Data Processing Addendum
Last updated September 2, 2026
This Data Processing Addendum (the "DPA") forms part of and is incorporated into the Terms of Service and any applicable Order Form between Social Kit, Inc. d/b/a Creally ("Creally") and the customer entity accepting this DPA or the Terms ("Customer").
This DPA applies where Creally Processes Personal Data on behalf of Customer in connection with the Services.
1. Definitions
Capitalized terms not defined in this DPA have the meanings given in the Terms. For purposes of this DPA:
"Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach", "Process" or "Processing", and "Supervisory Authority" have the meanings given to them in the GDPR.
"GDPR" means Regulation (EU) 2016/679.
"Transfer Abroad" means a transfer of Personal Data subject to the GDPR to a country outside the EEA that is not recognized by the European Commission as providing an adequate level of protection, unless the transfer is otherwise permitted under applicable Data Protection Laws.
"Sub-processor" means any third party engaged by Creally to Process Personal Data on behalf of Customer in connection with the Services.
"Data Protection Laws" means the GDPR and any applicable laws implementing or supplementing it, in each case as amended from time to time.
2. Scope and Roles
2.1 The parties acknowledge and agree that, with respect to the Processing of Personal Data under this DPA, Customer acts as the Controller and Creally acts as the Processor, except where applicable law requires otherwise.
2.2 This DPA applies only to the extent that Creally Processes Personal Data on behalf of Customer in providing the Services.
2.3 The subject matter, duration, nature, and purpose of the Processing, as well as the types of Personal Data and categories of Data Subjects, are described in Schedule 1 to this DPA.
3. Customer Instructions
3.1 Creally shall Process Personal Data only on documented instructions from Customer, including as necessary to provide the Services in accordance with the Terms, applicable Order Forms, Customer’s use of the Services, and Customer’s written instructions.
3.2 Customer instructs Creally to Process Personal Data as necessary to: (a) provide, maintain, support, and secure the Services; (b) prevent abuse, fraud, and security incidents; (c) comply with applicable law; and (d) carry out other reasonable and documented instructions from Customer consistent with the Terms and this DPA.
3.3 Customer is solely responsible for: (a) the lawfulness of the Personal Data and the means by which Customer acquired it; (b) the lawfulness of Customer’s instructions; and (c) ensuring that Customer has provided all notices and obtained all consents and other rights required under applicable Data Protection Laws.
3.4 If Creally believes that an instruction from Customer infringes applicable Data Protection Laws, Creally may notify Customer and suspend the affected Processing until the matter is resolved.
4. Confidentiality
Creally shall ensure that persons authorized to Process Personal Data are subject to appropriate obligations of confidentiality, whether contractual or statutory.
5. Security
5.1 Taking into account the state of the art, the costs of implementation, the nature, scope, context, and purposes of Processing, and the risks for the rights and freedoms of natural persons, Creally shall implement appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, including as described in Schedule 2.
5.2 Customer acknowledges that no security measure can guarantee absolute security.
6. Sub-processors
6.1 Customer grants Creally general written authorization to engage Sub-processors for the Processing of Personal Data under this DPA.
6.2 Creally shall impose data protection obligations on each Sub-processor that are no less protective than those set out in this DPA, to the extent applicable to the services provided by that Sub-processor.
6.3 Creally shall remain responsible for the performance of its Sub-processors’ obligations to the extent required by the GDPR.
6.4 Creally shall make available to Customer a current list of Sub-processors, as set out in Section 10 of Schedule 1, upon request or by other reasonable means, and shall provide Customer with notice of intended additions or replacements of Sub-processors.
6.5 If Customer reasonably objects to a new Sub-processor on data protection grounds, the parties shall discuss the objection in good faith. If the objection cannot reasonably be resolved, Creally may, at its option, either instruct Customer to cease using the affected part of the Services, or terminate the affected portion of the Services or the applicable Order Form.
7. Assistance to Customer
7.1 Taking into account the nature of the Processing, Creally shall provide reasonable assistance to Customer, insofar as possible, to enable Customer to respond to requests from Data Subjects to exercise their rights under applicable Data Protection Laws.
7.2 If Creally receives a request from a Data Subject relating to Personal Data Processed on behalf of Customer, Creally shall, to the extent legally permitted, direct the Data Subject to Customer and shall not respond to the request except on Customer’s documented instructions or as required by law.
