Legal Document
Data Processing Agreement
 Last updated: June 2, 2026
Version: 1.0
Effective: June 2, 2026
 AssurAI Inc., Delaware
Request Signed Copy
This agreement covers processing obligations under the following frameworks — reviewed by counsel and updated annually.
GDPR UK GDPR CCPA / CPRA SCCs IDTA
Template notice: This DPA is provided for convenience and is not legal advice. Have your own counsel review it before relying on it. For a countersigned executable copy, email privacy@getassurai.com.
§ 1

Definitions

For the purposes of this Data Processing Agreement, the following capitalised terms have the meanings set out below:

Personal Data
Any information relating to an identified or identifiable natural person, as defined in Article 4(1) GDPR.
Processing
Any operation performed on Personal Data, whether by automated means, including collection, storage, retrieval, use, disclosure, or erasure.
Controller
The Customer entity that determines the purposes and means of processing Personal Data using the AssurAI platform.
Processor
AssurAI Inc., which processes Personal Data solely on behalf of and under the documented instructions of the Controller.
Sub-processor
Any third party engaged by the Processor to carry out specific processing activities on behalf of the Controller.
Data Subject
The identified or identifiable natural person to whom the Personal Data relates.
GDPR
EU General Data Protection Regulation 2016/679, together with UK GDPR as retained in UK law by the European Union (Withdrawal) Act 2018.
SCCs
Standard Contractual Clauses for transfers to third countries, as approved by the European Commission on 4 June 2021.
Personal Data Breach
A breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of Personal Data.
Services
The AssurAI Agentic GRC Platform as described in the applicable order form or subscription agreement between the parties.
§ 2

Data Controller and Processor Roles

This DPA forms part of and is incorporated into the agreement between the Customer ("Controller") and AssurAI Inc. ("Processor"). The Controller determines the purposes and means of processing the audit, compliance, and risk data it uploads to AssurAI.

The Processor processes that Personal Data solely on the Controller's documented instructions, including those set out in this DPA, the Privacy Policy, and the platform's configuration settings. Where required by applicable Union or Member State law to process beyond those instructions, the Processor will inform the Controller unless that law prohibits such notice.

The Processor ensures that all persons authorised to process Personal Data are bound by appropriate confidentiality obligations and receive adequate data-protection training.

The Processor will not sell, rent, or otherwise transfer Personal Data to any third party for that third party's own commercial purposes.
§ 3

Processing Details

Subject Matter & Duration

Subject matter: the provision of the AssurAI Agentic GRC Platform for audit, compliance, and risk management, including AI-assisted workpaper generation, controls testing, findings tracking, and reporting.

Duration: processing continues for the term of the Controller's subscription and for any post-termination retention period described in Section 8 and the Privacy Policy.

Nature & Purpose

Personal Data is processed to host, secure, and operate the platform and to deliver its features. AssurAI does not use customer Personal Data to train, fine-tune, or improve AI models — AI processing produces outputs for the Controller only.

Processing ActivityPurposeLegal Basis (Controller)
Storage & hostingPersisting the Controller's audit data, workpapers, and findingsPerformance of contract
AuthenticationSecuring account access via email/SSOLegitimate interests
AI generationProducing workpapers, controls, and analysis on requestPerformance of contract
Transactional emailNotifications, reminders, and confirmationsLegitimate interests
Audit loggingSecurity event recording and trail integrityLegal obligation / legitimate interests

Categories of Data Subjects

  • The Controller's employees and authorised platform users
  • Control owners, remediation owners, and reviewers named in audit records
  • External auditors or third parties granted portal access
  • Individuals referenced within evidence or workpaper content uploaded by the Controller

Categories of Personal Data

  • Identity & contact data (name, email address, company, job title)
  • Account & usage data (logins, audit trail events, IP address, browser metadata)
  • Content data the Controller uploads (evidence files, findings, workpapers, control descriptions)

The Controller must not upload special categories of Personal Data (Article 9 GDPR) unless strictly necessary, lawful under a specific derogation, and notified to the Processor in advance.

