Data processing addendum

Effective Oct 9, 2026

This Data Processing Addendum (“DPA”) forms part of the agreement between Skyfield Digital LLC, doing business as Doily (“Doily”), and the customer accepting the Doily Terms of Service (“Customer”) (together the “Agreement”), and applies to the extent Doily processes Personal Data in Client Data on Customer’s behalf.

1. Definitions

“Data Protection Law” means all laws applying to the processing of Personal Data under the Agreement, including the EU GDPR, the UK GDPR and Data Protection Act 2018, the Swiss FADP, and U.S. state privacy laws including the CCPA/CPRA. “Personal Data”, “processing”, “controller”, “processor”, “business”, “service provider” and “data subject” have the meanings in the applicable law. “Client Data” means data Customer or its users submit to the Service, including data about Customer’s own clients and their end users. “SCCs” means the EU Standard Contractual Clauses (Commission Decision 2021/914). “UK Addendum” means the UK ICO’s International Data Transfer Addendum to the SCCs.

2. Roles and scope

2.1. For Client Data, Customer is the controller (or, where Customer is an agency processing on behalf of its own clients, a processor) and Doily is Customer’s processor (or subprocessor). Annex 1 describes the processing.

2.2. Where the CCPA applies, Doily is a service provider: Doily will not sell or share Personal Data, will not retain, use or disclose it other than to provide the Service or as the CCPA permits, will not combine it with data from other sources except to provide the Service, and certifies that it understands these restrictions.

2.3. Each party will comply with Data Protection Law applicable to it. Customer is responsible for the lawfulness of the Personal Data it submits, for its own privacy notices and lawful bases, and, where Customer is an agency, for its contracts with its own clients. Where Customer acts as a processor for its own clients, Customer is Doily’s single point of contact under this DPA, warrants that it has obtained all authorizations from the relevant controllers needed for Doily’s processing and for the subprocessor authorization in section 6, and will relay controller instructions to Doily as Customer’s own instructions.

3. Instructions

Doily will process Client Data only on Customer’s documented instructions, which are: the Agreement, Customer’s use and configuration of the Service, and other written instructions the parties agree. Doily will inform Customer if, in its opinion, an instruction infringes Data Protection Law, and may suspend the instruction until resolved. Doily will inform Customer before processing where required by law to process otherwise, unless the law prohibits that notice.

4. Confidentiality

Doily ensures that persons it authorizes to process Client Data are bound by confidentiality obligations and process it only as needed for their role. Access is role-based, least-privilege and logged.

5. Security

Doily implements and maintains the technical and organizational measures in Annex 2, which are designed in alignment with recognized industry frameworks (SOC 2 control criteria), and may update them provided the protection level does not materially decrease. Taking into account the nature of processing, Doily will assist Customer in meeting its own security obligations with information reasonably available to Doily.

6. Subprocessors

6.1. Customer gives general authorization for the subprocessors listed at doily.ai/subprocessors (reproduced at the effective date in Annex 3). Doily will provide notice of additions or replacements through that page’s notification list at least 15 days before the new subprocessor processes Client Data.

6.2. Customer may object on reasonable data protection grounds within that notice period. The parties will work in good faith to resolve the objection; if it cannot be resolved, Customer may terminate the affected services with a pro rata refund of prepaid unused fees.

6.3. Doily contracts with each subprocessor in writing on terms materially as protective as this DPA and remains liable for its subprocessors’ performance.

7. Data subject requests

Taking into account the nature of processing, Doily will assist Customer with appropriate technical and organizational measures to respond to data subject requests (access, correction, deletion, portability, restriction, objection), primarily through the Service’s own export, correction and deletion features. If a data subject contacts Doily directly about Client Data, Doily will not respond substantively except to direct them to Customer, unless the law requires otherwise. Doily will also reasonably assist Customer with related inquiries and complaints from data subjects and communications from supervisory authorities concerning the Service.

8. Personal data breach

Doily will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Client Data, including a reasonably suspected one, with the information reasonably available at the time: the nature of the breach, categories and approximate volumes affected, likely consequences, and measures taken or proposed, supplemented as the investigation proceeds. Any delay beyond 72 hours will be explained. Doily will take reasonable steps to contain and remediate the breach and will cooperate with Customer’s own notification obligations. Notification is not an admission of fault.

9. Assistance

Taking into account the nature of processing and information available to it, Doily will provide reasonable assistance with Customer’s data protection impact assessments and prior consultations with supervisory authorities, to the extent they concern the Service.

10. Deletion and return

Upon termination or expiry of the Agreement, the Service provides a 30-day window to export Client Data in full. After that window, Doily deletes Client Data from its systems (with backup copies aging out on the backup cycle shortly after and remaining protected under this DPA until then), except where law requires retention, in which case the data stays protected under this DPA and is isolated from further processing. Deletion on request during the term is available through the Service’s deletion features.

11. Audits

11.1. Doily will make available information reasonably necessary to demonstrate compliance with this DPA, including summaries of third-party assessments, penetration test attestations and security documentation.

11.2. Where Data Protection Law gives Customer an audit right that the information above does not satisfy, Customer may conduct, at its own expense and no more than once per 12 months (or more often where a supervisory authority requires it), an audit of Doily’s relevant controls: on reasonable written notice, during business hours, without access to other customers’ data, under confidentiality (including any third-party auditor), and through a mutually agreed scope and timing. Audit results are confidential and may be used only to confirm compliance with this DPA and to meet Customer’s regulatory requirements. Doily may charge reasonable costs for audits exceeding two business days of effort.

