Data Processing Agreement
Last updated: August 2026 · Version 1.0
This DPA sets out how AiVerd processes personal data contained in the chat logs you upload. It supplements our Terms of Service and Privacy Policy.
1. Parties
This Data Processing Agreement ("DPA") forms part of the Terms of Service and applies where personal data is processed on your behalf.
- Data Controller: the customer — the e-commerce store or organization that uploads data to AiVerd.
- Data Processor: AAIT, a sole proprietorship registered in CEIDG, Poland, NIP 6772515807, ul. Stanczyka 8a, 30-126 Krakow, Poland, operating the AiVerd service.
2. Subject matter of the processing
- Data: chat logs containing personal data of the Controller's customers, together with catalog and policy files supplied as source data.
- Categories of data: customer names and the questions they asked; occasionally email addresses, delivery addresses, order references or other details that customers included in a conversation.
- Categories of data subjects: the Controller's customers and website visitors who interacted with its chatbot.
- Purpose: exclusively to perform the quality audit requested by the Controller and deliver the resulting report.
- Duration: uploaded files are deleted automatically ninety (90) days after upload. Audit results and reports are kept for the term of the Controller's account and deleted within ninety (90) days of its closure, unless earlier deletion is requested.
3. AiVerd obligations as Processor
- Process personal data only on the documented instructions of the Controller, including for transfers to third countries.
- Never use the data for any other purpose. In particular, uploaded data is not used to train AI models, ours or anyone else's.
- Automatically anonymize personal data in submitted content before it is sent for AI analysis.
- Maintain appropriate technical and organizational measures: TLS in transit, encryption at rest, role-based access control, and least-privilege access for staff and services.
- Ensure that personnel authorized to process the data are bound by confidentiality.
- Not disclose personal data to third parties other than the approved sub-processors listed below, unless required by law.
- Notify the Controller without undue delay and in any case within seventy-two (72) hours after becoming aware of a personal data breach affecting the Controller's data.
- Assist the Controller, taking into account the nature of the processing, in responding to data subject rights requests and in meeting its obligations under Articles 32–36 GDPR.
- Delete the personal data on the Controller's request, or at the end of the contract in line with the retention period above, except where storage is required by law.
4. Approved sub-processors
The Controller authorises AAIT to engage the following sub-processors:
| Sub-processor | Purpose | Location | Transfer safeguard |
|---|---|---|---|
| Amazon Web Services | Application infrastructure, PostgreSQL database, file storage | EU (Frankfurt, eu-central-1) | Processing within the EEA |
| Clerk | Authentication and user management | USA | SCCs |
| Stripe | Payment processing | USA / EU | SCCs |
| Fireworks AI | AI analysis of submitted chat logs | USA | SCCs |
| OpenAI | Text embeddings used for retrieval during analysis | USA | SCCs |
| Anthropic | AI verification of findings (where enabled) | USA | SCCs |
We will notify the Controller at least fourteen (14) days before adding or replacing a sub-processor. The Controller may object within that period on reasonable data-protection grounds; if the objection cannot be resolved, the Controller may terminate the affected part of the Service.
5. International transfers
Core infrastructure — the application, the PostgreSQL database and all uploaded files — is hosted with AWS in the EU (Frankfurt, eu-central-1). No transfer outside the EEA takes place for storage of your data.
Transfers outside the EEA occur only where a sub-processor listed in section 4 performs a specific function from a third country, principally AI analysis in the United States. Each such transfer relies, in this order, on:
- an adequacy decision of the European Commission, including the EU-U.S. Data Privacy Framework where the sub-processor is certified under it; or
- the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 — Module Three (processor to processor), since AiVerd acts as your processor and engages the recipient as a sub-processor.
By accepting this DPA the Controller instructs and authorises AAITto enter into those Standard Contractual Clauses with each sub-processor in the Controller's name and on its behalf, and to exercise the Controller's rights under them. A copy of the clauses concluded for any sub-processor is available on request.
For data subject to the UK GDPR, the International Data Transfer Addendum issued by the UK Information Commissioner applies to the same clauses. For data subject to the Swiss FADP, the clauses apply with the amendments recognised by the Swiss Federal Data Protection and Information Commissioner.
Supplementary measures. We have assessed the transfers described above and apply, in addition to the clauses: automatic anonymization of personal data before content is submitted to AI providers (section 3), encryption in transit and at rest, data minimisation — only the material needed for the audit is transmitted — and no use of transferred data for model training. Our transfer impact assessment is available to the Controller on request.
If a public authority requests access to personal data processed under this DPA, we will notify the Controller unless legally prohibited, will challenge requests that appear unlawful or excessive, and will disclose only the minimum required. Where a transfer mechanism ceases to provide an adequate level of protection, we will suspend the affected transfer or agree an alternative safeguard with the Controller.
6. Audit rights
The Controller may request information demonstrating compliance with this DPA once per calendar year, or after a personal data breach affecting its data. We will provide the relevant documentation within thirty (30) days of the request. Requests should be sent to hello@ai-verd.com.
7. Acceptance
This DPA is accepted at registration by ticking the corresponding checkbox, and applies for as long as AiVerdprocesses personal data on the Controller's behalf. A separately signed copy is available on request — write to hello@ai-verd.com.