Data Processing Agreement (DPA)
Last updated: 7 August 2026
This Data Processing Agreement (the “DPA”) is an integral annex to the Prezzly Terms of Service and sets out the rules for processing personal data entrusted by the User in connection with use of the Service. The DPA is concluded under Art. 28 GDPR upon acceptance of the Terms and applies for the duration of use of the Service.
Capitalised terms have the meaning given to them in the Terms of Service.
1. Parties and roles
- Controller - the User who uploads or processes in the Service Content containing personal data of third parties and determines the purposes and means of its processing.
- Processor - the Provider (TAG CONCIERGE Sp. z o.o.), which processes the entrusted data solely on behalf of and on the documented instructions of the Controller, to the extent necessary to provide the Service.
- This DPA covers only personal data contained in User Content (including audience questions). It does not cover data for which the Provider is the controller (account data, technical data, security) - those are governed by the Privacy Policy.
2. Subject matter, nature and purpose of processing
- Subject matter: processing of personal data contained in User Content.
- Nature and purpose: storing, hosting, serving, sharing, versioning and presenting Content and operating related features (including audience questions) - solely for the purpose of providing the Service in accordance with the Terms.
- Duration: for the period of use of the Service, until deletion of the Content or the Account, subject to section 9.
3. Type of data and categories of data subjects
- Type of data: determined by the Controller through the content of the uploaded Content. This may include, in particular, identification and contact data (e.g. name, surname, email address, company name) and other data included by the Controller in the Content.
- Categories of data subjects: determined by the Controller; these may include, in particular, clients, contractors, employees, presentation recipients and participants of audience sessions.
- The Controller undertakes not to include in the Content special categories of personal data (Art. 9 GDPR) or data relating to criminal convictions and offences (Art. 10 GDPR), unless it first agrees appropriate additional measures with the Provider. The Service is not intended for processing such data.
4. Obligations of the Processor
The Provider undertakes to:
- process the entrusted data solely on the documented instructions of the Controller - use of the Service’s features by the Controller in accordance with the Terms and acceptance of this DPA are deemed such instructions; where processing is required by Union or Member State law, the Provider informs the Controller before processing, unless the law prohibits it;
- ensure that persons authorised to process the data are committed to confidentiality;
- apply the technical and organisational measures referred to in Art. 32 GDPR (section 6);
- comply with the conditions for engaging sub-processors (section 5);
- assist the Controller - insofar as possible and by appropriate technical and organisational measures - in fulfilling the obligation to respond to data subject requests (Chapter III GDPR), including by making available the Service features enabling access to, correction and deletion of Content;
- assist the Controller in complying with obligations under Art. 32-36 GDPR (security, breach notification, impact assessment, prior consultation), taking into account the nature of processing and the information available;
- after the end of the Service, delete or return the data in accordance with section 9;
- make available to the Controller the information necessary to demonstrate compliance with Art. 28 GDPR and allow for audits on the terms in section 8.
5. Sub-processors
- The Controller gives general authorisation for the Provider to engage sub-processors in order to provide the Service.
- As at the date of the DPA, the sub-processors are:
- Cloudflare, Inc. - cloud infrastructure (hosting of the application and API, database, storage of Content files, live sessions, abuse protection, sending emails); Content files are stored in a configuration for the European Union jurisdiction;
- Clerk, Inc. - authentication and sign-in management.
- The Provider imposes on sub-processors data protection obligations corresponding to those in this DPA and remains liable to the Controller for the performance of their obligations.
- The Provider will inform the Controller of any intended change of sub-processors (addition or replacement), allowing the Controller to object. In the event of a justified objection that the parties are unable to resolve, the Controller may terminate the contract for the Service (delete the Account).
- An up-to-date list of sub-processors is available on request sent to [email protected].
6. Security measures (Art. 32 GDPR)
The Provider applies appropriate technical and organisational measures taking into account the state of the art, the costs of implementation and the risk, in particular:
- encryption of data transmission (HTTPS/TLS),
- access control and authentication,
- isolation of served Content in a sandbox environment,
- separation of environments and secret management,
- abuse mitigation mechanisms (rate limiting, bot protection),
- measures ensuring continuity appropriate to the nature of the Service.
7. Transfers outside the EEA
Entrusted data may be transferred outside the European Economic Area to the extent arising from the use of sub-processors (section 5). Transfers take place on the basis of the mechanisms in Chapter V GDPR (an adequacy decision - Data Privacy Framework, or Standard Contractual Clauses together with additional measures). Details are described in the Privacy Policy.
8. Audit
- The Provider makes available to the Controller, on request, the information necessary to demonstrate compliance with the obligations under Art. 28 GDPR.
- The Controller has the right to conduct an audit, including an inspection. Given the multi-tenant (shared) nature of the Service, this right is exercised primarily by making available documentation, answering questions and - where necessary - reports or certificates of the infrastructure providers. An on-site inspection requires prior agreement of the date and scope and must not compromise the security of other customers’ data.
9. Deletion or return of data upon termination
- Upon the end of the Service (account deletion, termination of the contract), the Provider deletes the entrusted data within a reasonable period, unless the Controller first exports it using the Service’s features.
- The Provider may retain data for the period required by law or necessary to establish, pursue or defend claims - to that extent the data is appropriately secured and processed solely for that purpose.
- Mechanisms with a predefined lifetime (Guest Account, link expiry, trimming of revision history) result in the automatic deletion of the relevant data in accordance with the Terms.
10. Breach notification
The Provider, without undue delay after becoming aware of a breach of the protection of the entrusted data, notifies the Controller, providing the information necessary for the Controller to fulfil its obligations under Art. 33-34 GDPR, to the extent that such information is available to the Provider.
11. Liability
- Each party is liable for a breach of data protection law within the scope of its own obligations.
- The Controller is responsible for the lawfulness of the entrusted data and processing purposes, including holding a legal basis and required consents and the lawfulness of the Content.
- The limitations of liability set out in the Terms apply accordingly to this DPA, to the extent permitted by law.
12. Final provisions
- Matters not regulated herein are governed by the Terms and by the GDPR and Polish law.
- In the event of a conflict between the DPA and the Terms regarding the processing of entrusted data, the DPA prevails.