Legal

Data Processing Addendum

Last updated: 12 July 2026

Template for review — not legal advice.

This Data Processing Addendum (DPA) forms part of the Terms of Service between the Customer and Listly EURL and governs personal data that Listly processes on the Customer's behalf.

1. Scope and roles

The Customer acts as data controller for the personal data submitted to the service. Listly acts as data processor and processes personal data only on the Customer's documented instructions, as set out in the Terms and this DPA.

2. Processing details

ItemDescription
Subject matterProvision of the Listly AI listing-generation service
DurationFor the term of the Customer's subscription, plus retention periods below
Nature and purposeStorage, AI processing, export of product listings
Data categoriesProduct photos, catalog text, account identifiers, usage data
Data subjectsThe Customer's authorized users

3. Sub-processors

Listly uses the following sub-processors:

  • OpenAI, L.L.C. — AI model inference (United States, under SCCs)
  • Supabase, Inc. — database, authentication and file storage (EU region)
  • Stripe Payments Europe, Ltd. — subscription billing (EU/US, under SCCs)

The Customer authorizes these sub-processors. Listly will give at least 30 days' notice before adding or replacing a sub-processor, giving the Customer an opportunity to object on reasonable grounds.

4. Security measures

Listly maintains technical and organizational measures appropriate to the risk, including encryption in transit and at rest, access control with least-privilege, environment isolation, logging and monitoring, secure development practices, and staff confidentiality obligations.

5. Breach notification

Listly will notify the Customer without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting Customer data, and will cooperate to help the Customer meet its own notification obligations.

6. Return and deletion

On termination of the Customer's subscription, Listly will delete Customer personal data within 90 days, except where retention is required by law. The Customer may export data before termination via the CSV export.

7. Audit cooperation

Listly will make available information necessary to demonstrate compliance with this DPA and will contribute to reasonable audits carried out by the Customer or an independent auditor mandated by the Customer, subject to confidentiality and reasonable notice.

8. International transfers

Where personal data is transferred outside the EEA to a country without an adequacy decision, Listly relies on the European Commission's Standard Contractual Clauses (SCCs) and applies supplementary measures where required.

9. Contact

Listly EURL — Paris, France — contact@listly.business