๐Ÿ“„ Legal

Data Processing Agreement

GDPR-aligned terms governing AssurAI's processing of personal data on behalf of our customers.

Last updated: June 2, 2026 ยท Version 1.0
โš ๏ธ

Template notice: This DPA is provided as a template for convenience. It is not legal advice โ€” have your own counsel review it before relying on it. For a countersigned copy, email privacy@getassurai.com.

Contents
  1. Parties
  2. Roles & Responsibilities
  3. Subject Matter & Duration
  4. Nature & Purpose
  5. Data Subjects & Data
  6. Sub-Processors
  7. Security Measures
  8. Data Subject Rights
  9. International Transfers
  10. Breach Notification
  11. Deletion & Return
  12. Contact

1. Parties

This Data Processing Agreement ("DPA") forms part of the agreement between:

This DPA applies to the extent the Processor processes Personal Data (as defined under the EU General Data Protection Regulation 2016/679 ("GDPR") and the UK GDPR) on behalf of the Controller.

2. Roles & Responsibilities

The Controller determines the purposes and means of processing the audit, compliance, and risk data it uploads to AssurAI. The Processor processes that Personal Data only on the Controller's documented instructions, including those set out in this DPA, the Privacy Policy, and the platform's configuration (such as the selected data region).

The Processor ensures that persons authorised to process Personal Data are bound by confidentiality obligations.

3. Subject Matter & Duration

Subject matter: the provision of the AssurAI AI-native GRC platform for audit, compliance, and risk management.

Duration: processing continues for the term of the Controller's subscription and for any post-termination retention period described in Section 11 and the Privacy Policy.

4. Nature & Purpose of Processing

Personal Data is processed to host, secure, and operate the platform and to provide its features, including AI-assisted generation of workpapers, controls testing, findings, and reports. AI processing is performed to produce outputs for the Controller only and is not used to train AI models.

Processing activityPurpose
Storage & hostingPersisting the Controller's audit data
AuthenticationSecuring account access
AI generationProducing workpapers and analysis on request
Transactional emailNotifications, reminders, confirmations

5. Categories of Data Subjects & Personal Data

Data subjects

Categories of Personal Data

The Controller must not upload special categories of data unless strictly necessary and lawful.

6. Sub-Processors

The Controller authorises the Processor to engage the following sub-processors. Each is bound by a written agreement imposing data-protection obligations no less protective than this DPA.

Sub-processorServiceRegion
SupabaseDatabase & authenticationUS or EU (per org data region)
NetlifyApplication hosting & functionsUS / global edge
AnthropicAI processing (Claude API) โ€” no training on customer dataUS
ResendTransactional email deliveryUS

The Processor will give reasonable notice of any intended change to its sub-processors, allowing the Controller to object on reasonable data-protection grounds.

7. Security Measures

The Processor implements appropriate technical and organisational measures, including:

Further detail is available at getassurai.com/security.

8. Data Subject Rights

Taking into account the nature of the processing, the Processor assists the Controller (by appropriate technical and organisational measures, insofar as possible) in responding to requests to exercise data subject rights โ€” access, rectification, erasure, restriction, portability, and objection.

The platform provides self-service data export (portability) and data deletion (erasure) tools from account settings. Deletion is confirmed via an emailed verification code and applied as an immediate soft-delete pending permanent removal under the retention policy.

9. International Transfers & Data Residency

AssurAI offers a data region selection (US or EU). For organisations on the EU region, primary database storage is provisioned in an EU Supabase project. Certain sub-processors (e.g. AI processing) may still process data in the United States.

Where Personal Data is transferred outside the EEA, UK, or Switzerland, such transfers are governed by the EU Standard Contractual Clauses (SCCs) and the UK International Data Transfer Addendum, together with supplementary measures where required.

๐ŸŒ

EU data residency requires the organisation to be provisioned on AssurAI's EU deployment. See our EU setup documentation or contact us to enable EU residency for your organisation.

10. Personal Data Breach Notification

The Processor will notify the Controller without undue delay, and in any event within 72 hours of becoming aware of a Personal Data breach affecting the Controller's data, providing the information reasonably necessary for the Controller to meet its own notification obligations.

11. Deletion & Return of Data

On termination, or upon the Controller's request, the Processor will delete or return the Controller's Personal Data:

12. Contact

Need a countersigned DPA?

We'll provide an executable copy for your records.

privacy@getassurai.com