8. Personal Data Breaches
8.1 Creally shall notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Personal Data Processed on behalf of Customer.
8.2 Such notification shall include, to the extent available at the time: (a) a description of the nature of the Personal Data Breach; (b) the categories of affected Personal Data and Data Subjects, where known; (c) the likely consequences of the Personal Data Breach; and (d) the measures taken or proposed to address the Personal Data Breach and mitigate its possible adverse effects.
8.3 Creally’s notification of or response to a Personal Data Breach shall not be construed as an admission of fault or liability.
9. Audits and Information
9.1 Creally shall make available to Customer information reasonably necessary to demonstrate compliance with this DPA.
9.2 Where such information is insufficient for Customer reasonably to demonstrate compliance with Article 28 GDPR, Customer may, no more than once annually and upon reasonable prior written notice, request an audit conducted by Customer or an independent auditor bound by confidentiality obligations, provided that: (a) the audit is limited in scope to systems, records, and facilities relevant to the Processing of Personal Data under this DPA; (b) the audit does not unreasonably interfere with Creally’s business operations or compromise the confidentiality, security, or rights of other customers or third parties; (c) Customer bears the costs of the audit unless the audit reveals a material breach of this DPA by Creally; and (d) the parties first attempt in good faith to satisfy the request through security documentation, certifications, audit reports, and written responses.
10. Deletion and Return of Personal Data
10.1 Upon termination or expiry of the Services, Creally shall, at Customer’s choice and subject to the Terms, delete or return Customer Personal Data, unless applicable law requires storage of the Personal Data.
10.2 Notwithstanding the foregoing, Creally may retain Personal Data to the extent required by applicable law or in accordance with standard backup and archival practices, or to the extent necessary to maintain the integrity of its payout records and operational logs as a record of payout instructions transmitted and their outcome, provided that such retained Personal Data remains protected in accordance with this DPA and, in the case of payout records and operational logs, is Processed only to maintain the integrity of that record, to respond to a dispute or claim, and to comply with applicable law.
11. International Transfers
11.1 Customer acknowledges that Creally is established in the United States and that Personal Data Processed under this DPA may be transferred to, accessed from, or otherwise Processed in the United States.
11.2 To the extent that a Transfer Abroad is not covered by an adequacy decision or an applicable Data Privacy Framework certification, the parties agree that the Standard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914 (the "SCCs") shall be incorporated by reference into this DPA and apply as follows: (a) Module Two (Controller to Processor) shall apply where Customer is the Controller and Creally is the Processor; (b) Customer shall be the data exporter and Creally shall be the data importer; (c) the optional docking clause shall not apply unless the parties agree otherwise in writing; (d) the governing law shall be the law of the EU Member State in which the data exporter is established, or, if none, Cyprus; (e) disputes shall be resolved in the courts specified by the SCCs in accordance with the applicable governing law; (f) the information required for Annex I and Annex II to the SCCs is set out in Schedule 1 and Schedule 2 to this DPA, respectively; and (g) if and to the extent required, the parties shall implement supplementary measures appropriate to the relevant transfer and Processing.
11.3 If the transfer mechanism under this Section 11 is invalidated, amended, replaced, or no longer sufficient under applicable Data Protection Laws, the parties shall cooperate in good faith to implement an alternative lawful transfer mechanism.
12. Liability
The liability of each party under this DPA shall be subject to the exclusions and limitations of liability set out in the Terms, except to the extent prohibited by applicable law.
13. Order of Precedence
In the event of any conflict between this DPA and the Terms, this DPA shall prevail solely with respect to the Processing of Personal Data on behalf of Customer. In the event of any conflict between this DPA and the SCCs, the SCCs shall prevail.
14. Term
This DPA shall remain in effect for the duration of the Terms and for so long as Creally Processes Personal Data on behalf of Customer under or in connection with the Terms.
15. Governing Law
This DPA shall be governed by the governing law specified in the Terms or the applicable Order Form, except where the SCCs require otherwise with respect to matters governed by the SCCs.
SCHEDULE 1 — DETAILS OF PROCESSING
This Schedule also serves as Annex I to the SCCs where incorporated under Section 11 of the DPA.
