Data Processing Agreement
This Data Processing Agreement ("DPA") establishes the rights, obligations, and limitations regarding the processing of Personal Data within our execution infrastructure.
Important: This is a draft document provided for internal review and evaluation purposes.
1. Definitions
- "Controller" refers to the client organization determining the purpose and means of data processing.
- "Processor" refers to Avigrah AI, processing data strictly on behalf of the Controller.
- "Personal Data" means any information relating to an identified or identifiable natural person processed via the platform.
- "Processing" includes collection, storage, adaptation, retrieval, structuring, and execution of data within the system's pipelines.
- "Sub-processor" refers to any third-party entity engaged by the Processor to assist in fulfilling its obligations.
- "Data Subject" is the identified or identifiable natural person to whom the Personal Data relates.
- "Applicable Data Protection Laws" encompasses all global data protection and privacy laws relevant to the processing, including but not limited to the GDPR.
2. Scope & Role
The Controller retains full authority and responsibility for determining the purpose and means of processing Personal Data. The Processor acts exclusively as a data processor, executing operations solely based on the Controller's documented instructions. Processing activities are explicitly limited to the execution functionality provided by the platform.
3. Nature & Purpose of Processing
The Processor provides an AI-driven infrastructure execution layer. The nature and purpose of processing include:
- Processing data via automated and real-time project-based pipelines configured by the Controller.
- Generating outputs via AI systems dynamically influenced by Controller-provided data inputs and operational signals.
- Secure storage, transformation, structural analysis, and output generation as explicitly required to maintain continuous system operations.
4. AI Processing Limitations
The Processor enforces strict operational guardrails regarding the execution of intelligence systems:
- No training on client data: The Processor does not use Controller data to train, tune, or improve generalized AI models or neural networks unless explicitly agreed in writing.
- No model reuse: Models and configurations instantiated for the Controller are logic environments strictly isolated from other customers. Weights or processing patterns derived from Controller data are never shared or transferred to other entities.
- Output dependencies: Controller acknowledges that AI outputs depend dynamically on Controller inputs and prompts. The Processor does not guarantee deterministic accuracy or compliance for outputs derived from Controller data.
5. Types of Data & Data Subjects
The system processes general business data configured by the Controller. Standard processing covers:
- Customer Data: Contact details, identifiers, and transactional execution histories.
- Business Data: Pipeline configuration states, workflow metadata, and operational logic.
- Usage Data: System interaction logs and execution signals.
⚠️ Sensitive Personal Data Ban: The Controller shall not submit, configure, or process any sensitive personal data (including biometric data, health records, genetic data, or financial account credentials) through the platform unless explicitly agreed in writing by both parties in a separate, dedicated addendum. The Controller is solely responsible for ensuring no sensitive data enters standard pipelines.
6. Processor Obligations
The Processor shall:
- Process Personal Data strictly in accordance with the Controller’s documented instructions.
- Ensure that all personnel authorized to process Personal Data are bound by strict obligations of confidentiality.
- Implement robust technical and organizational security measures to protect the integrity of the data.
- Assist the Controller in fulfilling compliance obligations related to security, data protection impact assessments, and prior consultations, taking into account the nature of processing.
7. Security Measures
The Processor implements high-availability security standards appropriate to the risk of processing, including:
- Logical Environment Isolation: Strict logical isolation at the database, embedding, and runtime cache levels across all multi-tenant projects and environments to prevent data bleeding.
- No Cross-Tenant Leakage: Enforces rigorous boundary checks on every data query and pipeline execution to ensure zero cross-tenant leakage.
- Independent Environments: Execution runs in independent processing environments, ensuring Controller data is never commingled with other customers' processing memory.
- Access Control & Audit: Enforcement of granular Role-Based Access Control (RBAC) and immutability of core logs.
- Pipeline Security: Encrypted transit and at-rest protection of data flowing through the AI and execution mechanisms.
8. Sub-Processors
The Controller authorizes the Processor to engage third-party Sub-processors to support the delivery of the service. The Processor uses trusted enterprise infrastructure partners to host the system, including Amazon Web Services (AWS) and Google Cloud Platform (GCP). The Processor will:
- Impose data protection terms on Sub-processors that provide an equivalent level of protection as this DPA.
- Maintain a current list of active Sub-processors (available to the Controller upon request) and provide a notification mechanism for the Controller regarding any intended additions or replacements, allowing reasonable opportunity to object.
9. Data Transfers (Global)
The Processor may process and transfer Personal Data globally to ensure high availability and redundancy. To support GDPR (EU) and DPDP Act (India) compliance, the Controller may request an explicit region lock to restrict processing, storage, and transfers to a specific geographic region. If a region lock is requested in writing, the Processor shall restrict all processing activities to the designated region. Any international transfer of Personal Data originating from regions with strict data residency requirements shall be governed by appropriate safeguards, such as Standard Contractual Clauses (SCCs).
10. Data Subject Rights
The Processor will assist the Controller by appropriate technical and organizational measures, insofar as possible, to fulfill the Controller's obligation to respond to requests from Data Subjects exercising their rights. The Processor assumes no direct obligation to respond to Data Subjects unless explicitly mandated by law.
11. Data Breach
In the event of a confirmed Personal Data breach compromising the Controller's data, the Processor shall notify the Controller within 48 hours of confirmation. The Processor will provide reasonable cooperation and factual information regarding the breach to assist the Controller in meeting its own regulatory notification obligations.
12. Data Retention & Deletion
Personal Data is retained only as long as necessary to execute the pipelines and deliver the service. Upon termination of the underlying agreement, the Processor will, at the choice of the Controller, securely delete or return all Personal Data, unless retention is required by applicable law.
Optional Extended Retention / Context Persistence: The Controller may choose to configure extended context retention for advanced intelligence optimization features. If enabled, runtime context and session metadata are retained beyond default execution to improve personalized agent memory and context recall.
Advanced Retention (Optional)
Enable extended context retention to improve system intelligence, memory, and response continuity across workflows.
Extended retention is active for this project. Context data is retained to improve system behavior and continuity. Data remains isolated to your environment and is never used for cross-client training.
13. Audit & Verification
The Processor will make available to the Controller information reasonably necessary to demonstrate compliance with this DPA. The Controller may conduct audits or inspections, subject to the following strict boundaries:
- The Controller must provide at least fifteen (15) business days advance written notice.
- Audits may be conducted no more than once per calendar year.
- Audits must not cause any operational disruption to the Processor's services.
- Audits shall not under any circumstances provide access to other customers' data or environments.
14. Liability
The total aggregate liability of either party under this DPA is subject to the exclusions and limitations of liability set forth in the main service agreement, and shall in no event exceed the total amount paid by the Controller to the Processor under the main service agreement in the twelve (12) months preceding the event giving rise to liability. Neither party's liability shall be subject to unlimited or undefined exposure, except in cases of gross negligence, willful misconduct, or as strictly prohibited by applicable law.
15. Term & Termination
This DPA shall remain in effect for the duration of the main service agreement between the Controller and the Processor. It automatically terminates when the main service agreement ends, subject to any surviving obligations regarding data deletion and confidentiality.
16. Governing Law
This DPA is governed by the same jurisdiction and laws stipulated in the main service agreement between the parties, ensuring consistency in legal enforcement and interpretation.