Skip to main content

Presify Data Processing Agreement

Effective Date: June 27, 2026

This Data Processing Agreement (this "DPA") supplements and forms part of the Terms of Service (the "Agreement") between Presify, LLC, a Florida limited liability company ("Presify," "we," "us," or "our"), and the entity identified as Customer on the Agreement ("Customer" or "you").

This DPA governs Presify's processing of Personal Data on Customer's behalf in connection with the Service.


1. Definitions

Capitalized terms used and not defined in this DPA have the meanings given in the Agreement.

1.1 "Personal Data" means any information relating to an identified or identifiable natural person that is processed by Presify on Customer's behalf in connection with the Service, including without limitation the categories described in Schedule 1.

1.2 "Data Subject" means an identified or identifiable natural person whose Personal Data is processed under this DPA, including Authorized Users and Monitored Users.

1.3 "Processing" has the meaning given in applicable Data Protection Laws (typically, any operation performed on Personal Data, whether automated or not, including collection, storage, use, disclosure, and deletion).

1.4 "Controller" means the entity that determines the purposes and means of the Processing of Personal Data. Under this DPA, Customer is the Controller.

1.5 "Processor" means the entity that processes Personal Data on behalf of the Controller. Under this DPA, Presify is the Processor.

1.6 "Sub-processor" means any third party engaged by Presify to process Personal Data on Customer's behalf.

1.7 "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data Processed by Presify or its Sub-processors.

1.8 "Data Protection Laws" means all data protection and privacy laws and regulations applicable to the Processing of Personal Data under this DPA, including without limitation the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA"), and other United States state privacy laws of similar effect (such as those of Colorado, Connecticut, Virginia, and Utah) as and to the extent they apply.


2. Roles and Scope

2.1 Roles. With respect to Personal Data Processed under this DPA, Customer is the Controller, and Presify is the Processor. Each party will comply with its respective obligations under applicable Data Protection Laws.

2.2 Scope. This DPA applies to all Personal Data Processed by Presify on Customer's behalf in providing the Service.

2.3 Customer instructions. Presify will Process Personal Data only on the documented instructions of Customer, as set out in the Agreement, this DPA, and the configuration of the Service by Customer. The Service's published functionality (collecting presence events, generating reports, and similar activities) constitutes Customer's documented instructions. Presify will not Process Personal Data for its own purposes, will not determine the purposes or means of the Processing, and will make no independent use of Monitored User presence data beyond providing the Service to Customer. Presify does not act as a controller with respect to Monitored User Personal Data. If Presify reasonably believes that a Customer instruction violates applicable law, Presify will inform Customer (unless prohibited by law from doing so) and may refuse to process the instruction until the matter is resolved.

2.4 Subject matter, duration, nature, purpose, and categories. A description of the Processing under this DPA is set out in Schedule 1.

2.5 Customer representations. As Controller, Customer represents that it has established a lawful basis for the Processing and has provided, or will provide before monitoring begins, any notice of electronic monitoring required by applicable law. When Customer connects the Service to its Microsoft tenant, the administrator acting on Customer's behalf attests to these matters; Presify records that attestation, with its timestamp and the attesting administrator's identity, as described in Schedule 2. Determining what notice applies and giving it remains Customer's responsibility.


3. Presify Obligations

3.1 Confidentiality. Presify will ensure that persons authorized to Process Personal Data have committed to confidentiality or are under an appropriate statutory obligation of confidentiality. Presify limits access to Personal Data to personnel and contractors who need access to perform Presify's obligations under the Agreement.

3.2 Security measures. Presify will implement and maintain commercially reasonable technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access. A summary of these measures is set out in Schedule 2.

3.3 Assistance with Data Subject requests. Taking into account the nature of the Processing, Presify will provide reasonable assistance to Customer in fulfilling Customer's obligations to respond to Data Subject requests under applicable Data Protection Laws. The Service includes in-application functionality for Customer to fulfill access, deletion, and export requests. For requests that cannot be fulfilled using in-application functionality, Customer may contact Presify through our contact form for additional assistance, which may be subject to reasonable fees if the request requires significant manual effort.