12. International transfers

12.1. Doily processes Client Data in the United States.

12.2. For Personal Data protected by the EU GDPR, the SCCs are incorporated into this DPA: Module Two (controller to processor) where Customer is a controller and Module Three (processor to processor) where Customer is a processor; Doily is the data importer and Customer the exporter. Clause 7 (docking) is included; Clause 9 Option 2 with the notice period in section 6; Clause 11 optional language is not used; Clause 17 Option 1 with Irish law governing; Clause 18 forum Ireland. Annexes I and II to the SCCs are Annexes 1 and 2 of this DPA.

12.3. For Personal Data protected by UK law, the UK Addendum applies with the SCCs as modified by it; Table entries are completed by the details in this DPA and its Annexes. For Swiss data, the SCCs apply with the adaptations required by the FADP, and Swiss data subjects may bring claims in Switzerland.

12.4. If Doily later certifies under an adequacy framework covering these transfers (for example an EU-US data privacy framework), that framework may serve as an additional or alternative mechanism; the SCCs remain the fallback.

13. Liability and precedence

Each party’s liability under this DPA is subject to the limitations and exclusions in the Agreement, except where Data Protection Law does not permit that. In case of conflict: the SCCs prevail over this DPA; this DPA prevails over the Agreement for its subject matter.

Annex 1: Description of processing

Parties. Data exporter: Customer (controller, or processor for its own clients). Data importer: Skyfield Digital LLC (DBA Doily), 1 Prestige Drive, Suite 202, Meriden, CT 06450, USA; contact security@doily.ai.

Subject matter and duration. Hosting and processing of Client Data to provide the Doily platform for the term of the Agreement plus the export and deletion windows.

Nature and purpose. Storage, retrieval, organization, analysis, reporting, transmission and deletion of data to provide search and AI visibility tracking, site audits, reporting, delivery workflows, communications and related features, as configured by Customer.

Categories of data subjects. Customer’s personnel and users; Customer’s clients and their personnel; recipients Customer adds (for example report recipients); end users reflected in connected-tool data (for example website visitors in analytics data, callers in call-tracking data, customers in CRM or commerce data Customer connects).

Categories of Personal Data. Names, business contact details, account identifiers and roles; content of notes, tasks, meetings and documents Customer submits; identifiers and usage data contained in connected-tool data (for example analytics identifiers, phone numbers in call logs, order and customer records); email addresses and interaction events for recipients Customer adds. The Service is not designed for and Customer agrees not to submit special categories of data (health, biometric and similar) or payment card numbers.

Frequency. Continuous, as driven by Customer’s configuration and scheduled jobs.

Competent supervisory authority. For EU data, the supervisory authority of the exporter’s establishment or, where none, the Irish Data Protection Commission per Clause 13 of the SCCs; for UK data, the Information Commissioner’s Office; for Swiss data, the Federal Data Protection and Information Commissioner.

Annex 2: Technical and organizational measures

  • Encryption in transit (TLS) and at rest; third-party credentials additionally envelope-encrypted with per-workspace data keys under a managed KMS with hardware-backed master keys and audited key operations.
  • Tenant isolation enforced at the database layer with row-level security on every tenant table, independently of application checks, with automated tests on every change.
  • Access control: role-based permissions with per-capability and per-client scoping; least-privilege staff access; staff administrative actions require SSO plus multi-factor authentication and are logged at the statement level; customer-facing impersonation is opt-out-able, read-only, time-boxed, logged and notified.
  • Authentication: strong password policy with breached-password screening, optional and admin-enforceable two-factor authentication, per-hostname session isolation.
  • Audit logging: append-only logs of mutations, privileged reads, auth and permission events, retained per the published schedule.
  • Secrets management: centralized secrets store, no credentials in code, scheduled rotation, per-provider spend and access limits.
  • Network and application security: WAF and DDoS protection at the edge, security headers, signature-verified webhooks, malware scanning of uploads, dependency and container scanning in CI, vulnerability scanning, periodic third-party penetration testing.
  • Availability and resilience: point-in-time database recovery, nightly logical backups stored separately, restore drills, uptime monitoring with a public status page, documented incident response with severity tiers.
  • Data lifecycle: per-plan retention settings, self-service export (JSON and CSV), ordered hard deletion with a 30-day grace period, user-level anonymization honoring erasure requests.
  • Personnel: confidentiality obligations, security training for anyone with production access, background-appropriate vetting for administrative roles.
  • AI providers configured for zero data retention or no-training wherever the provider offers it.

Controls are designed in alignment with SOC 2 control criteria; formal certification follows the published security roadmap.

Annex 3: Subprocessors at the effective date

Published and maintained at doily.ai/subprocessors.

SubprocessorPurposeLocation of processing
Supabase Database, authentication, realtime USA
Railway Application hosting USA
Cloudflare DNS, CDN, security, edge hosting, object storage (R2) USA (global edge)
Amazon Web Services Key management (KMS) USA
Stripe Payments, billing, tax USA
Postmark (ActiveCampaign) Transactional and report email USA
Nango Connector OAuth management USA/EU
Inngest Background job orchestration USA
OneSignal Push notifications USA
Doppler Secrets management USA
Sentry Error monitoring USA
Axiom Logging and tracing USA
PostHog Product analytics USA
Better Stack Uptime monitoring and status page EU/USA
Google Workspace Business email and document infrastructure USA
DataForSEO Search and web data provider Varies (data collection)
Anthropic AI model provider USA
OpenAI AI model provider USA
Google (AI and APIs) AI model provider and connected-service APIs USA
Microsoft Azure AI model hosting, including open-weights models such as DeepSeek run in Microsoft's own U.S. data centers USA
Perplexity AI model provider USA
xAI AI model provider USA