Definitions
For the purposes of this Data Processing Agreement, the following capitalised terms have the meanings set out below:
Data Controller and Processor Roles
This DPA forms part of and is incorporated into the agreement between the Customer ("Controller") and AssurAI Inc. ("Processor"). The Controller determines the purposes and means of processing the audit, compliance, and risk data it uploads to AssurAI.
The Processor processes that Personal Data solely on the Controller's documented instructions, including those set out in this DPA, the Privacy Policy, and the platform's configuration settings. Where required by applicable Union or Member State law to process beyond those instructions, the Processor will inform the Controller unless that law prohibits such notice.
The Processor ensures that all persons authorised to process Personal Data are bound by appropriate confidentiality obligations and receive adequate data-protection training.
Processing Details
Subject Matter & Duration
Subject matter: the provision of the AssurAI Agentic GRC Platform for audit, compliance, and risk management, including AI-assisted workpaper generation, controls testing, findings tracking, and reporting.
Duration: processing continues for the term of the Controller's subscription and for any post-termination retention period described in Section 8 and the Privacy Policy.
Nature & Purpose
Personal Data is processed to host, secure, and operate the platform and to deliver its features. AssurAI does not use customer Personal Data to train, fine-tune, or improve AI models — AI processing produces outputs for the Controller only.
| Processing Activity | Purpose | Legal Basis (Controller) |
|---|---|---|
| Storage & hosting | Persisting the Controller's audit data, workpapers, and findings | Performance of contract |
| Authentication | Securing account access via email/SSO | Legitimate interests |
| AI generation | Producing workpapers, controls, and analysis on request | Performance of contract |
| Transactional email | Notifications, reminders, and confirmations | Legitimate interests |
| Audit logging | Security event recording and trail integrity | Legal obligation / legitimate interests |
Categories of Data Subjects
- The Controller's employees and authorised platform users
- Control owners, remediation owners, and reviewers named in audit records
- External auditors or third parties granted portal access
- Individuals referenced within evidence or workpaper content uploaded by the Controller
Categories of Personal Data
- Identity & contact data (name, email address, company, job title)
- Account & usage data (logins, audit trail events, IP address, browser metadata)
- Content data the Controller uploads (evidence files, findings, workpapers, control descriptions)
The Controller must not upload special categories of Personal Data (Article 9 GDPR) unless strictly necessary, lawful under a specific derogation, and notified to the Processor in advance.
Security Measures
The Processor implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required under Article 32 GDPR. These measures include:
Further detail is available at getassurai.com/security. The Processor will not materially reduce the overall security level during the term of the agreement.
Sub-processors
The Controller hereby provides general written authorisation for the Processor to engage the following sub-processors. Each is bound by a written agreement imposing data-protection obligations no less protective than this DPA.
| Sub-processor | Service | Region | DPA Status |
|---|---|---|---|
| Supabase | Database, storage, and authentication infrastructure | US or EU (per org data-region selection) | In place |
| Netlify | Application hosting and serverless edge functions | US / global edge | In place |
| Anthropic | AI processing (Claude API) — no training on customer data | US | In place |
| Resend | Transactional email delivery | US | In place |
The Processor will provide the Controller with at least 30 days' written notice of any intended change to its authorised sub-processors. The Controller may object on reasonable, documented data-protection grounds within 14 days. Where an objection cannot be accommodated, either party may terminate the agreement on 30 days' notice without penalty.
An up-to-date list is maintained at getassurai.com/subprocessors.
Data Subject Rights
Taking into account the nature of the processing, the Processor assists the Controller — by appropriate technical and organisational measures — in responding to requests from data subjects to exercise their rights under applicable data-protection law:
- Right of access (Art. 15): self-service data export available from account settings
- Right to rectification (Art. 16): users may correct profile data in-platform; content corrections are made by the Controller
- Right to erasure (Art. 17): self-service deletion from account settings, with email verification; permanent removal per Section 8
- Right to restriction (Art. 18): processing suspended on written request pending Controller instruction
- Right to data portability (Art. 20): structured JSON/CSV export available at any time while the account is active
- Right to object (Art. 21): referrals directed to the Controller as the accountable party
- Automated decision-making (Art. 22): AssurAI does not make decisions with legal or similarly significant effect based solely on automated processing
The Processor will forward to the Controller any data subject requests received directly and will not respond on its own authority unless instructed.
International Data Transfers
AssurAI offers a data region selection (US or EU) at organisation level. For organisations on the EU region, primary database storage is provisioned in an EU Supabase project (eu-west-1). Certain sub-processors — including Anthropic for AI processing — may still process data in the United States.
