1. Definitions
Terms such as "personal data", "processing", "controller", "processor", "data subject", and "supervisory authority" have the meanings given in applicable data protection law, including the GDPR where relevant. "Customer Data" means data you provide to the Services.
2. Roles and scope
This DPA applies only to the Managed Cloud (coming soon), where you are the controller (or processor) of Customer Data and we process it as your processor (or subprocessor) solely to provide the Services. In on-premise and private cloud deployments we do not process Customer Data and are therefore not a processor of it. The subject matter, duration, nature, and purpose of processing, and the types of personal data and categories of data subjects, are described in Annex I.
3. Processing instructions
We process personal data only on your documented instructions, including with regard to transfers, unless required by law. Your use and configuration of the Services constitute your instructions. We do not use Customer Data to train publicly available AI models. We will inform you if, in our opinion, an instruction infringes applicable law.
4. Confidentiality
We ensure that personnel authorized to process personal data are bound by appropriate confidentiality obligations and process personal data only as necessary to provide the Services.
5. Security measures
We implement appropriate technical and organizational measures to protect personal data, as summarized in Annex II and on our Security page, including encryption in transit and at rest, access controls, workspace isolation, and audit logging.
6. Subprocessors
You authorize us to engage subprocessors to provide the Services (for example, hosting and infrastructure providers, and any AI model providers you enable). We impose data protection obligations on subprocessors that are no less protective than those in this DPA and remain responsible for their performance. A current list of subprocessors is available on request, and we will give notice of intended changes so you may object on reasonable grounds.
7. Data subject rights
Taking into account the nature of the processing, we assist you with appropriate technical and organizational measures, insofar as possible, to respond to requests from data subjects exercising their rights. Where a data subject contacts us directly, we will refer them to you.
8. Personal data breach
We notify you without undue delay after becoming aware of a personal data breach affecting Customer Data, and provide information reasonably available to us to help you meet your notification obligations.
9. International transfers
Where processing involves the transfer of personal data across borders, we implement an appropriate transfer mechanism, such as the Standard Contractual Clauses, which are incorporated by reference where applicable.
10. Audits
We make available information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, subject to reasonable confidentiality and security safeguards and frequency limits.
11. Return and deletion
Upon termination of the Services, we will, at your choice, delete or return Customer Data and delete existing copies unless retention is required by law. Deletion is completed within a commercially reasonable period.
12. Annexes
Annex I — Details of processing
| Subject matter | Provision of the Promptly AI platform and related support. |
|---|---|
| Duration | For the term of the agreement plus any legally required retention period. |
| Nature and purpose | Hosting, indexing, retrieval, agent execution, and support in order to provide the Services. |
| Categories of data subjects | Your personnel and any individuals referenced in Customer Data you upload. |
| Types of personal data | Account and contact details, and any personal data contained in content you provide. |
Annex II — Security measures
Encryption in transit and at rest; role-based access control; single sign-on and multi-factor authentication; per-workspace isolation; tamper-evident audit logging; data-loss-prevention guardrails; and policy and risk engines. See our Security page for details.
Annex III — Subprocessors
A current list of subprocessors, including hosting/infrastructure providers and any AI model providers you enable, is available on request from info@promptly-ai.co.
13. Contact
Questions about this DPA or to request our subprocessor list? Contact info@promptly-ai.co.