EasyContent Data Processing Agreement
Last updated: October 1, 2026
This Data Processing Agreement ("DPA") forms part of the EasyContent Terms of Service, or any other written agreement for the EasyContent service (the "Agreement"), between EasyContent LLC, a Florida limited liability company ("EasyContent"), and the customer that has agreed to the Agreement ("Customer"). It applies automatically to every customer whose use of the Service involves the processing of Customer Personal Data. A customer that wants a countersigned copy can request one at support@easycontent.io.
Capitalized terms not defined in this DPA have the meanings given in the Agreement.
1. Definitions
"Data Protection Laws" means all data protection and privacy laws that apply to the processing of Customer Personal Data under the Agreement, including, where applicable, the EU GDPR, the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and United States state privacy laws such as the California Consumer Privacy Act as amended (the "CCPA").
"EU GDPR" means Regulation (EU) 2016/679. "UK GDPR" means the EU GDPR as it forms part of UK law.
"Customer Personal Data" means personal data contained in Content that EasyContent processes on behalf of Customer in providing the Service.
"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data while processed by EasyContent or its Subprocessors.
"Subprocessor" means any third party that EasyContent engages to process Customer Personal Data.
"SCCs" means the standard contractual clauses approved by the European Commission in Implementing Decision (EU) 2021/914.
"UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, version B1.0, as updated from time to time.
"Controller," "processor," "data subject," "personal data," "processing," and "supervisory authority" have the meanings given in the EU GDPR, and equivalent terms in other Data Protection Laws (such as "business" and "service provider" under the CCPA) are read accordingly.
2. Roles and scope
2.1 Customer is the controller of Customer Personal Data, or, where Customer acts on behalf of its own clients, a processor acting on its clients' instructions. EasyContent is Customer's processor, or subprocessor, as the case may be.
2.2 This DPA covers Customer Personal Data only. EasyContent processes account, billing, and usage data about Customer and its Users as an independent controller, as described in its Privacy Policy and GDPR Policy, and this DPA does not apply to that processing.
2.3 The subject matter, duration, nature and purpose of processing, and the categories of data subjects and personal data are described in Annex I.
3. Customer's obligations
3.1 Customer is responsible for the lawfulness of the Customer Personal Data it submits and for having a lawful basis, and giving any required notices and obtaining any required consents, for EasyContent's processing under this DPA.
3.2 Customer will not submit special categories of personal data (Article 9 EU GDPR), data relating to criminal convictions, government identification numbers, financial account numbers, or health information to the Service, unless agreed with EasyContent in writing.
3.3 Customer controls whether AI features are enabled for its account, projects, and Users, and acknowledges that when a User runs an AI feature, the relevant Content is processed by the AI Subprocessors listed in Annex III.
4. EasyContent's obligations
4.1 Instructions. EasyContent will process Customer Personal Data only on Customer's documented instructions, including with regard to international transfers, unless required to do otherwise by law, in which case EasyContent will inform Customer of that legal requirement before processing unless the law prohibits it. The Agreement, this DPA, and Customer's configuration and use of the Service are Customer's complete instructions. EasyContent will inform Customer if, in its opinion, an instruction infringes Data Protection Laws.
4.2 Confidentiality. EasyContent will ensure that every person it authorizes to process Customer Personal Data is bound by an appropriate obligation of confidentiality.
4.3 Security. EasyContent will implement and maintain the technical and organizational measures described in Annex II. EasyContent may update those measures, provided that updates do not materially reduce the overall level of protection.
4.4 No training. EasyContent will not use Customer Personal Data to train artificial intelligence or machine learning models.
4.5 CCPA. To the extent the CCPA applies, EasyContent will not sell or share Customer Personal Data, retain, use, or disclose it for any purpose other than providing the Service, or retain, use, or disclose it outside the direct business relationship between EasyContent and Customer, and will not combine it with personal data EasyContent receives from other sources except as the CCPA permits. EasyContent will notify Customer if it can no longer meet its obligations under the CCPA.