Where Personal Data is transferred outside the EEA, the United Kingdom, or Switzerland, such transfers are governed by:
- The EU Standard Contractual Clauses (SCCs) — Commission Implementing Decision (EU) 2021/914 — for EEA-originating data
- The UK International Data Transfer Addendum (IDTA) — as approved by the UK ICO — for UK-originating data
- Supplementary technical measures where required by the applicable transfer risk assessment
For California-based Controllers, AssurAI acts as a "service provider" under the CCPA/CPRA and agrees not to sell or share Personal Data, or use it for any purpose other than performing the contracted services.
Retention and Deletion
The Processor retains Personal Data for no longer than necessary to fulfil the purposes for which it was processed. Upon termination of the subscription, or upon the Controller's written request, the Processor will act as follows:
| Data Type | Retention Period | Deletion Method |
|---|---|---|
| Workpapers & audit content | 90 days post-termination | Secure overwrite; soft-delete immediately on request |
| Account & profile data | 30 days post-account closure | Hard delete after email-verified confirmation |
| Audit logs & security events | 12 months (regulatory) | Anonymised after the retention period |
| Backup copies | Up to 35 days (rolling) | Rotated automatically; not restored after deletion request |
| Email delivery logs | 30 days (Resend) | Per Resend's retention policy |
- Self-service data export is available at any time from Account Settings → Privacy → Export My Data.
- Deletion requests trigger an immediate soft-delete, followed by permanent removal per the table above.
- Upon written request, the Processor will provide written certification of deletion within 30 days.
Personal Data Breach Notification
The Processor will notify the Controller without undue delay — and in any event within 72 hours of becoming aware of a Personal Data breach affecting the Controller's data — providing at minimum:
- The nature of the breach, including categories and approximate number of data subjects and records concerned
- The name and contact details of the point of contact for further information
- The likely consequences of the breach
- Measures taken or proposed to address the breach and mitigate its possible adverse effects
Where full information cannot be provided within 72 hours, the Processor will provide it in phases without undue further delay. The Controller remains responsible for notifying its supervisory authority and affected data subjects where required by applicable law.
Audit Rights
The Processor makes available to the Controller all information reasonably necessary to demonstrate compliance with Article 28 GDPR obligations, and allows for and contributes to audits conducted by the Controller or a mandated auditor.
Information Requests
The Controller may, at most once per 12-month period, submit a written request for information sufficient to verify the Processor's compliance with this DPA. The Processor will respond within 30 calendar days.
On-Site Inspections
Where an information request does not adequately address the Controller's compliance concerns, the Controller may request an on-site audit on at least 30 days' written notice, subject to: execution of a mutually agreed confidentiality agreement with any third-party auditor; audit activities being conducted during business hours so as not to unreasonably disrupt operations; and the Controller bearing all costs of the audit unless it reveals a material breach by the Processor.
Third-Party Certifications
The Processor may satisfy audit requests by providing current third-party audit reports (SOC 2, ISO 27001, or equivalent) to the extent they address the subject matter of the Controller's request. Reports are shared under NDA upon written request.
Liability
Each party shall be liable to data subjects for damage caused by processing that infringes applicable data-protection law to the extent provided for under Article 82 GDPR or equivalent provisions under applicable law.
The Processor's total aggregate liability arising out of or in connection with this DPA shall not exceed the amounts paid or payable by the Controller to the Processor in the 12-month period immediately preceding the event giving rise to the claim. This limitation does not apply to:
- Death or personal injury caused by negligence
- Fraud or fraudulent misrepresentation
- Any other liability that cannot be excluded or limited by applicable law
The Processor shall not be liable for any indirect, incidental, consequential, special, or punitive damages, including loss of profits, data, business, or goodwill, arising from or related to this DPA.
To the extent the Processor has paid compensation for a breach attributable to the Controller, the Processor has the right to reclaim that portion from the Controller (Article 82(5) GDPR).
Termination
This DPA remains in force for the duration of the principal agreement and terminates automatically upon its termination or expiry, subject to the survival provisions below.
Effects of Termination
Upon termination of the principal agreement, the Processor will cease all processing of the Controller's Personal Data (except as required by applicable law); return or delete all Personal Data in accordance with Section 8; and provide written certification of deletion within 30 days of the Controller's request.
Surviving Obligations
The obligations in Sections 4 (Security Measures), 8 (Retention and Deletion), 9 (Breach Notification), 10 (Audit Rights), and 11 (Liability) survive termination of this DPA for as long as the Processor retains any Personal Data.
Governing Law & Jurisdiction
This DPA is governed by the laws of the State of Delaware, USA, without regard to its conflict-of-law provisions. For EEA data subjects, mandatory GDPR provisions prevail over any conflicting contractual term. Disputes shall be submitted to the exclusive jurisdiction of the courts of Santa Clara County, California.