Legal & Data Protection

Data Processing Addendum (DPA)

Last Updated: October 2026 · Complies with Regulation (EU) 2016/679 (GDPR) and UK GDPR

Standard Customer Agreement Notice: This Data Processing Addendum ("DPA") supplements the Glady Terms of Service and applies automatically to any Customer workspace handling Personal Data of individuals located in the European Economic Area (EEA), the United Kingdom, or Switzerland.

1. Definitions & Roles

1.1 "Customer" (or "Data Controller") refers to the individual creator, studio, brand, or entity maintaining an active Glady CRM workspace.

1.2 "Platform" (or "Data Processor") refers to Glady CRM, a Netdrix company, providing creator audience management, link-in-bio services, social automation, and deal tracking software.

1.3 "Customer Personal Data" refers to any personal data submitted by Customer or collected via Customer's published link-in-bio pages, lead capture forms, or social channels (such as names, email addresses, phone numbers, and social handles).

2. Processing Scope & Instructions

Glady processes Customer Personal Data solely on behalf of and in accordance with Customer's documented instructions, as necessary to provide the Services, and in compliance with applicable Data Protection Legislation.

Glady shall not sell, retain, use, or disclose Customer Personal Data for any purpose other than for the specific business purposes of operating, maintaining, and supporting the Customer's workspace.

3. Technical and Organizational Measures (TOMs)

Glady implements and maintains appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Encryption at Rest: AES-256-GCM encryption applied to all stored provider credentials, OAuth tokens, and sensitive integration keys.
  • Encryption in Transit: Mandatory TLS 1.3 encryption across all public web and API endpoints, with HSTS preload enforcement (63,072,000s).
  • Strict Tenant Isolation: Every database query is cryptographically and logically scoped to the authenticated workspace ID, preventing cross-tenant data leakage.
  • Automated Database Backups: Daily encrypted snapshot backups with tested recovery procedures and 14-day retention.
  • Rate Limiting & DDoS Protection: Redis sliding window rate limiters and Cloudflare WAF bot mitigation on all authentication and public intake routes.

4. Subprocessors

Customer grants general written authorization for Glady to engage the subprocessors listed on our Authorized Subprocessors Directory. Glady imposes contractual data protection obligations upon each subprocessor no less protective than those set forth in this DPA.

5. Personal Data Breach Notification

In the event of a confirmed Personal Data Breach affecting Customer Personal Data, Glady shall notify Customer without undue delay and, in any event, within seventy-two (72) hours of becoming aware of the breach, providing relevant details to assist Customer in meeting their regulatory obligations.

6. Data Subject Rights & Deletion

Glady provides self-serve capabilities within the Platform to enable Customer to fulfill requests from data subjects to access, rectify, export, or erase their personal data (GDPR Articles 15–20). Upon termination of the Services, Glady shall, at Customer's election, delete or return all Customer Personal Data within thirty (30) days.

For inquiries regarding this DPA, contact privacy@gladycrm.com.
View Privacy Policy →