5. Subprocessors
5.1 Customer gives EasyContent general authorization to engage Subprocessors. The Subprocessors in use on the date of this DPA are listed in Annex III, and Customer authorizes them.
5.2 EasyContent will enter into a written agreement with each Subprocessor that imposes data protection obligations no less protective than those in this DPA, and remains responsible to Customer for each Subprocessor's performance of those obligations.
5.3 EasyContent will notify Customer by email to the account owner at least 30 days before engaging a new Subprocessor. Customer may object on reasonable data protection grounds within that period by writing to support@easycontent.io. The parties will discuss the objection in good faith. If they cannot resolve it, Customer may terminate the affected part of the Service by written notice and receive a refund of prepaid fees for the remainder of the subscription term after termination.
6. Data subject requests
Taking into account the nature of the processing, EasyContent will assist Customer by appropriate technical and organizational measures in responding to requests from data subjects to exercise their rights. Customer can access, correct, export, and delete most Customer Personal Data directly in the Service. If EasyContent receives a request directly from a data subject that relates to Customer Personal Data, it will redirect the data subject to Customer and will not respond itself unless Customer authorizes it or the law requires it.
7. Personal Data Breach
7.1 EasyContent will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach.
7.2 The notice will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects. Where information is not available at first, EasyContent will provide it in phases as it becomes available.
7.3 EasyContent will take reasonable steps to contain, investigate, and mitigate the breach and will provide reasonable assistance to Customer in meeting its own notification obligations. A notice under this Section is not an admission of fault or liability.
8. Assistance
EasyContent will provide reasonable assistance to Customer, taking into account the nature of the processing and the information available to EasyContent, with data protection impact assessments and prior consultations with supervisory authorities that relate to Customer's use of the Service.
9. Audits
9.1 EasyContent will make available to Customer the information reasonably necessary to demonstrate compliance with this DPA, including by responding to Customer's reasonable written security questionnaires, no more than once in any 12-month period unless a Personal Data Breach has occurred or a supervisory authority requires it.
9.2 If that information is not sufficient to demonstrate compliance, or a supervisory authority requires it, Customer may conduct an audit, including an inspection, by an auditor bound by confidentiality, on at least 30 days' written notice, during normal business hours, in a manner that does not unreasonably disrupt EasyContent's operations or compromise the security of other customers' data. Customer bears its own costs of any audit. Information obtained through an audit is EasyContent's Confidential Information.
10. International transfers
10.1 EasyContent is located in the United States, and it and its Subprocessors process Customer Personal Data in the United States. Customer authorizes these transfers.
10.2 EEA transfers. To the extent Customer Personal Data subject to the EU GDPR is transferred to EasyContent outside the EEA and the transfer is not covered by an adequacy decision applicable to EasyContent, the SCCs are incorporated into this DPA by reference and apply as follows:
- Module Two (controller to processor) applies where Customer is a controller, and Module Three (processor to processor) applies where Customer is a processor.
- Customer is the "data exporter" and EasyContent is the "data importer."
- Clause 7 (docking clause) applies.
- Clause 9(a): Option 2 (general written authorization) applies, with the notice period set out in Section 5.3 of this DPA.
- Clause 11(a): the optional language does not apply.
- Clause 13: where Customer is established in the EEA, the supervisory authority of the member state in which Customer is established; where Customer is not established in the EEA but falls within Article 3(2) EU GDPR, the supervisory authority of the member state in which Customer's representative is established, or, where Customer is not required to appoint a representative under Article 27(2) EU GDPR, the supervisory authority of the member state in which the data subjects whose personal data is transferred are located. Where those data subjects are located in more than one member state, the competent authority is that of the member state Customer designates in writing, or, failing designation, the member state in which the largest number of affected data subjects are located.
- Clause 17: Option 1 applies, and the SCCs are governed by the laws of Ireland.
- Clause 18(b): disputes are resolved before the courts of Ireland.
- Annex I of the SCCs is completed by Annex I of this DPA, Annex II of the SCCs by Annex II of this DPA, and Annex III of the SCCs by Annex III of this DPA.
