Data Processing Agreement
Effective 20 August 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between the customer identified in an Order Form (“Controller”) and Pretty GmbH(“Processor”) for use of the Pretty Service.
This DPA applies when Pretty processes personal data on the Controller’s behalf. Defined terms not explained here have the meaning given in the Terms of Use, Order Form, or GDPR.
1. Subject matter
Pretty processes personal data for which the Controller is responsible in order to provide the Pretty web editor, PowerPoint add-in, and related contracted services (“Controller Data”). This DPA sets out the parties’ rights and obligations under data protection law in connection with that processing.
2. Scope of data processing
Pretty processes Controller Data on behalf of and according to the documented instructions of the Controller within the meaning of Article 28 GDPR. The Controller remains responsible as controller under data protection law.
Appendix 1 describes the purpose, nature, duration, data categories, and data subjects covered by the processing. The processing is limited to what is necessary to provide, secure, support, and delete the contracted Service.
3. Instructions from the Controller
Pretty processes Controller Data only on documented instructions from the Controller unless Union or Member State law requires other processing. Where legally permitted, Pretty will inform the Controller before carrying out processing required by law.
This DPA, the Main Contract, the Controller’s product settings, user actions, support requests, and written instructions together constitute documented instructions. Instructions that require a material change to the standard Service are binding only when the parties agree to them in writing, including any fees or technical conditions.
Pretty will inform the Controller without undue delay if it believes an instruction infringes applicable data protection law. Pretty may suspend the affected instruction until the parties resolve the issue.
4. Responsibility of the Controller
The Controller is responsible for the lawfulness, accuracy, and scope of Controller Data and its instructions. It must provide required notices, establish a legal basis, and ensure that users submit only data the Controller is permitted to process through the Service.
The Controller will provide information Pretty reasonably needs for records of processing, regulatory inquiries, or the performance of this DPA. The Controller is responsible for configuring its customer-provided AI gateway, upstream model providers, user permissions, and retention choices.
5. Security of processing
Pretty maintains appropriate technical and organizational measures under Article 32 GDPR, taking into account the state of the art, implementation costs, the nature and purpose of processing, and the risks to data subjects. Appendix 3 describes the measures in place when this DPA takes effect.
Pretty may update those measures as technology and risk change, provided that the overall level of protection for Controller Data does not materially decrease. Pretty will document material changes.
6. Requirements for personnel
Pretty limits access to Controller Data to personnel who need it to perform the Service, support the Controller, or maintain security. Authorized personnel are bound by contractual or statutory confidentiality duties and receive security and data protection guidance appropriate to their role.
7. Use of Sub-Processors
The Controller gives Pretty general authorization to engage the Sub-Processors listed in Appendix 2. Pretty remains responsible for each Sub-Processor’s performance of its data protection obligations to the extent required by Article 28(4) GDPR.
Pretty will give the Controller at least 14 days’ advance notice before adding or replacing a Sub-Processor. Notice may be sent to the workspace administrator or contractual contact. The Controller may object within that period on specific and reasonable data protection grounds. The parties will work in good faith to resolve the objection. If no reasonable solution is available, either party may terminate the affected Service on 30 days’ notice.
Pretty imposes data protection obligations on each Sub-Processor that provide substantially the same protection required by this DPA. Pretty ensures that an appropriate Chapter V GDPR transfer mechanism applies where a Sub-Processor processes Controller Data in a third country.
8. International data transfers
Core managed application, database, and object-storage resources are configured in the European Union. Limited account, transactional email, support, operational monitoring, or technical data may be processed outside the EEA by a Sub-Processor as described in Appendix 2.
Pretty transfers Controller Data outside the EEA only on the Controller’s instruction or where needed to use an authorized Sub-Processor, and only with a lawful mechanism under Articles 44 to 49 GDPR. Depending on the transfer, this may include an adequacy decision, the EU-U.S. Data Privacy Framework, or EU Standard Contractual Clauses with supplementary measures.
