Effective date: 6 October 2026
Last updated: 6 October 2026
The short version. This summary helps you read this Agreement. It is not part of it; if it differs from the Agreement below, the Agreement applies.
- Who it is for. Business customers of aSERP, on every plan and during a trial, unless a signed Custom agreement has its own data processing terms.
- What it covers. Personal data we process for you: your users' details, the people you send reports to, and any personal data in your content, such as your prompts.
- How we use it. Only to provide aSERP to you, on your instructions. We keep it confidential and secure, and we do not use it to train AI models.
- Who helps us. Our hosting provider, our e-mail provider and the companies that run the engines aSERP measures (Annex 3). We tell you at least 30 days before we add a new one, and you can object.
- Other countries. The data can be processed outside your country, with the safeguards the law requires.
- If something goes wrong. We tell you without undue delay after we become aware of a personal data breach.
- At the end. You can ask us to delete the data. We delete it, or make it anonymous, within 30 days of your request, unless the law requires us to keep it.
1. About this Agreement
1.1 Who it is between. This Data Processing Agreement (the "Agreement") is between WATS Est ("we", "us", "our"), registered in the Kingdom of Saudi Arabia under number 7053884479, with its registered address in Riyadh, Kingdom of Saudi Arabia, and the business customer that uses aSERP ("you"). Our contact details are in section 31 of our Terms of Service (the "Terms").
1.2 When it applies. This Agreement applies if you are a business customer (section 3 of the Terms), on any plan and during a trial, whenever we process personal data on your behalf to provide aSERP to you. It does not apply to the free tools (section 7 of the Terms). If you have a Custom plan and your signed agreement has its own data processing terms, those terms apply instead of this Agreement.
1.3 Part of your contract. This Agreement forms part of your contract with us under the Terms (section 1.4 of the Terms). You accept it when you accept the Terms as a business customer. Words defined in the Terms have the same meaning in this Agreement.
1.4 If this Agreement and the Terms differ. For Customer Personal Data, this Agreement prevails over the Terms where the two differ.
2. Words used in this Agreement
- "Customer Personal Data" means the personal data that we process on your behalf to provide aSERP to you. Annex 1 describes it.
- "data protection law" means every law on the protection of personal data that applies to the processing of Customer Personal Data.
- "controller", "processor", "personal data" and "processing" have the meanings that data protection law gives them. Where a law uses other words for the same ideas, those words have the same meaning here.
- "sub-processor" means a company that we engage to process Customer Personal Data for us.
- "personal data breach" means a breach of security that leads to the accidental or unlawful destruction, loss or alteration of Customer Personal Data, or to its unauthorised disclosure or access.
3. Roles and responsibilities
3.1 Your role and ours. For Customer Personal Data, you are the controller and we are your processor. If you use aSERP for your own clients, you may be their processor; we are then your sub-processor, and you make sure that your clients authorise the instructions you give us.
3.2 Our own processing. We process some personal data for our own purposes, as a controller in our own right: to run sign-in and keep aSERP secure, to bill and take payments, to communicate with users about aSERP, and to meet our legal obligations. For example, card payments are processed by our payment provider, Moyasar (section 9.4 of the Terms). Our Privacy Policy describes this processing. This Agreement does not apply to it.
3.3 Your responsibilities. You are responsible for:
- (a) having a lawful basis for the Customer Personal Data you put into aSERP and for the instructions you give us (section 15.4 of the Terms);
- (b) giving the people concerned, such as your users and the people you send reports to, the information the law requires;
- (c) putting into aSERP only the personal data needed to measure a brand (section 14.3(c) of the Terms), and no sensitive personal data, such as data about health; and
- (d) the members you invite, the roles you give them, and the share links and report recipients you add (sections 5.3 and 14.6 of the Terms).
