Legal

Sub-Processors

Last updated July 9, 2026

On this page

Plain-English summary

  • A sub-processor is a third-party company we use to deliver SEO Genius (hosting, databases, email, error tracking, AI calls, SEO data).
  • Each sub-processor only receives the data it needs for its specific job.
  • We use a Data Processing Agreement (DPA) with each sub-processor that handles personal information. Execution status per vendor is listed in the table below and is being completed before public publish.
  • When we add or change a sub-processor, we update this page and email active accounts at least 30 days before material changes take effect.
  • You can subscribe to change alerts at the bottom of this page.

1. What is a sub-processor?

A sub-processor is a third party we use to deliver the Service. Each sub-processor only receives the data needed for its function. We use Data Processing Agreements with sub-processors that handle personal information.

We treat sub-processor selection as a privacy decision, not just a procurement decision. Before adding a new vendor that will touch user data, we review:

  1. What data they will receive
  2. Where they store it (data residency)
  3. Whether they have a signed DPA available
  4. Their security certifications (SOC 2, ISO 27001) where applicable
  5. Their own sub-processor chain (sub-sub-processors)

2. Current sub-processor list

The table below lists every third party that processes user data on our behalf as of the "Last updated" date above.

Reading the table:

  • Vendor: the company name and link to their privacy resources.
  • Purpose: what role they play in delivering the Service.
  • Data shared: what categories of user data flow to them.
  • Data residency: where the data is stored (primary region).
  • DPA status: how data-processing terms apply with that vendor (published DPA, terms incorporation, or self-hosted). We describe only what is verifiably in place; we do not claim a separately executed agreement unless one exists.

2.1 Core infrastructure sub-processors

2.2 Billing and authentication

2.3 Communications

2.4 Observability

2.5 AI and language models

2.6 SEO data providers

2.7 User-connected Google APIs

2.8 Product analytics on our marketing pages

The vendors below receive data about visitors to our public marketing pages only. They receive nothing from the signed-in application, and they receive nothing at all from a visitor who has not accepted analytics cookies. See our Cookies page section 3.2.

Unlike section 2.7, this is not data a User connects. It is our own measurement of our own website, so we are responsible for the lawful basis and for asking permission.

3. Sub-processor changes

3.1 Notification commitment

When we add or change a sub-processor, we will update this page within 7 days of the change taking effect. For material changes, we will email active accounts at least 30 days before the change takes effect.

A material change is any of the following:

  1. A new vendor that receives a new category of personal information not previously disclosed.
  2. A change in data residency that moves user data to a new country or region.
  3. A vendor replacement that materially changes the privacy posture (for example, swapping a SOC 2-attested vendor for one that is not).

Non-material changes (for example, a sub-processor that a current vendor uses changes, but our data flow does not change) will be updated on this page without a separate email.

3.2 Right to object

If you object to a new sub-processor for a material reason, contact us at the address in section 5 before the change takes effect. We will work with you in good faith. If we cannot resolve your objection, your remedy is to cancel your subscription before the change takes effect; we will pro-rate any unused portion of an annual plan per our refund policy.

3.3 Sub-processor selection criteria

We evaluate every prospective sub-processor against the following criteria before adding them:

  • DPA availability: the vendor must offer a Data Processing Agreement.
  • Security posture: SOC 2 Type 2, ISO 27001, or equivalent independent attestation preferred.
  • Data residency: primary storage in the United States preferred during beta.
  • Sub-processor chain: the vendor must publish its own sub-processor list.
  • Incident history: material unresolved breach history is disqualifying.

4. Subscribe to sub-processor changes

To receive an email when we update this page, email support@seogenius.ai with the subject line "Subscribe: sub-processor changes" and we will add you to the notification list.

You can unsubscribe from sub-processor change alerts at any time. Unsubscribing does not affect transactional emails (billing, security, account) you receive as a User.

5. Contact

Privacy questions, sub-processor objections, and DPA requests:

Email: support@seogenius.ai Mail: Rize Digital LLC, 64 Codfish Hill Road, Bethel, CT 06801

We respond to all privacy and sub-processor inquiries within 5 business days.


6. Change log

  • August 3, 2026: added section 2.8 and two vendors, Microsoft Corporation (Microsoft Clarity, product analytics and session recording) and Google LLC (Google Tag Manager, tag loader). Both are limited to our public marketing pages, and Clarity receives nothing until a visitor accepts analytics cookies. Treated as a material change under section 3.1: active accounts are being notified, and neither vendor receives data from the signed-in application. See the Cookies page sections 3.2 and 3.3.
  • July 9, 2026: first published. Vendor list, retention statements, and all vendor links verified as of this date.