1. Parties and Roles
Data Exporter: the Customer, acting as Controller. Data Importer: Social Kit, Inc. d/b/a Creally, acting as Processor.
2. Subject Matter and Duration of Processing
Provision of the Services under the Terms and any applicable Order Form, including creator relationship management, AI-enabled workflow functionality, automated outreach functionality, campaign management, analytics, support, hosting, maintenance, and related technical and organizational operations.
Processing commences upon commencement of the Services and continues for the duration of the Services, plus any post-termination data export period specified in the Terms or the applicable Order Form (thirty (30) days unless otherwise stated), and thereafter only for so long as required to complete deletion, return, backup retention, or legal retention obligations in accordance with the Terms and the DPA.
3. Nature and Purpose of Processing
Creally Processes Personal Data solely on Customer’s documented instructions, for the following purposes:
- Platform access and authentication: processing Customer user credentials to provide secure access to the Platform.
- Creator list management: storing, indexing, and displaying creator lists uploaded by Customer from external sources.
- Outreach campaign execution: storing and transmitting email content and AI agent configurations authored by Customer, and sending outreach emails to Creators on Customer’s behalf via email delivery Sub-processors.
- Campaign management: processing campaign configurations, Creator selections, negotiation workflows, and related data within Customer’s projects.
- Communication logging: recording and storing outreach communications, Creator responses, and negotiation histories for Customer’s reference.
- Support, security, and maintenance: hosting, storage, troubleshooting, security monitoring, abuse prevention, and deletion of Personal Data as necessary to provide the Services.
- Data return: making Customer’s data available to Customer upon request during the Services and during any post-termination export period.
- Payout workflow: where Customer enables the payout feature, recording payout instructions created by Customer, sending the payout invitation to the Creator on Customer's instruction, and displaying and reconciling payout status within Customer's workspace. The disclosure of Personal Data to, and the receipt of Personal Data from, the payment provider is not Processing on Customer's behalf and is described in Section 7 of this Schedule.
4. Categories of Data Subjects
| Category | Description |
|---|---|
| Customer’s Authorized Users | Employees, agents, or contractors of Customer who are granted Platform access, and other Customer personnel and business contacts included in Customer Data. |
| Creators (Customer-uploaded) | Influencers or content creators whose data Customer uploads to the Platform from external sources. |
| Creators (engaged through the Platform) | Creators whom Customer adds to a project, contacts via outreach, or engages in negotiations through the Platform (see Section 8 of this Schedule). |
| Other individuals | Campaign contacts, end users, and other individuals whose Personal Data is included in Customer Data or otherwise Processed through the Services on Customer’s behalf. |
5. Categories of Personal Data
Customer user data: email addresses and account credentials (authentication, session management, access control); usage/session data linked to individual users (providing the Services, audit trails).
Creator data from Customer-uploaded lists: Creator names and identifiers; social media handles and profile URLs; any other personal data included by Customer (storage, indexing, matching, and display within Customer’s campaigns).
Outreach and communication data: email content and templates; AI agent configurations; communication logs (messages, timestamps, delivery status); Creator responses and negotiation messages (storage, rendering, transmission, logging, and display within Customer’s campaign workflow).
Campaign configuration data: search filters and targeting criteria; project parameters and campaign settings (executing searches and managing workflows on Customer’s behalf).
Payout data: Creator email addresses, payout amounts and currencies, payment descriptions entered by Customer, payout status and status history, payout identifiers, and payout method type reported by the payment provider (recording, displaying and reconciling payouts within Customer's workspace) .
6. Sensitive Data
The Processing described in this Schedule does not involve special categories of personal data (Article 9 GDPR) or personal data relating to criminal convictions or offences (Article 10 GDPR), and no sensitive data is required for normal use of the Services. Customer shall not submit special categories of personal data or other sensitive data to the Platform unless strictly necessary, lawful, and expressly agreed by Creally in writing.
7. Processing Outside the Scope of this Schedule (Independent Controller Activities)
The following categories of data are Processed by Creally as an independent Controller under Creally’s Privacy Policy and are not subject to the processor obligations of this DPA:
- Creator database (Creally-sourced): Creator profile data, engagement metrics, and audience demographics collected by Creally from publicly available sources and social media platform APIs. This database is maintained independently by Creally and serves all Platform users.
