Data Processing Agreement

Last updated: June 18, 2026

1. Introduction

This Data Processing Agreement (“DPA”) forms part of the agreement between Draftly (“we,” “us,” or “Processor”) and the customer or user of the Service (“Controller”) regarding the use of Draftly’s AI website builder platform (the “Service”).

Where Draftly processes personal data on behalf of the Controller — for example, personal data contained in content you upload or generate — Draftly acts as a data processor. For personal data that Draftly collects and determines the purposes of (such as account data, billing data, and usage analytics), Draftly acts as a data controller; such processing is described in our Privacy Policy.

This DPA applies to the extent that applicable data protection law — including the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the UK GDPR, and equivalent legislation — requires a data processing agreement between a controller and processor.

2. Nature and Purpose of Processing

Draftly processes personal data solely to provide and operate the Service. The nature and purpose of processing includes:

  • AI website generation: Processing prompts, instructions, and content you submit to generate website layouts, copy, images, and other assets using AI models.
  • Project storage and delivery: Storing your generated projects, assets, and configurations and making them accessible to you through the dashboard and published URLs.
  • Service operation: Authentication, subscription management, usage tracking, and customer support.
  • Security and integrity: Abuse detection, fraud prevention, and maintaining the reliability and security of the platform.

Processing is carried out on documented instructions from the Controller (i.e., your use of the Service). Draftly will not process personal data for any other purpose unless required by applicable law, in which case we will notify the Controller before processing unless prohibited by law.

3. Types of Personal Data Processed

Depending on how you use the Service, the following categories of personal data may be processed by Draftly on behalf of the Controller:

  • Identity and contact data: Name, email address, and authentication identifiers (e.g., Google sign-in ID) provided at account creation.
  • Usage and technical data: IP address, device and browser information, session identifiers, page views, feature usage logs, and timestamps generated during your use of the Service.
  • Content and generated data: Prompts, text, images, project metadata, and any other content you submit to or generate through the Service. This content may contain personal data if you or your end-users include it.
  • Payment data: Subscription status, plan type, and transaction references. Full payment card details are processed directly by our payment processor, Dodo, and are not stored on our servers.

The Controller is responsible for ensuring that any personal data submitted to the Service is done so lawfully and that data subjects have been informed appropriately.

4. Data Subject Rights

Draftly will assist the Controller — to the extent technically feasible and commercially reasonable — in fulfilling its obligations to respond to data subject rights requests under applicable data protection law, including:

  • Right of access: The right to obtain confirmation of whether personal data is being processed and to receive a copy of that data.
  • Right to rectification: The right to have inaccurate personal data corrected or incomplete data completed.
  • Right to erasure (“right to be forgotten”): The right to request deletion of personal data where there is no overriding legitimate ground for its retention.
  • Right to data portability: The right to receive personal data in a structured, commonly used, machine-readable format and to transmit it to another controller.
  • Right to restriction of processing: The right to request that processing be restricted in certain circumstances.
  • Right to object: The right to object to processing based on legitimate interests or for direct marketing purposes.

To exercise any of these rights, contact us at support@draftly.business. We may need to verify your identity before fulfilling requests. We will respond within the timeframes required by applicable law (generally 30 days, extendable by a further two months for complex requests).

5. Security Measures

Draftly implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk of processing, including:

  • Encryption at rest: Personal data stored in Google Firestore and Google Cloud Platform (GCP) infrastructure is encrypted at rest using AES-256 encryption managed by Google.
  • Encryption in transit: All data transmitted between clients and our servers, and between our services, is protected using TLS 1.2 or higher.
  • Access controls: Access to personal data is restricted to authorized personnel on a need-to-know basis. We use role-based access controls and enforce the principle of least privilege.
  • Authentication: Multi-factor authentication and strong credential policies are enforced for internal systems with access to personal data.
  • Incident response: We maintain procedures for detecting, reporting, and investigating data breaches, and will notify Controllers without undue delay (and no later than 72 hours where required) upon becoming aware of a personal data breach affecting data processed under this DPA.
  • Vendor security: Sub-processors are subject to contractual security obligations and are assessed for their security posture prior to onboarding.

6. Sub-processors

The Controller authorizes Draftly to engage the following sub-processors. We will notify the Controller of any intended changes to this list (additions or replacements) and provide a reasonable opportunity to object. Objections must be raised in writing within 14 days of notification.

  • Google LLC (Firebase, Firestore, Gemini AI) — United States. Provides database and backend infrastructure (Firebase / Cloud Firestore) for storing user accounts, project data, and application state; and AI model inference (Gemini) for generating website content. Data processed: account data, content, usage data.
  • Vercel Inc. — United States. Provides hosting and edge delivery for the Service frontend and serverless functions. Data processed: usage and technical data (request logs, IP addresses).
  • Wasabi Technologies LLC — United States. Provides object storage for user-uploaded assets and generated website files. Data processed: content (uploaded images and generated assets).
  • ZeptoMail (Zoho Corporation) — India / United States. Provides transactional email delivery for account notifications, subscription alerts, and service communications. Data processed: email address, communication metadata.
  • Dodo Payments — United States. Provides payment processing and subscription management. Payment card data is collected and processed directly by Dodo; Draftly does not store full card numbers. Data processed: billing contact details, transaction references, subscription status.

All sub-processors are engaged under written contracts that impose data protection obligations no less protective than those set out in this DPA.

7. Data Retention

Draftly retains personal data processed under this DPA for the duration of the Controller’s active subscription or account. Upon account deletion or a verified erasure request:

  • Personal data is scheduled for deletion or anonymization within 90 days of the deletion request or account closure, except where retention is required by applicable law (for example, financial records required under tax or accounting regulations).
  • Backup copies may persist for up to 90 additional days in encrypted backup archives before being purged from our systems.
  • Aggregated or de-identified data that cannot reasonably be re-linked to an individual may be retained indefinitely for product improvement and analytics purposes.

Upon termination of the agreement, Draftly will, at the Controller’s election, return or securely delete personal data processed on the Controller’s behalf, except as required by law.

8. International Transfers

Draftly is headquartered in India, and the Service is primarily operated on infrastructure located in the United States (Google Cloud, Vercel, Wasabi) and India (ZeptoMail/Zoho). Personal data may therefore be transferred to and processed in countries outside the European Economic Area (EEA), the United Kingdom (UK), or Switzerland.

Where such transfers are subject to GDPR or UK GDPR requirements, Draftly relies on the following transfer mechanisms:

  • Standard Contractual Clauses (SCCs): For transfers to the United States and other countries without an adequacy decision, we rely on the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) and, where applicable, the UK International Data Transfer Addendum.
  • Supplementary measures: Where required by applicable supervisory authority guidance, we implement supplementary technical measures (such as encryption) to ensure an essentially equivalent level of protection.

Our sub-processors maintain their own transfer mechanisms for onward transfers. Upon request, we can provide further information on the transfer mechanisms applicable to specific sub-processors.

9. Contact

For questions about this DPA, to submit a data subject rights request, or to report a data protection concern, please contact us at: support@draftly.business

Data processor: Draftly. For privacy inquiries and data subject rights, contact: support@draftly.business.