WhizWiser Logo
Know Your Rankings.
Control Your Growth.

Connect with us

Data Processing Agreement

Last updated: September 5, 2026


WhizWiser

Effective Date: September 5, 2026

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Consultwhiz Consultancy & E-Commerce Services, a sole proprietorship registered in India (“WhizWiser,” “we,” “us,” or “our”), and the customer or organization using the WhizWiser Services (“Customer,” “you,” or “your”).

This DPA governs the processing of personal data by WhizWiser on behalf of the Customer where WhizWiser acts as a processor, service provider, or equivalent role under applicable data protection law.

This DPA applies primarily to business, agency, enterprise, and other organizational customers. It may also apply where an individual customer uses WhizWiser to process personal data on behalf of another person or organization.


1. Definitions

For purposes of this DPA:

“Applicable Data Protection Law”

Means all applicable laws and regulations relating to privacy, data protection, and processing of personal data applicable to the processing contemplated under this DPA, including, where applicable:

  • The EU General Data Protection Regulation (“EU GDPR”)
  • The UK General Data Protection Regulation (“UK GDPR”)
  • The Data Protection Act 2018 of the United Kingdom
  • The California Consumer Privacy Act, as amended (“CCPA”)
  • India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”) and applicable rules
  • Other applicable privacy and data protection laws

“Customer Data”

Means information submitted to, uploaded to, transmitted through, or otherwise processed using the Services by or on behalf of the Customer.

“Personal Data”

Means information relating to an identified or identifiable individual, or equivalent information protected under Applicable Data Protection Law.

“Processing”

Has the meaning given to it under Applicable Data Protection Law and includes collecting, recording, organizing, storing, retrieving, using, analyzing, transmitting, modifying, disclosing, deleting, or otherwise handling personal data.

“Services”

Means WhizWiser’s websites, software, applications, APIs, products, features, integrations, and related services, including Keyword Rank Checker, BlogPilot, AI Visibility Checker, AdsPilot, reporting, analytics, and future services.

“Subprocessor”

Means a third party engaged by WhizWiser to process Customer Data on WhizWiser’s behalf.


2. Roles of the Parties

The parties acknowledge that their roles depend on the nature of the processing.

Where the Customer determines the purposes and means of processing Personal Data and WhizWiser processes that data on the Customer’s behalf, the Customer is the Controller or equivalent business, and WhizWiser is the Processor, Service Provider, or equivalent role.

Where WhizWiser determines the purposes and means of processing personal information for its own business purposes, WhizWiser may act as an independent controller or equivalent entity.

Examples of WhizWiser’s independent processing may include:

  • Account administration
  • Billing
  • Security
  • Fraud prevention
  • Service analytics
  • Product improvement
  • Legal compliance
  • Direct business communications

The parties will comply with their respective responsibilities under Applicable Data Protection Law.


3. Scope of Processing

WhizWiser will process Customer Data only:

  1. To provide and operate the Services;
  2. To perform the Customer’s instructions;
  3. As necessary to maintain security and reliability;
  4. To prevent fraud, abuse, and unauthorized access;
  5. To provide customer support;
  6. To perform other activities expressly permitted by the Terms of Service, this DPA, or Applicable Data Protection Law.

WhizWiser will not use Customer Data for purposes inconsistent with the Customer’s documented instructions or Applicable Data Protection Law.


4. Customer Instructions

The Customer instructs WhizWiser to process Customer Data as reasonably necessary to provide the Services.

The Customer’s instructions may include:

  • Creating and managing accounts
  • Storing Customer Data
  • Processing uploaded documents
  • Processing website and SEO information
  • Processing prompts and AI-generated content
  • Generating reports
  • Performing analytics requested through the Services
  • Processing advertising-account information
  • Processing information through enabled integrations
  • Maintaining historical data
  • Providing support
  • Performing security and operational activities

The Customer may provide additional lawful processing instructions where supported by the Services.

WhizWiser may refuse instructions that it reasonably believes violate Applicable Data Protection Law or materially compromise the security of the Services.