10.3 UK transfers. To the extent Customer Personal Data subject to the UK GDPR is transferred, the SCCs as completed in Section 10.2 apply as amended by the UK Addendum, which is incorporated into this DPA by reference. Table 1 of the UK Addendum is completed with the parties' details in Annex I; Table 2 with the modules and options selected in Section 10.2; Table 3 with Annexes I to III of this DPA; and in Table 4 neither party may end the UK Addendum under its Section 19.
10.4 Swiss transfers. To the extent Customer Personal Data subject to the Swiss Federal Act on Data Protection (FADP) is transferred, the SCCs as completed in Section 10.2 apply with these amendments: references to the EU GDPR are read as references to the FADP; the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner; the term "member state" does not exclude data subjects in Switzerland from bringing claims in their place of habitual residence; and the SCCs are governed by Swiss law where the FADP so requires.
10.5 If the SCCs or the UK Addendum are replaced or invalidated, the parties will cooperate in good faith to put in place an alternative lawful transfer mechanism. If EasyContent adopts an alternative mechanism recognized under Data Protection Laws, such as certification under the EU-U.S. Data Privacy Framework, it may rely on that mechanism instead, to the extent it covers the transfer.
10.6 If the SCCs conflict with this DPA or the Agreement, the SCCs prevail to the extent of the conflict.
11. Return and deletion
11.1 Customer can export Content from the Service at any time during its subscription.
11.2 After the Agreement ends, EasyContent retains and then deletes Customer Personal Data in accordance with the retention schedule in the Agreement and the GDPR Policy, under which a cancelled paid account is retained for 2 years after the last billing period so Customer may reactivate it, and is then permanently deleted. By entering into this DPA, Customer instructs that retention. Customer may instead delete its account at any time with the Delete account button in Account Settings, which permanently deletes the account and its Customer Personal Data from the Service immediately, or instruct deletion by writing to support@easycontent.io, in which case EasyContent will complete deletion within 30 days.
11.3 Customer Personal Data in encrypted backups is deleted as the backups are overwritten in the ordinary course. Copies held by EasyContent or its Subprocessors in logs, diagnostics, or records of AI requests are deleted on the applicable retention periods, which for EasyContent's server logs is no longer than 90 days, for records of AI requests in LangSmith is no longer than 14 days, and for error diagnostics in Sentry is no longer than 90 days. Customer Personal Data in support correspondence, including email held in Google Workspace, is kept no longer than needed to handle the request and any follow-up, and in any case no longer than the account data it relates to. Customer Personal Data remains protected by this DPA until it is deleted. EasyContent may retain Customer Personal Data where the law requires it, subject to continued confidentiality and security under this DPA.
12. Liability
Each party's liability arising out of or related to this DPA, including the SCCs to the extent permitted by law, is subject to the limitations and exclusions of liability in the Agreement. Nothing in this DPA limits either party's liability to data subjects under the SCCs.
13. Term, precedence, and governing law
13.1 This DPA remains in effect for as long as EasyContent processes Customer Personal Data.
13.2 If this DPA conflicts with the Agreement on the processing of Customer Personal Data, this DPA prevails, subject to Section 10.6.
13.3 Except as stated in Section 10 for the SCCs and the UK Addendum, this DPA is governed by the law and forum provisions of the Agreement.
13.4 EasyContent may update this DPA to reflect changes in Data Protection Laws or in the Service, provided that updates do not materially reduce the protection given to Customer Personal Data. EasyContent will notify Customer of material updates in the same way as material changes to the Agreement.