3.4 Assistance with breach notification. In the event of a Personal Data Breach affecting Customer's Personal Data, Presify will, without undue delay and in any event within seventy-two (72) hours of becoming aware of the breach: (a) notify Customer, (b) provide a description of the nature of the breach including, where possible, the categories and approximate number of Data Subjects and records affected, (c) describe the likely consequences of the breach, and (d) describe the measures taken or proposed to be taken to address the breach.

3.5 Assistance with assessments. Presify will provide reasonable assistance to Customer in conducting data protection impact assessments and consultations with supervisory authorities, where required by applicable Data Protection Laws.

3.6 Records. Presify will maintain records of its Processing activities as required by applicable Data Protection Laws and will make such records available to Customer upon reasonable request.

3.7 CCPA service provider. To the extent Presify Processes Personal Data that constitutes "personal information" of California residents under the California Consumer Privacy Act, as amended (the "CCPA"), the parties agree as follows:

(a) Status. Presify is a "service provider" as defined in CCPA § 1798.140(ag), and Customer is the "business." Presify Processes such personal information solely on Customer's behalf.

(b) Limited purpose. Presify will Process personal information only for the specific business purpose of providing the Service, as described in the Agreement and in Schedule 1 of this DPA, and for no other purpose. Presify will not retain, use, or disclose personal information for any purpose other than that business purpose, including outside the direct business relationship between Presify and Customer, except as permitted by the CCPA.

(c) No sale; no sharing; no targeted advertising. Presify will not sell or share personal information (as "sell" and "share" are defined in the CCPA), and will not Process personal information for cross-context behavioral advertising.

(d) No combining. Presify will not combine personal information it receives from, or on behalf of, Customer with personal information it receives from, or on behalf of, any other person, or that it collects from its own interaction with any consumer, except as the CCPA permits a service provider to do.

(e) Certification. Presify certifies that it understands the restrictions in this Section 3.7 and will comply with them.

(f) Sub-processor flow-down. Presify will impose the same CCPA service-provider restrictions on any Sub-processor it engages to Process such personal information, consistent with Section 4.5.

(g) Notice of inability to comply. Presify will notify Customer if it determines that it can no longer meet its obligations under the CCPA, and Customer may take reasonable and appropriate steps to stop and remediate unauthorized Processing.

3.8 Data minimization. Presify Processes only the categories of Personal Data described in Schedule 1. The Service does not Process the contents of any communication or work product, including without limitation the text of email, chat, or Teams messages; the contents of files or documents; calendar event contents; call or meeting audio, video, recordings, or transcripts; screenshots; or keystrokes. This data-minimization design is a technical and organizational measure described in Schedule 2 and is reflected in the Service's read-only, presence-only Microsoft Graph permissions.


4. Sub-processors

4.1 General authorization. Customer provides Presify with a general authorization to engage Sub-processors to assist with providing the Service.

4.2 Current Sub-processors. The current list of Sub-processors is set out in Schedule 3 and is maintained on the Presify Privacy Policy at https://presify.io/legal/privacy.

4.3 Notice of new Sub-processors. Presify will provide Customer with at least thirty (30) days' notice before engaging a new Sub-processor or changing an existing Sub-processor that materially affects the Processing of Customer's Personal Data. Notice will be provided by email to Customer's Account Owner or by an updated Sub-processor list on the Privacy Policy page combined with notice in the in-application notifications center.

4.4 Customer objection. Customer may object to a new or changed Sub-processor on reasonable grounds related to the Sub-processor's ability to comply with this DPA by sending written notice to legal@presify.io within thirty (30) days of Presify's notice. If Customer objects, the parties will work together in good faith to resolve the objection. If no resolution is reached, Customer's exclusive remedy is to terminate the Agreement for the affected portion of the Service.

4.5 Sub-processor obligations. Presify will impose data protection obligations on each Sub-processor that are no less protective than those in this DPA. Presify remains liable for the acts and omissions of its Sub-processors with respect to the Processing of Personal Data.


5. International Transfers

5.1 Current geographic scope. The Service is operated entirely on infrastructure located in the United States. By using the Service, Customer instructs Presify to transfer and Process Personal Data in the United States.

