Data Processing Agreement (DPA)
Last updated: 1 May 2026
This DPA forms part of your subscription contract whenever engagelayer.io processes personal data on your behalf. It satisfies Article 28 GDPR.
1. Roles
You are the Data Controller for personal data of your website visitors. engagelayer.io is the Data Processor — we process this data only on your documented instructions.
2. Subject matter & purpose
Subject matter: personal data submitted by your website visitors when interacting with the AI assistant. Purpose: enabling the assistant to answer questions, qualify leads, and forward conversation summaries to your sales tools as you configure.
3. Categories of data
Identification (name, email, phone — only when voluntarily submitted by visitor), professional (company name, role, country), behavioural (questions asked, language used, source page).
4. Categories of data subjects
Your website visitors who choose to interact with the assistant.
5. Duration
For the duration of your subscription, plus your configured retention period (30 / 90 / 180 / 365 days), plus 30 days of secure deletion buffer.
6. Sub-processors
We use sub-processors strictly necessary to deliver the service: Stripe (billing only), our hosting provider (EU regions), and the managed AI provider that powers the assistant, which processes each tenant's conversations in isolation. We notify you 30 days in advance of any new sub-processor — you can object and terminate without penalty if the change materially affects your obligations.
7. Security measures
TLS 1.3 in transit, AES-256 at rest, key rotation every 90 days, role-based access internally with least-privilege, signed audit log, bulk-export blocking, intrusion detection on production systems.
8. International transfers
EU data stays in EU data centres by default. If you opt for non-EU storage, we apply Standard Contractual Clauses (SCCs) and document the transfer in your account.
9. Data subject rights
We help you respond to data subject requests (access, rectification, erasure, portability, objection) within 30 days. We forward any direct request from a data subject to you within 3 business days.
10. Breach notification
If we discover a personal data breach, we notify you without undue delay, and within 24 hours if the breach is likely to result in a risk to data subjects. We provide details, mitigation, and remediation plan.
11. Audit
You can request a written summary of our security controls once per year. Independent third-party audit reports (such as SOC 2) will be provided once available.
12. Return & deletion
On termination, you can export all data within 30 days. After that, all your data is securely deleted, including from backups, within 90 days. We provide a deletion certificate on request.
The English version of these documents is the legally authoritative reference.