§ 4

Security Measures

The Processor implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required under Article 32 GDPR. These measures include:

Encryption in Transit & at Rest
TLS 1.2+ for all data in transit; AES-256 encryption for all data at rest.
Row-Level Security
Strict tenant isolation enforced at the database layer by organisation ID.
Least-Privilege Access
Role-based access control; server-derived org/role authorisation on all API functions.
MFA & Enterprise SSO
Multi-factor authentication available; SAML 2.0 / OIDC for enterprise organisations.
Audit Logging
Per-user rate limiting and immutable audit logging of all sensitive actions.
Security Assessments
Regular vulnerability assessments; SOC 2 Type II programme in progress.

Further detail is available at getassurai.com/security. The Processor will not materially reduce the overall security level during the term of the agreement.

§ 5

Sub-processors

The Controller hereby provides general written authorisation for the Processor to engage the following sub-processors. Each is bound by a written agreement imposing data-protection obligations no less protective than this DPA.

Sub-processorServiceRegionDPA Status
SupabaseDatabase, storage, and authentication infrastructureUS or EU (per org data-region selection)In place
NetlifyApplication hosting and serverless edge functionsUS / global edgeIn place
AnthropicAI processing (Claude API) — no training on customer dataUSIn place
ResendTransactional email deliveryUSIn place

The Processor will provide the Controller with at least 30 days' written notice of any intended change to its authorised sub-processors. The Controller may object on reasonable, documented data-protection grounds within 14 days. Where an objection cannot be accommodated, either party may terminate the agreement on 30 days' notice without penalty.

An up-to-date list is maintained at getassurai.com/subprocessors.

§ 6

Data Subject Rights

Taking into account the nature of the processing, the Processor assists the Controller — by appropriate technical and organisational measures — in responding to requests from data subjects to exercise their rights under applicable data-protection law:

  • Right of access (Art. 15): self-service data export available from account settings
  • Right to rectification (Art. 16): users may correct profile data in-platform; content corrections are made by the Controller
  • Right to erasure (Art. 17): self-service deletion from account settings, with email verification; permanent removal per Section 8
  • Right to restriction (Art. 18): processing suspended on written request pending Controller instruction
  • Right to data portability (Art. 20): structured JSON/CSV export available at any time while the account is active
  • Right to object (Art. 21): referrals directed to the Controller as the accountable party
  • Automated decision-making (Art. 22): AssurAI does not make decisions with legal or similarly significant effect based solely on automated processing

The Processor will forward to the Controller any data subject requests received directly and will not respond on its own authority unless instructed.

Personal Data processed in compliance with statutory audit obligations cannot be erased until the applicable retention period has elapsed.
§ 7

International Data Transfers

AssurAI offers a data region selection (US or EU) at organisation level. For organisations on the EU region, primary database storage is provisioned in an EU Supabase project (eu-west-1). Certain sub-processors — including Anthropic for AI processing — may still process data in the United States.

Where Personal Data is transferred outside the EEA, the United Kingdom, or Switzerland, such transfers are governed by:

  • The EU Standard Contractual Clauses (SCCs) — Commission Implementing Decision (EU) 2021/914 — for EEA-originating data
  • The UK International Data Transfer Addendum (IDTA) — as approved by the UK ICO — for UK-originating data
  • Supplementary technical measures where required by the applicable transfer risk assessment
EU data residency requires the organisation to be provisioned on AssurAI's EU deployment. Contact privacy@getassurai.com to enable EU residency.

For California-based Controllers, AssurAI acts as a "service provider" under the CCPA/CPRA and agrees not to sell or share Personal Data, or use it for any purpose other than performing the contracted services.