5.2 EEA, UK, and Swiss data. The Service is not currently designed for the Processing of Personal Data of Data Subjects located in the European Economic Area, the United Kingdom, or Switzerland. Customer shall not enroll individuals based in those regions as Monitored Users, and the Service technically prevents their enrollment and automatically stops monitoring a Monitored User whose directory location changes to one of those regions. As of the Effective Date, Presify has not implemented Standard Contractual Clauses or other approved cross-border transfer mechanisms for data from those regions. The Service likewise does not support, and technically blocks the enrollment of, Monitored Users located in Canada (subject to PIPEDA and Quebec Law 25).

5.3 Future expansion. If Customer requires Processing of EEA, UK, or Swiss data in the future, the parties will execute additional documentation as required by applicable Data Protection Laws before such Processing begins.


6. Data Subject Rights

6.1 Customer responsibility. As Controller, Customer is responsible for responding to Data Subject requests. Customer is solely responsible for the legal basis of the Processing, providing required notices to Data Subjects, and obtaining required consents.

6.2 Presify forwarding. If Presify receives a Data Subject request directly relating to Customer's Personal Data, Presify will (a) acknowledge receipt to the Data Subject, (b) forward the request to Customer without undue delay, and (c) not respond to the Data Subject regarding the substance of the request except to confirm receipt and forwarding, unless directed by Customer or required by law.

6.3 Self-service tools. Customer may use the Service's in-application functionality to fulfill the following Data Subject requests for Monitored Users:

  • Right to know: the per-user data export provides the presence events the Service holds for a specified Monitored User, and the anomalies export provides the derived anomaly findings for that user, in each case within the applicable retention window. The categories, sources, and purposes of the data the Service processes are described in this DPA and the Privacy Policy.
  • Right to delete: the per-user data deletion feature deletes all presence data for a specified Monitored User, with display-name confirmation to prevent accidental deletion.
  • Right to correct: presence data reflects what Microsoft Graph reported and is not directly editable. Inaccuracies in display name or UPN propagate via Microsoft's user directory and are picked up automatically by the Service's user delta sync.

7. Personal Data Breach Notification

7.1 Notification timeline. Per Section 3.4, Presify will notify Customer of a Personal Data Breach affecting Customer's Personal Data without undue delay and in any event within seventy-two (72) hours of becoming aware of the breach.

7.2 Cooperation. The parties will cooperate in the investigation, remediation, and notification (where required) of any Personal Data Breach.

7.3 No public disclosure without consent. Neither party will make any public disclosure of a Personal Data Breach affecting Customer's data without the prior written consent of the other party, except where required by applicable law.


8. Audits

8.1 Information requests. Presify will make available to Customer information reasonably necessary to demonstrate compliance with this DPA, including summaries of security measures, third-party audit reports, and certifications when available.

8.2 Audit rights. Customer may, upon reasonable written notice and no more than once per twelve (12) month period (or more frequently if required by a supervisory authority or following a confirmed Personal Data Breach), conduct an audit of Presify's compliance with this DPA. Audits will be conducted during regular business hours, will not unreasonably interfere with Presify's operations, and will be subject to confidentiality obligations. Customer will bear the costs of any audit unless the audit reveals material non-compliance, in which case Presify will reimburse Customer for reasonable audit costs.

8.3 Alternative to on-site audit. As an alternative to an on-site audit, Customer may request and Presify will provide: (a) a written response to a security questionnaire, (b) summaries of internal security assessments, or (c) once available, third-party audit reports such as SOC 2 or ISO 27001 attestations.


9. Liability and Indemnification

Liability under this DPA is subject to the limitations of liability set out in the Agreement, including the cap on cumulative liability. Nothing in this DPA expands or contracts the liability allocations in the Agreement, except as required by applicable Data Protection Laws.


10. Term and Termination

10.1 Term. This DPA takes effect on the Effective Date and continues for the duration of the Agreement. Provisions of this DPA that by their nature should survive termination (including obligations regarding return or deletion of Personal Data and confidentiality) survive termination.

