This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Seahawk PSP (“Company”) and the customer (“Customer”) and applies where Company processes Personal Data on Customer’s behalf in connection with the Seahawk PSP services (“Services”).
1. Roles of the Parties
For the purposes of applicable data protection laws: Customer acts as the Data Controller. Company (Seahawk PSP) acts as the Data Processor. Company may engage authorized third-party subprocessors to assist in providing the Services.
2. Scope of Processing
2.1 Subject Matter – Processing relates to the provision of white-label WordPress professional services, including hacked site repair, site optimization, SEO, Core Web Vitals improvements, PHP upgrades, site builds, and custom web design.
2.2 Duration – Processing continues for the duration of the Services.
2.3 Categories of Data Subjects – Customer’s end users; website visitors and viewers; authorized users.
2.4 Categories of Personal Data – Contact details; IP addresses and technical data; related communications. No special category data is intended.
3. Processing Instructions
Company shall process Personal Data solely to provide the Services, on documented instructions from Customer, and in accordance with this DPA and applicable law.
4. Confidentiality
Company ensures that personnel authorized to process Personal Data are subject to confidentiality obligations.
5. Security Measures
Company shall implement appropriate technical and organizational measures designed to protect Personal Data against unauthorized access, disclosure, alteration, or destruction, taking into account the nature of the data and industry standards.
6. Subprocessors
Customer authorizes Company to engage subprocessors, provided they are bound by data protection obligations no less protective than this DPA, and Company remains responsible for their compliance. Current subprocessors include Company’s cloud hosting, database, and payment processing providers. A current list is available upon request at privacy@proservices.net.
7. Data Subject Requests
Company shall reasonably assist Customer in responding to requests from data subjects where required under applicable law.
8. Personal Data Breach
Company shall notify Customer without undue delay after becoming aware of a Personal Data Breach and provide information reasonably necessary to enable Customer to comply with its legal obligations.
9. International Data Transfers
Where Personal Data is transferred outside the jurisdiction in which it was collected, Company shall ensure such transfers are subject to appropriate safeguards in accordance with applicable data protection laws. For transfers subject to GDPR or UK GDPR, such safeguards may include approved standard contractual clauses or equivalent mechanisms.
10. Data Return or Deletion
Upon termination of the Services, Company shall delete or return Personal Data, unless retention is required by law.
11. Audit & Compliance
Company shall make available information reasonably necessary to demonstrate compliance with this DPA. Audits shall be limited, reasonable in scope, and subject to confidentiality obligations.
12. Liability
Liability arising from this DPA shall be subject to the limitations set forth in the Terms of Service, except where prohibited by applicable law.
13. Governing Law
This DPA shall be governed by and construed in accordance with the laws of the United States of America, consistent with the Terms of Service, unless mandatory data protection law requires otherwise.
14. Precedence
In the event of a conflict between this DPA and the Terms of Service, this DPA shall govern with respect to data protection matters.
15. Contact Us
For questions or concerns about this Data Processing Agreement, please contact us at ryan@seahawkmedia.com.