Data Processing Addendum
Last updated: 10 August 2026
This Data Processing Addendum applies between Neyli (Soulcore Ltd, a company registered in England and Wales (No. 14143714), Flat 1, 132 Haverstock Hill, London NW3 2AY, United Kingdom, registered with the UK Information Commissioner's Office under number ZB497063, the “Processor”) and the customer workspace owner (the “Controller”). It is incorporated by reference into the Terms of Service for customers whose use is subject to GDPR/UK GDPR.
1. Subject matter and duration
Processing of workspace content and member account data, for the duration of the customer's use of Neyli plus the deletion window in the Privacy Policy.
2. Nature and purpose
Hosting, storage, backup, display, messaging/notification delivery and AI-assisted processing of workspace content, solely to provide the Service.
3. Categories of data and data subjects
Workspace members (names, emails, roles) and any personal data the Controller's team places in projects, tasks, notes, messages and files.
4. Controller instructions
We process only on the Controller's documented instructions — using the Service's features is the instruction — unless law requires otherwise.
5. Confidentiality and security
Encryption in transit and at rest, per-workspace row-level isolation enforced in the database, role-based access, revocable server keys, weekly offsite backups, and error/rate-limit shielding at the API edge. Persons authorized to process data are bound to confidentiality.
6. Subprocessors
The Controller authorizes the subprocessors listed in the Privacy Policy. We will give 30 days' notice before adding or replacing one; the Controller may object on reasonable data-protection grounds.
7. International transfers
Where data leaves the EEA/UK, transfers rely on adequacy decisions or the EU Standard Contractual Clauses (Module 2).
8. Assistance, breaches, audits
We assist the Controller with data-subject requests and security-incident obligations, notify the Controller without undue delay after becoming aware of a personal-data breach, and make available information reasonably necessary to demonstrate compliance.
9. Deletion and return
On termination, workspace content is deleted per the retention terms in the Privacy Policy; the Controller can export data at any time from within the app before deletion.
10. Supervisory authority and complaints
Our supervisory authority as Processor is the UK Information Commissioner's Office (ICO), where Soulcore Ltd is registered under number ZB497063. We cooperate with the ICO, and with the Controller's own supervisory authority, on request in relation to the processing covered by this Addendum.
Data subjects should raise complaints with the Controller in the first instance, since the Controller decides how their data is used. Anyone may nonetheless complain to a supervisory authority at any time — in the UK, the ICO:
- Online: ico.org.uk/make-a-complaint
- Helpline: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom
In the EEA, the competent authority is the one where the data subject lives or works, or where the Controller is established. Complaints about our processing can also be sent to hello@neyli.app and are handled under the Privacy Policy.