AI-Copliance · aicopliance.com

Data Processing Agreement

Version 1.0 Effective Date: 10 June 2026 GDPR Article 28 Compliant
This Data Processing Agreement ("DPA") is entered into between AI-Copliance ("Processor") and the Customer identified in the associated subscription agreement ("Controller"). It applies where AI-Copliance processes personal data on behalf of the Customer as part of delivering the Service.

01 Definitions

In this DPA, the following terms have the meanings set out below. Terms not defined here have the meanings given in the GDPR or the Terms of Service.

02 Scope & Relationship

This DPA applies to all personal data that AI-Copliance processes as a Processor on behalf of the Customer (Controller) in the course of providing the Service, as further described in Schedule A.

AI-Copliance will process personal data only:

This DPA is published on the AI-Copliance website and applies automatically to all Customers upon acceptance of the Terms of Service. No separate signature or counter-signature is required.

For avoidance of doubt: personal data processed for account administration, billing, and customer support (where AI-Copliance determines the purpose) is processed under AI-Copliance's own Privacy Policy, not under this DPA.

03 Controller's Obligations

The Customer (Controller) is responsible for:

04 AI-Copliance's Obligations as Processor

AI-Copliance agrees to:

05 Sub-Processors

The Controller grants AI-Copliance a general authorisation to engage the sub-processors listed in Schedule B. AI-Copliance will:

06 Security Measures

AI-Copliance implements the technical and organisational measures described in Schedule C, including but not limited to:

AI-Copliance will review and update these measures periodically and promptly upon becoming aware of any material security risks.

07 Data Subject Rights

If AI-Copliance receives a request directly from a data subject relating to personal data processed under this DPA, AI-Copliance will:

AI-Copliance will provide reasonable assistance to the Controller in fulfilling data subject requests (access, rectification, erasure, portability, restriction, objection), using available technical features of the Service. AI-Copliance may charge a reasonable fee for assistance that requires significant manual effort beyond standard platform capability.

08 Security Incident Notification

In the event AI-Copliance becomes aware of a Security Incident affecting personal data processed under this DPA, AI-Copliance will:

Security incidents should be reported to: privacy@aicopliance.com

09 International Transfers

The sub-processors listed in Schedule B are located in the United States. Transfers of personal data from the EEA or UK to these sub-processors are made pursuant to:

Where SCCs or IDTA apply, the following annexes are deemed completed: Annex I as per Schedule A of this DPA; Annex II as per Schedule C of this DPA.

10 Audit Rights

AI-Copliance will make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA. Upon the Controller's written request with at least 30 days' notice, AI-Copliance will permit and contribute to audits conducted by the Controller or a third-party auditor appointed by the Controller, provided that:

AI-Copliance may fulfill the audit obligation by providing relevant third-party audit certifications or penetration test reports in lieu of direct audit access, where these adequately address the scope of the audit.

11 Deletion & Return of Data

Upon termination of the Service or upon written request by the Controller:

12 Term & Termination

This DPA comes into force when both parties enter into the Terms of Service and remains in force for the duration of the subscription. It terminates automatically on expiry or termination of the subscription, subject to the survival of obligations regarding data deletion, confidentiality, and audit rights.

This DPA is governed by the same law as the Terms of Service and takes precedence over any conflicting provisions in the Terms of Service regarding data protection matters.

Schedule A Processing Details

ElementDetail
Subject matter ISO 27001 compliance implementation services including risk assessment, policy generation, and audit preparation
Duration Subscription term plus 90-day post-termination retention period
Nature of processing Collection, storage, structuring, use (AI inference), and deletion of personal data
Purpose of processing Providing the Service: building organizational context, generating compliance documents, and enabling audit readiness
Categories of personal data Names and job titles of employees referenced in organizational profiles; contact details of system owners and responsible persons; names appearing in uploaded documents
Special category data None anticipated; Customers are advised not to upload special category data into the Service
Categories of data subjects Customer's employees, contractors, and any individuals referenced in the Customer's organizational and security documentation
Controller's contact The email address and organization name provided at account registration

Schedule B Approved Sub-Processors

Sub-ProcessorPurposeData ProcessedLocation
Supabase, Inc. Database, authentication, file storage All Customer Data and account personal data USA (AWS us-east-1)
Vercel, Inc. Application hosting IP addresses, request metadata, logs USA / Global CDN
Anthropic, PBC AI model inference (Claude API) Customer Data included in AI prompts USA
Lemon Squeezy LLC Payment processing (Merchant of Record) Email address, billing information USA
Zoho Corporation Transactional email Email address, email content USA / EU

Schedule C Technical & Organisational Security Measures

AI-Copliance implements and maintains the following measures in accordance with Article 32 GDPR:

Pseudonymisation & Encryption

Confidentiality

Integrity & Availability

Resilience

Testing & Evaluation

Organisational Measures

Acceptance

This DPA is incorporated by reference into the AI-Copliance Terms of Service. By subscribing to and using the Service, the Customer agrees to be bound by this DPA without the need for a separate signature. The DPA takes effect on the date the Customer first accepts the Terms of Service.

This DPA is published at aicopliance.com/dpa and may be updated in accordance with the update provisions in Section 12. The version in effect at the time of the Customer's subscription renewal governs that renewal period.

If you have questions about this DPA or wish to discuss data processing arrangements, contact us at privacy@aicopliance.com.
DPA enquiries: privacy@aicopliance.com
AI-Copliance · aicopliance.com ·