Data Processing Addendum
The terms on which SEMRS processes personal data on a client's behalf. Forms part of the Terms & Conditions.
Last reviewed: 7 September 2026
1. Roles
For personal data belonging to a client's own customers and leads, the client is the controller and SEMRS is the processor. SEMRS acts only on the client's documented instructions — the signed order, plus anything later agreed in writing.
2. What is processed
Lead records submitted through the client's own capture points — typically a name, phone number, email, and whatever else that form asked for — plus aggregate analytics and campaign data from platforms the client has connected. SEMRS collects only what the client's own form or call-to-action asked for, never more.
3. Purpose limitation
Data is used solely to deliver the ordered services for that client. It is never sold, never shared with another client, never used to enrich SEMRS's own marketing, and never used to train a general-purpose model.
4. Security
Access tokens are encrypted at rest with AES-256-GCM, access is scoped per client, sessions are signed and validated server-side, and inbound webhooks are signature-checked before their payload is trusted. Full detail, including current gaps, is on the Security page.
5. Sub-processors
SEMRS uses the third parties listed on the Sub-processors page. Clients are informed before a new sub-processor handling personal data is engaged, and may object.
6. Data subject rights
Where one of the client's data subjects exercises a right — access, correction, deletion, objection — the client remains responsible for responding. SEMRS will assist, and can locate, export or delete that person's records on the client's written instruction.
7. Retention and deletion
Briefs, drafts, approval records, message logs and lead records are kept for the life of the engagement plus twelve months, then archived or deleted on request. Leads that never converted are covered by the same rule. A client may request deletion earlier, subject to anything SEMRS must retain for tax or legal reasons.
8. Breach notification
If SEMRS becomes aware of a personal data breach affecting a client's data, that client is notified without undue delay — what is known, what is affected, and what is being done about it.
9. Automated decisions
Lead scoring assigns HOT, WARM or COLD from data the lead themselves submitted. It informs the client's own follow-up priority; it produces no legal or similarly significant effect on the individual, and no automated system contacts, negotiates with, or contracts with a lead. That is an architectural boundary in this system, not a configurable setting.
10. Audit
On reasonable notice, SEMRS will provide the information needed to demonstrate compliance with this addendum.
11. Precedence
Where this addendum and the Terms & Conditions conflict on the handling of personal data, this addendum prevails.
This page describes how SEMRS actually operates. It is written to match this system's documented practices rather than generic boilerplate, but it is not legal advice, and a qualified review is recommended before relying on it in a dispute.

