Data Processing Agreement

How we process data for you

The GDPR Article 28 terms between you (the controller) and Assio (the processor). Last updated 4 October 2026.

Scope and acceptance

This Data Processing Agreement (“DPA”) forms part of the agreement between Assio (“Assio”, the processor) and each customer that uses Assio (the controller). It applies automatically when you create a workspace; there is nothing to sign.

If you need a countersigned copy for your records, email support@assio.net and we will send one.

It covers personal data Assio processes on your behalf. Data we control ourselves, such as your account and billing details, is covered by our Privacy Policy.

Details of the processing

  • Subject matter: providing the Assio service: learning your sites, audits, keyword research, rank tracking, AI-assisted suggestions, and publishing changes you approve.
  • Duration: for as long as you use Assio, and until deletion under “Deletion at the end” below.
  • Nature and purpose: reading your sites’ public pages; storing, analysing and displaying that content; retrieving data from services you connect (Google Search Console, GA4, WordPress); sending content to AI model providers when you use AI features; and writing approved changes to your WordPress site.
  • Categories of personal data: whatever personal data appears on your public pages or in the content you write (for example names, job titles, business contact details); workspace members’ names and email addresses; and aggregated reports from connected Google services.
  • Data subjects: your workspace members, and people named or described on your sites, such as your staff, authors and customers.
  • Special categories: Assio is not designed for special-category data. Please don’t put it in project context or prompts.

Our obligations

Assio will:

  • process personal data only on your documented instructions, which are this DPA, our terms and your use of the product, unless the law requires otherwise (and then tell you first where the law allows);
  • tell you if we believe an instruction breaks data protection law;
  • make sure anyone authorised to process the data is bound by confidentiality;
  • keep appropriate technical and organisational security measures in place (see below);
  • make available the information needed to show we meet Article 28.

Sub-processors

You authorise Assio to use the sub-processors listed in our Privacy Policy. Each is bound by written terms that protect personal data at least as well as this DPA. We will update that list before adding or replacing a sub-processor; if you object on reasonable data protection grounds, tell us at support@assio.net and we will work with you on it, and you may stop using the affected feature or close your account. We remain responsible for our sub-processors.

Security measures

  • All traffic is encrypted in transit with TLS.
  • Data is encrypted at rest by our hosting and database providers.
  • Workspace data is accessible only to that workspace’s members.
  • Passwords and API keys are stored only as hashes.
  • Connection credentials (OAuth tokens, WordPress application passwords) are kept server-side and never sent to the browser.
  • Assio reads only public pages and publishes only changes you approve.

Personal data breaches

If we become aware of a personal data breach affecting your data, we will tell you without undue delay, with what we know about its nature, likely consequences and the steps we are taking, and keep you updated so you can meet your own notification duties.

Helping with requests

Taking into account the nature of the processing, we will help you respond to data subjects exercising their rights (access, rectification, erasure, restriction, portability, objection), and with security, breach notification, data protection impact assessments and prior consultation where required. Much of this is self-serve: you can edit or delete site data in the app, and account holders can export or delete their data in Settings → Account.

Deletion at the end

When an account is deleted, we delete the user and every workspace where they were the only member, including all of its sites and the personal data we process for it, except where the law requires us to keep it. A workspace with an active subscription must cancel billing first. Stripe customer records and invoices are kept for billing and tax records, and erased on request to support@assio.net where the law allows. Before deletion you can export your data from Settings → Account, or ask us at support@assio.net to return it. Deleted data may remain in database backups until they rotate out on our provider’s schedule.

Audits

On reasonable request to support@assio.net, we will provide the information needed to show we comply with this DPA, and allow for and contribute to audits by you or an auditor you appoint, with reasonable notice, at a mutually agreed time, and subject to confidentiality.

Where data is stored

Customer Personal Data is stored and processed in the United States. Where personal data is transferred from the UK, European Economic Area or Switzerland to the US, the transfer is covered by the European Commission’s Standard Contractual Clauses, which are incorporated into this DPA and into our sub-processors’ terms where they apply.

General

If this DPA conflicts with other terms between us, this DPA wins for anything about personal data. We may update it to reflect changes in law or our sub-processors; the date at the top shows the latest version. Questions: support@assio.net.