Annex I: Description of processing
A. List of parties
Data exporter
- Name: the Customer that has agreed to the Agreement, as identified in its account or Order Form
- Address and contact details: as provided in Customer's account
- Activities relevant to the transfer: use of the EasyContent service to plan, create, review, approve, and publish content
- Role: controller (Module Two) or processor (Module Three)
- Signature and date: Customer's acceptance of the Agreement is treated as its signature of the SCCs and this Annex, on the date of that acceptance
Data importer
- Name: EasyContent LLC
- Address: 11505 Fountainhead Dr, Tampa, Florida 33626, United States
- Contact: support@easycontent.io
- Activities relevant to the transfer: provision of the EasyContent content workflow service
- Role: processor
- Signature and date: EasyContent's publication and acceptance of this DPA is treated as its signature, on the date Customer accepts the Agreement
B. Description of transfer
Categories of data subjects: Customer's Users (employees, contractors, and guest reviewers), and any individuals whose personal data Customer or its Users include in Content, such as Customer's clients, their staff, and people named in content.
Categories of personal data: names, email addresses, job titles, and other identifiers and contact details included in Content; comments, messages, approvals, and feedback; files and images uploaded to the Service; and any other personal data Customer chooses to include in Content.
Sensitive data: none. Customer agrees not to submit special categories of data (Section 3.2).
Frequency of the transfer: continuous, for the duration of the Agreement.
Nature of the processing: hosting, storage, organization, retrieval, transmission, display, AI-assisted drafting and editing when invoked by Customer's Users, backup, and deletion.
Purpose of the processing: to provide the Service to Customer under the Agreement, including customer support and securing and maintaining the Service.
Retention period: as set out in Section 11 of this DPA.
Transfers to Subprocessors: as listed in Annex III, for the purposes stated there, for durations governed by the retention periods in Section 11, and in any case no longer than the duration of EasyContent's processing under this DPA.
C. Competent supervisory authority
The supervisory authority identified under the Clause 13 rule in Section 10.2 of this DPA, including its rule for data subjects located in more than one member state.
Annex II: Technical and organizational security measures
- Hosting. The Service is hosted on Amazon Web Services infrastructure in the United States, whose physical data center security, redundancy, and environmental controls are managed by AWS.
- Encryption. Customer Personal Data is encrypted in transit using TLS and encrypted at rest in the database, in file storage (Amazon S3), and in backups.
- Authentication. User passwords are stored only as one-way hashes. Single sign-on is available on the Business and Enterprise plans.
- Access control within the Service. Role-based permissions at the account, project, and User level; workflow permissions restricting editing and approval by stage; review links limited to the item shared, with access set per link (view, comment, or edit), where commenting, editing, and approving require a registered guest account and anyone holding a link can view the item and view and download its attachments; and account-, project-, and User-level controls over AI features.
- Access control for EasyContent personnel. Access to production systems and Customer Personal Data is limited to personnel who need it to operate, support, and secure the Service, and who are bound by confidentiality obligations.
- Availability and resilience. Daily encrypted database backups for disaster recovery; file storage on Amazon S3, designed by AWS for 99.999999999% durability of stored objects.
- Monitoring. Continuous monitoring of the Service and application error monitoring, and ongoing application of security updates.
- Security review. Periodic security audits of the Service and its infrastructure.
- Payment data. Payment card data is processed by Stripe, a PCI-compliant payment processor, and is never stored on EasyContent systems.
- Data minimization in AI processing. Content is sent to AI Subprocessors only when a User invokes an AI feature, and only the content and instructions needed for that request.
- Incident response. Procedures for handling suspected Personal Data Breaches, including containment, investigation, and notification as set out in Section 7.
- Deletion. Retention and deletion according to the schedule in Section 11, including permanent deletion on Customer instruction.
- Subprocessor management. Written data protection terms with each Subprocessor, as set out in Section 5.
Annex III: Subprocessors
| Subprocessor | Purpose | Location of processing |
|---|---|---|
| Amazon Web Services, Inc. | Hosting, database, file storage, backups, and transactional email (Amazon SES) | United States |
| Anthropic, PBC | AI model processing and web search for EasyAI features, when invoked by Users | United States |
| LangChain, Inc. (LangSmith) | Monitoring and quality control of AI requests | United States |
| Functional Software, Inc. (Sentry) | Application error monitoring | United States |
| Google LLC (Google Workspace) | Customer support email | United States |