This DPA supplements our Terms of Service and Privacy Policy
Last Updated: November 5, 2025
This Data Processing Agreement ("DPA") forms part of the agreement between PromptAssist ("Data Processor") and the customer ("Data Controller" or "you") for the provision of PromptAssist services. This DPA governs the processing of personal data by PromptAssist on behalf of its customers in compliance with applicable data protection laws, including the General Data Protection Regulation (GDPR).
For purposes of this DPA:
This DPA applies to the processing of personal data by PromptAssist as Data Processor for the Data Controller in connection with the provision of PromptAssist services. This DPA is legally binding and forms an integral part of the service agreement.
The subject matter of the data processing is the optimization and management of AI prompts and related analytics.
This DPA will remain in effect for the duration of the service agreement between PromptAssist and the Data Controller.
PromptAssist processes personal data to provide the following services:
Depending on customer usage, PromptAssist may process:
PromptAssist will process personal data only on documented instructions from the Data Controller, including with regard to international data transfers, unless required to do so by applicable law.
PromptAssist ensures that persons authorized to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
PromptAssist implements appropriate technical and organizational measures, including:
PromptAssist assists the Data Controller by appropriate technical and organizational measures, insofar as possible, for the fulfilment of the Data Controller's obligation to respond to requests for exercising the data subject's rights.
PromptAssist assists the Data Controller in:
At the choice of the Data Controller, PromptAssist will delete or return all personal data to the Data Controller after the end of the provision of services relating to processing, and delete existing copies unless EU or Member State law requires storage.
PromptAssist may engage sub-processors for specific processing activities. A current list of sub-processors is available below and may be updated from time to time.
PromptAssist uses the following categories of sub-processors:
| Sub-processor | Purpose | Location | Data Protection |
|---|---|---|---|
| OpenAI | AI processing | US/EU | DPA available |
| Anthropic | AI processing | US | DPA available |
| Paddle | Payment processing | EU/US | PCI-DSS compliant |
| Cloud Hosting Provider | Infrastructure | EU/US | SOC 2, ISO 27001 |
| Analytics Provider | Usage analytics | US/EU | Anonymized data only |
PromptAssist ensures that sub-processors are bound by data protection obligations no less protective than those in this DPA.
PromptAssist remains fully liable to the Data Controller for the acts and omissions of its sub-processors.
When transferring personal data outside the EEA or UK, PromptAssist ensures adequate protection through:
All international transfers are conducted in accordance with applicable data protection laws and with appropriate safeguards in place.
PromptAssist provides reasonable assistance to the Data Controller with data protection impact assessments and prior consultations with supervisory authorities where required by GDPR Articles 35 and 36.
PromptAssist will notify the Data Controller without undue delay after becoming aware of a personal data breach affecting the Data Controller's data. Such notification will include:
PromptAssist makes available to the Data Controller all information necessary to demonstrate compliance with this DPA and allows for and contributes to audits and inspections.
PromptAssist's total liability arising out of or related to this DPA shall be limited as set forth in the main service agreement. Nothing in this DPA reduces PromptAssist's liability for non-compliance with its obligations under GDPR or the Data Controller's obligations under GDPR.
This DPA is governed by the same law as the main service agreement, unless otherwise required by applicable data protection law.
In the event of a conflict between this DPA and the main service agreement, this DPA shall prevail with respect to the subject matter herein.
Upon termination of the service agreement, PromptAssist will delete or return personal data in accordance with Section 5.6 of this DPA.
For questions about this DPA or data processing:
The following security measures are implemented by PromptAssist:
Note: This DPA is provided as a standard template. Enterprise customers may request a customized DPA with additional safeguards based on their specific requirements. Contact our legal team at legal@promptassist.com.
We use cookies to enhance your experience, analyze site traffic, and personalize content. You can customize your preferences or accept all to continue.