This Data Processing Agreement ("DPA") forms an integral part of the Terms of Use and applies to personal data that Praxtify processes on your behalf. You are the controller; Praxtify, LLC is the processor.
This English text is the binding version.
1. Scope
| Item | Content |
|---|---|
| Subject matter | Providing the Praxtify service |
| Duration | For the term of your subscription and until the end of the deletion period in Section 9 |
| Nature and purpose | Handling buyer inquiries, drafting replies, preparing quotes, booking meetings and follow-up |
| Types of data | Name, work email, phone, company details, message content, product and price preferences |
| Data subjects | Employees and contacts of buyer companies, and your own staff |
| Special categories | None. Not to be uploaded, per the Acceptable Use Policy |
2. Instructions
We process personal data only on your documented instructions; your use of the service and your settings constitute those instructions. If we believe an instruction breaches applicable law, we will tell you. Where law requires us to act beyond your instructions, we will notify you first unless prohibited.
3. Confidentiality
Our personnel with access to the data are bound by confidentiality, and access is granted only to those who need it, to the extent they need it.
4. Security Measures (GDPR Art. 32 / KVKK Art. 12)
- Encryption in transit and at rest (TLS, disk encryption).
- Tenant separation: an organization identifier on every business table and row level security (RLS).
- Role-based access, least privilege, audit logging for administrative actions.
- Password storage and session management at the identity provider (Supabase Auth); administrative access uses multi-factor authentication.
- Backups and restore testing; an incident response process.
- Vulnerability reporting: Security and Responsible Disclosure.
5. Other Service Providers (Subprocessors)
You give general authorization for us to use other service providers — subprocessors in the language of the law (GDPR Art. 28, KVKK Art. 12). The current list is on the Other Service Providers page. We update that page and notify you at least 30 days before adding a new subprocessor; if you object on reasonable grounds and no solution is found, you may terminate the affected service without penalty. We impose obligations on subprocessors equivalent to those in this DPA and remain responsible to you for their performance.
6. Data Subject Requests
If a data subject contacts us directly, we refer them to you. We provide the technical means (export, correction, deletion) inside the service and assist you to a reasonable extent.
7. Breach Notification
On becoming aware of a personal data breach we notify you without undue delay and within 48 hours at the latest. The notice covers the nature of the breach, the categories of data affected, likely consequences and measures taken. Notifying the competent authority is your responsibility.
8. Assessment and Audit
On request we provide reasonable information and documentation about the security of the service (architecture summary, list of security measures, third-party reports where available). Where this is insufficient, we accept one audit per year, with at least 30 days' notice and under confidentiality, at your cost.
9. Deletion and Return
On termination we allow 30 days for you to export the data. At the end of that period we delete or anonymize it; copies in backups age out within the backup cycle (at most 90 days). Where law requires retention, we keep the data and process it for that purpose only.
10. International Transfers and Annexes
Transfer safeguards are set out per region in the annexes below. The annexes form part of this DPA; the relevant official texts are incorporated by reference and are not reproduced here.
Annex A — EU/EEA and United Kingdom
- The requirements of GDPR Art. 28 are met by this DPA.
- For transfers from the EEA, the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914), Module 2 (controller to processor), apply; in case of conflict the SCCs prevail over this DPA.
- For transfers from the United Kingdom, the UK International Data Transfer Addendum (ICO) is appended to the SCCs.
- We provide the information needed for a transfer impact assessment on request.
- For Swiss transfers, the SCCs apply as adapted to the FADP (supervisory authority FDPIC; references to "member state" read as Switzerland).
Annex B — Türkiye
- This DPA satisfies the data security obligations under KVKK Art. 12.
- For regular transfers abroad, a standard contract under KVKK Art. 9 is executed and notified to the Authority; we share a copy on request.
- As controller, the transparency duty and, where required, obtaining explicit consent remain yours.
- If VERBİS registration applies to you, we provide the information you need for your own registration.
Annex C — United States
- For CCPA/CPRA purposes, Praxtify acts as a service provider.
- We do not sell or share personal information, and do not retain, use or disclose it outside the purposes of the agreement.
- We certify that we will comply with these restrictions; you may notify us of non-compliance and require us to take appropriate steps.
11. Conflict
If this DPA conflicts with the Terms of Use, this DPA prevails on personal data matters. If an annex conflicts with the body of this DPA, the annex prevails.
12. Contact
Data protection matters: privacy@praxtify.com · Praxtify, LLC, 131 Continental Dr, Suite 305, Newark, DE 19713, USA.

