WGM
← HomeRUEN

Data Processing Addendum (DPA) — WGM Service

Version dated June 25, 2026

PrivacyTermsCookieDPA

This Data Processing Addendum (the "DPA") forms an integral part of the agreement (the Terms of Use, the "Main Agreement") under which the service operator provides access to the multi-tenant SaaS platform WGM (Website Growth Manager) hosted at https://wgm.49port.ru. This DPA governs the processing of data that the Customer connects or uploads in respect of the Customer's own website and its official analytics and with respect to which WGM acts as a processor on the Customer's behalf. The processing of the Customer's own account and user data (name, email, organisation, projects, activity logs, IP, cookies), with respect to which WGM acts as an independent controller, is governed by the service's Privacy Policy and is not covered by this DPA. With respect to the data covered by this DPA, the Customer acts as the controller (the party determining the purposes and means of processing) and WGM acts as the processor (the party processing data on the Customer's behalf). This DPA is prepared in accordance with Article 28 of Regulation (EU) 2016/679 (GDPR) and Federal Law No. 152-FZ of 27 July 2006 "On Personal Data". Effective date: June 25, 2026. This English version is provided for convenience; in the event of any discrepancy, the Russian text prevails.

1. Parties and Definitions

The parties to this DPA are the Customer (a website owner or agency using the service) and the operator of the WGM service.

Service operator/owner: Individual Entrepreneur Marina Vladimirovna Sleptsova; INN 561407059668; OGRNIP 323508100225874; address: Vidnoe, Moscow Region, Russia; contact email: ya@49port.ru. In this DPA, the service operator, in its role as processor acting on the Customer's behalf, is referred to as "WGM" or the "Processor".

Terms used in this DPA have the meaning given to them by applicable data protection law, in particular:

  • "Personal Data" means any information relating to a directly or indirectly identified or identifiable natural person (data subject) processed in the course of providing the services.
  • "Controller" (operator under 152-FZ) means the Customer, who determines the purposes and means of processing the data connected or uploaded in respect of its website and analytics.
  • "Processor" (person processing on instruction under 152-FZ) means WGM, processing such data solely on the Customer's documented instructions.
  • "Data Subject" means a natural person to whom the personal data relates.
  • "Processing" means any operation or set of operations performed on data (collection, storage, use, transfer, erasure, etc.).
  • "Sub-processor" means a third party engaged by the Processor to carry out specific processing activities on the Customer's behalf.
  • "Personal Data Breach" means a breach leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, data.
  • "Applicable Data Protection Law" means the GDPR, Federal Law No. 152-FZ, and other applicable regulations.

2. Subject Matter, Nature and Purpose of Processing

WGM processes data connected or uploaded by the Customer about the Customer's own website and its analytics solely for the purpose of providing the service in accordance with the Main Agreement and the Customer's documented instructions. The Customer's connection of a project (website) and analytics, and the Customer's initiation of the relevant service functions, are treated as the Customer's documented instructions regarding the processing.

The nature and purpose of processing include:

  • technical and SEO audit of the Customer's website, including crawling pages and analysing their content;
  • semantic clustering and rank tracking;
  • connecting the Customer's official analytics via the OAuth protocol (Google Search Console, Google Analytics 4, Yandex.Webmaster, Yandex.Metrica) and retrieving the corresponding metrics;
  • generating AI recommendations;
  • securely applying changes to the Customer's website (write-back, e.g. title and meta description) — only after the Customer's explicit approval, which is treated as the Customer's instruction for the relevant operation;
  • optionally, assessing brand visibility in AI assistants (GEO).

The service does not take decisions in respect of data subjects based solely on automated processing that produce legal or similarly significant effects (Article 22 GDPR): recommendations are informational, and any write-back to the website is performed only after the Customer's explicit approval. Recommender technologies are operated in accordance with Article 10.2-2 of Federal Law No. 149-FZ.

Processing takes place for the term of the Main Agreement and for the period necessary to return or delete data upon its termination. WGM does not use the Customer's data for its own purposes and makes no guarantee of traffic or ranking growth.

3. Categories of Data Subjects and Data

Processing on the Customer's behalf may concern the following categories of data subjects: visitors and users of the Customer's website, representatives of the Customer, and other individuals whose data may be contained in the connected analytics or in the content of the Customer's website pages.

