This Data Processing Addendum ("DPA") forms part of the Terms of Service (the "Terms") between Proyecta Labs, Inc. ("Proyecta," "we," "us," or "our") and the customer that accepted them ("Customer," "you," or "your"). It applies whenever Proyecta processes personal data on your behalf, and it applies to every customer, wherever located. Capitalized terms not defined here have the meanings given in the Terms.
No separate signature is needed. This DPA is incorporated into the Terms by reference: you execute it by accepting the Terms, and Proyecta executes it by publishing it here. You may download or print this page as your signed copy. It is effective from the date you accepted the Terms or September 22, 2026, whichever is later.
1. Definitions
- "Applicable Data Protection Law" means every law that applies to the processing of Customer Personal Data under the Terms, including, where applicable: the EU General Data Protection Regulation 2016/679 ("GDPR"); the GDPR as incorporated into UK law and the UK Data Protection Act 2018 ("UK GDPR"); the Swiss Federal Act on Data Protection ("FADP"); the California Consumer Privacy Act as amended by the CPRA ("CCPA") and other U.S. state privacy laws; Mexico's Ley Federal de Protección de Datos Personales en Posesión de los Particulares ("LFPDPPP"); and Brazil's Lei Geral de Proteção de Dados ("LGPD").
- "Customer Personal Data" means personal data that Proyecta processes on Customer's behalf in providing the Services, as described in Annex I. It includes the personal data of the End Users of your Published Applications.
- "Controller," "processor," "data subject," "personal data," "processing," and "supervisory authority" have the meanings given in the GDPR. The equivalent terms under other Applicable Data Protection Law (for example "business" and "service provider" under the CCPA, or "responsable" and "encargado" under the LFPDPPP) are read accordingly.
- "Personal Data Breach" means a breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
- "Subprocessor" means any third party that Proyecta engages to process Customer Personal Data.
- "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses approved by the European Commission in Implementing Decision (EU) 2021/914.
2. Roles and Scope
2.1. Customer is the controller; Proyecta is the processor. For Customer Personal Data, you are the controller (or a processor acting for your own controller), and Proyecta is your processor (or subprocessor). This matches Section 28.3 of the Terms.
2.2. What this DPA does not cover. Proyecta is an independent controller of the personal data it processes to run its own business: your account and billing information, your use of the builder, security logs, and our own marketing. That processing is described in our Privacy Policy, not in this DPA.
2.3. Your responsibilities as controller. You are responsible for the lawfulness of the processing you instruct. That includes providing a privacy notice to your End Users, having a lawful basis for the processing, obtaining any consent that is required, and making sure the data you or your End Users submit may lawfully be processed through the Services.
2.4. Analytics in Published Applications. The built-in analytics of a Published Application does not store cookies or any other identifier in the End User's browser. Proyecta counts visitors on its servers with a pseudonymous identifier computed from the request (IP address and browser details) and a random value that is replaced every day and deleted within 48 hours, so identifiers cannot be linked from one day to the next. The IP address is not stored with analytics data. Published Applications built with an earlier version of the analytics may still set a first-party cookie (_pry_vid) until they are updated; Proyecta no longer uses its value. Consent for anything else your Published Application stores in the End User's browser — third-party embeds, pixels, chat widgets — remains your responsibility as controller.
3. Processing on Your Instructions
3.1. Proyecta will process Customer Personal Data only on your documented instructions, including for transfers to a third country, unless the law requires otherwise. In that case we will tell you about that legal requirement before processing, unless the law prohibits it on important grounds of public interest.
3.2. Your instructions are: (a) the Terms and this DPA; (b) the way you configure and use the Services, including what your Published Applications collect and do; and (c) any other reasonable written instruction you give us that is consistent with the Terms. An instruction that would change the scope of the Services may require a separate agreement.
3.3. We will tell you promptly if, in our opinion, an instruction infringes Applicable Data Protection Law. We are not obliged to carry out an infringing instruction.
4. Confidentiality
Proyecta will ensure that every person it authorizes to process Customer Personal Data is bound by a duty of confidentiality, whether contractual or statutory. Access is limited to the personnel who need it to provide, support, or secure the Services.
