Data Processing Agreement

Last updated September 2, 2026

This Data Processing Agreement (the "DPA") forms part of the agreement between Aidelly Corporation and the customer for use of the Aidelly service (the "Agreement"). It applies where Aidelly processes personal data on the customer's behalf.

How to execute this DPA. This DPA takes effect automatically as part of the Agreement when you use the service. No signature is required for it to apply. If your procurement process needs a countersigned copy, email legal@aidelly.com and we will return one.

1.Definitions

"Personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meanings given in the General Data Protection Regulation (EU) 2016/679 (the "GDPR").

"Customer Personal Data" means personal data that Aidelly processes on the customer's behalf in providing the service. "Data Protection Law" means the GDPR, the UK GDPR, the Data Protection Act 2018, the Swiss Federal Act on Data Protection, and the California Consumer Privacy Act as amended, each to the extent applicable.

2.Roles of the parties

The customer is the controller and Aidelly is the processor in respect of Customer Personal Data. Where the customer is itself acting as a processor for its own clients, which is the normal arrangement for an agency using Aidelly, Aidelly acts as a sub-processor and the customer confirms it has the authority from its client to appoint Aidelly on these terms.

Aidelly acts as a controller for its own account data, billing records, and product usage analytics. That processing is described in the Privacy Policy and is not governed by this DPA.

3.Processing on documented instructions

Aidelly processes Customer Personal Data only on the customer's documented instructions, which comprise the Agreement, this DPA, and the customer's use of the service's features and configuration. Aidelly does not sell Customer Personal Data and does not use it to train models for its own purposes.

If Aidelly is required by law to process Customer Personal Data other than on those instructions, it will inform the customer before processing unless the law prohibits that notice.

4.Confidentiality

Aidelly ensures that personnel authorised to process Customer Personal Data are bound by confidentiality obligations, and limits access to those who need it to provide or support the service.

5.Security measures

Aidelly implements the technical and organisational measures set out in Annex II, having regard to Article 32 of the GDPR. Those measures are described in more detail, and kept current, on the security page. Aidelly may update the measures provided the level of protection is not reduced.

6.Sub-processors

The customer gives general authorisation for Aidelly to appoint sub-processors. The current list is published at aidelly.ai/subprocessors and is incorporated into this DPA as Annex III.

Aidelly will update that page before a new sub-processor begins processing Customer Personal Data. Customers who ask to join the sub-processor notice list at privacy@aidelly.com will be notified directly. The customer may object on reasonable data protection grounds within 30 days, in which case the parties will discuss a resolution in good faith; if none is reached the customer may terminate the affected part of the service.

Aidelly imposes data protection obligations on each sub-processor no less protective than those in this DPA, and remains liable for its sub-processors' performance.

7.Assistance with data subject rights

The service provides features allowing the customer to access, correct, export, and delete Customer Personal Data itself. Where a data subject request cannot be satisfied through those features, Aidelly will provide reasonable assistance, taking into account the nature of the processing.

If a data subject contacts Aidelly directly about Customer Personal Data, Aidelly will refer them to the customer rather than respond on the customer's behalf, and will tell the customer promptly.

8.Personal data breach

Aidelly will notify the customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. The notice will describe the nature of the breach, the categories and approximate number of data subjects and records affected so far as known, the likely consequences, and the measures taken or proposed.

Where all that information is not available at once, Aidelly will provide it in phases as it is established rather than delay the first notice.

9.Assistance with impact assessments and consultation

Aidelly will provide reasonable assistance with data protection impact assessments and prior consultation with a supervisory authority under Articles 35 and 36 of the GDPR, taking into account the nature of the processing and the information available to Aidelly.

10.Deletion and return

On termination or expiry of the Agreement, Aidelly will delete Customer Personal Data within 30 days, except where retention is required by law. The customer may export its data through the service before termination, and may request a copy within that 30-day window.

Backups are deleted on their own rotation. Until that rotation completes, residual copies remain subject to this DPA.

11.Audits and information

Aidelly will make available the information reasonably necessary to demonstrate compliance with this DPA, and will respond to reasonable written questionnaires no more than once a year, or more often following a personal data breach or a supervisory authority request.

Aidelly does not currently hold a SOC 2 or ISO 27001 certification and does not offer an audit report in place of these responses. If an on-site or third-party audit is required by Data Protection Law, the parties will agree its scope and timing in advance and the customer bears the cost.

