Data Processing Addendum

Denly · Operated by Control Plane · Effective: August 3, 2026

This Data Processing Addendum ("DPA") forms part of the Terms of service between you (the "Customer", acting as data Controller) and Control Plane (the "Processor") for Denly (the "Service"). It applies wherever Denly processes personal data on the Customer's behalf. By using the Service, the Customer agrees to this DPA; no countersignature is required, in line with how Denly is self-served through the dashboard rather than sold through a separately negotiated contract. If your organization requires a countersigned copy, contact us at legal@denly.dev.

1. Definitions

"Personal Data", "Processing", "Controller", "Processor", and "Data Subject" have the meanings given in applicable data protection law (including the EU/UK GDPR, where applicable). "Sub-processor" means a third party the Processor engages to process Personal Data in providing the Service.

2. Roles

The Customer is the Controller of the Personal Data it submits to the Service. Control Plane is the Processor, acting only on the Customer's instructions as set out in the Terms of Service, this DPA, and the Customer's ordinary configuration of the Service.

3. Subject Matter & Duration

The subject matter is Control Plane's provision of Denly to the Customer. Processing continues for the duration of the Customer's use of the Service and thereafter only as needed to meet the retention and deletion obligations in §7.

4. Nature, Purpose & Categories of Data

The nature and purpose of processing, and the categories of Personal Data and Data Subjects involved, are as described in our Privacy policy and, in full schema detail, in our published data map. In summary: account identity of the Customer's own users, organization/project/task metadata, and (with end-to-end encryption enabled) encrypted task content the Processor cannot read. Data Subjects are the Customer's own personnel who use the Service.

5. Processor Obligations

6. Sub-processors

The Customer authorizes the Processor to engage the sub-processors listed on our Subprocessors page, which is kept current and describes what each one does and what it receives. The Processor will give reasonable notice of a new sub-processor via that page's effective date; the Customer's objection rights are described there.

7. Data Retention & Deletion

Personal Data is retained as described in our Privacy policy §6 (automatic, schedule-based deletion by category) and deleted immediately on account deletion at the Customer's request, except where a copy must be retained to meet a legal obligation.

8. Security Incidents

The Processor will notify the Customer without undue delay after becoming aware of a Personal Data breach affecting the Customer's data, and will provide information reasonably available to help the Customer meet its own notification obligations.

9. International Transfers

Where Personal Data is transferred outside the Data Subject's region, the Processor relies on the transfer mechanisms available under applicable law (such as the sub-processors' own Standard Contractual Clauses or equivalent safeguards) via the sub-processors listed on our Subprocessors page.

10. Audit

On reasonable written request, and no more than once per year absent a security incident, the Processor will provide the Customer with information reasonably necessary to demonstrate compliance with this DPA, which may include a summary of security measures in lieu of an on-site audit.

11. Liability & Governing Law

Liability under this DPA is subject to the limitations in the Terms of Service. This DPA is governed by the laws of the State of Israel, the same as the Terms of Service.

12. Contact

Data protection questions, or a request for a countersigned copy of this DPA: legal@denly.dev.