This DPA is incorporated by reference into the Terms of Service. By creating a ZinkWP account or purchasing IndexFixer Pro, the customer accepts the Terms and thereby enters into this DPA — no signature is required. On written request ([email protected]) we will countersign a copy for your records.
This Data Processing Agreement ("DPA") is entered into between the customer using IndexFixer Pro (the "Controller") and MuseAnn Paweł Zinkiewicz, ul. Droga Męczenników Majdanka 32/6, 20-334 Lublin, Poland, VAT ID PL9462484480 (the "Processor", operating the ZinkWP brand). It governs the processing of personal data under Regulation (EU) 2016/679 ("GDPR") in connection with the IndexFixer Pro service.
The Processor operates a hosted service (api.zinkwp.com) that, on the Controller's behalf:
webmasters.readonly),| Category | Data | Data subjects |
|---|---|---|
| Account data | Email address, hashed password, plan/billing status | The Controller's staff who register the account |
| Authorization data | Google OAuth refresh token (encrypted at rest), Google account email | The person authorizing GSC access |
| Service data | Public URLs of the Controller's website and their Google indexing statuses | Not personal data in typical use; may incidentally contain personal data if URLs embed it |
The Controller authorizes the following sub-processors. The Processor will inform of changes in advance and the Controller may object on reasonable grounds.
| Sub-processor | Purpose | Location |
|---|---|---|
| OVH SAS | Server hosting (dedicated server, EU) | France/Poland (EU) |
| Cloudflare, Inc. | DNS, TLS, DDoS protection, request proxying | EU/US (EU-U.S. Data Privacy Framework) |
| Google LLC | Search Console API (data source, on Controller's authorization) | EU/US (EU-U.S. Data Privacy Framework) |
| Stripe, Inc. | Payment processing (billing data only) | EU/US (EU-U.S. Data Privacy Framework) |
| Resend (Plus Five Five, Inc.) | Transactional email | US (SCC) |
The Processor shall: process data only on documented instructions of the Controller (the service configuration constitutes such instructions); ensure confidentiality of persons authorized to process; assist the Controller in fulfilling data-subject requests (Art. 12–23) and security obligations (Art. 32–36); notify the Controller without undue delay after becoming aware of a personal data breach; make available information necessary to demonstrate compliance and allow audits within reason; delete or return data at the end of the service as described in Section 4.
Primary processing and storage take place in the EU. Where sub-processors transfer data outside the EEA (Cloudflare, Google, Stripe, Resend), transfers rely on the EU-U.S. Data Privacy Framework or Standard Contractual Clauses as indicated in Section 5.
Data protection contact: [email protected]