A customer-provided AI gateway is controlled by the Controller. The Controller determines its location, providers, credentials, and transfer safeguards. Routing a request to that gateway is a documented Controller instruction.
9. Data subject rights
Taking into account the nature of the processing, Pretty will assist the Controller through available product functions and reasonable technical measures with requests to access, correct, export, restrict, or delete Controller Data.
If Pretty receives a data subject request concerning Controller Data, Pretty will forward it to the Controller without undue delay and will not answer it independently unless the Controller instructs Pretty to do so or law requires a response. Pretty may respond directly to routine account-verification or account-deletion requests where the Controller has enabled that workflow and the requester’s identity is verified.
10. Notification and support obligations
Pretty will notify the Controller without undue delay and no later than 48 hours after becoming aware of a confirmed personal data breach affecting Controller Data. The first notice will contain the information reasonably available at that time. Pretty will provide material updates as the investigation progresses.
Taking into account the nature of processing and information available to Pretty, Pretty will reasonably assist the Controller with breach notifications, communications to data subjects, data protection impact assessments, and prior consultations under Articles 32 to 36 GDPR. If a request requires significant work beyond the standard Service, the parties will agree on scope and reasonable fees in advance.
11. Data deletion
Users and workspace administrators may delete stored Controller Data through available product functions. Pretty stores presentation files and source documents when a user uploads or saves them. Chat prompts and generated responses are retained as part of chat history. Temporary processing copies created from uploaded content are automatically deleted after 14 days.
After termination of the Main Contract, Pretty will make available any standard export function and delete Controller Data from active systems within 30 days, unless the Controller requests earlier deletion and it is technically feasible. Backup copies expire through Pretty’s 30-day backup retention cycle. Pretty may retain records required by law or needed to demonstrate compliance, but will isolate them and process them only for that purpose.
Pretty will confirm completion of deletion on written request.
12. Verifications and audits
Pretty will provide information reasonably necessary to demonstrate compliance with this DPA and Article 28 GDPR. Pretty may satisfy routine requests with current policies, audit-readiness material, independent reports, security questionnaires, or certifications when available.
Pretty’s information security management system is audit ready and certification work is underway. Pretty does not represent that an ISO 27001 certificate has been issued.
If the supplied evidence is not sufficient for a specific, substantiated concern, the Controller may conduct a remote or on-site inspection during normal business hours on reasonable notice. Audits must avoid unreasonable disruption and protect other customers’ data, security information, and trade secrets. An external auditor must be independent, not a competitor of Pretty, and bound by confidentiality.
13. Liability
The liability provisions of the Main Contract apply to this DPA, including agreed exclusions and limits. Nothing in this DPA limits mandatory liability under Article 82 GDPR or another law that does not permit limitation.
14. Term and termination
This DPA begins when Pretty first processes Controller Data under the Main Contract and remains in force for as long as Pretty retains Controller Data. Termination of the Main Contract terminates this DPA after Pretty has completed the required return or deletion of Controller Data. This DPA cannot be terminated separately while Pretty continues processing Controller Data for the Controller.
15. Final provisions
The Main Contract governs matters not addressed in this DPA, including governing law and jurisdiction. This DPA takes priority over conflicting terms of the Main Contract for data protection matters. Standard Contractual Clauses take priority where their mandatory text conflicts with this DPA.
If a provision is invalid, the remaining provisions remain effective. The parties will replace the invalid provision with a valid provision that best preserves its purpose and complies with Article 28 GDPR.
Appendix 1. Purpose, nature and scope of processing
Purpose
Provision, operation, security, support, and deletion of the Pretty web editor, PowerPoint add-in, and related presentation and AI functions under the Main Contract.
Nature of processing
Collection, recording, organization, storage, retrieval, use, modification, rendering, transmission to authorized endpoints, analysis for support and security, restriction, export, and deletion.
