Last updated: September 9, 2026
This Data Processing Addendum ("DPA") supplements the Terms of Service between Conterity and customer organizations ("Controller") subject to the EU General Data Protection Regulation (GDPR) or California Consumer Privacy Act (CCPA).
Conterity acts as a Data Processor. We process personal data exclusively on documented instructions from the Controller and for the agreed purposes of content creation, editorial workflow, and distribution.
Conterity maintains strict technical and organizational safeguards including multi-tenant database isolation, TLS 1.3 in transit, AES-256-GCM at rest, continuous audit logging, and least-privilege role-based access control.
Customers will be notified at least 30 days prior to the engagement of any new subprocessors. An up-to-date list of subprocessors is maintained on our Privacy Policy page.
Upon termination of the service agreement, Conterity will return or securely destroy all Customer Personal Data in accordance with our data retention schedule.