- Usage Data for product improvement: technical logs, telemetry, analytics, performance data, and statistical information relating to the operation, support, security, or use of the Services, in de-identified and/or aggregated form. Where any such data constitutes Personal Data prior to de-identification or aggregation, Creally applies appropriate safeguards, including de-identification, aggregation, or pseudonymization, before use for analytics, product insight, or model improvement purposes.
- Platform operations: data processed through Creally’s operational tools (including product analytics and error monitoring services) for platform reliability and improvement purposes.
- Business administration: data processed for Creally’s own account management, billing, and relationship management purposes.
- Payout disclosures to the payment provider: where Customer enables the payout feature, Creally’s disclosure of Personal Data to its payment provider, and its receipt of Personal Data from that provider, as described in Creally’s Privacy Policy. The payment provider acts as an independent Controller and is not a Sub-processor. Customer’s relationship with the payment provider is governed by the payment provider’s own terms, to which Creally is not a party. Personal Data held in Customer’s payout records within the Platform remains subject to the processor obligations of this DPA.
8. Application of the Processor Relationship to Creator Data
The Controller-Processor relationship under this DPA applies to Creator data originating from Creally’s independently controlled creator database from the point at which Customer takes an affirmative action with respect to a specific Creator, including: adding a Creator to a project; initiating outreach to a Creator; storing Creator data within Customer’s campaign workflow; or requesting return of Creator data from the Platform. Prior to such affirmative action (for example, browsing search results), Customer is accessing Creally’s independently controlled creator database, and Creally is not acting as Processor for that access.
9. Frequency of Transfer
Continuous / on an ongoing basis for the duration of the Services.
10. Sub-processors
Creally’s current Sub-processors, their legal entities, locations, and processing purposes are set out in the Sub-processor List made available by Creally at request and updated from time to time. As of the date of this DPA, the list comprises: AWS and Amazon SES (Amazon Web Services, Inc., US – hosting; email delivery); Resend (Plus Five Five, Inc., US – email delivery); OpenAI (OpenAI, Inc., US – data enrichment and email personalization); YouTube API (Google LLC, US), TikTok API (TikTok Inc., US), and Instagram API (Meta Platforms, Inc., US) – creator data sources; PostHog (PostHog, Inc., US – product analytics); and Sentry (Functional Software, Inc., US – error monitoring). Engagement of Sub-processors, updates to the list, and Customer’s objection rights are governed by Section 6 of the DPA.
11. Competent Supervisory Authority
The supervisory authority competent for the Customer, as determined under the GDPR and, where the SCCs apply, in accordance with Clause 13 of the SCCs.
12. Retention and Deletion
Customer user account data, Customer-uploaded creator lists, outreach content and communication logs, and campaign configuration data are retained for the duration of the Services plus the post-termination export period, and deleted upon termination or expiration in accordance with Section 10 of the DPA (or earlier, upon Customer’s instruction, in the case of Customer-uploaded creator lists). Following expiry of the post-termination export period, Creally shall delete all Personal Data Processed as Processor on Customer’s behalf, except to the extent applicable law requires further retention or as permitted for standard backup and archival practices under the DPA. Creally shall confirm deletion in writing upon Customer’s request. Payout records and the related operational log are retained after expiry of the post-termination export period to the extent necessary to maintain the integrity of Creally’s record of payout instructions transmitted and their outcome, in accordance with Section 10.2 of the DPA.
SCHEDULE 2 — TECHNICAL AND ORGANIZATIONAL MEASURES
This Schedule also serves as Annex II to the SCCs where incorporated under Section 11 of the DPA.
Creally shall implement and maintain appropriate technical and organizational measures, which may include as appropriate:
- access controls based on role and need-to-know;
- password controls and authentication safeguards;
- encryption or equivalent protection for data in transit and, where appropriate, at rest;
- logging, monitoring, and incident detection measures;
- vulnerability management and security patching processes;
- backup and recovery procedures;
- personnel confidentiality obligations;
- internal policies and procedures for handling Personal Data; and
- incident response procedures for security events and Personal Data Breaches.
Creally shall review and update these measures periodically to ensure continued appropriateness. A description of specific measures in place may be provided upon Customer’s reasonable written request.
