Data Processing Addendum (DPA)

Effective date: October 15, 2025

Last updated: November 12, 2025

This Data Processing Addendum ("Addendum") forms part of the Terms of Service or other written or electronic agreement ("Agreement") between CONTENT24 TECHNOLOGIES LIMITED, operating as Content24 ("Processor"), and the customer ("Controller" or "Customer") that uses the Content24 platform and related services (the "Service").

1. Purpose

This Addendum governs the processing of personal data by the Processor on behalf of the Controller in connection with the provision of the Service, in accordance with Article 28 of the GDPR.

2. Definitions

For the purposes of this Addendum:

  • "Personal Data" means any information relating to an identified or identifiable natural person.
  • "Processing" means any operation performed on Personal Data, including collection, storage, alteration, retrieval, disclosure, or deletion.
  • "Controller" means the entity that determines the purposes and means of the processing of Personal Data.
  • "Processor" means the entity that processes Personal Data on behalf of the Controller.
  • "Subprocessor" means a third party engaged by the Processor that processes Personal Data on behalf of the Controller.
  • "Applicable Law" means the GDPR and any other data-protection or privacy laws applicable to the parties.

3. Scope of Processing

3.1 Nature and Purpose

The Processor will process Personal Data only to provide, maintain, and improve the Service, perform technical operations, and fulfill contractual obligations under the Agreement.

3.2 Subject Matter and Duration

Processing will continue for the term of the Agreement and only for the duration necessary to provide the Service or comply with legal obligations.

3.3 Type of Data and Categories of Data Subjects

  • Data Subjects: end users, customers, or authorized users of the Controller.
  • Personal Data: name, email, IP address, payment data (via third-party processor), user-generated content, and other information provided or collected during use of the Service.

4. Obligations of the Processor

The Processor shall:

  • Process Personal Data only on documented instructions from the Controller.
  • Ensure that personnel authorized to process Personal Data are bound by confidentiality obligations.
  • Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including encryption, access control, and regular audits.
  • Notify the Controller without undue delay after becoming aware of a Personal Data breach.
  • Assist the Controller, where possible, in fulfilling obligations regarding data-subject rights, data-protection impact assessments, and prior consultations with supervisory authorities.
  • Upon termination of the Agreement, delete or return all Personal Data, unless storage is required by law.
  • Make available to the Controller all information necessary to demonstrate compliance with this Addendum and allow reasonable audits.

5. Obligations of the Controller

The Controller shall:

  • Ensure that all Personal Data provided to the Processor has been collected lawfully and that all required consents are obtained.
  • Determine the lawful basis for processing under the GDPR.
  • Maintain an up-to-date record of processing activities.
  • Respond to data-subject requests and provide notice to the Processor where its cooperation is required.

6. Subprocessors

  • The Controller authorizes the Processor to engage subprocessors including Amazon Web Services (AWS) for hosting and storage, Cloudflare for security and CDN, OpenAI and Anthropic for AI content generation, Stripe, Klarna, and PayPal for payment processing (including credit card and bank transfer), and email, analytics, and CRM tools as disclosed in the Privacy Policy.
  • The Processor shall ensure that each Subprocessor is bound by written terms imposing data-protection obligations equivalent to those in this Addendum.
  • The Processor will notify the Controller in advance of any intended addition or replacement of Subprocessors, giving the Controller an opportunity to object on reasonable grounds.

7. Security Measures

The Processor maintains an ISO/IEC 27001-certified Information Security Management System (ISMS) and implements the following controls:

  • Encryption of data at rest and in transit (AES-256 / TLS 1.2+).
  • Access control, MFA, and role-based permissions.
  • Regular penetration testing and vulnerability scanning.
  • Secure backups and disaster-recovery systems.
  • Employee security training and confidentiality agreements.
  • Logging and continuous monitoring.

8. International Data Transfers

When transferring Personal Data outside the European Economic Area (EEA), the Processor ensures adequate protection by relying on Standard Contractual Clauses (SCCs) approved by the European Commission, using providers certified under the EU-US Data Privacy Framework (DPF), and conducting Transfer Impact Assessments (TIAs) as required.

9. Data-Subject Rights

The Processor shall promptly notify the Controller if it receives a request from a data subject and shall not respond directly without the Controller's authorization, unless required by law.

10. Data Breach Notification

The Processor will notify the Controller without undue delay (and within 72 hours where feasible) upon becoming aware of a confirmed Personal Data breach.

  • The nature of the breach.
  • Categories and approximate number of affected data subjects.
  • Likely consequences.
  • Measures taken or proposed to mitigate its effects.

11. Audit and Certification

  • The Processor maintains independent ISO/IEC 27001 and ISO/IEC 9001 certifications.
  • Upon written request, the Processor will provide relevant certification reports or summaries to demonstrate compliance.
  • On-site audits may be requested no more than once per year and shall not unreasonably interfere with operations.

12. Liability

Liability for any breach of this Addendum shall be governed by the limitations and exclusions of liability set out in the main Agreement.

13. Duration and Termination

This Addendum remains in effect for the duration of the Agreement. Upon termination, the Processor shall, at the Controller's choice, delete or return all Personal Data unless retention is required by law.

14. Governing Law and Jurisdiction

This Addendum is governed by and construed in accordance with the laws of Cyprus, and the parties submit to the exclusive jurisdiction of the courts of Cyprus.

15. Contact

CONTENT24 TECHNOLOGIES LIMITED, operating as Content24.

Address: 34 Falirou, 1st Floor, Office 103, 2066 Strovolos, Nicosia, Cyprus.

Email: legal@content24.ai.

Support: support@content24.ai.

Newsletter

Stay ahead with Content24

Product updates, AI marketing tips, and launch news.

By subscribing, you agree to hear from Content24. See our Privacy Policy.