Data Processing Agreement (DPA)

Last Updated: 24-1-2026

1. Introduction

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Contenvo (“Processor”) and the User (“Controller”).

 

By using the Contenvo platform to process personal data (e.g., generating content for your clients or connecting your website data), you agree to the terms of this DPA.

2. Definitions

  • “Controller”: You, the customer/user of Contenvo.

  • “Processor”: Us, Contenvo (the SaaS platform).

  • “Personal Data”: Any information relating to an identified or identifiable natural person (e.g., names in your blog posts, user emails).

  • “Sub-processor”: Third-party businesses we use to run our service (e.g., OpenAI, AWS, Stripe).

3. Details of Processing

  • Subject Matter: The provision of AI content generation and website insights via the Contenvo platform.

  • Duration: For the term of the User’s subscription to Contenvo.

  • Nature and Purpose: Storing, retrieving, and generating text data based on User instructions (API inputs).

  • Categories of Data: Text content, website metadata, and user account details.

4. Obligations of the Processor (Contenvo)

We agree to:

  1. Process Data Only on Instructions: We will only process your data to provide the Service as described in our Terms of Service.

  2. Confidentiality: Ensure that all employees authorized to process personal data have committed themselves to confidentiality.

  3. Security Measures: Implement appropriate technical and organizational measures (e.g., encryption, access controls) to ensure a level of security appropriate to the risk.

  4. Data Deletion: Upon termination of your account, we will delete or return all personal data to you, unless EU or Member State law requires storage.

5. Sub-processors

You grant us general authorization to engage the following sub-processors to provide the Service:

  • Hosting: Hetzner

  • AI Models: OpenAI

  • Analytics: Google Analytics, Hotjar

  • Email: MailerLite

  • Payments: Stripe

We will inform you of any intended changes concerning the addition or replacement of other processors, giving you the opportunity to object to such changes.

6. Data Breaches

In the event of a Personal Data Breach affecting your data, we will notify you without undue delay after becoming aware of it. We will provide you with sufficient information to allow you to meet any obligations to report the breach to data protection authorities.

7. International Transfers

If we transfer data outside the European Economic Area (EEA), we ensure such transfers are supported by an adequate legal mechanism, such as the EU Standard Contractual Clauses (SCCs).

8. Audit Rights

Upon reasonable request and subject to confidentiality agreements, we will make available to you all information necessary to demonstrate compliance with this DPA.

Table of Contents