Data Processing Agreement (DPA)

Effective date: 13 August 2026 · Version 1.0 · This DPA forms part of the Terms of Service for IndexFixer Pro.

0. How this DPA is concluded

This DPA is incorporated by reference into the Terms of Service. By creating a ZinkWP account or purchasing IndexFixer Pro, the customer accepts the Terms and thereby enters into this DPA — no signature is required. On written request ([email protected]) we will countersign a copy for your records.

1. Parties and roles

This Data Processing Agreement ("DPA") is entered into between the customer using IndexFixer Pro (the "Controller") and MuseAnn Paweł Zinkiewicz, ul. Droga Męczenników Majdanka 32/6, 20-334 Lublin, Poland, VAT ID PL9462484480 (the "Processor", operating the ZinkWP brand). It governs the processing of personal data under Regulation (EU) 2016/679 ("GDPR") in connection with the IndexFixer Pro service.

2. Subject matter and nature of processing

The Processor operates a hosted service (api.zinkwp.com) that, on the Controller's behalf:

3. Categories of data and data subjects

CategoryDataData subjects
Account dataEmail address, hashed password, plan/billing statusThe Controller's staff who register the account
Authorization dataGoogle OAuth refresh token (encrypted at rest), Google account emailThe person authorizing GSC access
Service dataPublic URLs of the Controller's website and their Google indexing statusesNot personal data in typical use; may incidentally contain personal data if URLs embed it

4. Duration and retention

5. Sub-processors

The Controller authorizes the following sub-processors. The Processor will inform of changes in advance and the Controller may object on reasonable grounds.

Sub-processorPurposeLocation
OVH SASServer hosting (dedicated server, EU)France/Poland (EU)
Cloudflare, Inc.DNS, TLS, DDoS protection, request proxyingEU/US (EU-U.S. Data Privacy Framework)
Google LLCSearch Console API (data source, on Controller's authorization)EU/US (EU-U.S. Data Privacy Framework)
Stripe, Inc.Payment processing (billing data only)EU/US (EU-U.S. Data Privacy Framework)
Resend (Plus Five Five, Inc.)Transactional emailUS (SCC)

6. Security measures (Art. 32 GDPR)

7. Processor obligations

The Processor shall: process data only on documented instructions of the Controller (the service configuration constitutes such instructions); ensure confidentiality of persons authorized to process; assist the Controller in fulfilling data-subject requests (Art. 12–23) and security obligations (Art. 32–36); notify the Controller without undue delay after becoming aware of a personal data breach; make available information necessary to demonstrate compliance and allow audits within reason; delete or return data at the end of the service as described in Section 4.

8. International transfers

Primary processing and storage take place in the EU. Where sub-processors transfer data outside the EEA (Cloudflare, Google, Stripe, Resend), transfers rely on the EU-U.S. Data Privacy Framework or Standard Contractual Clauses as indicated in Section 5.

9. Contact

Data protection contact: [email protected]