Data Processing Agreement (DPA)

Version: September 6, 2026

This Data Processing Agreement ("DPA") forms part of the Prozly Terms of Service available at /terms (the "Agreement") between the entity named in our Impressum ("Prozly", the "Processor") and the business customer using the Prozly service (the "Customer", the "Controller"). It is incorporated into the Agreement by reference and applies automatically to all customers — no signature is required. Customers who require a countersigned copy (e.g. for their records of processing under Art. 30 GDPR) can request one at legal@prozly.ai. A German version is available at /avv; in case of discrepancies, the German version prevails. In case of conflicts between this DPA and the Agreement, this DPA prevails with regard to the processing of personal data.

1. Definitions

Terms such as "personal data", "processing", "controller", "processor", "data subject" and "supervisory authority" have the meaning given to them in Regulation (EU) 2016/679 ("GDPR"). "Customer Data" means all personal data that Prozly processes on behalf of the Customer in the course of providing the service, as further described in Annex 1.

2. Roles and scope

For the processing of Customer Data, the Customer is the controller (Art. 4 No. 7 GDPR) and Prozly is the processor (Art. 4 No. 8 GDPR). Customer Data includes in particular: content, drafts, media, voice notes, documents, and knowledge sources that the Customer and its users bring into the workspace; the social media accounts connected by the Customer's users together with the profile, post, and analytics data retrieved for them; content ingested from sources the Customer connects (e.g. RSS feeds, websites, YouTube channels); and the scheduling, publishing, and engagement data processed to provide the contracted features.

Prozly determines neither the purposes nor the essential means of processing Customer Data: the Customer decides which accounts and sources are connected, which content is created, edited, scheduled, and published, and which team members have access. Prozly processes Customer Data solely to provide, secure, and support the contracted service.

This DPA does not apply to processing for which Prozly is itself the controller, in particular: managing user and customer accounts, authentication, contract administration, billing and payment; securing and monitoring the service and preventing abuse; aggregate product analytics and error diagnostics; Prozly's own marketing and communication; compliance with Prozly's own legal obligations; and the operation of cross-customer indexes of publicly available content (e.g. industry news and content-inspiration features). Such processing is described in our Privacy Policy. The parties are not joint controllers (Art. 26 GDPR) for any processing under the Agreement.

3. Subject matter, duration, nature and purpose

The subject matter, duration, nature, and purpose of the processing as well as the types of personal data and the categories of data subjects are set out in Annex 1.

4. Instructions

Prozly processes Customer Data only on the Customer's documented instructions, including with regard to transfers to third countries, unless required to process by Union or Member State law; in such a case, Prozly informs the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest (Art. 28 (3) (a) GDPR). The Agreement, this DPA, and the Customer's configuration and use of the service (including settings made by the Customer's authorized users, e.g. connecting accounts and sources, scheduling posts) constitute the complete documented instructions. Additional instructions require agreement in text form. Prozly informs the Customer without undue delay if, in Prozly's opinion, an instruction infringes applicable data protection law.

5. Confidentiality

Prozly ensures that all persons authorized to process Customer Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality (Art. 28 (3) (b) GDPR), and process Customer Data only to the extent required for their tasks.

6. Security of processing

Prozly implements and maintains appropriate technical and organizational measures pursuant to Art. 32 GDPR, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing as well as the risks for data subjects. The measures in place at the time of this version are described in Annex 2. Prozly may update these measures, provided the level of protection does not fall below the level provided by Annex 2.

7. Sub-processors

The Customer grants Prozly a general written authorization to engage sub-processors for the processing of Customer Data (Art. 28 (2) GDPR). The sub-processors engaged at the time of this version are listed at /subprocessors, which forms part of this DPA as Annex 3. Prozly announces intended additions or replacements on that page at least 30 days before the new sub-processor processes Customer Data; customers can subscribe to change notifications by e-mailing legal@prozly.ai. The Customer may object to a change on reasonable data protection grounds within 30 days of the announcement; in that case the parties will seek a mutually agreeable solution (e.g. opting out of an affected optional feature), failing which either party may terminate the affected services with effect from the date the change takes effect. Prozly imposes on each sub-processor data protection obligations essentially equivalent to those in this DPA (Art. 28 (4) GDPR) and remains fully liable for each sub-processor's performance.

8. International transfers

Prozly stores Customer Data primarily within the European Union. Where Customer Data is transferred to a country outside the EU/EEA that is not subject to an adequacy decision of the European Commission, Prozly ensures appropriate safeguards pursuant to Art. 44 et seq. GDPR, in particular the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) with the respective sub-processor and/or reliance on the EU–U.S. Data Privacy Framework where the recipient is certified. An overview is provided at /subprocessors.

9. Assistance to the Customer

Taking into account the nature of the processing, Prozly assists the Customer by appropriate technical and organizational measures, insofar as this is possible, in fulfilling the Customer's obligation to respond to data subject requests under Chapter III GDPR (Art. 28 (3) (e) GDPR). If a data subject contacts Prozly directly regarding Customer Data, Prozly forwards the request to the Customer without undue delay. Prozly further assists the Customer in ensuring compliance with Art. 32 to 36 GDPR (security, breach notification, data protection impact assessments, prior consultation), taking into account the nature of processing and the information available to Prozly (Art. 28 (3) (f) GDPR).

