Effective September 3, 2026
Data Processing Addendum
This DPA allocates controller and processor duties, sets security and breach commitments, and describes the processing performed for a Cloud customer.This Data Processing Addendum, or DPA, forms part of the Terms of Service between the business or organization using Prosewire Cloud, “Customer,” and the Cloud provider identified in those Terms, “Provider.” It applies when Provider processes Customer Personal Data on Customer’s behalf.
The DPA becomes effective when Customer accepts the Terms and uses Cloud for business processing. A customer that needs a signed counterpart, vendor form, or international transfer instrument must follow the execution process in Section 15 before sending covered data.
1. Definitions
“Applicable Data Protection Law” means a law that applies to the processing of Customer Personal Data, including the GDPR, UK GDPR, and applicable United States state privacy laws.
“Customer Personal Data” means personal data that Provider processes as a processor or service provider on Customer’s behalf through Prosewire Cloud. It excludes account, security, support, and relationship data that Provider processes as a controller under the Privacy Policy.
“Data Subject,” “personal data,” “personal data breach,” “process,” “processor,” and “controller” have the meanings given by Applicable Data Protection Law. “Subprocessor” means a third party appointed by Provider to process Customer Personal Data.
The European Commission controller and processor clauses inform this DPA, but this document does not replace a required international transfer instrument.
2. Roles and scope
Customer is the controller of Customer Personal Data. If Customer processes the data for another controller, Customer is a processor and Provider is its subprocessor. Provider is a processor or subprocessor as applicable.
The processing details in Annex A apply unless an order form gives more specific instructions. Customer instructs Provider to process Customer Personal Data to provide, secure, support, and maintain Prosewire Cloud; follow Customer’s use of service features; prevent or address technical problems and abuse; and comply with this DPA and law.
Provider will process Customer Personal Data only on documented instructions from Customer, including instructions about international transfers, unless law requires other processing. If law allows, Provider will tell Customer before processing under that requirement.
Provider will promptly tell Customer if, in Provider’s reasonable opinion, an instruction violates Applicable Data Protection Law. Provider may pause the affected processing while the parties resolve the issue.
3. Customer duties
Customer is responsible for:
- a lawful basis, required notices, and valid instructions for the processing;
- the accuracy, quality, and legality of Customer Personal Data;
- configuring roles, publication status, keys, embeds, and integrations appropriately;
- answering Data Subjects and regulators as controller;
- completing any transfer assessment or consultation required for its use; and
- avoiding restricted data listed in the Acceptable Use Policy unless a written order permits it.
Customer will not instruct Provider to process data in violation of law. Customer acknowledges that publishing a post makes its content public and may cause third parties outside Provider’s control to copy it.
4. Confidentiality
Provider will limit Customer Personal Data access to people and subprocessors who need it for the service, support, security, or legal compliance. Anyone authorized by Provider to process the data must have a contractual, professional, or statutory duty of confidentiality and receive appropriate security instructions.
The confidentiality duty continues after access ends.
5. Security
Provider will maintain technical and organizational measures appropriate to the risk, taking account of available technology, implementation cost, and the nature, scope, context, and purpose of processing. Current measures are described in Annex B and on the Security page.
Provider may update a measure if the change does not materially reduce the overall protection of Customer Personal Data. Customer is responsible for security controls under its account and in systems outside Prosewire Cloud.
6. Subprocessors
Customer gives general written authorization for the subprocessors on the Subprocessors page. Provider will bind each subprocessor by written data protection terms that provide substantially the same protection relevant to its work. Provider remains responsible for the subprocessor’s performance of those duties to the extent required by Applicable Data Protection Law.
Provider will give at least 15 days’ notice before a new subprocessor begins processing Customer Personal Data. Customer may object during that period on reasonable data-protection grounds. The parties will try to find a practical alternative. If none is available, Customer may stop using the affected feature or terminate the affected Cloud service before the change takes effect. An urgent security replacement may occur sooner, with notice as soon as practical.
7. Data Subject requests
Provider will promptly send Customer a request that clearly concerns Customer Personal Data unless law prevents it. Provider will not answer on Customer’s behalf without written instructions, except to confirm that the request was redirected.
Taking account of the nature of processing, Provider will give reasonable assistance through available product functions and support so Customer can respond to a request to access, correct, delete, restrict, object, or port data. Customer remains responsible for its response and may have to reimburse exceptional, documented costs for assistance beyond ordinary service operation.
8. Security incidents and personal data breaches
Provider will notify Customer without undue delay after becoming aware of a personal data breach involving Customer Personal Data. Provider’s operational target for an initial notice is 48 hours after awareness. Failure to meet the target does not change the “without undue delay” standard or create a service credit.
As information becomes available, the notice will describe:
- the nature of the breach;
- affected data and categories and approximate numbers of Data Subjects and records;
- likely consequences;
- containment, mitigation, and remediation;
- recommended Customer action; and
- a contact point for follow-up.
Provider may send information in stages and will not delay an initial notice solely because the investigation is incomplete. Provider will take reasonable steps to contain, investigate, mitigate, and document the breach. Notice is not an admission of fault.
Customer is responsible for notice to its Data Subjects and authorities. Provider will give reasonable assistance with those duties, taking account of the information available and the nature of processing. The public Security and Incident Response page describes the operational process.
9. Assessments and regulator consultation
Provider will provide information reasonably needed for Customer’s data protection impact assessment or prior consultation where the requested information concerns Prosewire Cloud and is not otherwise available. Provider may satisfy a request with current documentation, provider reports, or a confidential response.