5. Security
5.1. Proyecta will implement and maintain appropriate technical and organizational measures to protect Customer Personal Data, taking into account the state of the art, the cost of implementation, and the nature, scope, context, and purposes of the processing, as required by Article 32 of the GDPR. The current measures are described in Annex II.
5.2. We may update these measures over time, provided that an update does not materially reduce the overall level of protection.
6. Subprocessors
6.1. General authorization. You give Proyecta a general authorization to engage Subprocessors. The current list, with each Subprocessor's purpose and location, is published at /subprocessors.
6.2. Notice and objection. We will give you at least 30 days' notice before a new Subprocessor begins processing Customer Personal Data, by updating that page and emailing your account contacts. You may object on reasonable data-protection grounds by writing to privacy@proyecta.dev within that period. We will then work with you in good faith on an alternative. If none is reasonably possible, you may terminate the affected Services, and we will refund any prepaid Platform Fees for the period after termination.
6.3. Flow-down and liability. We will bind each Subprocessor by a written contract with data protection obligations no less protective than this DPA. We remain liable to you for our Subprocessors' performance of those obligations.
7. Assistance to You
7.1. Data subject requests. Taking into account the nature of the processing, Proyecta will assist you, through appropriate technical and organizational measures, in responding to requests from data subjects to exercise their rights. The Services provide tools in your Published Application's admin console to access, correct, export, and delete your End Users' data. If a data subject contacts us directly about Customer Personal Data, we will forward or redirect the request to you and will not answer it ourselves unless you instruct us to.
7.2. Other assistance. Taking into account the information available to us, we will reasonably assist you with your obligations on security, Personal Data Breach notification, data protection impact assessments, and prior consultation with supervisory authorities (Articles 32 to 36 of the GDPR). We may charge a reasonable fee for assistance that goes beyond the information we make available to all customers.
8. Personal Data Breaches
8.1. Proyecta will notify you without undue delay after becoming aware of a Personal Data Breach and, where feasible, within 72 hours. Notice goes to your account contacts.
8.2. The notice will describe, as far as then known: the nature of the breach, including the categories and approximate number of data subjects and records concerned; its likely consequences; and the measures taken or proposed to address it and mitigate its effects. Where it is not possible to provide all of this at once, we will provide it in phases without undue further delay.
8.3. We will take reasonable steps to contain and remediate the breach. Our notice is not an acknowledgment of fault or liability.
9. Return and Deletion
9.1. When the Services end, you may export your Customer Personal Data for 30 days, as described in Section 21.5 of the Terms. After that period, Proyecta will delete it from its active systems, unless the law requires us to keep it.
9.2. Copies held in backups are deleted as the backups expire on their normal rotation. Until then they stay protected by this DPA and are not used for any other purpose.
9.3. You may also delete Customer Personal Data at any time while the Services are active: by deleting records in your admin console, by unpublishing a Published Application, or by closing your account.
10. Audits and Information
10.1. Proyecta will make available all information reasonably necessary to demonstrate compliance with this DPA and Article 28 of the GDPR. That information includes this DPA, the security measures in Annex II, the Subprocessor list, and written answers to reasonable security questionnaires.
10.2. If that information is not enough to demonstrate compliance, or a supervisory authority requires it, you may audit our compliance, including by inspection, through an independent auditor bound by confidentiality. Audits are limited to once in any 12-month period (except after a Personal Data Breach or at an authority's request), need at least 30 days' written notice, must take place during business hours without unreasonably disrupting our operations, and are at your cost. They cover only systems that process Customer Personal Data.
11. International Transfers
11.1. Proyecta is based in the United States, and Customer Personal Data may be processed in the United States and the other countries where our Subprocessors operate, as listed at /subprocessors.
11.2. EEA transfers. To the extent Customer Personal Data subject to the GDPR is transferred to a country without an adequacy decision, the SCCs are incorporated into this DPA by reference and apply as follows:
- Module Two (controller to processor) applies where you are a controller, and Module Three (processor to processor) where you are a processor. You are the "data exporter" and Proyecta is the "data importer."
- Clause 7 (docking clause) applies.
