Legal

GDPR Compliance

Our commitment to protecting EU/EEA users' data in accordance with the General Data Protection Regulation.

Last updated: April 1, 2026

Our Commitment

Pressly is committed to full compliance with the General Data Protection Regulation (GDPR). We process personal data lawfully, fairly, and transparently. This page outlines our specific GDPR compliance measures.

Legal Basis for Processing

We process personal data under the following legal bases:

  • Contract performance: Processing necessary to provide the Service you requested (account data, press release generation)
  • Legitimate interests: Processing for product improvement, fraud prevention, and security (usage analytics, error logging)
  • Consent: Processing where you have given explicit consent (marketing emails, optional analytics cookies)
  • Legal obligation: Processing required to comply with applicable laws (tax records, regulatory requirements)

Your Rights Under GDPR

As a data subject in the EU/EEA, you have the following rights:

Right of Access (Article 15)

You can request a copy of all personal data we hold about you. We will respond within 30 days. You can initiate this from your account settings or by emailing us.

Right to Rectification (Article 16)

You can update or correct your personal data at any time through your account settings, or by contacting us directly.

Right to Erasure (Article 17)

You can request deletion of your personal data. Upon request, we will delete your data within 30 days, except where retention is required by law.

Right to Restrict Processing (Article 18)

You can request that we restrict processing of your data in certain circumstances, such as while we verify the accuracy of your data or assess a deletion request.

Right to Data Portability (Article 20)

You can request your data in a structured, machine-readable format (JSON or CSV). This includes your account data and all press releases you have created.

Right to Object (Article 21)

You can object to processing based on legitimate interests. We will cease processing unless we demonstrate compelling legitimate grounds.

Data Processing Agreements

We maintain Data Processing Agreements (DPAs) with all sub-processors that handle personal data on our behalf. Our current sub-processors include:

  • Amazon Web Services (AWS): Cloud infrastructure - US, EU (Frankfurt)
  • Stripe: Payment processing - US
  • SendGrid: Email delivery - US
  • Mixpanel: Product analytics - US
  • OpenAI: AI model inference - US (data not used for training)

International Data Transfers

When personal data is transferred outside the EU/EEA, we ensure adequate protection through Standard Contractual Clauses (SCCs) approved by the European Commission. EU customer data is primarily stored in AWS EU (Frankfurt) data centers.

Data Protection Officer

Our Data Protection Officer can be reached at:

Email: dpo@presslyai.com
Address: smartpress LLC, 30 N Gould St Ste R, Sheridan, WY 82801

Supervisory Authority

If you believe we have not adequately addressed your data protection concerns, you have the right to lodge a complaint with your local supervisory authority. A list of EU data protection authorities can be found on the European Data Protection Board website.