10. Return and deletion
During the service term, Customer may use available exports to retrieve content. Customer should export needed data before closure.
At the end of the covered service, Provider will delete Customer Personal Data from the active service within 30 days, unless Customer requests return before deletion or law requires retention. Protected backups roll off within the period in the Deletion and retention policy. Provider will keep retained data isolated and use it only for the required purpose.
Customer can request written confirmation after the deletion period. Public copies made by third parties and data sent to Customer-controlled integrations are not within Provider’s deletion control.
11. Information and audits
Provider will make information reasonably necessary to show compliance with this DPA available to Customer. Once in any 12-month period, Customer may request a remote audit of relevant policies, records, and systems. Extra audits are allowed after a material breach or when a regulator requires one.
Customer must give at least 30 days’ notice unless urgency makes that impractical. An audit must protect other customers, avoid access to their data, follow reasonable security rules, and avoid unnecessary service disruption. Provider may use an independent report or written responses when they reasonably address the request. Customer pays its audit costs and Provider’s reasonable costs for work beyond ordinary compliance support.
12. Government demands
Provider will review a government demand for Customer Personal Data and disclose only what law requires. Unless prohibited, Provider will notify Customer before disclosure so Customer may seek protection. Where reasonable and lawful, Provider will challenge a demand that appears invalid, overbroad, or inconsistent with applicable safeguards.
13. International transfers
The Data location disclosure applies. Prosewire Cloud does not currently promise country-specific residency.
If Customer Personal Data is transferred from the EEA to a country that lacks an applicable adequacy decision and Provider is not already directly subject to the GDPR for that processing, the parties will use Module 2 of the European Commission Standard Contractual Clauses when Customer is controller and Module 3 when Customer is processor. For the UK, the parties will also complete the ICO International Data Transfer Addendum or another valid mechanism.
Those instruments require completed party details, selections, and annexes. This public DPA does not by itself complete them. Customer must request a countersigned transfer package under Section 15 before making a restricted transfer. Customer remains responsible for deciding whether a transfer impact assessment or extra safeguard is required.
14. United States state privacy terms
Where an applicable United States state privacy law treats Provider as a service provider, processor, or contractor, Provider will:
- process Customer Personal Data only for the business purposes in this DPA and Customer’s instructions;
- not sell or share Customer Personal Data for cross-context behavioral advertising;
- not retain, use, or disclose it outside the direct business relationship except as permitted by law;
- not combine it with personal data received from another source except as allowed to provide the service; and
- provide the same level of privacy protection required of Customer for the delegated processing.
Customer may take reasonable and appropriate steps to confirm compliant processing and to stop and remediate unauthorized use, subject to the audit process above. Provider will notify Customer if it determines it can no longer meet an applicable obligation.
15. Execution and contact
For an ordinary business account, this DPA is incorporated into the Terms electronically. To request a signed counterpart or transfer package, email legal@prosewire.com with “DPA request” in the subject and provide:
- Customer’s full legal name and postal address;
- the workspace name;
- the signatory’s name, title, and email;
- Customer’s role as controller or processor;
- the countries from which covered data will be transferred; and
- any required procurement deadline.
Do not send Customer Personal Data with the request. A required transfer instrument is effective only after the parties complete the mandatory information and make it binding.
16. Term, conflict, and liability
This DPA continues while Provider processes Customer Personal Data. If it conflicts with the Terms on personal data processing, this DPA controls. A signed order controls only if it expressly identifies the provision it replaces. A mandatory transfer instrument controls over both for a covered transfer.
The liability terms in the Terms apply to this DPA to the extent law permits. Nothing in this DPA limits a Data Subject’s rights under a mandatory transfer instrument or limits liability where Applicable Data Protection Law forbids a limit.
Annex A. Processing details
| Item | Description |
|---|---|
| Subject matter | Hosted editorial workspaces, publications, readers, APIs, exports, authentication, support, and security |
| Duration | The Cloud service term plus deletion and backup periods stated in this DPA |
| Nature and purpose | Receive, store, organize, retrieve, render, publish, transmit, secure, export, correct, restrict, and delete data according to Customer’s use and instructions |
| Data Subjects | Customer users, invited team members, authors, people named in Customer content, publication visitors, and other people whose data Customer submits |
| Personal data | Names, contact details, role and membership, authentication and session records, IP address and user agent, customer content, author profiles, audit history, API key metadata, referrer, and reader event identifiers |
| Special category data | Not intended or approved without a written order |
| Frequency | Continuous as Customer and its readers use the service |
| Customer instructions | The Terms, this DPA, a signed order, product configuration, and documented support instructions from an authorized Customer contact |
Annex B. Technical and organizational measures
Provider maintains measures that include:
- HTTPS for public service traffic;
- server-side authentication and authorization;
- workspace and publication tenancy checks;
- role-based access for management actions;
- hashed management keys and protected authentication records;
- separate editorial states for draft, scheduled, published, and archived content;
- rich-content sanitization before public rendering;
- audit records for management changes;
- secret configuration outside source control and redaction of sensitive configuration in application logging;
- dependency and source scanning in the development and release process;
- protected infrastructure backups under the retention schedule;
- incident intake, containment, investigation, notification, recovery, and review; and
- confidentiality and least-access expectations for maintainers and subprocessors.
Customer controls user roles, content status, key distribution, integrations, public domains, exports, and endpoint use. Security measures for a self-hosted deployment are outside this DPA.
Annex C. Approved subprocessors
The current Subprocessors page is incorporated into this Annex. It identifies the provider, purpose, data, and processing-location disclosure and records its last review date.