# Threadline Data Processing Agreement (DPA)

**Version:** 1.0  
**Effective date:** 1 May 2026  
**Document:** Standard template under GDPR Article 28  

This Data Processing Agreement (“**Agreement**” or “**DPA**”) forms part of the agreement between the customer embedding Threadline Comments (“**Controller**”) and Threadline Technologies (“**Processor**”) for the provision of the Threadline Comments service (the “**Service**”).

> **How to use this template.** Download and complete the signature block. For a countersigned copy, email the completed DPA to [privacy@threadline.io](mailto:privacy@threadline.io). Publisher-plan and above customers receive priority countersignature.

---

## 1. Parties

| Role | Party |
|------|--------|
| **Controller** | The legal entity that owns or operates the website(s) on which Threadline is embedded, as identified in the Controller signature block |
| **Processor** | Threadline Technologies (operating threadline.io and the Threadline Comments service) |
| **Contact (Processor)** | privacy@threadline.io · legal@threadline.io |

## 2. Subject matter and duration

1. **Subject matter.** Processor processes personal data on behalf of Controller solely to host, display, moderate, and operate comment threads and related account features for pages where Controller has installed the Threadline embed.
2. **Duration.** This DPA applies for as long as Processor processes personal data for Controller under the Service, and thereafter for any period required to return or delete data as set out below.
3. **Nature and purpose.** Storage, transmission, display, moderation tooling, authentication, abuse prevention, and aggregated usage metrics necessary to operate the Service as instructed by Controller through the product configuration.

## 3. Categories of data subjects and personal data

**Data subjects** may include:

- Visitors who read comments  
- Authenticated commenters and guest commenters  
- Controller’s staff users of the Threadline dashboard  

**Personal data** may include:

- Account identifiers (email, display name, avatar URL where provided)  
- Comment content and metadata (page/thread URL, timestamps, votes/reactions)  
- Session and security cookies required for authentication and CSRF protection  
- Moderation and audit records related to comments on Controller’s sites  
- Aggregated or anonymized pageview / engagement metrics (not individual visitor profiles)

Processor does **not** process payment card data for commenters through the embed. Processor does **not** sell personal data or use commenter data for cross-site behavioral advertising.

## 4. Controller instructions

1. Processor shall process personal data only on documented instructions from Controller, including configuration in the Threadline dashboard, unless required to do so by Union or Member State law (in which case Processor will inform Controller unless prohibited).
2. Controller is responsible for the lawfulness of its instructions, for providing any notices required to data subjects, and for determining the lawful basis for processing on its sites.

## 5. Confidentiality

Processor ensures that persons authorized to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

## 6. Security of processing (Art. 32)

Taking into account the state of the art, costs, and the nature of the processing, Processor implements appropriate technical and organizational measures, including:

- Encryption of data in transit (TLS)  
- Password hashing (bcrypt) for account credentials  
- HTTP-only, Secure, SameSite session cookies  
- Access controls and least-privilege access to production systems  
- Logging of administrative actions for security auditing  
- Procedures for testing and evaluating security measures  

A current description of practices is summarized in the Threadline Privacy Policy and security documentation.

## 7. Sub-processors

1. Controller authorizes Processor to engage sub-processors necessary to provide the Service (for example, cloud hosting and transactional email providers).
2. Processor shall impose data-protection obligations on sub-processors that are no less protective than those in this DPA.
3. Processor will maintain a list of material sub-processors available on request at privacy@threadline.io and will provide reasonable advance notice of intended changes so Controller may object on reasonable data-protection grounds.

## 8. International transfers

Where personal data is transferred outside the EEA/UK, Processor shall ensure an appropriate transfer mechanism under Chapter V GDPR (for example, Standard Contractual Clauses, adequacy decision, or equivalent UK mechanism) as applicable to the transfer.

## 9. Assistance with data subject rights

Taking into account the nature of processing, Processor shall assist Controller by appropriate technical and organizational measures, insofar as possible, for the fulfilment of Controller’s obligation to respond to requests under GDPR Chapter III, including access, rectification, erasure, restriction, portability, and objection, via product tools (export, account deletion/anonymization, moderation) and support at privacy@threadline.io / dsar@threadline.io.

## 10. Personal data breach

Processor shall notify Controller without undue delay after becoming aware of a personal data breach affecting Controller’s personal data, and shall provide information reasonably required for Controller to meet its own notification obligations.

## 11. Deletion and return

Upon termination of the Service for Controller, or upon Controller’s written request, Processor shall, at Controller’s choice, delete or return personal data (except where retention is required by law). Account deletion and comment anonymization follow Threadline’s published retention practices (including any recovery window disclosed in product settings).

## 12. Audits

Upon reasonable written notice, Processor shall make available information necessary to demonstrate compliance with Article 28 and this DPA, and shall allow for and contribute to audits (including inspections) conducted by Controller or an auditor mandated by Controller, limited to processing of Controller’s personal data and subject to confidentiality, security, and reasonable scheduling constraints. Controller shall bear its own audit costs unless a material breach of this DPA is identified.

## 13. Liability

Liability under this DPA is subject to the limitations and exclusions in the Threadline Terms of Service, except to the extent prohibited by applicable data-protection law.

## 14. Precedence

If there is a conflict between this DPA and other agreements regarding the processing of personal data, this DPA prevails for that subject matter.

## 15. Governing law

This DPA is governed by the same governing law as the Threadline Terms of Service, without prejudice to mandatory data-protection rules applicable to the parties.

---

## Annex A — Processing description (summary)

| Item | Description |
|------|-------------|
| Service | Threadline Comments (hosted embed + dashboard) |
| Processing operations | Collect, store, display, transmit, moderate, export, anonymize/delete |
| Retention | Per product settings and Privacy Policy; anonymization on account erasure |
| Controller contact | As specified in signature block |
| Processor contact | privacy@threadline.io |

## Annex B — Signature

**Controller**

| Field | |
|-------|--|
| Legal name | ________________________________ |
| Registered address | ________________________________ |
| Signatory name / title | ________________________________ |
| Email | ________________________________ |
| Date | ________________________________ |
| Signature | ________________________________ |

**Processor — Threadline Technologies**

| Field | |
|-------|--|
| Signatory | Authorized representative |
| Email | privacy@threadline.io / legal@threadline.io |
| Date | ________________________________ |
| Signature | ________________________________ |

---

*This document is a standard contractual template for GDPR Article 28. It is not legal advice. Controllers should obtain their own counsel before relying on it in regulated environments.*
