Data Processing Addendum
This Addendum applies when you use bklink as a business and, in doing so, submit personal data that you control. It forms part of the Terms of Service and takes effect automatically — you do not need to sign anything. Where this Addendum and the Terms conflict on data protection, this Addendum wins.
Who is who
The roles differ by data type, and conflating them is the mistake this section exists to prevent.
- Your account data — your name, email, billing records, sign-in history. We are thecontroller. We decide what to collect and why, and the Privacy Policy governs it.
- Data you submit for audit — backlink lists, URLs, uploaded documents and campaign data. You are the controller and we are your processor. We act on your instructions and do not decide what goes in.
- Data we obtain about domains from our own vendors — domain metrics, ratings, reach estimates. We are an independent controller of that data. It is about domains, not about you, and we obtain it whether or not you asked.
Scope of processing
| Subject matter | Backlink auditing and valuation |
| Duration | For as long as your account exists, plus the retention periods in the Privacy Policy |
| Nature and purpose | Storing, fetching, analysing and reporting on the URLs and documents you submit |
| Types of personal data | Whatever your submitted lists and documents happen to contain. Typically URLs and publication names; potentially author names, contact details or other personal data embedded in the material you upload |
| Categories of data subject | Your own staff and clients, and individuals named in the material you submit |
We do not need special-category data and ask you not to submit it. Nothing in the product requires health, biometric, political, religious or similar data, and uploading it is outside the scope of this Addendum.
Our obligations
- We process your data only on your documented instructions. Using the product is an instruction; so is a written request to us.
- We will tell you if an instruction appears to breach data protection law, rather than silently complying.
- Everyone with access is bound by confidentiality.
- We maintain appropriate technical and organisational measures — described on the Security page.
- We assist you, so far as we reasonably can, with data subject requests, impact assessments and regulator consultations.
- We will not sell your data or use it to train models for other customers.
We may use aggregated data derived from your use — information that has been aggregated or de-identified so that it cannot reasonably be used to identify you, any individual, or your confidential business information — to operate and improve the service. This never includes your backlink lists, documents or campaign data in identifiable form.
Subprocessors
You give general authorisation for us to engage subprocessors. The current list, with purpose and location, is at /legal/subprocessors. We impose data protection obligations on each of them no less protective than those in this Addendum, and we remain liable to you for their performance.
We update that page before a new subprocessor begins handling customer data. If you object on reasonable, documented data-protection grounds, we will discuss commercially reasonable alternatives with you. If we cannot resolve the objection, then either we stop processing your affected personal data through that subprocessor, or you may terminate the affected part of the service and we refund, pro rata, any prepaid unused fees attributable to it.
International transfers
We are established in the United States, and several of our subprocessors are too. Where personal data originating in the United Kingdom, the European Economic Area or Switzerland is transferred outside it, the transfer relies on the Standard Contractual Clauses approved by the European Commission (Module 2, controller to processor, where we act as your processor; Module 1 where we act as an independent controller), together with the UK International Data Transfer Addendum for UK data and the equivalent Swiss provisions.
Location by provider is listed on the subprocessors page. Notably, our error monitoring is hosted in the European Union, so error data does not leave the EEA. Where a provider is certified under the EU–US Data Privacy Framework, we rely on that certification in addition to the Clauses.
Security incidents
We will notify you without undue delay after becoming aware of a personal data breach affecting personal data we process on your behalf. Where reasonably practicable, we will notify you within 48 hours of becoming aware of it.
The distinction is deliberate rather than evasive. The binding obligation is the statutory one — without undue delay. The 48 hours is the target we run to, and we would rather state it as a target we mean than as a warranty we could breach by an hour on a contained incident that harmed nobody. We do not operate a 24/7 on-call rotation and will not write one into a contract.
The notice will describe the nature of the breach, the categories and approximate volume of data involved, the likely consequences, and the measures we have taken. Where we cannot provide all of that at once, we will provide it in phases as it becomes available.
Data subject requests
If someone contacts us directly about data you control, we will not respond substantively. We will tell them to contact you and let you know it happened, unless the law prevents us. You can export and delete your data from within the product; where you need our help to satisfy a request, email us.
Audits
On reasonable written notice, and normally no more than once a year, we will provide the information reasonably necessary to demonstrate compliance with this Addendum. What that means in practice:
- Any customer — we will complete a security questionnaire.
- Enterprise customers — we will additionally provide a security and architecture overview, our data flows, the subprocessor list, our incident-response procedure, relevant internal policies, and any penetration-test summary or independent security report we hold at the time.
We do not hold a SOC 2 or ISO 27001 report and will not imply otherwise. If your procurement process requires one, tell us before you buy rather than after.
An on-site audit is available where:
- applicable law or a regulator requires it;
- it is reasonably necessary following a material security incident affecting your data; or
- we have agreed to it in a separate written agreement.
Any such audit is on reasonable notice, of reasonable scope, during business hours, subject to confidentiality, must not access any other customer's data, and is at your reasonable cost.
Deletion and return
You can delete your data at any time from within the product. When your account is closed, we delete customer data on the schedule in the Privacy Policy. Encrypted backups roll off within 30 days and are not selectively edited — we do not restore deleted data from backup on request, which is the same rule that protects it from being resurrected by a restore.
Liability
Each party's liability under this Addendum is subject to the limitations and exclusions in theTerms of Service, except where applicable data protection law does not permit those limits to apply.
Questions
Email support@bklink.uk. If you require a countersigned copy of this Addendum for your records, ask and we will provide one.
bklink is operated by Immortal Reality PA LLC, 6375 Penn Ave Ste B, Pittsburgh, Pennsylvania 15206, United States. Questions about this page: support@bklink.uk.