Help / Security & compliance / Compliance for agencies
Compliance for agencies
For admins & DPOs · ~6 min read · Last reviewed 22 July 2026
As an agency you are the controller for the data you process about your clients; SeoKestrel processes it on your behalf under the Data Processing Agreement. This page walks through the tooling that backs that arrangement day to day: handling data-subject requests, consent records, the security-incident register, and the audit log. Where a claim is contractual, this page links to the governing document rather than restating it.
Data-subject requests
There are two paths, matching the two kinds of request:
- Self-service (access and erasure) — every user handles their own under Settings → Privacy: a full personal-data export delivered as a downloadable archive via an expiring link, and account deletion with a 30-day grace period during which the user can sign back in and cancel. Both are processed automatically.
- The admin register (manual review) — under Settings → DSARs (admin-only), you log and track the request types that need human judgement: rectification (Art. 16), restriction (Art. 18), and objection (Art. 21). Each entry records the user, type, request date, and notes, and moves through pending → processing → completed or rejected.
When a data subject contacts your agency rather than the platform, log the request in the register so the response has a dated trail. Timelines and scope are defined in the Privacy Policy.
Consent records
Settings → Privacy shows each user’s current consent state — analytics cookies, marketing cookies, marketing emails — as toggles, above the full consent history: every grant and withdrawal with the policy version it applied to and when it was recorded. Consent changes are captured with technical context and written to the audit log, so “when did this user consent, and to which version?” has a lookupable answer.
The security-incident register
- Settings → Incidents (admin-only) tracks security incidents through their lifecycle — detection and containment are timestamped — in line with our NIS2 obligations; significant incidents are reported to the national authority within 24 hours.
- For each incident the register can render pre-filled notification drafts — one for the authority, one for affected users — so the deadline hours are spent verifying facts, not drafting from scratch.
- Incidents cannot be deleted. Every update to an incident is recorded in the audit log.
The audit log
- Settings → Audit log (admin-only) records administrative and privacy-relevant actions: who acted (user and email), what they did, on which resource, when, from which IP address and browser, and at what severity.
- It is filterable by actor, action, resource type, severity, and date range, newest first.
- The log is append-only: there is no interface for editing or deleting entries. Aged, complete months are archived to backed-up storage on the platform side and retained long-term.
The governing documents
- Data Processing Agreement — the controller–processor terms for agencies.
- Sub-processors — the public register of who else touches the data, and where they are.
- Privacy Policy — what personal data is processed, why, and for how long.
- Terms of Service and Cookie Policy — the rest of the set.
FAQ
- Can I export the audit log?
- There is no export button today. The viewer supports filtering by actor, action, resource, severity, and date range, with pagination. Completed months are additionally archived on the platform side and retained long-term.
- Does the DSAR register show statutory deadlines?
- No. It records the request, its type, and its status; tracking the response deadline against your own obligations remains your process. The register gives you the dated evidence trail to do that.
- Who logs entries in the incident register?
- Admins. The register is admin-only, incidents cannot be deleted once logged, and every change to an incident is itself recorded in the audit log.
- Where do I send a client’s security questionnaire?
- Start with Security & privacy and the five linked documents there — they answer most questionnaires. The documents, not the summaries, are authoritative.