5. Customer Responsibilities

The Customer is responsible for:

  • Ensuring that it has a lawful basis for providing Personal Data to WhizWiser;
  • Providing appropriate privacy notices to individuals where required;
  • Obtaining required consents or authorizations;
  • Ensuring that its instructions to WhizWiser are lawful;
  • Ensuring that Customer Data is accurate where required;
  • Determining appropriate retention periods;
  • Responding to data-subject or consumer requests where the Customer is the responsible controller;
  • Ensuring that its use of WhizWiser complies with applicable laws;
  • Not uploading unnecessary sensitive or highly regulated information;
  • Obtaining appropriate authorization before connecting third-party accounts;
  • Ensuring that employees, contractors, and agency users are authorized to access Customer Data.

For agencies, the agency is responsible for ensuring that it has appropriate authorization from its clients to process their information through WhizWiser.


6. Categories of Data

Customer Data processed through WhizWiser may include, depending on the Services and Customer’s use:

  • Names
  • Email addresses
  • Phone numbers
  • Company information
  • Job titles
  • Business contact information
  • Website information
  • IP addresses
  • Online identifiers
  • SEO and marketing information
  • Advertising information
  • Account information
  • Prompts and instructions
  • Documents
  • Images
  • Articles and other content
  • AI-generated outputs
  • Reports
  • Google Ads account and campaign information
  • Conversion and performance information
  • Other information submitted by the Customer

WhizWiser does not require customers to submit special categories of personal data or sensitive personal information for ordinary use of the Services.

Customers should not upload sensitive personal information unless there is a lawful and necessary reason to do so and the relevant Service expressly supports such processing.


7. Categories of Data Subjects

Depending on the Customer’s use of the Services, Customer Data may relate to:

  • Customer employees
  • Customer contractors
  • Customer representatives
  • Customer clients
  • Customer’s clients’ customers
  • Website visitors
  • Leads
  • Business contacts
  • Marketing contacts
  • Advertising audiences
  • Other individuals whose information the Customer lawfully submits

The specific categories depend on the Customer’s activities and use of the Services.


8. Confidentiality

WhizWiser will ensure that persons authorized to process Customer Data:

  • Are subject to appropriate confidentiality obligations;
  • Access Customer Data only as necessary to perform their responsibilities;
  • Receive appropriate instructions regarding the handling of Customer Data.

WhizWiser will take reasonable steps to prevent unauthorized use or disclosure of Customer Data.


9. Security Measures

WhizWiser will maintain reasonable technical and organizational measures designed to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access.

Depending on the nature of the Services, security measures may include:

Encryption

  • HTTPS/TLS encryption for data transmitted over the internet;
  • Encryption or equivalent safeguards for stored data where implemented.

Access Controls

  • Authentication controls;
  • Restricted administrative access;
  • Access based on operational necessity where supported;
  • Credential and access management procedures.

Infrastructure Security

WhizWiser uses third-party infrastructure and hosting providers and maintains reasonable controls intended to protect its infrastructure.

Backups

WhizWiser may maintain backups for operational continuity and disaster recovery.

Backup copies may remain temporarily after Customer Data is deleted from active systems.

Security Monitoring

WhizWiser may use logging, monitoring, abuse detection, and other security mechanisms appropriate to the Services and reasonably available to the business.

WhizWiser does not represent that every security control described in this section is implemented in every system or environment at all times.


10. Security Incidents and Personal Data Breaches

If WhizWiser becomes aware of a confirmed Personal Data breach affecting Customer Data processed on the Customer’s behalf, WhizWiser will take reasonable steps to:

  1. Investigate the incident;
  2. Contain and mitigate its effects;
  3. Restore affected systems where reasonably possible;
  4. Assess the nature and scope of the incident;
  5. Notify the Customer where required by Applicable Data Protection Law or the circumstances reasonably warrant notification.

Where reasonably possible, notification will include information available at the time concerning:

  • The nature of the incident;
  • Categories of affected data;
  • Potential impact;
  • Measures taken or proposed to address the incident.

WhizWiser may provide information in stages where complete information is not initially available.

The Customer remains responsible for determining whether notification to regulators or affected individuals is legally required unless Applicable Data Protection Law places that obligation directly on WhizWiser.