4. How we process Customer Personal Data
4.1 Only on your instructions. We process Customer Personal Data only on your documented instructions. Your instructions are the Terms, this Agreement, and what you and your members do in aSERP, for example the brands, competitors and prompts you track, the members you invite, the report recipients you add and the share links you create. Any other instruction needs our written agreement. If the law requires us to process Customer Personal Data in another way, we tell you before we do so, unless that law forbids it.
4.2 Instructions we think are unlawful. If we think that an instruction breaks data protection law, we tell you. We may then pause the processing concerned until you confirm or change the instruction.
4.3 Only to provide aSERP. We use Customer Personal Data only to provide aSERP to you, to keep it secure and to support you. We do not use it to train AI models, and our aggregated statistics use only content that is not personal data (section 15.2 of the Terms).
4.4 Details of the processing. Annex 1 describes the subject matter, nature, purposes and duration of the processing, the types of personal data and the people concerned.
5. Confidentiality
Everyone we authorise to process Customer Personal Data is bound by a duty of confidentiality, by contract or by law, and has access to it only as far as their work requires. Section 20 of the Terms also applies.
6. Security
6.1 Our measures. We take appropriate technical and organisational measures to protect Customer Personal Data, taking into account the state of the art, the costs, the nature, scope, context and purposes of the processing, and the risks to people. Annex 2 describes our measures in plain terms.
6.2 Changes to our measures. We may change our measures as technology and risks change, but never in a way that lowers the overall protection of Customer Personal Data.
6.3 Your part. You are responsible for how you and your members use aSERP securely, for example for keeping sign-in details private (section 4.3 of the Terms) and for who receives share links and reports (section 14.6 of the Terms).
7. Sub-processors
7.1 Your authorisation. You authorise us to engage sub-processors. Annex 3 lists the sub-processors we use today.
7.2 Our duties. Before a sub-processor processes Customer Personal Data, we bind it in writing to data protection obligations that protect Customer Personal Data at least as well as this Agreement. We remain responsible to you for its work (section 30.2 of the Terms).
7.3 New sub-processors. We tell you by e-mail at least 30 days before a new sub-processor starts to process Customer Personal Data, and we update Annex 3. If we must replace a sub-processor sooner, for example because it stops its service or for security reasons, we tell you as early as we can.
7.4 If you object. You can object to a new sub-processor on reasonable grounds of data protection by writing to us at complaints@aserp.com before it starts. We discuss your objection with you in good faith. If we cannot resolve it, you can end your plan within the time and in the way that section 21.3 of the Terms sets out for changes to aSERP, and we refund the unused part of any prepaid billing period.
8. Requests from the people concerned
8.1 Requests we receive. If a person asks us to act on their rights over Customer Personal Data, for example to see, correct or delete it, we pass the request on to you without undue delay. We do not answer it ourselves, except to tell the person to contact you, unless the law requires otherwise.
8.2 Doing it yourself. You can deal with many requests yourself in aSERP: you can remove members, delete invitations, change or remove report recipients, disconnect a messaging service, change the names on report covers and delete a brand with everything in it. Where you cannot do what a request needs yourself, we help you, taking into account the nature of the processing.
9. Other help we give you
9.1 Your duties under the law. Taking into account the nature of the processing and the information available to us, we give you reasonable help to meet your duties under data protection law on security, personal data breaches, data protection impact assessments and consultations with authorities.
9.2 Requests from authorities. If an authority or a court asks us to disclose Customer Personal Data, we refer it to you where we can. We tell you about the request before we disclose anything, unless the law forbids it, and we disclose only what the law requires.
10. Personal data breaches
10.1 Telling you. If we become aware of a personal data breach, we tell you without undue delay, by e-mail to the owners of the company account concerned.
10.2 What we tell you. We tell you what we know about what happened, the types of data and the approximate number of people and records concerned, the likely consequences, what we have done or plan to do about it, and whom you can contact for more information. If we cannot give you all of this at once, we give it to you in stages, without undue delay.
10.3 What we do. We take reasonable steps to contain the breach, to limit its effects and to prevent it from happening again. We help you with any notice that you must give to an authority or to the people concerned.
