This Data Processing Addendum ("DPA") forms part of the Terms of Service between the customer ("Controller") and APPKITEKT ("Processor") and applies to the extent APPKITEKT processes Personal Data on behalf of the Controller in providing the AIAO Service.
1. Subject matter & duration
Processor will process Personal Data only to provide the Service for the duration of the underlying agreement and as instructed by Controller through the Service configuration.
2. Nature & purpose
Auditing, monitoring, and optimizing how AI agents interact with Controller's brand, websites, and apps; generating Output; account administration; security; and support.
3. Categories of data subjects & data
- Controller's authorized users (name, email, role).
- End-users whose data is included in URLs, prompts, or content submitted by Controller.
- Usage and diagnostic data necessary to operate the Service.
4. Processor obligations
- Process Personal Data only on documented instructions from Controller.
- Ensure persons authorized to process data are bound by confidentiality.
- Implement appropriate technical and organizational security measures.
- Assist Controller with data subject requests and DPIA obligations as reasonably required.
- Notify Controller without undue delay after becoming aware of a personal data breach affecting Controller data.
- Delete or return Personal Data at the end of the Service, unless retention is required by law.
5. Sub-processors
Controller authorizes Processor to engage sub-processors to provide the Service, including hosting, database, authentication, AI model providers, search/SEO data providers, email, analytics, and payments. Processor remains responsible for their compliance and will impose data protection obligations no less protective than this DPA.
6. International transfers
Where Personal Data is transferred outside the EEA, UK, or Switzerland, the parties rely on the EU Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), incorporated by reference.
7. Audits
Processor will make available information reasonably necessary to demonstrate compliance, including third-party certifications and reports, and will allow audits subject to reasonable notice, confidentiality, and security restrictions.
8. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service.
9. Requests
To request a signed DPA or the current list of sub-processors, contact privacy@appkitekt.com.