Data Processing Addendum
Stub — last updated: [TODO: date at launch]
Status: this is a template outline of the DPA that will apply between Neyli ([TODO: legal entity], the “Processor”) and the customer workspace owner (the “Controller”). It is incorporated by reference into the Terms of Service for customers whose use is subject to GDPR/UK GDPR.
1. Subject matter and duration
Processing of workspace content and member account data, for the duration of the customer's use of Neyli plus the deletion window in the Privacy Policy.
2. Nature and purpose
Hosting, storage, backup, display, messaging/notification delivery and AI-assisted processing of workspace content, solely to provide the Service.
3. Categories of data and data subjects
Workspace members (names, emails, roles) and any personal data the Controller's team places in projects, tasks, notes, messages and files.
4. Controller instructions
We process only on the Controller's documented instructions — using the Service's features is the instruction — unless law requires otherwise.
5. Confidentiality and security
Encryption in transit and at rest, per-workspace row-level isolation enforced in the database, role-based access, revocable server keys, weekly offsite backups, and error/rate-limit shielding at the API edge. Persons authorized to process data are bound to confidentiality.
6. Subprocessors
The Controller authorizes the subprocessors listed in the Privacy Policy. We will give [TODO: e.g. 30] days' notice before adding or replacing one; the Controller may object on reasonable data-protection grounds.
7. International transfers
Where data leaves the EEA/UK, transfers rely on adequacy decisions or the EU Standard Contractual Clauses (Module 2) [TODO: confirm mechanism per subprocessor with counsel].
8. Assistance, breaches, audits
We assist the Controller with data-subject requests and security-incident obligations, notify the Controller without undue delay after becoming aware of a personal-data breach, and make available information reasonably necessary to demonstrate compliance.
9. Deletion and return
On termination, workspace content is deleted per the retention terms in the Privacy Policy; the Controller can export data at any time from within the app before deletion.
Contact
[TODO: privacy email]