10.2 Deletion or return of Personal Data. Upon termination or expiry of the Agreement (including expiry of a free trial that is not upgraded), Presify will delete Personal Data in accordance with the cancellation and trial-expiry lifecycle described in the Agreement, except where retention is required by applicable law. Specifically:

  • During the thirty (30) day read-only window following cancellation, Customer may export its Personal Data using in-application functionality.
  • At the end of the read-only window, Presify deletes Customer Data including all presence events, daily rollups, anomaly findings, pending enrollment records, monitored user records, tenant settings, monitor scope assignments, report jobs, report files in S3, cancellation surveys, and checkout sessions.
  • The Customer's organization name, primary domain, and Microsoft tenant identifier are retained (not anonymized): they are low-sensitivity business identifiers needed to attribute the retained authorization and billing records to the correct organization. An anonymized billing audit trail is preserved as required for tax and accounting purposes.
  • Audit log entries are retained as part of Presify's compliance evidence, subject to security access controls.
  • Records of legal-document acceptances and of the connection-time data-controller and employee-monitoring-notice attestations are retained beyond deletion to establish that the monitoring was authorized and consented to and for the establishment, exercise, or defense of legal claims. Each record includes the document version and the exact text accepted, the date and time, the originating IP address, and the name and email of the accepting Authorized User, together with the Customer's organization name and primary domain. These records contain no Monitored User Personal Data.
  • Service operational and security logs, including per-tenant Microsoft Graph API availability records, are retained beyond deletion as evidence that the Service operated as described. These logs contain no Monitored User Personal Data.
  • The Customer may request immediate deletion (bypassing the read-only window) via the in-application "Delete all data" feature.

10.3 Confirmation of deletion. Upon request, Presify will confirm deletion in writing.


11. General

11.1 Order of precedence. In the event of a conflict between this DPA and the Agreement, this DPA controls with respect to the Processing of Personal Data.

11.2 Governing law. This DPA is governed by the laws of the State of Florida, consistent with the Agreement.

11.3 No third-party beneficiaries. This DPA does not create any third-party beneficiary rights.

11.4 Modifications. Presify may modify this DPA as necessary to comply with changes in Data Protection Laws or to reflect changes to the Service. Material changes will be communicated to Customer by email at least thirty (30) days before they take effect.


Schedule 1: Description of Processing

Subject matter of Processing: Provision of the Presify service, including collection, storage, analysis, and reporting of Microsoft Teams presence data.

Duration of Processing: For the term of the Agreement, including any free trial period and the post-trial or post-cancellation read-only window, plus retention periods required by law.

Nature of Processing: Automated collection of presence status by polling the Microsoft Graph API on a regular interval; storage of presence events in a relational database; aggregation into daily summaries; generation of reports; detection of anomaly patterns; display of dashboards; export of data on Customer's request.

Purpose of Processing: To provide Customer with historical reporting and analytics on Microsoft Teams presence data for Customer's Monitored Users.

Types of Personal Data:

  • Microsoft user identifier (immutable)
  • User principal name (UPN)
  • Display name
  • Microsoft tenant identifier
  • Organizational department (when set in the directory) and work location (country and, where present, state or province), the latter used solely to enforce the regional exclusion and US state notice reminders
  • Presence status changes (Available, Busy, Away, In a Meeting, etc.) with timestamps
  • Aggregated presence statistics (daily totals, anomaly findings)
  • For Authorized Users: name, work email, Microsoft user identifier, last sign-in timestamp
  • For billing contacts: name, email, organization name (managed by Stripe)

Categories of Data Subjects:

  • Authorized Users of the Service (typically IT administrators of Customer)
  • Monitored Users selected by Customer for presence data collection

Excluded categories (not processed by the Service):

  • Special categories of personal data under GDPR Article 9 (such as health, racial or ethnic origin, religious beliefs, political opinions, biometric data)
  • Children's data (under thirteen)
  • Email, chat, or file content
  • Calendar event content
  • Government-issued identifiers

Schedule 2: Technical and Organizational Measures

Presify implements the following technical and organizational measures:

Encryption

  • Data at rest encrypted using AES-256 within AWS managed services (RDS / Aurora encrypted storage, S3 with server-side encryption)
  • Microsoft Graph access tokens stored as encrypted columns using AES-256-GCM
  • Data in transit encrypted using TLS 1.2 or higher

