Data Processing Addendum

Last updated: September 9, 2026

Template — not legal advice. This is a structured draft for the operator's convenience. It must be reviewed and adapted by qualified counsel before go-live. Do not rely on it as-is.

This Data Processing Addendum describes how the Operator processes personal data on behalf of Customers using PRAgency and the wider suite, and lists the subprocessors involved. Bracketed items are placeholders to be completed before go-live.

1. Parties and scope

This Data Processing Addendum (“DPA”) forms part of the agreement between you (the “Customer” and data controller) and [Operator Legal Entity, Inc.] (the “Operator” and data processor) for your use of the suite — PodOps and PRAgency, including PRAgency (the “Service”).

It applies where we process personal data on your behalf and supplements our Terms of Service and Privacy Policy. If there is a conflict on data-protection matters, this DPA controls.

2. Roles of the parties

The Customer is the controller (or processor acting for its own customers) and determines the purposes and means of processing. The Operator is the processor (or subprocessor) and processes personal data only on the Customer's documented instructions, including as set out in this DPA and by use of the Service.

3. Subject matter and nature of processing

We process personal data to provide, secure, support, and improve the Service — for example, hosting and storing the records you create, powering AI-assisted features you invoke, and sending transactional messages. Processing lasts for the term of your subscription plus any wind-down/retention period described below.

4. Categories of data and data subjects

Data subjects may include: the Customer's account users and team members; and the people the Customer records in the Service — for example, podcast guests, hosts, and contacts (PodOps); and represented talent, media contacts, and outreach recipients (PRAgency).

Categories of personal data may include: names, email addresses and contact details, professional/profile information, communications and pitch content, files, and usage/technical data. The Customer should not submit special categories of data unless expressly agreed.

5. Operator obligations

  • process personal data only on the Customer's documented instructions;
  • ensure personnel authorized to process data are bound by confidentiality;
  • implement appropriate technical and organizational security measures;
  • assist the Customer, taking into account the nature of processing, with data-subject requests and with security, breach-notification, and impact-assessment obligations;
  • make available information necessary to demonstrate compliance and allow for audits as described below;
  • delete or return personal data at the end of the engagement, subject to legal retention.

6. Subprocessors

The Customer authorizes the Operator to engage subprocessors to deliver the Service. We impose data-protection obligations on each subprocessor no less protective than those in this DPA, and we remain responsible for their performance. Current subprocessor categories:

SubprocessorPurposeLocation
[Hosting / infrastructure provider]Application hosting, storage, and compute[region]
[Email / notification relay]Transactional and account emails[region]
[AI / model provider]AI-assisted drafting features (on content you submit)[region]
[Payment processor] (future)Billing and payments once paid plans launch[region]
[Analytics / error monitoring]Usage analytics and reliability monitoring[region]

We will give the Customer reasonable notice of any intended addition or replacement of a subprocessor, giving the Customer an opportunity to object on reasonable data-protection grounds.

7. International transfers

Where processing involves transferring personal data across borders, the parties rely on an approved transfer mechanism — for example, the EU Standard Contractual Clauses and the UK Addendum, which are incorporated by reference where applicable. [Confirm the modules and mechanism with counsel.]

8. Security measures

The Operator maintains technical and organizational measures appropriate to the risk, including encryption in transit, access controls and least-privilege, logging and monitoring, and regular review. A detailed description of measures is available on request. [Attach or link the security-measures schedule before go-live.]

9. Personal data breaches

The Operator will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's data, and will provide information reasonably needed for the Customer to meet its own notification obligations.

10. Assistance with data-subject requests

Taking into account the nature of processing, the Operator will assist the Customer in responding to requests from data subjects to exercise their rights (access, portability, correction, deletion, restriction, and objection). Individuals can also use the export and deletion paths described in our Privacy Policy.

11. Audits

The Operator will make available information necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Customer or an appointed auditor, subject to reasonable notice, confidentiality, and frequency limits. Where available, third-party certifications or reports may be provided to satisfy audit requests.

12. Return and deletion of data

On termination or expiry of the Service, and at the Customer's choice, the Operator will delete or return the personal data and delete existing copies, unless retention is required by law. Backups are purged on a rolling schedule.

13. Liability and precedence

Each party's liability under this DPA is subject to the limitations in the Terms of Service. This DPA does not create rights beyond those required by applicable data-protection law.

14. Contact

To request a signed copy of this DPA or discuss data-protection matters, reach out through our contact page or email [privacy@your-domain.com].