Legal

Data Processing

Last updated: September 15, 2026

How Contrics processes personal data on behalf of business customers, and how to obtain a Data Processing Agreement.

A signed DPA is available on request. We have not yet published a standard Data Processing Agreement for self-service acceptance — the contractual text is being finalised with legal counsel. In the meantime, business customers who need an executed Art. 28 agreement should email support@contrics.com and we will arrange one. This page describes the processing itself, which is accurate today.

1. Roles

For personal data you upload or generate inside your workspace — your content, your knowledge uploads, and data retrieved from the social accounts you connect — you are the controller and Contrics acts as processor on your instructions.

For your own account and billing data — the identity of the person using Contrics, subscription and payment records — we are the controller. That processing is described in our Privacy Policy.

2. Subject matter and duration

Processing lasts for as long as your account is active, and ends when you delete your workspace or account (see Data Deletion). The subject matter is the provision of the Contrics service: content generation, analysis, content planning and analytics.

3. Nature and purpose of processing

  • Storing and retrieving your workspace content and brand information.
  • Submitting your content and prompts to an AI provider to generate or analyse content.
  • Retrieving metrics and content from the social accounts you choose to connect.
  • Sending transactional email relating to your account, billing and requests.

4. Categories of data and data subjects

The categories depend on what you choose to put into the service. Typically: identifiers and contact details of your own team members, and the content and audience metrics of the social accounts you connect. Contrics is not designed for special categories of personal data, and you should not upload them.

5. Subprocessors

We use the providers listed on our Subprocessors page. That list is maintained against what the product actually uses.

6. Security, assistance and deletion

We apply technical and organisational measures appropriate to the risk, including row-level database isolation between workspaces, encryption in transit, and least-privilege access to production systems. We will assist you with data-subject requests and, on termination, delete workspace data in line with our Data Deletion process.

The full description of technical and organisational measures required as an annex to an Art. 28 agreement is part of the DPA being prepared.

7. International transfers

Some subprocessors are located in or transfer data to countries outside the EU/EEA, including the United States. Where that happens we rely on appropriate safeguards such as Standard Contractual Clauses or an adequacy decision. The specific mechanism per provider is being confirmed — see Subprocessors.

8. Requesting a DPA

Email support@contrics.com with your company details and we will arrange an executed agreement.