The Customer, as controller, is responsible for the legal basis for processing third-party data (in particular visitors to the Customer's website), for informing them and for obtaining any required consents; WGM processes such data solely on the Customer's instructions.

Categories of data processed:

  • URLs and content of the Customer's website pages obtained through crawling;
  • metrics from Google Search Console, Google Analytics 4, Yandex.Webmaster and Yandex.Metrica;
  • OAuth access/refresh tokens for accessing the Customer's analytics (stored in encrypted form);
  • audit results and generated recommendations.

Special categories of personal data are not intended to be processed; the Customer undertakes not to submit such data to the service without separate written agreement.

4. Obligations of the Processor

WGM, as Processor, undertakes to:

  1. process data only on the Customer's documented instructions, including with regard to international transfers, except where processing is required by applicable law (including Union or Member State law to which the Processor is subject); in the latter case WGM informs the Customer before such processing, unless prohibited by law;
  2. ensure that persons authorised to process data have committed to confidentiality or are under an appropriate statutory obligation;
  3. implement technical and organisational security measures in accordance with Article 32 of the GDPR and the requirements of 152-FZ (see the "Security Measures" section);
  4. comply with the requirements of Part 5 of Article 18 (localisation) and Article 19 of Federal Law No. 152-FZ, including the measures under Part 2 of Article 19, ensuring the confidentiality and security of personal data processed on the Customer's behalf;
  5. taking into account the nature of processing, provide reasonable assistance to the Customer by appropriate technical and organisational measures in fulfilling data subject rights (access, rectification, erasure, restriction, portability, objection, withdrawal of consent and other applicable rights), and promptly forward to the Customer any data subject requests received directly by WGM without responding to them itself, unless otherwise agreed with the Customer; the Customer, as controller, ensures the lawful basis for processing and the information of and consent from data subjects (including the Customer's website visitors) where required, and WGM, as processor, does not obtain data subject consent;
  6. taking into account the nature of processing and the information available to WGM, assist the Customer in ensuring compliance with obligations relating to security, breach notification, data protection impact assessments (DPIA) and prior consultation with supervisory authorities;
  7. promptly inform the Customer if, in WGM's opinion, an instruction infringes applicable data protection law;
  8. maintain records of processing activities carried out on the Customer's behalf to the extent required by law.

5. Security Measures

WGM applies, taking into account the state of the art, the nature, scope and purposes of processing and the risks to the rights of data subjects, technical and organisational data protection measures appropriate to the risk, including:

  • encryption of secrets and OAuth tokens;
  • role-based access control (RBAC);
  • logging of activity and access;
  • regular backups;
  • isolation of tenant data (multi-tenant isolation);
  • regular testing and evaluation of the effectiveness of the measures;
  • control and periodic review of the measures in place taking into account the state of the art and the nature of the risks.

6. Sub-processors

The Customer grants WGM general authorisation to engage sub-processors necessary to provide the services. This general authorisation constitutes the Customer's (controller's) consent to the engagement of third parties for processing within the meaning of Part 3 of Article 6 of Federal Law No. 152-FZ. The list of sub-processors is maintained in a sub-processor register and may be updated. The Customer is notified at least 30 days before a new sub-processor begins processing and may, within that period, raise reasonable objections. If an objection cannot be resolved, the Customer may suspend use of the relevant function or terminate the Main Agreement to the extent affected by such change.

Categories of sub-processors and recipients engaged (on the Customer's behalf or to provide the service):

  • Google (Google Search Console, Google Analytics 4);
  • Yandex (Yandex.Webmaster, Yandex.Metrica and related services);
  • LLM providers accessed via a proxy gateway (for generating recommendations and GEO);
  • payment providers (for processing the subscription);
  • an email delivery service;
  • an error monitoring service;
  • hosting and object storage (located in the Russian Federation).
  • The specific names of sub-processors are recorded in the sub-processor register.

WGM enters into an agreement with each sub-processor imposing, in writing, the same data protection obligations as set out in this DPA, in particular sufficient guarantees to implement appropriate technical and organisational measures, and remains liable to the Customer for the sub-processors' performance of their obligations to the same extent as for its own acts.

