Data Processing Addendum

Last updated: June 26, 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Service between AI Aware Certified ("Processor") and the customer entity that has accepted the Terms ("Controller"). It applies when Processor processes Personal Data on behalf of Controller in connection with the Service.

1. Definitions

Capitalized terms not defined here have the meaning given in Regulation (EU) 2016/679 (the "GDPR"). "Personal Data", "Processing", "Controller", "Processor", and "Data Subject" have the meanings given in the GDPR.

2. Scope and roles

Controller is the controller of Personal Data submitted to the Service. Processor processes Personal Data only on Controller's documented instructions, which include the Terms and Controller's use of the Service's features.

3. Subject matter and duration

  • Subject matter: provision of the Service.
  • Duration: the term of Controller's subscription, plus the deletion period below.
  • Nature and purpose: hosting, storage, processing, and document generation for EU AI Act compliance.
  • Data subjects: Controller's employees, contractors, end users, and individuals referenced in Controller's content.
  • Categories of data: business contact details, account identifiers, and any Personal Data Controller chooses to include in evidence files or assessment responses.

4. Processor obligations

  • Process Personal Data only on Controller's documented instructions.
  • Ensure personnel are bound by confidentiality.
  • Implement appropriate technical and organizational measures (see Annex 1).
  • Assist Controller with data subject requests and DPIAs to the extent reasonably required.
  • Notify Controller without undue delay (and in any case within 72 hours) of a confirmed Personal Data Breach.

5. Subprocessors

Controller grants Processor general authorization to engage subprocessors, subject to written contracts imposing equivalent data protection obligations. The current list is published in our Privacy Policy. Processor will notify Controller of material changes by in-product or email notice with at least 14 days to object.

6. International transfers

Where Personal Data is transferred outside the EEA or UK, the parties rely on the European Commission's Standard Contractual Clauses (Module 2, controller-to-processor) and the UK International Data Transfer Addendum, which are deemed incorporated by reference.

7. Data subject rights

Processor will, taking into account the nature of the Processing, assist Controller by appropriate technical and organizational measures, insofar as possible, to respond to requests from data subjects exercising their rights under Chapter III of the GDPR.

8. Audits

Processor will make available all information necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits conducted by Controller or an independent auditor mandated by Controller, no more than once per year and subject to reasonable confidentiality and scheduling.

9. Deletion and return

On termination, Controller may export Personal Data through the Service for 30 days. After that, Processor will delete Personal Data within 30 days, except to the extent retention is required by law.

10. Liability

Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms.

Annex 1 — Technical and organizational measures

  • Encryption in transit (TLS 1.2+) and at rest.
  • Role-based access control with least privilege and audit logging.
  • Row-level security on the database; per-user signed URLs for evidence files.
  • Hosting in EU regions where supported by our subprocessors.
  • Regular backups, vulnerability scanning, and dependency monitoring.
  • Security incident response plan with 72-hour breach notification.

How to execute

Customers requiring a countersigned copy may email legal@compliance-now.io with their legal entity name, address, and DPO contact.