Categories of personal data
- account data such as names, business email addresses, organization, role, and authentication data;
- usage and technical data such as session identifiers, timestamps, defined product events, and errors;
- content data such as presentations, slide text, notes, images, metadata, source documents, prompts, selected presentation context, and AI-generated output;
- configuration data such as workspace settings, permissions, templates, and saved project context; and
- support data such as feedback, messages, attachments, and customer-supplied diagnostic information.
Categories of data subjects
- employees, contractors, and other authorized users of the Controller; and
- third parties whose personal data the Controller or its users include in Customer Content.
Special categories and duration
The Controller decides whether to submit special-category or criminal-conviction data and must apply the legal and organizational safeguards required for that data. Processing lasts for the Main Contract and the deletion period in Section 11.
Appendix 2. List of authorized Sub-Processors
| Company | Purpose and data | Processing location | Transfer safeguard |
|---|---|---|---|
| Google Cloud EMEA Limited / Google LLC | Application hosting, database, object storage, logs, and managed infrastructure; Controller Data | Core resources in europe-west1, Belgium | Google Cloud data processing terms and EU Standard Contractual Clauses where applicable |
| Plus Five Five, Inc. (Resend) | Transactional authentication and invitation email; recipient address, message details, and delivery metadata | Sending may use Ireland; account data, email metadata, logs, and API records may be stored in the United States | EU-U.S. Data Privacy Framework and EU Standard Contractual Clauses |
| PostHog, Inc. | Defined product analytics and exception diagnostics; identifiers, product events, session IDs, and errors | PostHog Cloud EU in Germany; global edge and controlled organizational access may apply | EU-U.S. Data Privacy Framework and EU Standard Contractual Clauses |
| Gleap GmbH | In-product feedback and customer-requested support; identity, feedback, attachments, and supplied diagnostics | Primary infrastructure in Frankfurt with additional EU workloads and published supporting providers | Data processing terms and EU Standard Contractual Clauses where applicable |
| Slack Technologies Limited | Operational chat monitoring and incident diagnostics; user and organization metadata, prompts, responses, files, images, and error details | Slack workspace and authorized subprocessors; data may be processed outside the EEA | Slack data processing addendum and EU Standard Contractual Clauses; EU-U.S. Data Privacy Framework where applicable |
A customer-provided AI gateway is controlled and selected by the Controller. It is not a Sub-Processor engaged by Pretty. The Controller controls its location, credentials, upstream model providers, logging, retention, and transfer safeguards.
Contact support@make-pretty.com for current provider documentation or transfer safeguards.
Appendix 3. Technical and organizational measures
Access and organization
- passwordless user authentication and owner, administrator, and member roles;
- staff multi-factor authentication, least-privilege access, and periodic access review;
- confidentiality obligations and defined security and privacy responsibilities; and
- managed secrets and separation between development, test, and production environments.
Confidentiality and isolation
- logical tenant isolation and row-level access controls for organization data;
- encryption in transit using current TLS and encryption at rest for managed storage;
- restricted administrative access and logged privileged operations; and
- Customer-controlled credentials and endpoints where the Customer supplies its AI gateway.
Monitoring and secure operations
- security and application monitoring, error detection, and incident-response procedures;
- restricted operational monitoring and incident channels that may contain chat content;
- dependency, vulnerability, and change-management controls; and
- customer-requested diagnostic collection with controlled access and deletion.
Availability and recovery
- automated backups at least daily with at least 30 days of retention;
- a recovery point objective of 24 hours and recovery time objective of 12 business hours;
- annual testing of backup restoration and disaster-recovery procedures; and
- production monitoring and a documented incident-communication process.
Retention and deletion
- storage of uploaded or saved presentation content and retention of chat history;
- automatic deletion of temporary processing copies created from uploaded content after 14 days;
- application-level deletion for stored presentations and generated assets; and
- contract-termination deletion and backup expiry as described in Section 11.