Data Processing Addendum

Stub — last updated: [TODO: date at launch]

Status: this is a template outline of the DPA that will apply between Neyli ([TODO: legal entity], the “Processor”) and the customer workspace owner (the “Controller”). It is incorporated by reference into the Terms of Service for customers whose use is subject to GDPR/UK GDPR.

1. Subject matter and duration

Processing of workspace content and member account data, for the duration of the customer's use of Neyli plus the deletion window in the Privacy Policy.

2. Nature and purpose

Hosting, storage, backup, display, messaging/notification delivery and AI-assisted processing of workspace content, solely to provide the Service.

3. Categories of data and data subjects

Workspace members (names, emails, roles) and any personal data the Controller's team places in projects, tasks, notes, messages and files.

4. Controller instructions

We process only on the Controller's documented instructions — using the Service's features is the instruction — unless law requires otherwise.

5. Confidentiality and security

Encryption in transit and at rest, per-workspace row-level isolation enforced in the database, role-based access, revocable server keys, weekly offsite backups, and error/rate-limit shielding at the API edge. Persons authorized to process data are bound to confidentiality.

6. Subprocessors

The Controller authorizes the subprocessors listed in the Privacy Policy. We will give [TODO: e.g. 30] days' notice before adding or replacing one; the Controller may object on reasonable data-protection grounds.

7. International transfers

Where data leaves the EEA/UK, transfers rely on adequacy decisions or the EU Standard Contractual Clauses (Module 2) [TODO: confirm mechanism per subprocessor with counsel].

8. Assistance, breaches, audits

We assist the Controller with data-subject requests and security-incident obligations, notify the Controller without undue delay after becoming aware of a personal-data breach, and make available information reasonably necessary to demonstrate compliance.

9. Deletion and return

On termination, workspace content is deleted per the retention terms in the Privacy Policy; the Controller can export data at any time from within the app before deletion.

Contact

[TODO: privacy email]