§ 8

Retention and Deletion

The Processor retains Personal Data for no longer than necessary to fulfil the purposes for which it was processed. Upon termination of the subscription, or upon the Controller's written request, the Processor will act as follows:

Data TypeRetention PeriodDeletion Method
Workpapers & audit content90 days post-terminationSecure overwrite; soft-delete immediately on request
Account & profile data30 days post-account closureHard delete after email-verified confirmation
Audit logs & security events12 months (regulatory)Anonymised after the retention period
Backup copiesUp to 35 days (rolling)Rotated automatically; not restored after deletion request
Email delivery logs30 days (Resend)Per Resend's retention policy
  • Self-service data export is available at any time from Account Settings → Privacy → Export My Data.
  • Deletion requests trigger an immediate soft-delete, followed by permanent removal per the table above.
  • Upon written request, the Processor will provide written certification of deletion within 30 days.
§ 9

Personal Data Breach Notification

The Processor will notify the Controller without undue delay — and in any event within 72 hours of becoming aware of a Personal Data breach affecting the Controller's data — providing at minimum:

  • The nature of the breach, including categories and approximate number of data subjects and records concerned
  • The name and contact details of the point of contact for further information
  • The likely consequences of the breach
  • Measures taken or proposed to address the breach and mitigate its possible adverse effects

Where full information cannot be provided within 72 hours, the Processor will provide it in phases without undue further delay. The Controller remains responsible for notifying its supervisory authority and affected data subjects where required by applicable law.

Report any suspected breach involving platform credentials or API keys immediately to security@getassurai.com.
§ 10

Audit Rights

The Processor makes available to the Controller all information reasonably necessary to demonstrate compliance with Article 28 GDPR obligations, and allows for and contributes to audits conducted by the Controller or a mandated auditor.

Information Requests

The Controller may, at most once per 12-month period, submit a written request for information sufficient to verify the Processor's compliance with this DPA. The Processor will respond within 30 calendar days.

On-Site Inspections

Where an information request does not adequately address the Controller's compliance concerns, the Controller may request an on-site audit on at least 30 days' written notice, subject to: execution of a mutually agreed confidentiality agreement with any third-party auditor; audit activities being conducted during business hours so as not to unreasonably disrupt operations; and the Controller bearing all costs of the audit unless it reveals a material breach by the Processor.

Third-Party Certifications

The Processor may satisfy audit requests by providing current third-party audit reports (SOC 2, ISO 27001, or equivalent) to the extent they address the subject matter of the Controller's request. Reports are shared under NDA upon written request.

§ 11

Liability

Each party shall be liable to data subjects for damage caused by processing that infringes applicable data-protection law to the extent provided for under Article 82 GDPR or equivalent provisions under applicable law.

The Processor's total aggregate liability arising out of or in connection with this DPA shall not exceed the amounts paid or payable by the Controller to the Processor in the 12-month period immediately preceding the event giving rise to the claim. This limitation does not apply to:

  • Death or personal injury caused by negligence
  • Fraud or fraudulent misrepresentation
  • Any other liability that cannot be excluded or limited by applicable law

The Processor shall not be liable for any indirect, incidental, consequential, special, or punitive damages, including loss of profits, data, business, or goodwill, arising from or related to this DPA.

To the extent the Processor has paid compensation for a breach attributable to the Controller, the Processor has the right to reclaim that portion from the Controller (Article 82(5) GDPR).

§ 12

Termination

This DPA remains in force for the duration of the principal agreement and terminates automatically upon its termination or expiry, subject to the survival provisions below.

Effects of Termination

Upon termination of the principal agreement, the Processor will cease all processing of the Controller's Personal Data (except as required by applicable law); return or delete all Personal Data in accordance with Section 8; and provide written certification of deletion within 30 days of the Controller's request.

Surviving Obligations

The obligations in Sections 4 (Security Measures), 8 (Retention and Deletion), 9 (Breach Notification), 10 (Audit Rights), and 11 (Liability) survive termination of this DPA for as long as the Processor retains any Personal Data.

Governing Law & Jurisdiction

This DPA is governed by the laws of the State of Delaware, USA, without regard to its conflict-of-law provisions. For EEA data subjects, mandatory GDPR provisions prevail over any conflicting contractual term. Disputes shall be submitted to the exclusive jurisdiction of the courts of Santa Clara County, California.

Questions about this DPA? Contact our Privacy Team at privacy@getassurai.com or write to AssurAI Inc., Attn: Privacy, 2600 E. Bayshore Road, Palo Alto, CA 94303.