Legal
Data Processing & Compliance
This page explains how Addlaa processes data on your behalf, the safeguards we apply, and how we help you meet your own compliance obligations. It complements our Privacy Policy and, for Enterprise customers, a signed Data Processing Agreement (DPA).
Last updated: July 2026
1. Roles: controller and processor
For the marketing and business data you connect to run analyses, you are the data controller and Addlaa acts as a data processor, processing that data only on your documented instructions to provide the service. For account and website information, Addlaa acts as a controller as described in our Privacy Policy.
2. Scope of processing
- Subject matter: providing AI analysis, reporting, and collaboration on the data you connect.
- Data types: the marketing, advertising, and business metrics in the files, sheets, or sources you connect.
- Duration: for the term of your subscription, and deletion afterward as described below.
3. Security measures
We apply technical and organizational measures appropriate to the risk, including encryption in transit and at rest, role-based access control, workspace isolation, audit logging, and least-privilege operational access. Enterprise adds SSO, advanced access controls, and a security & compliance review. See Security & Trust.
4. Sub-processors
We use a limited set of vetted sub-processors (for example, cloud hosting, email, and CRM) under written terms that require confidentiality and equivalent data-protection commitments. We maintain a current list and provide notice of material changes to customers under a DPA.
5. International transfers
Where data is transferred across borders, we rely on appropriate safeguards such as Standard Contractual Clauses and equivalent mechanisms. Enterprise customers can discuss data-region requirements as part of their agreement.
6. Your compliance (GDPR, CCPA & more)
- We support your data-subject requests (access, correction, deletion, export) for data processed on your behalf.
- We do not sell personal information and do not use your connected data to train models for other customers.
- We notify you without undue delay of any confirmed personal-data breach affecting your data.
7. Retention & deletion
You control the data in your workspace and can delete analyses at any time. On termination, we delete or return customer data within a commercially reasonable period, except where retention is required by law.
8. Data Processing Agreement
Enterprise and regulated customers can request a signed DPA covering the commitments above. Contact privacy@addlaa.com or your account team to put one in place.
This document is provided for general information and does not constitute legal advice. Please have qualified counsel review it before you rely on it.