- Clause 9: Option 2 (general written authorization) applies, with the notice period in Section 6.2 of this DPA.
- Clause 11: the optional language does not apply.
- Clause 13: the competent supervisory authority is the one determined under Clause 13(a). Where you are not established in the EEA, it is the supervisory authority of the Member State in which your EU representative is established or, if you have none, the Austrian Data Protection Authority (the Member State of our Article 27 representative).
- Clause 17: the SCCs are governed by the law of Ireland. Clause 18: disputes are resolved by the courts of Ireland.
- Annexes I and II of the SCCs are completed by Annexes I and II of this DPA. Annex III is completed by the list at /subprocessors.
11.3. UK transfers. For transfers subject to the UK GDPR, the SCCs apply as amended by the International Data Transfer Addendum issued by the UK Information Commissioner (version B1.0), which is incorporated by reference. Its tables are completed with the information in Section 11.2 and in Annexes I and II of this DPA, and either party may end it as permitted by its Section 19.
11.4. Swiss transfers. For transfers subject to the FADP, the SCCs apply with these changes: references to the GDPR are read as references to the FADP; the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority for those transfers; and the term "Member State" does not prevent data subjects in Switzerland from bringing claims in their place of habitual residence.
11.5. Data Privacy Framework. Where a recipient is certified under the EU-US Data Privacy Framework (or its UK Extension or the Swiss-US framework), the transfer may rely on that certification instead of the SCCs.
11.6. Government access. If Proyecta receives a legally binding request from a public authority for Customer Personal Data, we will, unless prohibited by law, notify you promptly and give you the chance to seek a protective order. We will challenge a request we reasonably consider unlawful, and we will disclose only the minimum data the request requires.
12. U.S. State Privacy Laws
Where Proyecta processes Customer Personal Data as your "service provider," "contractor," or "processor" under the CCPA or another U.S. state privacy law, Proyecta:
- will not sell or share Customer Personal Data (as those terms are defined in the CCPA);
- will not retain, use, or disclose Customer Personal Data for any purpose other than the business purposes specified in the Terms and this DPA, or outside the direct business relationship between you and us;
- will not combine Customer Personal Data with personal data it receives from or on behalf of anyone else, or that it collects itself, except as those laws permit;
- will comply with the obligations those laws place on service providers and give the same level of privacy protection they require;
- will notify you if it determines that it can no longer meet those obligations; and
- agrees that you may take reasonable and appropriate steps to stop and remediate any unauthorized use of Customer Personal Data.
We certify that we understand and will comply with these restrictions.
13. Mexico and Brazil
13.1. Mexico. For Customer Personal Data subject to the LFPDPPP, you are the "responsable" and Proyecta is the "encargado." Proyecta will process Customer Personal Data only on your instructions, will not use it for its own purposes, will keep it confidential, will apply the security measures in Annex II, will delete it as set out in Section 9, and will pass it to third parties only as Subprocessors under Section 6, which constitutes a "remisión" under that law.
13.2. Brazil. For Customer Personal Data subject to the LGPD, you are the "controlador" and Proyecta is the "operador," and this DPA applies accordingly.
14. General Terms
14.1. Order of precedence. For the processing of Customer Personal Data, this DPA prevails over any conflicting provision of the Terms. The SCCs, where they apply, prevail over this DPA.
14.2. Liability. Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms, except where Applicable Data Protection Law or the SCCs do not allow such a limitation.
14.3. Duration. This DPA lasts as long as Proyecta processes Customer Personal Data on your behalf, including the export and deletion period in Section 9.
14.4. Changes. We may update this DPA to reflect changes in the law, in our Subprocessors, or in the Services, with notice as provided in Section 25 of the Terms. An update will not materially reduce the protection this DPA gives Customer Personal Data unless the law requires it.
14.5. Language. This DPA may be made available in several languages. If they conflict, the English version controls.
14.6. Contact. Data protection questions: privacy@proyecta.dev. Legal notices: legal@proyecta.dev. Our EU representative under Article 27 of the GDPR is iuro Rechtsanwälte GmbH t/a Prighter, Schellinggasse 3, 1010 Vienna, Austria (https://app.prighter.com/portal/proyecta).
