Data Processing Agreement - Compoundly ← Back to Home

Data Processing Agreement

Effective Date: March 16, 2026
Last Updated: March 16, 2026

GDPR Article 28 Compliance: This Data Processing Agreement (DPA) governs the processing of personal data by Compoundly as a data processor on behalf of data controllers, ensuring compliance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.

1. Definitions and Interpretation

2. Scope and Purpose of Processing

Subject Matter of Processing

Duration of Processing

Nature and Purpose

Categories of Data Subjects

Categories of Personal Data

3. Processor Obligations

🛡️ GDPR Article 28 Compliance

Processing Instructions

Personnel and Confidentiality

Technical and Organizational Measures

4. Sub-processor Management

Authorized Sub-processors

Compoundly may engage the following sub-processors for specific processing activities:

Sub-processor Service Location Safeguards
OpenAI, LLC AI-powered advice generation United States Data anonymization, SCCs
Stripe, Inc. Payment processing United States/Global PCI DSS compliance, SCCs
Amazon Web Services Cloud hosting and storage United States/EU SOC 2, ISO 27001, SCCs
Google Analytics Usage analytics (anonymized) United States Data anonymization, SCCs

Sub-processor Requirements

Changes to Sub-processors

5. Data Subject Rights Support

6. Security and Data Protection

Technical Safeguards

Organizational Safeguards

Compliance Certifications

7. Data Breach Response

Breach Detection and Assessment

Notification Requirements

Data Subject Notification

8. International Data Transfers

Transfer Mechanisms

Transfer Safeguards

9. Audit and Compliance

Audit Rights

Compliance Reporting

10. Return and Deletion of Data

Service Termination

Automatic Deletion

11. Liability and Indemnification

Processor Liability

Indemnification

12. Contact Information

Data Protection Officer

Email: dpo@compoundly.com

Address: [Physical Address for Legal Service]

Legal and Compliance

Legal Team: legal@compoundly.com

Privacy Team: privacy@compoundly.com

Technical Support

Data Requests: support@compoundly.com

Security Issues: security@compoundly.com

This Data Processing Agreement ensures GDPR compliance and protects personal data rights.

Privacy Policy | Terms of Service | Contact Legal Team