11. Subprocessors

WhizWiser may engage third-party service providers to assist with:

  • Hosting
  • Cloud infrastructure
  • Databases
  • Storage
  • Payment processing
  • Authentication
  • Analytics
  • Security
  • AI processing
  • APIs
  • Customer support
  • Communications
  • Advertising and measurement
  • Other infrastructure necessary to provide the Services

These providers may process Customer Data only to the extent necessary for the relevant service and subject to appropriate contractual or legal safeguards.

WhizWiser remains responsible for its Subprocessors’ processing to the extent required by Applicable Data Protection Law.


12. AI Service Providers

Certain WhizWiser features may use third-party artificial intelligence providers or APIs.

Depending on the feature, Customer Data may be processed by an AI provider to:

  • Generate content;
  • Analyze information;
  • Produce reports;
  • Perform requested AI functionality;
  • Improve or operate AI-powered features.

WhizWiser selects and configures AI providers based on the applicable product and service requirements.

Where WhizWiser uses a third-party AI provider to process Customer Data, WhizWiser will seek to maintain contractual and technical safeguards appropriate to the processing.

AI providers may have their own terms, privacy policies, data-processing commitments, and retention practices. The applicable provider terms may therefore apply to processing performed through that provider.

WhizWiser will not intentionally instruct a third-party AI provider to use Customer Data for unrelated purposes where such use is prohibited by Applicable Data Protection Law or the Customer’s applicable contractual protections.


13. Product Improvement and AI Development

WhizWiser may process data to maintain, secure, analyze, and improve its Services, subject to Applicable Data Protection Law and the Customer’s applicable controls and agreements.

Where Customer Data is processed on behalf of a Customer in a processor/service-provider capacity, WhizWiser will not use that data for independent purposes that are incompatible with its processor/service-provider obligations.

Any use of Customer Data for AI development, model improvement, RAG systems, product analytics, or similar purposes will be subject to Applicable Data Protection Law and the applicable contractual relationship.


14. Google Ads and Third-Party Integrations

Some WhizWiser features, including AdsPilot, may connect to third-party platforms such as Google Ads.

Where the Customer authorizes such an integration:

  • WhizWiser may access information permitted by the Customer’s authorization;
  • The information may include account, campaign, keyword, advertising, landing-page, conversion, performance, and historical information;
  • WhizWiser may process this information to provide the requested Services;
  • Certain features may allow recommendations or changes to advertising campaigns;
  • Automated changes may occur only where the Customer has enabled the applicable automation functionality and granted the necessary authorization.

The Customer is responsible for ensuring that its use of third-party integrations complies with the applicable third-party terms and policies.

When an integration is disconnected, WhizWiser will take reasonable steps to stop using the applicable authorization credentials and revoke or delete stored authorization tokens where technically appropriate and required.


15. Data Subject Requests

Where WhizWiser processes Personal Data as a Processor or Service Provider, WhizWiser will provide reasonable assistance to the Customer in responding to legally valid requests from individuals, taking into account the nature of the processing and information available to WhizWiser.

Such requests may include:

  • Access
  • Correction
  • Deletion
  • Portability
  • Restriction
  • Objection
  • Opt-out requests
  • Other rights under Applicable Data Protection Law

Where the request is directed to WhizWiser but the Customer is the controller, WhizWiser may direct the individual to the Customer where appropriate.

WhizWiser will not independently respond to a data-subject request in a manner that conflicts with the Customer’s lawful instructions unless required by law.


16. Assistance With Regulatory Obligations

Taking into account the nature of processing and information reasonably available to WhizWiser, WhizWiser will provide reasonable assistance to the Customer concerning:

  • Security obligations;
  • Personal Data breach response;
  • Data-subject requests;
  • Data protection impact assessments;
  • Regulatory consultations where required;
  • Other processor-related obligations required by Applicable Data Protection Law.

Any assistance will be subject to reasonable limitations based on the Services, available information, technical feasibility, and applicable law.


17. International Data Transfers

WhizWiser is an India-based business and may process Customer Data using infrastructure and service providers located in multiple countries.

The current infrastructure environment may include processing or storage in jurisdictions such as India, Singapore, the United States, or other countries where service providers operate.

Where Applicable Data Protection Law requires a specific transfer mechanism, the parties will use an appropriate mechanism, which may include:

  • Standard Contractual Clauses approved or recognized under applicable law;
  • UK International Data Transfer Agreement or Addendum where applicable;
  • Adequacy decisions where applicable;
  • Other legally recognized transfer mechanisms.

