Legal

Data Processing Agreement

Last updated July 24, 2026

Data Processing Agreement

Last updated: July 24, 2026

This Data Processing Agreement ("DPA") supplements the AnnounceFly Terms of Service and applies where you ("Controller") process personal data of your end-users using AnnounceFly ("Processor") under the UK GDPR, EU GDPR, or equivalent data protection legislation.

1. Definitions

  • Personal Data — any information relating to an identified or identifiable natural person processed through the Service.
  • Controller — the entity that determines the purposes and means of processing.
  • Processor — AnnounceFly, acting on the Controller's instructions.
  • Sub-processor — a third-party processor engaged by AnnounceFly.

2. Processing Instructions

AnnounceFly will process personal data only on documented instructions from you and not for any other purpose. If applicable law requires otherwise, we will inform you unless legally prohibited.

3. Confidentiality

AnnounceFly ensures that persons authorised to process personal data are bound by confidentiality obligations and have access only on a need-to-know basis.

4. Security Measures

We implement appropriate technical and organisational measures including:

  • TLS 1.2+ encryption for data in transit
  • AES-256 encryption for data at rest
  • Access controls and principle of least privilege
  • Regular security assessments and patching
  • Incident response procedures

5. Sub-processors

You authorise AnnounceFly to engage sub-processors for cloud hosting, email delivery, and payment processing. We will notify you of material changes with at least 14 days' notice. Sub-processors are bound by obligations at least as protective as this DPA.

6. Data Subject Rights

AnnounceFly will assist you in fulfilling obligations to respond to data subject requests (access, rectification, erasure, restriction, portability, objection) through the admin dashboard tools.

7. Data Breach Notification

AnnounceFly will notify you without undue delay (within 72 hours where feasible) of a personal data breach, including: description of the breach, categories and approximate number of affected data subjects and records, likely consequences, and measures taken or proposed.

8. Data Protection Impact Assessments

AnnounceFly will provide reasonable assistance for DPIAs where processing is likely to result in high risk to data subjects, and for prior consultations with supervisory authorities where required.

9. Return and Deletion of Data

Upon termination or written request, AnnounceFly will delete or return all personal data within 30 days and certify such deletion, unless retention is required by applicable law.

10. Audits

AnnounceFly will provide information necessary to demonstrate compliance with this DPA and support audits by you or your mandated auditor, subject to reasonable notice and confidentiality obligations.

11. International Transfers

Where data is transferred internationally, AnnounceFly relies on Standard Contractual Clauses or equivalent mechanisms approved by the relevant supervisory authority.

12. Governing Law

This DPA is governed by the same law as the Terms of Service.

13. Contact

DPA queries: privacy@announcefly.com.