintains appropriate technical and organisational measures to protect Personal Data, including:

  • Encryption in transit (TLS 1.2 or higher)
  • Encryption at rest (AES-256)
  • Access controls and role-based permissions with least-privilege principles
  • Regular penetration testing and vulnerability assessments
  • Logical isolation of customer data
  • Audit logging of access to Personal Data
  • Incident response and business continuity procedures

4.4 Sub-processors

Thriven has the Controller’s general authorisation to engage sub-processors, subject to the requirements in Section 5. Thriven remains fully liable to the Controller for the performance of sub-processors’ obligations under this DPA.

4.5 Assistance with Data Subject Rights

Taking into account the nature of the processing, Thriven will assist the Controller by appropriate technical and organisational measures to respond to requests from Data Subjects exercising their rights under applicable data protection law (access, rectification, erasure, portability, restriction, objection).

4.6 Assistance with Controller Obligations

Thriven will assist the Controller in ensuring compliance with its obligations relating to security, breach notification, data protection impact assessments (DPIAs), and prior consultation with Supervisory Authorities.

4.7 Deletion or Return

At the choice of the Controller, Thriven shall delete or return all Personal Data to the Controller upon termination of the service, and delete existing copies unless applicable law requires storage.

4.8 Audit

Thriven shall make available to the Controller all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits and inspections conducted by the Controller or a mandated third-party auditor, subject to reasonable notice (minimum 30 days) and appropriate confidentiality undertakings. Audits are limited to once per calendar year unless a Security Incident occurs.

5. Sub-processors

The Controller grants Thriven general authorisation to engage the following sub-processors. Thriven will impose data protection obligations on sub-processors equivalent to those in this DPA.

Sub-processorRoleLocationDPA / Safeguards
Vercel, Inc.Application hosting and CDNUSASCCs + Vercel DPA
Neon, Inc.PostgreSQL database hostingUSA (AWS us-east-1)SCCs + Neon DPA
Stripe, Inc.Payment processingUSASCCs + Stripe DPA
OpenAI, L.L.C.AI content generation (no training on customer data)USASCCs + OpenAI DPA
Resend / PostmarkTransactional email deliveryUSASCCs + Provider DPA

Thriven will notify the Controller at least 30 days in advance of adding or replacing a sub-processor by updating this page and sending an email notification to the primary account contact. If the Controller has reasonable objections to a new sub-processor, it may notify Thriven within 14 days of the notice. Thriven will use reasonable efforts to address the concern. If the parties cannot agree, the Controller may terminate the affected subscription with a pro-rata refund for the unused period.

6. International Transfers

Where Thriven transfers Personal Data outside the EEA, the UK, or another territory with an adequacy decision, such transfer is subject to:

  • The Standard Contractual Clauses (Module 3: Processor to Sub-processor) issued by the European Commission Decision 2021/914, incorporated herein by reference; or
  • Another appropriate transfer mechanism recognised under applicable data protection law.

The SCC Module 2 (Controller to Processor) applies to transfers of Personal Data from the Controller (in the EEA/UK) to Thriven (where Thriven operates from a non-adequate country). These SCCs are incorporated into this DPA by reference.

7. Security Incidents

In the event of a Security Incident, Thriven shall:

  • Notify the Controller without undue delay and, where feasible, within 72 hours of becoming aware.
  • Provide sufficient information to allow the Controller to meet its own notification obligations under applicable law.
  • Include in the notification: nature of the incident, categories and approximate number of data subjects affected, categories and approximate number of records affected, likely consequences, and measures taken or proposed to address the incident.
  • Cooperate fully with the Controller and take reasonable steps to mitigate the effects of the Security Incident.

8. Controller Obligations

The Controller represents and warrants that:

  • It has a lawful basis for the Personal Data it submits to the platform.
  • It has provided all required notices and obtained all required consents from Data Subjects.
  • Its instructions to Thriven comply with applicable data protection law.
  • It will not submit sensitive categories of Personal Data (Art. 9 GDPR) to the platform unless explicitly agreed in writing.

9. Term & Termination

This DPA is effective from the date the Controller first accesses the Service and remains in effect for the duration of the Terms of Service. Termination of the Terms of Service automatically terminates this DPA. Thriven’s obligations regarding deletion/return of Personal Data under Section 4.7 survive termination.

10. Liability

Each party’s liability under this DPA is subject to the limitations of liability set out in the Terms of Service. Nothing in this DPA limits either party’s liability to Data Subjects or Supervisory Authorities under applicable data protection law.

11. Governing Law

This DPA is governed by the same law as the Terms of Service. Where SCCs apply, they are governed by the law of the EU member state where the lead Supervisory Authority is located, or as otherwise specified in the SCCs.

12. Execution

By accepting the Thriven Terms of Service, the Customer acknowledges and agrees to the terms of this DPA without the need for a separate signature. If your organisation requires a countersigned DPA, please email legal@thriven.ai.

Annex A — Technical & Organisational Measures

A.1 Access Control

  • Role-based access control (RBAC) with least-privilege principle
  • Multi-factor authentication (MFA) enforced for all Thriven staff accessing production systems
  • Privileged access management and just-in-time access for database access
  • Automated access review and de-provisioning on employee offboarding

A.2 Encryption

  • Data in transit: TLS 1.2+ for all web traffic; TLS for all internal service-to-service communication
  • Data at rest: AES-256 encryption for all database storage
  • Encryption key management via cloud provider KMS

A.3 Availability & Resilience

  • Automated daily database backups with point-in-time recovery
  • High-availability deployment across multiple availability zones
  • Incident response plan with defined RTO and RPO targets
  • Monitoring and alerting for system availability and anomalies

A.4 Testing & Review

  • Annual penetration testing by a qualified third party
  • Automated vulnerability scanning in CI/CD pipeline
  • Security review for new features and significant changes
  • Employee security awareness training (annual)

A.5 Physical Security

Physical infrastructure is hosted by Vercel (on AWS). Physical security controls are the responsibility of the cloud provider. Thriven staff do not have physical access to production servers.

© 2026 Thriven. All rights reserved.  ·  Security · Privacy · Terms · Cookies · DPA · Blog · Referral