Where required, the parties will cooperate to implement the appropriate transfer safeguards.


18. EU and UK Processing

Where the Customer is subject to the EU GDPR or UK GDPR, the parties agree that the relevant GDPR processor requirements apply to processing performed under this DPA.

WhizWiser will:

  • Process Personal Data only on documented instructions;
  • Maintain confidentiality;
  • Implement appropriate security measures;
  • Provide reasonable assistance with data-subject rights;
  • Provide breach-related assistance;
  • Address subprocessors appropriately;
  • Support international transfer requirements;
  • Delete or return Personal Data where required following termination, subject to applicable legal and operational requirements.

Where required by applicable law, the parties may execute additional EU or UK transfer documentation.


19. California Processing

Where the Customer is subject to the CCPA and WhizWiser processes personal information on the Customer’s behalf, WhizWiser will process such information in accordance with applicable CCPA requirements governing service providers or contractors.

WhizWiser will not:

  • Sell Customer Personal Information;
  • Share Customer Personal Information for cross-context behavioral advertising for WhizWiser’s independent commercial purposes where prohibited by applicable service-provider/contractor requirements;
  • Retain, use, or disclose Customer Personal Information outside the permitted business purposes of providing the Services and other purposes allowed by applicable law;
  • Combine Customer Personal Information with personal information obtained from other sources except as permitted by applicable law.

WhizWiser will provide reasonable assistance to the Customer in responding to applicable consumer requests.


20. India Data Protection

Where the Customer is subject to India’s Digital Personal Data Protection Act, 2023 or applicable rules, WhizWiser will process Personal Data in accordance with the applicable contractual and legal requirements governing its role.

Where WhizWiser acts as a processor on behalf of the Customer, the Customer remains responsible for determining the purposes and lawful basis for processing unless otherwise required by law.

WhizWiser will implement reasonable safeguards appropriate to the processing and will cooperate with the Customer concerning applicable data-protection obligations.


21. Data Protection Assessments and Audits

Where required by Applicable Data Protection Law, WhizWiser will provide reasonable information necessary to demonstrate compliance with applicable processor obligations.

Subject to confidentiality, security, and protection of proprietary information, WhizWiser may provide:

  • Relevant security information;
  • Privacy documentation;
  • Applicable certifications or assessments, if available;
  • Responses to reasonable privacy questionnaires;
  • Other documentation reasonably necessary to assess WhizWiser’s compliance.

Any audit or assessment rights will be exercised in a manner that:

  • Does not compromise the security of other customers;
  • Does not expose confidential information belonging to other customers;
  • Does not require disclosure of trade secrets;
  • Does not materially disrupt WhizWiser’s operations.

Where an on-site audit is legally required, the parties will coordinate the scope, timing, confidentiality, and security requirements in advance.


22. Data Protection Officer and Privacy Contact

WhizWiser does not currently maintain a separately appointed statutory Data Protection Officer unless required by applicable law.

For privacy, data protection, DPA, security, or legal matters, contact:

legal@whizwiser.com


23. Deletion and Return of Customer Data

Upon termination of the Customer’s use of the Services, WhizWiser will delete or return Customer Data in accordance with the applicable Services, Customer instructions, and Applicable Data Protection Law.

Unless otherwise agreed:

  • Customer Data may be deleted from active systems following account termination or deletion;
  • Certain information may be retained where required by law;
  • Security logs may be retained for legitimate security purposes;
  • Backup copies may remain temporarily until overwritten according to applicable backup cycles;
  • Billing and transaction records may be retained as required by law;
  • Aggregated or de-identified information that no longer identifies an individual may be retained where permitted by law.

24. Customer Data Ownership

As between the parties, the Customer retains its rights in Customer Data.

Nothing in this DPA transfers ownership of Customer Data to WhizWiser.

WhizWiser receives only the rights necessary to process, store, transmit, reproduce, modify, and otherwise handle Customer Data to provide the Services and fulfill the purposes permitted under the Terms of Service and this DPA.


25. Confidentiality of Customer Data

WhizWiser will treat Customer Data as confidential information and will not disclose it except:

  • To authorized personnel;
  • To authorized Subprocessors;
  • To provide the Services;
  • At the Customer’s direction;
  • Where required by law;
  • To protect the security, rights, or property of WhizWiser, its customers, or third parties;
  • As otherwise permitted by this DPA or the Terms of Service.

