Data Processing Addendum
This addendum forms part of the agreement between you (controller) and us (processor).
This Data Processing Addendum ("DPA") forms part of the agreement between the customer ("Controller") and Phronesis AI Lab Private Limited ("Processor", "we", "us", "our") for the Social Media Digital Marketer service ("the Service"). It governs our processing of personal data on the Controller's behalf and applies to the extent the GDPR, UK GDPR, the Indian DPDP Act, 2023, the CCPA/CPRA, or similar laws apply.
1. Definitions
"Controller", "Processor", "Data Subject", "Personal Data", "Processing", and "Subprocessor" have the meanings given in applicable data-protection law. "Customer Personal Data" means personal data we process on the Controller's behalf under the agreement.
2. Roles and scope
The Controller determines the purposes and means of processing Customer Personal Data. We process it only as a Processor, on the Controller's documented instructions, including as set out in the agreement and this DPA. Under the CCPA/CPRA we act as a "service provider" and do not sell or share Customer Personal Data.
3. Details of processing
| Item | Description |
|---|---|
| Subject matter | Provision of AI content generation and social-media publishing |
| Duration | The term of the agreement plus applicable retention periods |
| Nature and purpose | Hosting, generating, scheduling, and publishing content; analytics |
| Categories of data subjects | Controller's personnel, and audiences engaging with published content |
| Categories of personal data | Contact and account data, content data, connected-account identifiers and tokens, engagement metadata |
| Special categories | Not intended; Controller should not submit special-category data |
4. Processor obligations
- Process Customer Personal Data only on documented instructions, unless required by law.
- Ensure persons authorised to process are bound by confidentiality.
- Implement appropriate technical and organisational security measures (Section 7).
- Assist the Controller in responding to Data Subject requests.
- Assist with security, breach notification, data protection impact assessments, and prior consultation.
- Delete or return Customer Personal Data at the end of the agreement, subject to legal retention.
- Make available information necessary to demonstrate compliance and allow audits (Section 8).
5. Subprocessors
The Controller authorises us to engage the subprocessors listed in our Privacy Policy and Trust Center, including Cloudflare (hosting/storage), Razorpay and Stripe (payments), Resend (email), and AI providers such as Anthropic and OpenAI. We impose data-protection terms on each subprocessor no less protective than this DPA and remain responsible for their performance. We will give advance notice of new subprocessors and allow the Controller to object on reasonable data-protection grounds.
6. International transfers
Where we transfer Customer Personal Data across borders, we rely on the Standard Contractual Clauses, the UK International Data Transfer Addendum, and equivalent safeguards, which are incorporated into this DPA by reference.
7. Security measures
- Encryption in transit and at rest.
- Access controls, least-privilege access, and secrets management.
- Network security and monitoring provided in part through Cloudflare.
- Regular backups and tested recovery procedures.
- Secure software-development practices.
See our Security page for further detail.
8. Audits
We will make available documentation and, where reasonable, respond to audit requests, using third-party reports and questionnaires where available to minimise disruption while meeting the Controller's compliance needs.
9. Personal data breaches
We will notify the Controller without undue delay after becoming aware of a personal data breach affecting Customer Personal Data and provide information reasonably required for the Controller to meet its notification obligations.
10. Return and deletion
On termination, we will delete or return Customer Personal Data as instructed, subject to backup cycles and legal retention, within the timeframes stated in our Privacy Policy.
11. Contact
Data protection queries: [email protected].
Last updated: 20 September 2026.