Data processing & AVV/DPA
Every integration that moves data through Lokrix is governed by our data-processing terms. If you operate in the EU you generally need an Auftragsverarbeitungsvertrag (AVV) — the German term for a GDPR data processing agreement (DPA). This page explains what data flows where and how to put that agreement in place.
This is documentation for engineers and administrators, not legal advice. For a binding assessment of your obligations, involve your own data-protection counsel.
What Lokrix processes
The core of what Lokrix handles is public web data and derived metrics: the URLs you track, the prompt universe generated for them, the answers returned by the engines, and the scores and recommendations computed from those answers. Account data (workspace members, billing) and any analytics you connect are processed to run the service.
- Property & scan data — tracked URLs, prompts, engine answers, citations and scores, stored tenant-scoped to your workspace.
- Connected analytics — read-only GSC / GA4 reporting data if you connect Google.
- Account & usage — members, roles, and credit metering needed to operate and bill the service.
Sub-processors
To run live scans, Lokrix sends prompts to third-party answer-engine providers (such as OpenAI, Anthropic, Google, Perplexity and xAI) and, when configured, to a search provider (Serper or SerpAPI) used to observe Google's AI surfaces. These providers act as sub-processors. An up-to-date list of sub-processors is maintained and referenced from the DPA so you can assess the chain and where data is processed.
Requesting the AVV / DPA
EU customers can request the data processing agreement before or after signing up. The AVV names Lokrix as processor, lists the sub-processors above, and sets out the technical and organisational measures we apply. Reach out through your workspace's billing or support contact to receive and countersign it. Keep the executed agreement with your records of processing activities.
Retention and controls
Data is scoped to your workspace and no tenant's data is exposed to another. You can disconnect analytics integrations to revoke their tokens, and deleting a property removes its scan history. For questions about specific retention windows or export, contact support through your workspace.