7. International Data Transfers

Where personal data subject to the GDPR is transferred outside the European Economic Area, such transfer takes place only where appropriate safeguards under the GDPR are in place, in particular on the basis of the Standard Contractual Clauses (SCC) approved by the European Commission, or another applicable legal mechanism.

Where necessary, the parties enter into the relevant SCC, which in that case prevail in respect of the regulation of the international transfer.

Cross-border transfers of the personal data of citizens of the Russian Federation are carried out in accordance with Article 12 of Federal Law No. 152-FZ — to the territory of states that ensure adequate protection of the rights of data subjects, or where another legal basis provided by law exists (including, where applicable, the data subject's consent); localisation of the primary processing in the Russian Federation is ensured in accordance with the localisation section. The Customer, as controller, is responsible for the basis of such transfers in respect of data processed on its behalf, and WGM provides reasonable assistance.

8. Personal Data Breach Notification

WGM notifies the Customer of any personal data breach of which it becomes aware affecting data processed on the Customer's behalf, without undue delay and, as a rule, no later than 72 hours after WGM becomes aware of such breach.

The notification contains, to the extent possible: a description of the nature of the breach, the categories and approximate number of affected data subjects and records, the likely consequences, and the measures taken or proposed to address the breach and mitigate its adverse effects. WGM provides the Customer with reasonable assistance in fulfilling its own obligations to notify supervisory authorities and data subjects. The provision of such notification does not in itself constitute an admission by WGM of fault or liability in respect of the breach.

9. Audits and Inspections

WGM makes available to the Customer the information reasonably necessary to demonstrate compliance with the obligations under this DPA and allows for and contributes to audits, including inspections, conducted by the Customer or an independent auditor mandated by the Customer.

Audits are carried out on reasonable prior notice, during business hours, no more than once a year (except in the event of a personal data breach or a supervisory authority requirement), without unduly disrupting WGM's operations and while preserving the confidentiality and security of other customers' data.

To demonstrate compliance, WGM may provide the Customer with independent audit reports and/or available certifications; an on-site inspection is carried out where these are insufficient. The costs of an audit initiated by the Customer are borne by the Customer, except where the audit reveals a material breach by WGM.

10. Return and Deletion of Data on Termination

At the Customer's choice, after the provision of services ends, WGM returns the processed data to the Customer or deletes it, and deletes existing copies, within 30 days after the provision of services ends, unless the Customer specifies another reasonable period, and unless retention of the data is required by applicable law. In the latter case, WGM continues to ensure the confidentiality of such data and does not process it for any other purpose.

At the Customer's request, WGM confirms the return and deletion of the data.

11. Data Localisation for the Russian Federation

With respect to the personal data of citizens of the Russian Federation, WGM ensures that the recording, systematisation, accumulation, storage, updating (modification) and retrieval of such data are carried out using databases located within the territory of the Russian Federation, in accordance with Part 5 of Article 18 of Federal Law No. 152-FZ. The hosting and object storage used for these purposes are located within the Russian Federation.

12. Liability

The allocation and limits of the parties' liability in connection with the processing of personal data under this DPA are determined by the Main Agreement. The limitation-of-liability provisions of the Main Agreement apply to this DPA to the extent permitted by applicable data protection law.

In accordance with Part 5 of Article 6 of Federal Law No. 152-FZ, the Customer (operator) is liable to the data subject for WGM's actions as processor. WGM is liable to the Customer for compliance with this DPA and the requirements of data protection law. This provision applies regardless of the limitations of liability provided for in the Main Agreement, to the extent that their application is not permitted by law.

13. Term

This DPA takes effect on June 25, 2026 and remains in force for the term of the Main Agreement and for as long as WGM processes data on the Customer's behalf. Provisions that by their nature should survive termination of this DPA (in particular, those on confidentiality, return and deletion of data, and liability) continue to apply after its termination.

14. Order of Precedence

In the event of a conflict between this DPA and the Terms of Use (Main Agreement) regarding the processing of personal data on the Customer's behalf, the provisions of this DPA prevail. With respect to international transfers, any SCC entered into by the parties prevail.