Parties and roles
The customer is the controller of personal data placed in its Growth Intelligence workspace, or a processor acting for another controller. Consultdemy LLC is the processor or subprocessor for that Customer Data. Consultdemy remains an independent controller for its own account administration, security, billing, demo, and direct business-contact records.
Processing details
Processing lasts for the service term and the deletion period stated in the Privacy Policy. Its purpose is to authenticate users; host company workspaces; import data from connections the customer authorizes; produce reporting, research, AI-assisted analysis, and draft experiments; provide support; and protect the service. Data subjects may include the customer’s personnel, leads, customers, and business contacts. Data may include account identifiers, advertising and website activity, CRM pipeline records, order and refund records, support content, and the business context submitted by authorized users.
Documented instructions and confidentiality
Consultdemy will process Customer Data only to provide and secure the service, follow the customer’s documented instructions, comply with law, or as otherwise agreed in writing. If an instruction appears unlawful, Consultdemy may pause it and notify the customer. People permitted to process Customer Data are bound by confidentiality duties and receive access only as needed for their work.
Customer responsibilities
The customer will provide lawful instructions, appropriate notices, and any consent or other legal basis required for its data and connected accounts. The customer will limit workspace access, avoid uploading unnecessary sensitive data, and respond to its data subjects and regulators. The customer may not instruct Growth Intelligence to collect content behind a login, defeat access controls, or process data it lacks authority to use.
Security
Consultdemy will maintain technical and organizational measures appropriate to the risk, including encrypted transport and provider storage, scoped authentication, row-level tenant rules, server-side credential handling, encrypted OAuth tokens, audit records, backups, access review, and incident response. The current measures are summarized on the Security page. The service does not promise that any security program can eliminate every risk.
Subprocessors
The customer gives general authorization for the subprocessors on the dated Subprocessor page. Consultdemy will require materially protective data-processing terms from subprocessors. Consultdemy will provide at least 30 days’ notice before a new subprocessor processes Customer Data. A customer may object during that period on reasonable data-protection grounds. The parties will work in good faith on a reasonable alternative; if none is available, either party may end the affected service.
Assistance and requests
Taking account of the nature of processing, Consultdemy will reasonably assist the customer with verified data-subject requests, security obligations, impact assessments, and regulator consultations. If Consultdemy receives a request concerning Customer Data, it will refer the requester to the customer unless law requires another response. The customer remains responsible for deciding and communicating the response.
Personal data incidents
Consultdemy will notify the customer without undue delay after confirming a personal data breach affecting Customer Data and, where feasible, within 48 hours. The notice will include information then reasonably available about the nature of the event, affected data and workspaces, likely consequences, containment, and a contact point. Consultdemy may provide information in phases and will preserve relevant evidence. Notice does not admit fault.
Deletion, return, and audit
At termination or a verified request, Consultdemy will delete or return Customer Data unless law requires retention. Normal deletion and backup-expiry periods are stated in the Privacy Policy. On reasonable written request no more than once per year, Consultdemy will provide information reasonably necessary to demonstrate compliance. Additional audits must protect other customers, confidentiality, security, and service availability, and are at the customer’s cost unless a material breach is found.
International transfers
If Customer Data protected by European transfer law is moved to a country without an adequacy decision, the applicable European Commission Standard Contractual Clauses are incorporated: Module 2 when the customer is a controller and Consultdemy is a processor, and Module 3 when both parties act as processors. The parties will complete the relevant annexes and supplementary measures as reasonably required.
Private workspace boundary
Consultdemy does not use one customer’s private connected data, metrics, creative, or work product to produce another customer’s report, chat, or company memory. Product reliability may be measured with aggregate or de-identified operational data that cannot reasonably identify a customer or its strategy. Any future cross-customer benchmark or learning program will require a separate, explicit written choice.
Conflict and contact
If this DPA conflicts with the Terms about processing Customer Data, this DPA controls. All other terms remain in effect. Data-protection questions may be sent to erkan@consultdemy.com.