10.4 No admission. Telling you about a breach is not an admission of fault.
11. When your use of aSERP ends
11.1 Before it ends. You can download your reports, including their data, as PDF and XLSX files, and you can see your brands, prompts, members and report recipients in aSERP.
11.2 Deletion. When your use of aSERP ends, you can ask us to delete Customer Personal Data by writing to complaints@aserp.com. We delete it, or make it anonymous so that it can no longer be linked to anyone, within 30 days of your request, unless the law requires us to keep it. Data that the law requires us to keep stays protected under this Agreement, and we use it only for that legal purpose.
11.3 A person's own account. How a person deletes their own account is described in our Privacy Policy (section 4.4 of the Terms).
12. Showing that we comply
12.1 Information. On request, we give you the information you reasonably need to show that we comply with this Agreement, such as a description of our security measures and our list of sub-processors.
12.2 Audits. If that information is not enough to show that we comply, or a data protection authority requires it, you can audit our compliance with this Agreement, yourself or through an independent auditor who is bound by confidentiality and is not our competitor. You give us at least 30 days' written notice, and we agree the scope, timing and length of the audit in advance. An audit takes place no more than once in any 12 months, unless a personal data breach or an authority makes another one necessary. It must not disrupt aSERP, and it gives no access to other customers' data or to our confidential information that does not concern you. You bear its costs.
13. Transfers to other countries
13.1 Where the data is processed. We are registered in the Kingdom of Saudi Arabia, and aSERP serves customers around the world. We and our sub-processors may process Customer Personal Data outside your country. Annex 3 shows the country of each sub-processor's legal entity; processing can also take place in other countries where a sub-processor operates.
13.2 Safeguards. Where data protection law allows a transfer of Customer Personal Data to another country only with a safeguard, we make the transfer only with a safeguard that the law accepts, such as standard contractual clauses approved under that law. Where that law requires such clauses between you and us, they form part of this Agreement, with the details set out in Annexes 1 to 3, and they prevail over this Agreement where the two differ. Transfers by our sub-processors follow the same rule.
14. Liability
The limits and exclusions of liability in section 24 of the Terms apply to this Agreement. Liability under this Agreement and under the Terms counts towards one limit, not one limit for each. Nothing in this Agreement limits any liability that data protection law does not allow to be limited, or any right that people have under that law.
15. How long this Agreement lasts, and changes to it
15.1 Duration. This Agreement applies for as long as we process Customer Personal Data for you, including after your plan ends, until the data is deleted or made anonymous under section 11.
15.2 Changes. We may update this Agreement for the reasons in section 26.1 of the Terms, and sections 26.2 to 26.4 of the Terms apply to the update as if this Agreement were part of the Terms. A new sub-processor is dealt with under section 7 instead.
16. General
16.1 Governing law. This Agreement is governed by the same law as the Terms (section 27.2 of the Terms), except where data protection law, or clauses that form part of this Agreement under section 13.2, require another law.
16.2 Notices. Section 29 of the Terms applies. We send notices under this Agreement to the owners of the company account concerned. Send notices to us at complaints@aserp.com.
16.3 Language. This Agreement is published in the same two languages as the Terms, and section 28 of the Terms applies to it: both versions are equally authoritative and are intended to say the same thing.
16.4 If a clause is invalid. Section 30.4 of the Terms applies to this Agreement.
Annex 1. Details of the processing
- Subject matter. Providing aSERP to you under the Terms.
- Duration. As set out in section 15.1.
- Nature of the processing. Hosting, organising, displaying and sending Customer Personal Data in aSERP: sending your tracked prompts to the engines every day, showing your company account's data to its members, and sending e-mails such as invitations and reports.
- Purposes. Providing aSERP to you as the Terms describe: measuring how the engines answer your prompts, showing results, letting your members work together in your company account, delivering reports to the recipients you choose, keeping aSERP secure, and supporting you.
- People concerned.
- Your users: the owners and members of your company account, and the people you invite to it.