Access controls

  • Multi-factor authentication required for all personnel with administrative access to production systems
  • Role-based access controls with least-privilege design
  • Customer access via Microsoft Entra ID single sign-on
  • Internal admin access scoped via Secrets Manager allowlist
  • All administrative impersonation requires Customer opt-in and is logged with both the impersonating personnel UPN and the impersonated user UPN

Network security

  • Database access requires IAM-authenticated, short-lived credentials (no stored database password) over certificate-pinned TLS 1.2 or higher; database login activity is continuously monitored for anomalies (for example, AWS GuardDuty RDS Protection)
  • Lambda compute resources in private subnets with restricted egress to known service endpoints
  • AWS Web Application Firewall (WAF) on public endpoints with rate limiting and OWASP rule sets
  • Stripe webhook signature verification on every billing event; Microsoft Graph accessed over TLS using encrypted, short-lived application tokens

Logical isolation

  • Multi-tenant data model with tenant_id scoping on every database query
  • PostgreSQL Row Level Security policies enforce tenant isolation as a second layer
  • Per-tenant S3 key prefixes with per-object tenant-identifier verification at the application layer before any time-limited download URL is issued; report and export objects are encrypted with a customer-managed key
  • Cross-tenant data leakage tests run on every code change

Monitoring and detection

  • AWS GuardDuty for threat detection
  • AWS Security Hub for security posture
  • AWS CloudTrail for API audit logging
  • Application-level audit log (append-only, row-level-security enforced)
  • Failed sign-in attempt logging and alerting

Backup and recovery

  • Automated database backups with point-in-time recovery
  • Database storage automatically replicated across multiple Availability Zones (single-instance Aurora Serverless v2 writer)
  • Documented recovery procedures; restore validation performed as part of operational runbooks

Vulnerability and incident management

  • Automated dependency scanning with vulnerability blocking on high-severity findings
  • License audit on all dependencies
  • Source bill of materials (SBOM) generation
  • Incident response runbooks and severity classification framework

Personnel security

  • Background checks for personnel with production access (as feasible for a small organization)
  • Confidentiality obligations for all personnel and contractors
  • Acceptable use and security policies provided to personnel

Data minimization and retention

  • Only data necessary to provide the Service is collected; the Service is designed not to collect communication or work-product contents (no email, chat, or message text; no file or calendar contents; no call recordings or transcripts; no screenshots or keystrokes)
  • Read-only, presence-only Microsoft Graph permissions, enforcing the data-minimization design at the access layer
  • Plan-gated retention with automatic deletion of expired data
  • Per-user deletion and per-user export features available to Customers

Accountability and evidence

  • Connection-time operator attestations (Customer's data-controller status, authority to connect the Service, and responsibility for required employee-monitoring notice) recorded with timestamp, attesting-administrator identity, content hash, and IP address in an append-only acknowledgment log
  • Owner acceptance of the Terms, Privacy Policy, AUP, and this DPA recorded with version and content hash at acceptance

Schedule 3: Sub-processors

The following Sub-processors process Personal Data on behalf of Presify in connection with the Service. The current list is also maintained at https://presify.io/legal/privacy. Website analytics and advertising providers used on our public marketing website (for example, Google) are not Sub-processors of Customer Personal Data and are disclosed in our Privacy Policy instead.

Sub-processorService providedLocationCategories of data
Amazon Web Services, Inc.Cloud hosting, compute, storage, networking, security toolingUnited StatesAll Personal Data
Postmark (ActiveCampaign, LLC)Delivery of transactional and account-notification emailUnited StatesRecipient email address, subject, and contents of Presify notification and digest emails (never Teams message content)
Stripe, Inc.Subscription billing and payment processingUnited StatesBilling email, organization name, subscription tier
Functional Software, Inc. (Sentry)Application error and performance monitoring (PII scrubbed before submission)United StatesApplication telemetry, error reports
Microsoft CorporationAuthentication (Entra ID) and presence data source (Microsoft Graph)Customer's Microsoft tenant regionAuthentication tokens, presence events accessed under Customer's tenant consent

Last updated: June 27, 2026