Data Processing Addendum (DPA)
1. Application
This DPA forms part of the Terms of Service between Customer ("Controller") and AuditAI ("Processor"). It applies whenever Processor processes personal data on Controller's behalf in connection with the Service.
2. Definitions
Unless otherwise defined, terms have the meanings given in the GDPR. "Processor" and "Subprocessor" carry their GDPR meanings.
3. Subject matter and details
- Subject matter: provision of a multi-tenant SaaS platform for AI workflow audits.
- Duration: for the term of the subscription, plus any retention periods specified in this DPA or the Privacy Policy.
- Nature and purpose: hosting, processing, transmitting, displaying, generating audit findings and reports, and improving the Service.
- Categories of data subjects: Customer's employees and contractors (auditor users), Customer's clients' employees (survey respondents, evidence uploaders, interview participants).
- Categories of personal data: name, business email, role, organisation, free-text survey responses, evidence-file metadata and contents (which may include personal data Customer elects to upload), interview transcripts.
- Special categories: Customer must not upload special-category data unless it has lawful basis and a separate written agreement with AuditAI.
4. Processor obligations
AuditAI will:
- process personal data only on Controller's documented instructions;
- ensure persons authorised to process are bound by confidentiality;
- implement the technical and organisational measures described in Annex II below;
- only engage subprocessors per Section 5;
- assist Controller in responding to data-subject rights requests;
- notify Controller of personal-data breaches affecting Controller's data without undue delay and in any event within 72 hours of confirmation;
- on termination, return or delete personal data per Controller's choice, subject to retention required by law and the audit-log immutability principle (the audit log retains action / timestamp / org id / resource id; personal-identifying metadata fields are scrubbed on tenant deletion);
- make available all information necessary to demonstrate compliance and contribute to audits, including by sharing the most recent SOC 2 Type II report (under NDA) once available.
5. Subprocessors
Controller authorises AuditAI to engage the subprocessors listed at /legal/subprocessors. AuditAI will:
- impose data-protection obligations on each subprocessor that are no less protective than this DPA;
- provide at least 30 days' advance notice of any new subprocessor that processes personal data; Controller may object on reasonable grounds, in which case the parties will work in good faith to resolve, including by providing an alternative;
- remain responsible for the acts and omissions of its subprocessors.
6. International transfers
For transfers of personal data from the EEA, UK, or Switzerland to a country without an adequacy decision, the parties incorporate the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module 2 (controller to processor) and Module 3 (processor to processor), with the following selections:
- Clause 7 (docking): not used.
- Clause 9: option 2 (general written authorisation for subprocessors), 30 days' notice.
- Clause 11(a): does not include the optional language on data-subject redress body.
- Clause 17: governing law of Ireland.
- Clause 18(b): courts of Ireland.
- Annex I.A (parties): as set out in the order form.
- Annex I.B (description of transfer): as set out in Section 3 of this DPA.
- Annex I.C (competent supervisory authority): the Irish Data Protection Commission.
- Annex II (TOMs): as set out below.
For UK transfers, the UK International Data Transfer Addendum to the EU SCCs is incorporated by reference, with the parties' details and the SCC version above.
7. Annex II - Technical and Organisational Measures
AuditAI maintains controls including:
- encryption in transit (TLS 1.2+) and at rest (AES-256);
- multi-tenant isolation enforced via Postgres Row-Level Security;
- immutable audit log with database-level UPDATE/DELETE triggers;
- AES-256-GCM encryption of stored integration credentials with random 96-bit IVs;
- role-based access controls including per-engagement role overrides;
- tenant-visible record of every platform-admin impersonation session;
- signed webhook endpoints, rate-limited public endpoints, content-type allowlists for uploads;
- least-privilege production access; MFA enforced via Clerk; access reviews quarterly;
- dependency vulnerability scanning in CI (npm audit critical-only blocking);
- 72-hour security-incident notification to controllers;
- annual penetration test and SOC 2 Type II audit (in progress).
The current state of these controls is documented on the Security page; Customer can request the most recent SOC 2 Type II report under NDA from asarewilliam0@gmail.com.
8. Order of precedence
In the event of a conflict, the order of precedence is: SCCs > this DPA > the Terms of Service > the Privacy Policy.
9. Signing this DPA
For most customers this DPA is incorporated by reference when you accept the Terms. Enterprise customers can request a counter-signed copy from legal@auditai.example.