Promptly AI Logo Promptly AI Back to site
Home

Data Processing Addendum

Last updated: July 26, 2026

When this DPA applies

Promptly AI is delivered today as on-premise and private cloud deployments, with a multi-tenant Managed Cloud Coming soon.

  • On-Premise & Private Cloud Available now: The platform runs entirely within your environment and Promptly AI does not process your Customer Data. In this model we are not a processor of Customer Data, and this DPA does not apply to that data—you remain both controller and processor.
  • Managed Cloud Coming soon: When you use the managed, Promptly-hosted service, we process Customer Data as your processor and this DPA applies in full.

In all cases we never use Customer Data to train publicly available AI models.

This Data Processing Addendum ("DPA") forms part of the agreement between the customer ("Controller", "you") and Promptly AI ("Processor", "we") and governs the processing of personal data that we carry out on your behalf when you use the Managed Cloud. Where you act as a processor for a third party, we act as your subprocessor. It does not apply to on-premise or private cloud deployments, where we do not access or process your Customer Data.

Contents 1. Definitions 2. Roles and scope 3. Processing instructions 4. Confidentiality 5. Security measures 6. Subprocessors 7. Data subject rights 8. Personal data breach 9. International transfers 10. Audits 11. Return and deletion 12. Annexes 13. Contact

1. Definitions

Terms such as "personal data", "processing", "controller", "processor", "data subject", and "supervisory authority" have the meanings given in applicable data protection law, including the GDPR where relevant. "Customer Data" means data you provide to the Services.

2. Roles and scope

This DPA applies only to the Managed Cloud (coming soon), where you are the controller (or processor) of Customer Data and we process it as your processor (or subprocessor) solely to provide the Services. In on-premise and private cloud deployments we do not process Customer Data and are therefore not a processor of it. The subject matter, duration, nature, and purpose of processing, and the types of personal data and categories of data subjects, are described in Annex I.

3. Processing instructions

We process personal data only on your documented instructions, including with regard to transfers, unless required by law. Your use and configuration of the Services constitute your instructions. We do not use Customer Data to train publicly available AI models. We will inform you if, in our opinion, an instruction infringes applicable law.

4. Confidentiality

We ensure that personnel authorized to process personal data are bound by appropriate confidentiality obligations and process personal data only as necessary to provide the Services.

5. Security measures

We implement appropriate technical and organizational measures to protect personal data, as summarized in Annex II and on our Security page, including encryption in transit and at rest, access controls, workspace isolation, and audit logging.

6. Subprocessors

You authorize us to engage subprocessors to provide the Services (for example, hosting and infrastructure providers, and any AI model providers you enable). We impose data protection obligations on subprocessors that are no less protective than those in this DPA and remain responsible for their performance. A current list of subprocessors is available on request, and we will give notice of intended changes so you may object on reasonable grounds.

7. Data subject rights

Taking into account the nature of the processing, we assist you with appropriate technical and organizational measures, insofar as possible, to respond to requests from data subjects exercising their rights. Where a data subject contacts us directly, we will refer them to you.

8. Personal data breach

We notify you without undue delay after becoming aware of a personal data breach affecting Customer Data, and provide information reasonably available to us to help you meet your notification obligations.

9. International transfers

Where processing involves the transfer of personal data across borders, we implement an appropriate transfer mechanism, such as the Standard Contractual Clauses, which are incorporated by reference where applicable.

10. Audits

We make available information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, subject to reasonable confidentiality and security safeguards and frequency limits.

11. Return and deletion

Upon termination of the Services, we will, at your choice, delete or return Customer Data and delete existing copies unless retention is required by law. Deletion is completed within a commercially reasonable period.

12. Annexes

Annex I — Details of processing

Subject matter Provision of the Promptly AI platform and related support.
Duration For the term of the agreement plus any legally required retention period.
Nature and purpose Hosting, indexing, retrieval, agent execution, and support in order to provide the Services.
Categories of data subjects Your personnel and any individuals referenced in Customer Data you upload.
Types of personal data Account and contact details, and any personal data contained in content you provide.

Annex II — Security measures

Encryption in transit and at rest; role-based access control; single sign-on and multi-factor authentication; per-workspace isolation; tamper-evident audit logging; data-loss-prevention guardrails; and policy and risk engines. See our Security page for details.

Annex III — Subprocessors

A current list of subprocessors, including hosting/infrastructure providers and any AI model providers you enable, is available on request from info@promptly-ai.co.

13. Contact

Questions about this DPA or to request our subprocessor list? Contact info@promptly-ai.co.

Promptly AI Logo Promptly AI
Privacy Policy Terms of Service Security DPA Home
© 2026 Promptly AI · All rights reserved.
Enterprise-grade security · SOC 2 Type II in progress