Back to home

Data Processing Agreement (DPA)

Last updated: 1 May 2026

This DPA forms part of your subscription contract whenever engagelayer.io processes personal data on your behalf. It satisfies Article 28 GDPR.

1. Roles

You are the Data Controller for personal data of your website visitors. engagelayer.io is the Data Processor — we process this data only on your documented instructions.

2. Subject matter & purpose

Subject matter: personal data submitted by your website visitors when interacting with the AI assistant. Purpose: enabling the assistant to answer questions, qualify leads, and forward conversation summaries to your sales tools as you configure.

3. Categories of data

Identification (name, email, phone — only when voluntarily submitted by visitor), professional (company name, role, country), behavioural (questions asked, language used, source page).

4. Categories of data subjects

Your website visitors who choose to interact with the assistant.

5. Duration

For the duration of your subscription, plus your configured retention period (30 / 90 / 180 / 365 days), plus 30 days of secure deletion buffer.

6. Sub-processors

We use sub-processors strictly necessary to deliver the service: Stripe (billing only), our hosting provider (EU regions), and the managed AI provider that powers the assistant, which processes each tenant's conversations in isolation. We notify you 30 days in advance of any new sub-processor — you can object and terminate without penalty if the change materially affects your obligations.

7. Security measures

TLS 1.3 in transit, AES-256 at rest, key rotation every 90 days, role-based access internally with least-privilege, signed audit log, bulk-export blocking, intrusion detection on production systems.

8. International transfers

EU data stays in EU data centres by default. If you opt for non-EU storage, we apply Standard Contractual Clauses (SCCs) and document the transfer in your account.

9. Data subject rights

We help you respond to data subject requests (access, rectification, erasure, portability, objection) within 30 days. We forward any direct request from a data subject to you within 3 business days.

10. Breach notification

If we discover a personal data breach, we notify you without undue delay, and within 24 hours if the breach is likely to result in a risk to data subjects. We provide details, mitigation, and remediation plan.

11. Audit

You can request a written summary of our security controls once per year. Independent third-party audit reports (such as SOC 2) will be provided once available.

12. Return & deletion

On termination, you can export all data within 30 days. After that, all your data is securely deleted, including from backups, within 90 days. We provide a deletion certificate on request.

Service provider — legal entity
PRO AGENCY EUROPE SRL
Reg. No.: 50684851
VAT: RO50684851
Str. Academiei 35-37, sc. A, et. 3, ap. 16, Bucharest 030167, Romania

The English version of these documents is the legally authoritative reference.