12.International transfers

Customer Personal Data is processed and stored in the United States. The application runs on Vercel in AWS us-east-1 and the database and file storage run on Supabase in AWS us-east-2.

Where Aidelly processes personal data subject to the GDPR, the Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor), are incorporated into this DPA by reference and apply to that transfer. Where the customer acts as a processor, Module Three (processor to processor) applies instead. Annex I and Annex II of this DPA serve as the corresponding annexes to those clauses, and the docking clause is not used.

For personal data subject to the UK GDPR, the UK International Data Transfer Addendum applies to the Standard Contractual Clauses. For personal data subject to Swiss law, references to the GDPR are read as references to the Swiss Federal Act on Data Protection and the Swiss Federal Data Protection and Information Commissioner is the competent authority.

13.Order of precedence and governing law

If this DPA conflicts with the Agreement, this DPA prevails in respect of the processing of Customer Personal Data. If this DPA conflicts with the Standard Contractual Clauses, those clauses prevail.

Liability under this DPA is subject to the limitations and exclusions in the Agreement. Except where the Standard Contractual Clauses require otherwise, this DPA is governed by Georgia law and disputes are resolved by binding arbitration in Georgia, USA, consistent with the Terms of Service.

A.Annex I: description of the processing

Data exporter. The customer, acting as controller or as processor for its own clients. Contact details are those on the customer's account.

Data importer. Aidelly Corporation, a Delaware corporation, 8 The Green STE B, Dover, DE 19901, United States. Contact: privacy@aidelly.com. Activities: the provision of a social media management platform.

Categories of data subjects. The customer's personnel and authorised users; the customer's own clients and their personnel where an agency uses the service on their behalf; and members of the public who interact with content the customer publishes, including people who comment on or send messages to a connected social account.

Categories of personal data. Account and contact details; authentication data; content the customer creates, uploads, or schedules, which may itself contain personal data; access credentials for connected social accounts; messages and comments retrieved from connected accounts; engagement and analytics metrics; product usage and support correspondence.

Special category data. The service is not designed for special category data and the customer should not use it to process such data. Aidelly applies no additional safeguards specific to special category data beyond the measures in Annex II.

Frequency and duration. Continuous, for the duration of the Agreement, followed by deletion in accordance with clause 10.

Nature and purpose of processing. Hosting, storage, scheduling, publication to connected social accounts, retrieval of engagement data, generation of content using AI providers at the customer's direction, analytics, and support.

B.Annex II: technical and organisational measures

The measures below are current as at the date of this page. The security page carries the maintained description.

  • Encryption in transit. TLS across all services, with HTTP Strict Transport Security enforced and preloaded.
  • Encryption at rest. Application-level AES-256-GCM with a unique initialisation vector per record and authenticated decryption, applied to credentials for connected social accounts, in addition to storage-layer encryption provided by the hosting platform.
  • Credential handling. Access tokens for connected social accounts are encrypted before storage, refreshed automatically, and deleted on disconnection. API keys are stored only as a SHA-256 hash and are never retrievable after issue.
  • Access control. Role-based access control with owner, admin, member, and client roles, enforced through a single permission module, with per-workspace overrides.
  • Tenant isolation. Database row level security policies scope records to the owning workspace, applied across content, media, connected accounts, and inbox data.
  • Logging. An append-only workspace activity log recording actor, action, target, before and after state, IP address, and user agent, visible to the customer, plus a separate audit log for public API requests.
  • Rate limiting. Applied to authentication, OAuth, and public endpoints.
  • Authentication. Delegated to the hosting platform's managed authentication service. Session cookies are HTTP-only, same-site, and secure in production. Multi-factor authentication is not currently available.
  • Data retention. Documented retention windows by record type and plan tier, applied through scheduled pruning.

C.Annex III: sub-processors

The authorised sub-processors are those listed at aidelly.ai/subprocessors as updated from time to time in accordance with clause 6. That page records what each sub-processor does and what categories of data it can process.

Contact

Questions about this DPA, or a request for a countersigned copy: legal@aidelly.com. Privacy and data processing questions: privacy@aidelly.com.

Aidelly Corporation, a Delaware corporation. 8 The Green STE B, Dover, DE 19901.