Data Processing Addendum

Last updated: 12 September 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Service between Neurai Technologies Private Limited ("CommentFor", "we") and the customer that holds a CommentFor account ("Customer", "you"). It applies whenever we process personal data on your behalf in providing the service, and takes effect on the date you accept the Terms or, if later, on the date above. If there is a conflict between this DPA and the Terms, this DPA prevails for the processing it covers.

1. Definitions

"Data protection law" means the laws that apply to the processing of personal data under this DPA, which may include the GDPR, the UK GDPR, the Swiss FADP, the CCPA and India's Digital Personal Data Protection Act, 2023. "Personal data", "processing", "controller", "processor", "data subject" and "personal data breach" have the meanings given in those laws, and "Customer Data" means the personal data we process on your behalf, as described in Annex 1.

2. Roles

For Customer Data, you are the controller and we are your processor. You determine why and how the people who interact with your connected accounts are messaged, and you are responsible for having a lawful basis, for any consent or notice those people require, and for the content you configure. For the personal data of your own account, such as your login details and billing records, we are an independent controller and our Privacy Policy applies.

3. Our obligations

We will process Customer Data only on your documented instructions, which are the Terms, this DPA and the settings you configure in the service, unless the law requires otherwise, in which case we will tell you before processing unless the law prevents it. We will ensure that people authorised to process Customer Data are bound by confidentiality. We will implement appropriate technical and organisational measures, described in Annex 2, to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. We will, taking into account the nature of the processing, assist you in responding to requests from data subjects and in meeting your obligations on security, breach notification and impact assessments, to the extent the information is available to us.

4. Sub-processors

You authorise us to engage the sub-processors listed in Annex 3, and to add or replace sub-processors. We will give you notice of a change, by updating this page and, for a material change, by notifying account holders through the service, at least fourteen days before the new sub-processor processes Customer Data. If you object on reasonable data-protection grounds and we cannot resolve the objection, you may terminate the affected service and receive a pro-rated refund of any prepaid fees for the remaining term. We remain responsible for our sub-processors' performance of the obligations in this DPA.

5. Data subject requests

If we receive a request from a data subject about Customer Data, we will direct the person to you where we can identify you, and will not respond further except on your instructions or as the law requires. Where a request reaches us through a platform's own mechanism, such as a data-deletion request forwarded by Meta, we act on it as the platform's rules require and record that we did.

6. Personal data breach

We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Data, and will provide the information reasonably available to us to help you meet your own notification obligations. Our notice is not an admission of fault or liability.

7. International transfers

We process Customer Data in India, and our sub-processors may process it in other countries. Where data protection law restricts a transfer, we rely on appropriate safeguards, such as the standard contractual clauses approved by the European Commission and the UK addendum to them, which are incorporated into this DPA by reference, with you as data exporter and us as data importer. On request we will provide a signed copy.

8. Audit and information

We will make available the information reasonably necessary to demonstrate our compliance with this DPA, and will allow and contribute to audits conducted by you or an auditor you mandate, no more than once a year unless the law or a supervisory authority requires otherwise, on at least thirty days' notice, during business hours, under confidentiality, and without disrupting the service. We may first satisfy an audit request with written answers and existing documentation.

9. Retention and deletion

We retain Customer Data for as long as needed to provide the service and as the Terms and Privacy Policy describe. When you disconnect an account, delete your account or terminate the service, we delete the related Customer Data from our live systems promptly. Encrypted backup copies may be retained for up to 60 days for operational and legal reasons. We may keep information that the law requires us to keep, or that is needed to resolve disputes, prevent abuse or enforce our agreements.

10. Liability

Each party's liability under this DPA is subject to the exclusions and limits in the Terms, and the same aggregate cap applies to the Terms and this DPA together.

11. General

This DPA lasts as long as we process Customer Data on your behalf. We may update it to reflect changes in the law or the service; a material change will be notified through the service, and continued use after the effective date is acceptance. Nothing in this DPA reduces the protection the applicable data protection law gives to data subjects.

Annex 1 — Processing details

Annex 2 — Security measures

Encryption of data in transit; encryption at rest of platform access tokens and captured contact details; access to production systems limited to authorised personnel with two-factor authentication; two-factor authentication available to every account; logging of security-relevant events; encrypted backups with bounded retention and a tested restore procedure; separation of each customer's data by account; automatic removal of platform identifiers, received comment content and click records after a retention period; secure development practices including code review, dependency scanning and secret scanning before every release.

Annex 3 — Sub-processors

Integrations you connect yourself, such as an email-marketing tool or a webhook destination, are your own processors and are not sub-processors under this DPA. Our payment processor handles your billing details as described in the Privacy Policy and does not process Customer Data.

Contact

privacy@commentfor.com