Legal
Data Processing Addendum
Last updated: 12 July 2026
Template for review — not legal advice.
This Data Processing Addendum (DPA) forms part of the Terms of Service between the Customer and Listly EURL and governs personal data that Listly processes on the Customer's behalf.
1. Scope and roles
The Customer acts as data controller for the personal data submitted to the service. Listly acts as data processor and processes personal data only on the Customer's documented instructions, as set out in the Terms and this DPA.
2. Processing details
| Item | Description |
|---|---|
| Subject matter | Provision of the Listly AI listing-generation service |
| Duration | For the term of the Customer's subscription, plus retention periods below |
| Nature and purpose | Storage, AI processing, export of product listings |
| Data categories | Product photos, catalog text, account identifiers, usage data |
| Data subjects | The Customer's authorized users |
3. Sub-processors
Listly uses the following sub-processors:
- OpenAI, L.L.C. — AI model inference (United States, under SCCs)
- Supabase, Inc. — database, authentication and file storage (EU region)
- Stripe Payments Europe, Ltd. — subscription billing (EU/US, under SCCs)
The Customer authorizes these sub-processors. Listly will give at least 30 days' notice before adding or replacing a sub-processor, giving the Customer an opportunity to object on reasonable grounds.
4. Security measures
Listly maintains technical and organizational measures appropriate to the risk, including encryption in transit and at rest, access control with least-privilege, environment isolation, logging and monitoring, secure development practices, and staff confidentiality obligations.
5. Breach notification
Listly will notify the Customer without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting Customer data, and will cooperate to help the Customer meet its own notification obligations.
6. Return and deletion
On termination of the Customer's subscription, Listly will delete Customer personal data within 90 days, except where retention is required by law. The Customer may export data before termination via the CSV export.
7. Audit cooperation
Listly will make available information necessary to demonstrate compliance with this DPA and will contribute to reasonable audits carried out by the Customer or an independent auditor mandated by the Customer, subject to confidentiality and reasonable notice.
8. International transfers
Where personal data is transferred outside the EEA to a country without an adequacy decision, Listly relies on the European Commission's Standard Contractual Clauses (SCCs) and applies supplementary measures where required.
9. Contact
Listly EURL — Paris, France — contact@listly.business