Legal Document

Data Processing Addendum (DPA)

Last updated: September 9, 2026

1. Scope and Application

This Data Processing Addendum ("DPA") supplements the Terms of Service between Conterity and customer organizations ("Controller") subject to the EU General Data Protection Regulation (GDPR) or California Consumer Privacy Act (CCPA).

2. Processing of Personal Data

Conterity acts as a Data Processor. We process personal data exclusively on documented instructions from the Controller and for the agreed purposes of content creation, editorial workflow, and distribution.

3. Technical & Organizational Measures (TOMs)

Conterity maintains strict technical and organizational safeguards including multi-tenant database isolation, TLS 1.3 in transit, AES-256-GCM at rest, continuous audit logging, and least-privilege role-based access control.

4. Subprocessor Notification

Customers will be notified at least 30 days prior to the engagement of any new subprocessors. An up-to-date list of subprocessors is maintained on our Privacy Policy page.

5. Data Deletion and Return

Upon termination of the service agreement, Conterity will return or securely destroy all Customer Personal Data in accordance with our data retention schedule.

← Return to Conterity | Privacy Policy | Terms