Data Processing Addendum
Effective September 8, 2026 · Version 2026-09-08
This Data Processing Addendum ("DPA") describes how AI Assurance Hub LLC processes personal data on behalf of customers (the "Controller") when they use the Service. It forms part of the Terms of Service.
1. Roles
For Customer Content, the customer is the controller/business and we are the processor/service provider. We process personal data only to provide the Service and on the customer’s documented instructions, and not for our own commercial purposes.
2. Scope of processing
- Subject matter: provision of the AI governance Service.
- Duration: the term of the customer’s subscription.
- Nature & purpose: hosting, storing, and processing governance records the customer submits.
- Data subjects: individuals the customer chooses to reference in use cases, evidence, or related records.
- Data types: as determined by the customer; the customer controls whether to include personal or regulated data.
3. Our obligations
- Process personal data only on documented instructions;
- Ensure persons authorized to process are bound by confidentiality;
- Implement appropriate technical and organizational security measures;
- Assist the Controller with data-subject requests and security obligations, taking into account the nature of processing;
- Delete or return personal data at the end of the engagement, subject to legal retention and backup cycles;
- Make available information necessary to demonstrate compliance.
4. Subprocessors
The Controller authorizes our use of the subprocessors listed at /subprocessors. We impose data-protection obligations on subprocessors and remain responsible for their performance. We will provide a mechanism to notify of changes.
5. Security measures
Measures include encryption in transit, encryption of sensitive fields at rest, strict per-tenant isolation, access controls, security headers, and audit logging. See our Privacy Policy.
6. Data-subject requests & breach
We will promptly notify the Controller of any data-subject request we receive directly, and assist the Controller in responding. We will notify the Controller without undue delay after becoming aware of a personal-data breach affecting Customer Content.
7. International transfers
Where personal data originates in the EU/EEA/UK, the parties will put in place an appropriate transfer mechanism (e.g. Standard Contractual Clauses) as an addendum to this DPA.
8. Contact
To execute a countersigned DPA or ask questions, contact [email protected].