26. Government and Legal Requests

If WhizWiser receives a legally binding request from a government authority for Customer Data, WhizWiser may disclose the information where legally required.

Where legally permitted and reasonably practicable, WhizWiser may notify the Customer before responding.

WhizWiser may challenge or narrow an unlawful or overbroad request where reasonably appropriate.


27. Security of Credentials and Integrations

Customers are responsible for protecting:

  • Account credentials;
  • API credentials;
  • Google authentication;
  • Third-party integration permissions;
  • Workspace access;
  • User invitations;
  • Other access mechanisms under the Customer’s control.

Customers should immediately notify WhizWiser if they believe credentials or access tokens have been compromised.


28. Agency and Client Data

Agencies may use WhizWiser to process information relating to their own clients.

The agency is responsible for:

  • Having authorization from its clients;
  • Providing appropriate privacy disclosures;
  • Ensuring lawful processing;
  • Configuring appropriate access permissions;
  • Ensuring that client information is not uploaded without appropriate authorization.

WhizWiser does not become the agency’s client’s direct controller merely because the agency uses WhizWiser to provide services to that client.


29. No Sale of Customer Data

WhizWiser does not sell Customer Data as a standalone data product or data-broker service.

Customer Data is not provided to third parties for independent commercialization except where permitted by Applicable Data Protection Law and the applicable contractual relationship.


30. Sensitive and Regulated Information

The Services are not designed as a general-purpose repository for highly sensitive or regulated information.

Unless expressly supported by a specific WhizWiser product or separately agreed in writing, Customers should not use the Services to process:

  • Government identification numbers;
  • Financial account credentials;
  • Health records;
  • Medical information;
  • Biometric identifiers;
  • Passwords;
  • Authentication secrets;
  • Highly sensitive personal information;
  • Other regulated information requiring specialized safeguards.

If the Customer needs to process such information, it should contact WhizWiser before doing so.


31. Security and Privacy Contact

All privacy and data-protection communications should be directed to:

legal@whizwiser.com

This includes:

  • DPA requests
  • Data-processing questions
  • Data-subject assistance
  • Privacy complaints
  • Security-related privacy concerns
  • Breach notifications
  • Regulatory correspondence
  • Contractual data-protection requests

32. Conflict With Other Agreements

If there is a conflict between this DPA and the Terms of Service concerning the processing of Personal Data, this DPA will control to the extent of that conflict.

If a mandatory requirement of Applicable Data Protection Law conflicts with either document, the mandatory legal requirement will prevail.


33. Changes to This DPA

WhizWiser may update this DPA when reasonably necessary to reflect:

  • Changes in Applicable Data Protection Law;
  • Changes to the Services;
  • Changes to subprocessors;
  • Changes to security practices;
  • Regulatory requirements;
  • Changes to data-processing activities.

Where required by law or contract, WhizWiser will provide appropriate notice of material changes.


34. Term and Termination

This DPA begins when the Customer accepts the Terms of Service or otherwise begins using the applicable Services.

It remains effective for as long as WhizWiser processes Customer Data on behalf of the Customer.

Sections concerning:

  • Confidentiality;
  • Security;
  • Data deletion;
  • Legal compliance;
  • Liability;
  • Dispute resolution;
  • Other provisions that by their nature should survive

will survive termination to the extent applicable.


35. Governing Law

Unless mandatory Applicable Data Protection Law requires otherwise, this DPA is governed by the laws of India.

Subject to mandatory rights and jurisdictional requirements applicable to the Customer, courts located in Sirohi, Rajasthan, India will have jurisdiction over disputes arising under this DPA.

Nothing in this section prevents a party from exercising rights or seeking remedies that cannot legally be excluded under Applicable Data Protection Law.


36. Contact Information

Consultwhiz Consultancy & E-Commerce Services
Sole Proprietorship registered in India

Business Address:
00, Rowara, Rowara Bus Stand
Rowara, Sirohi, Rajasthan 307028
India

Privacy & Legal Contact:
legal@whizwiser.com

Website:
whizwiser.com

Effective Date: September 5, 2026