Data Processing Agreement
Last updated: January 2025
For Enterprise Customers: This Data Processing Agreement ("DPA") supplements our Terms of Service and applies when Ayari processes personal data on behalf of business customers subject to GDPR, CCPA, or similar data protection laws.
1. Definitions
- "Controller" means the Customer who determines the purposes and means of processing Personal Data
- "Processor" means Aiether Ltd (Company No: 16811773) ("Aiether"), with registered office at 71-75 Shelton Street, Covent Garden, London, processing Personal Data on behalf of the Controller
- "Personal Data" means any information relating to an identified or identifiable natural person
- "Data Subject" means the individual to whom Personal Data relates
- "Processing" means any operation performed on Personal Data
- "Sub-processor" means any third party engaged by Processor to process Personal Data
2. Processing of Personal Data
2.1 Scope and Roles
Customer acts as the Controller and Aiether Ltd acts as the Processor for Personal Data processed through the Service. This DPA applies to all Personal Data processed by Ayari on behalf of Customer.
2.2 Customer Instructions
Processor shall process Personal Data only on documented instructions from Controller, including:
- Instructions conveyed through use of the Service features
- Instructions in the Terms of Service and this DPA
- Instructions required to comply with applicable laws
2.3 Nature of Processing
Categories of Data:
- Email metadata (sender, recipient, subject, date, labels)
- Email body content (cached for 30 days, then automatically purged)
- Attachment metadata (filename, size, type - NOT file contents)
- Calendar event details (title, description, location, times, attendees)
- User authentication tokens (encrypted with AES-256)
- AI conversation history
- User-generated content (drafts, AI proposals)
Purpose of Processing:
- Providing AI-powered email and calendar management
- Caching data for fast panel access (under 100ms loading)
- AI analysis and reply generation via third-party AI providers
- Service authentication and security
- Customer support and service improvement
3. Security Measures
Processor implements and maintains appropriate technical and organizational measures to protect Personal Data:
3.1 Technical Measures
- Encryption at rest (AES-256) and in transit (TLS 1.3+)
- Access controls and authentication mechanisms
- Regular security patches and updates
- Network security and firewalls
- Secure API design with rate limiting
- Regular automated backups
3.2 Organizational Measures
- Access limited to authorized personnel only
- Confidentiality agreements for all personnel
- Regular security training
- Incident response procedures
- Regular security assessments
4. Sub-processors
4.1 Authorized Sub-processors
Controller consents to Processor's use of the following Sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Microsoft Azure | OAuth & Graph API access (Outlook) | United States |
| Google Cloud | OAuth & API access (Gmail, Calendar) | United States |
| Supabase | Database hosting (email/calendar cache) | United States |
| Vercel | Application Hosting | Global CDN |
| Clerk | User Authentication | United States |
| Stripe | Payment Processing | United States |
| Anthropic | AI Processing (Claude models) | United States |
| OpenRouter | AI Routing (OpenAI, Google models) | United States |
4.2 Sub-processor Changes
Processor shall notify Controller of any intended changes concerning the addition or replacement of Sub-processors at least 30 days in advance. Controller may object to such changes within 14 days of notification.
5. Data Subject Rights
Processor shall assist Controller in fulfilling its obligations to respond to Data Subject requests:
- Access: Provide Data Subjects with access to their Personal Data
- Rectification: Correct inaccurate Personal Data
- Erasure: Delete Personal Data when required
- Portability: Export Personal Data in a structured format
- Restriction: Limit processing when requested
- Objection: Cease processing upon valid objection
Processor will respond to Data Subject requests within 5 business days or refer them to Controller as appropriate.
6. International Transfers
Personal Data may be transferred and processed in countries outside the European Economic Area. Such transfers are protected by:
- Standard Contractual Clauses (Module 2: Controller → Processor) approved by the European Commission
- UK Addendum (IDTA) where applicable
- Adequacy decisions where applicable
- Additional safeguards as required by applicable law
7. Data Breach Notification
In the event of a Personal Data breach, Processor shall:
- Notify Controller without undue delay upon becoming aware
- Provide details of the breach including:
- Nature and categories of data affected
- Number of Data Subjects affected
- Likely consequences of the breach
- Measures taken to address the breach
- Cooperate with Controller in investigating and remediating the breach
- Document all breaches and remediation efforts
8. Audits and Inspections
Processor shall:
- Make available all information necessary to demonstrate compliance
- Allow for and contribute to audits conducted by Controller or appointed auditor
- Provide annual security assessment reports upon request
- Maintain records of all processing activities
Audits shall be conducted with 30 days advance notice and during regular business hours, not more than once per year unless required by law or following a breach.
9. Data Retention and Deletion
Data retention during active use:
- Email body content: Cached for 30 days, then automatically purged
- Email metadata: Kept while account is active
- Calendar events: Kept while account is active
- Draft emails: Kept until sent or deleted
- Conversation history: Kept indefinitely, deletable by user anytime
Upon termination of the Service or upon Controller's request:
- Processor shall delete all Personal Data immediately upon request
- Processor shall delete existing copies unless required by law to retain
- Processor shall certify in writing the deletion of Personal Data upon request
- Audit logs are anonymized (user ID replaced) but retained for legal compliance
10. Liability and Indemnification
Each party's liability arising out of or related to this DPA shall be subject to the limitations of liability in the Terms of Service. Each party shall indemnify the other against damages arising from its breach of this DPA.
11. Governing Law and Jurisdiction
This DPA is governed by the same law as the Terms of Service. Any disputes shall be resolved according to the dispute resolution provisions in the Terms of Service.
12. Contact Information
For DPA-related inquiries:
- Processor: Aiether Ltd (Company No: 16811773)
- Registered office: 71-75 Shelton Street, Covent Garden, London
- Data Protection Inquiries: [email protected] (Subject: DPO)
- Legal: [email protected] (Subject: Legal)
- Security: [email protected] (Subject: Security)
- General Support: Contact Form
Enterprise Compliance
This DPA is designed to meet GDPR and CCPA requirements for enterprise customers. For custom enterprise agreements or specific compliance needs, please contact our legal team.
Data Minimization: We cache email and calendar data for performance, with email body content automatically purged after 30 days. Attachment files are never stored - they're downloaded directly from your provider when needed. All data is encrypted at rest and in transit.
Standard Contractual Clauses
By entering into this DPA, the parties agree to abide by the Standard Contractual Clauses for the transfer of personal data to processors established in third countries, as approved by the European Commission. The full SCCs are incorporated by reference and available upon request.