10. Personal data breach

Prozly notifies the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data (Art. 33 (2) GDPR). The notification describes, as far as known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Prozly documents breaches and reasonably cooperates with the Customer in investigating and mitigating them.

11. Deletion and return of Customer Data

During the term, the Customer can export Customer Data through the service or request assistance at legal@prozly.ai. After the end of the provision of services, Prozly deletes all Customer Data remaining on its systems irretrievably within 30 days, unless Union or Member State law requires further storage (Art. 28 (3) (g) GDPR). Backups are deleted or overwritten in the ordinary backup cycle. No right of retention or lien exists in respect of Customer Data.

12. Audits

Prozly makes available to the Customer all information necessary to demonstrate compliance with Art. 28 GDPR and this DPA, in particular relevant certifications, attestations, and audit reports of Prozly's infrastructure sub-processors (Art. 28 (3) (h) GDPR). Where such information is insufficient in an individual case, the Customer (or an independent auditor mandated by the Customer that is not a competitor of Prozly) may audit the processing operations concerned. Audits require at least 30 days' notice, take place during regular business hours no more than once per calendar year (except following a personal data breach or where required by a supervisory authority), must not disrupt operations disproportionately, and are subject to confidentiality. Each party bears its own costs.

13. No use for model training; no cross-customer use

Prozly does not use Customer Data to train machine-learning models for the benefit of other customers or third parties. AI personalization (e.g. brand voice profiles and workspace knowledge) is built exclusively from the respective Customer's own data and used only for that Customer's workspace. Prozly contractually requires its AI sub-processors not to use Customer Data submitted through Prozly to train their foundation models. For clarity: cross-customer indexes of publicly available content (industry news, content inspiration) are operated by Prozly as controller outside this DPA (see Section 2 and the Privacy Policy).

14. Term, liability, final provisions

This DPA applies as long as Prozly processes Customer Data under the Agreement. Liability is governed by the liability provisions of the Agreement; Art. 82 GDPR remains unaffected. This DPA is governed by German law; place of jurisdiction is the registered seat of Prozly. Prozly may update this DPA where required by law, supervisory guidance, or changes to the service, provided the level of protection is not materially reduced; material updates are announced on this page with reasonable advance notice.

Annex 1 — Details of the processing

Subject matter: provision of the Prozly platform — an application for ingesting content sources, creating, personalizing, scheduling, publishing, and analyzing social media content for the Customer's workspace, including collaboration, knowledge base, image and carousel creation, analytics, and optional integrations (e.g. Chrome extension, Telegram).

Duration: term of the Agreement, plus the deletion period under Section 11.

Nature and purpose of processing: hosting and storage; transcription of voice notes; AI-supported content generation and editing based on the Customer's inputs; retrieval and processing of profile, post, and analytics data for connected social accounts via official APIs; ingestion, relevance scoring, and summarization of content from sources connected by the Customer; image and carousel generation; scheduling and publishing of posts to member profiles and company pages; analytics and reporting; notifications (e-mail, in-app, connected messengers); support.

Categories of data subjects: users of the Customer (team members, administrators); persons whose personal data appears in content, recordings, documents, or knowledge sources provided by the Customer; persons interacting with the Customer's social media presence, to the extent retrieved for the Customer; persons appearing in content from sources the Customer connects.

Types of personal data: identification and contact data (name, e-mail address, profile image, workspace role); connected account and profile data (profile information, OAuth tokens, connection status); content data (drafts, published posts, comments, media, documents, knowledge sources); audio recordings and transcripts (voice notes); analytics and engagement data (impressions, reactions, comments, follower statistics); usage and technical data required to provide the service; communication data of connected channels activated by the Customer (e.g. Telegram).

Special categories of data (Art. 9 GDPR): not intended to be processed; may be incidentally contained in content the Customer chooses to process. The Customer is responsible for ensuring a legal basis for such content.

Annex 2 — Technical and organizational measures (Art. 32 GDPR)

  • Encryption and transport security: all data in transit is encrypted using TLS; data at rest is encrypted at the infrastructure level by our hosting providers (managed database, object storage, backups).
  • Access control: authentication via a managed identity provider; role-based access within workspaces; row-level security and logical tenant separation at workspace level; access to production systems restricted to authorized personnel on a need-to-know basis; platform account access exclusively via OAuth tokens that users can revoke at any time — Prozly never receives platform passwords.
  • Infrastructure: hosting on established cloud providers (see Annex 3) with certified data centers (e.g. ISO 27001 / SOC 2 attestations of the providers); primary data storage in the EU.
  • Availability and resilience: redundant managed infrastructure, automated backups, queue-based processing with retries, monitoring and alerting, documented incident response.
  • Data minimization and retention: deletion workflows for accounts and workspaces; minimized capture of platform data; configurable data exports.
  • Personnel and organization: confidentiality obligations for all personnel; least-privilege administration; data protection contact (legal@prozly.ai); vendor due diligence with Art. 28 agreements for all sub-processors; logging of security-relevant events.

Annex 3 — Sub-processors

The current list of sub-processors, including entities, countries, purposes, and transfer safeguards, is published and maintained at /subprocessors and forms part of this DPA.

Data Processing Agreement — Prozly · Prozly