Annex I — Details of the Processing {#annex-1}
Parties.
- Data exporter / controller: the Customer, as identified by its account. Activity: building and operating websites and applications with the Services. Contact: the account's owner email.
- Data importer / processor: Proyecta Labs, Inc., 2803 Philadelphia Pike, Suite B 1708, Claymont, DE 19703, United States. Activity: provider of the Services. Contact: privacy@proyecta.dev.
Categories of data subjects.
- End Users of your Published Applications: visitors, customers and buyers, people who make bookings, people who submit forms or leads, members and signed-in users, newsletter subscribers, and people who message your business through connected channels (such as WhatsApp or email)
- Members of your team and other users you invite to your Organization or to your Published Application's admin console
- Any other individuals whose personal data you or your End Users submit to the Services
Categories of personal data.
- Identification and contact data: name, email address, phone number, postal or delivery address
- Account and sign-in data of End Users: user identifiers, sign-in method, one-time codes, linked third-party login identifiers
- Transaction data: orders, bookings, subscriptions, invoices, and payment status (card data is handled by the payment provider you connect, not stored by Proyecta)
- Content that End Users submit: form responses, messages and their media, reviews, files and uploads
- Communication data: email and messaging content, delivery and unsubscribe status
- Analytics and technical data: a daily pseudonymous visitor identifier and a per-visit session identifier, pages visited, referrer, UTM parameters, browser, operating system and device type, and page-performance metrics. The IP address is processed transiently to compute the visitor identifier and to protect the Services against abuse, and is not stored with analytics data
- Any other personal data you choose to collect through your Published Applications
Special categories of data. The Services are not designed specifically for special categories of personal data (Article 9 of the GDPR) or for data relating to criminal convictions. If your Published Application collects them (for example, health information in a clinic's booking form), you are responsible for having a lawful basis and for judging whether the measures in Annex II are appropriate. They receive the same protection as all other Customer Personal Data.
Frequency of transfer. Continuous, for as long as the Services are used.
Nature of the processing. Hosting, storage, retrieval, transmission, display, organization, analysis for reporting to you, backup, and deletion. Where you use AI features (such as an AI assistant that answers your customers), also processing by AI model providers to generate responses.
Purpose of the processing. Providing the Services to you: hosting and operating your Published Applications and their data, email and messaging, commerce and bookings, analytics, sign-in for your End Users, AI features you enable, support, and securing the Services.
Duration and retention. For the term of the Terms, and then until deletion under Section 9 of this DPA.
Subprocessors. As listed at /subprocessors, for the purposes and in the locations stated there.
Annex II — Technical and Organizational Security Measures {#annex-2}
- Encryption. Data is encrypted in transit with TLS 1.2 or higher, and at rest by our cloud infrastructure providers.
- Tenant isolation. Published-application data is held in a multi-tenant database in which every read and write is scoped to its own tenant, with database-level row security on content records. Code runs in isolated, sandboxed Runtime Environments that cannot reach other customers' data.
- Network protection. Production databases have no public IP address and are reachable only from within our private network. Administrative access goes through an identity-aware gateway. Published applications are served behind an edge network with DDoS protection.
- Access control. Access to production systems and Customer Personal Data is limited to personnel who need it, on least-privilege roles, with individual accounts protected by strong authentication. Routine investigation uses read-only access.
- Logging and monitoring. Access and changes are logged. Errors and anomalies are monitored and alerted on.
- Availability and resilience. Managed databases with automated backups, and infrastructure managed as code with change review.
- Secure development. Code review, automated testing and static checks before release, and dependency and vulnerability management.
- Secrets management. Credentials and API keys are kept in a managed secret store, never in source code. Published applications authenticate with per-application keys that can be rotated or revoked.
- Incident response. A documented process to detect, contain, investigate, and notify Personal Data Breaches under Section 8.
- Personnel. Confidentiality obligations and security training for everyone with access to Customer Personal Data.
- Subprocessor diligence. Subprocessors are selected for their security practices and bound under Section 6.3.
- Data minimization and deletion. Data subject requests are supported through the Services, and data is deleted under Section 9.