- The people you send reports to.
- Any person named or described in your content, for example in a prompt, a topic, a brand or competitor name, or on a report cover.
- Types of personal data.
- Your users: name, e-mail address and profile picture, if one is added; their role in the company account; invitations; and records of which user made a change or sent a report.
- The people you send reports to: e-mail addresses.
- Report covers: the names you put on them.
- Your content: any personal data you put into it, for example into the text of a prompt.
- Sensitive personal data. None is needed, and you must not put any into aSERP (section 3.3(c)).
- What the engines receive. The text of your tracked prompts, including the brand, competitor and market details in them (section 15.2 of the Terms). They do not receive the names or e-mail addresses of your users.
- Frequency. Continuous while you use aSERP. Tracked prompts are sent every day.
Annex 2. Security measures
- Encrypted connections. aSERP is served only over HTTPS: plain HTTP requests are redirected, and browsers are told to use HTTPS only. aSERP also connects to the engines and to its e-mail provider over encrypted connections.
- Separation between customers. Rules in the database itself limit each company account's data to that company account's members. Automated tests check that one customer cannot read another customer's data.
- Roles. Each member has a role. Only owners can manage billing, and owners decide who joins.
- Staff access. Our administration tools require a staff role and a two-step sign-in.
- Server access. Our servers sit behind firewalls, on the servers and at our hosting provider, that let in only web traffic and the private network we use to administer them.
- Sign-in protection. Users must confirm their e-mail address before they can use aSERP. Sign-up, sign-in and password reset are protected by a check against automated abuse. Invitations expire after 7 days. Share links expire, by default after 7 days, and you can revoke them at any time.
- Logs. Our web server removes sign-in credentials and keys from what it logs. Our records of e-mail delivery contain no message content.
- Secrets. Keys that give full access to the database stay on our servers and are never sent to browsers.
- Changes to aSERP. Every change goes through a protected process with automated checks before it is released. The software we release is scanned for known critical and high-severity vulnerabilities that have a fix, and its build fails if one is found.
- People. Everyone who can access Customer Personal Data is bound by confidentiality (section 5).
Annex 3. Sub-processors
Who they are.
| Provider | Approved legal name | Country of the legal entity |
|---|---|---|
| Hetzner | Hetzner Online GmbH | Germany |
| Resend | Plus Five Five, Inc. | United States of America |
| OpenAI | OpenAI OpCo, LLC | United States of America |
| Anthropic — Claude | Anthropic, PBC | United States of America |
| Google — Paid Gemini API, Middle East billing | Google Cloud EMEA Limited | Ireland |
| Perplexity | Perplexity AI, Inc. | United States of America |
| xAI — Grok | SpaceXAI LLC | United States of America |
| DeepSeek | Hangzhou DeepSeek Artificial Intelligence Co., Ltd. | China |
The country column identifies the legal entity's country, not the location of its servers or all countries in which processing takes place.
What they do.
| Provider | What it does for aSERP | Customer Personal Data it processes |
|---|---|---|
| Hetzner | Hosts the servers that run aSERP, including its database, sign-in and file storage | All Customer Personal Data |
| Resend | Sends aSERP's e-mails, such as sign-in e-mails, invitations, reports and notices | The e-mail addresses of your users and of the people you send reports to, and the content of those e-mails |
| OpenAI | Runs an engine that aSERP measures | The text of your tracked prompts |
| Anthropic | Runs an engine that aSERP measures | The text of your tracked prompts |
| Runs an engine that aSERP measures | The text of your tracked prompts | |
| Perplexity | Runs an engine that aSERP measures | The text of your tracked prompts |
| xAI | Runs an engine that aSERP measures | The text of your tracked prompts |
| DeepSeek | Runs an engine that aSERP measures | The text of your tracked prompts |
Services that you or your users choose, such as sign-in with Google or a messaging service that you connect for report delivery, are not our sub-processors. Their own terms apply to them (section 19.1 of the Terms).

