Data Processing Agreement

Last updated: January 2025

For Enterprise Customers: This Data Processing Agreement ("DPA") supplements our Terms of Service and applies when Ayari processes personal data on behalf of business customers subject to GDPR, CCPA, or similar data protection laws.

1. Definitions

  • "Controller" means the Customer who determines the purposes and means of processing Personal Data
  • "Processor" means Aiether Ltd (Company No: 16811773) ("Aiether"), with registered office at 71-75 Shelton Street, Covent Garden, London, processing Personal Data on behalf of the Controller
  • "Personal Data" means any information relating to an identified or identifiable natural person
  • "Data Subject" means the individual to whom Personal Data relates
  • "Processing" means any operation performed on Personal Data
  • "Sub-processor" means any third party engaged by Processor to process Personal Data

2. Processing of Personal Data

2.1 Scope and Roles

Customer acts as the Controller and Aiether Ltd acts as the Processor for Personal Data processed through the Service. This DPA applies to all Personal Data processed by Ayari on behalf of Customer.

2.2 Customer Instructions

Processor shall process Personal Data only on documented instructions from Controller, including:

  • Instructions conveyed through use of the Service features
  • Instructions in the Terms of Service and this DPA
  • Instructions required to comply with applicable laws

2.3 Nature of Processing

Categories of Data:

  • Email metadata (sender, recipient, subject, date, labels)
  • Email body content (cached for 30 days, then automatically purged)
  • Attachment metadata (filename, size, type - NOT file contents)
  • Calendar event details (title, description, location, times, attendees)
  • User authentication tokens (encrypted with AES-256)
  • AI conversation history
  • User-generated content (drafts, AI proposals)

Purpose of Processing:

  • Providing AI-powered email and calendar management
  • Caching data for fast panel access (under 100ms loading)
  • AI analysis and reply generation via third-party AI providers
  • Service authentication and security
  • Customer support and service improvement

3. Security Measures

Processor implements and maintains appropriate technical and organizational measures to protect Personal Data:

3.1 Technical Measures

  • Encryption at rest (AES-256) and in transit (TLS 1.3+)
  • Access controls and authentication mechanisms
  • Regular security patches and updates
  • Network security and firewalls
  • Secure API design with rate limiting
  • Regular automated backups

3.2 Organizational Measures

  • Access limited to authorized personnel only
  • Confidentiality agreements for all personnel
  • Regular security training
  • Incident response procedures
  • Regular security assessments

4. Sub-processors

4.1 Authorized Sub-processors

Controller consents to Processor's use of the following Sub-processors:

Sub-processorPurposeLocation
Microsoft AzureOAuth & Graph API access (Outlook)United States
Google CloudOAuth & API access (Gmail, Calendar)United States
SupabaseDatabase hosting (email/calendar cache)United States
VercelApplication HostingGlobal CDN
ClerkUser AuthenticationUnited States
StripePayment ProcessingUnited States
AnthropicAI Processing (Claude models)United States
OpenRouterAI Routing (OpenAI, Google models)United States

4.2 Sub-processor Changes

Processor shall notify Controller of any intended changes concerning the addition or replacement of Sub-processors at least 30 days in advance. Controller may object to such changes within 14 days of notification.

5. Data Subject Rights

Processor shall assist Controller in fulfilling its obligations to respond to Data Subject requests:

  • Access: Provide Data Subjects with access to their Personal Data
  • Rectification: Correct inaccurate Personal Data
  • Erasure: Delete Personal Data when required
  • Portability: Export Personal Data in a structured format
  • Restriction: Limit processing when requested
  • Objection: Cease processing upon valid objection

Processor will respond to Data Subject requests within 5 business days or refer them to Controller as appropriate.

6. International Transfers

Personal Data may be transferred and processed in countries outside the European Economic Area. Such transfers are protected by:

  • Standard Contractual Clauses (Module 2: Controller → Processor) approved by the European Commission
  • UK Addendum (IDTA) where applicable
  • Adequacy decisions where applicable
  • Additional safeguards as required by applicable law

7. Data Breach Notification

In the event of a Personal Data breach, Processor shall:

  • Notify Controller without undue delay upon becoming aware
  • Provide details of the breach including:
    • Nature and categories of data affected
    • Number of Data Subjects affected
    • Likely consequences of the breach
    • Measures taken to address the breach
  • Cooperate with Controller in investigating and remediating the breach
  • Document all breaches and remediation efforts

8. Audits and Inspections

Processor shall:

  • Make available all information necessary to demonstrate compliance
  • Allow for and contribute to audits conducted by Controller or appointed auditor
  • Provide annual security assessment reports upon request
  • Maintain records of all processing activities

Audits shall be conducted with 30 days advance notice and during regular business hours, not more than once per year unless required by law or following a breach.

9. Data Retention and Deletion

Data retention during active use:

  • Email body content: Cached for 30 days, then automatically purged
  • Email metadata: Kept while account is active
  • Calendar events: Kept while account is active
  • Draft emails: Kept until sent or deleted
  • Conversation history: Kept indefinitely, deletable by user anytime

Upon termination of the Service or upon Controller's request:

  • Processor shall delete all Personal Data immediately upon request
  • Processor shall delete existing copies unless required by law to retain
  • Processor shall certify in writing the deletion of Personal Data upon request
  • Audit logs are anonymized (user ID replaced) but retained for legal compliance

10. Liability and Indemnification

Each party's liability arising out of or related to this DPA shall be subject to the limitations of liability in the Terms of Service. Each party shall indemnify the other against damages arising from its breach of this DPA.

11. Governing Law and Jurisdiction

This DPA is governed by the same law as the Terms of Service. Any disputes shall be resolved according to the dispute resolution provisions in the Terms of Service.

12. Contact Information

For DPA-related inquiries:

Enterprise Compliance

This DPA is designed to meet GDPR and CCPA requirements for enterprise customers. For custom enterprise agreements or specific compliance needs, please contact our legal team.

Data Minimization: We cache email and calendar data for performance, with email body content automatically purged after 30 days. Attachment files are never stored - they're downloaded directly from your provider when needed. All data is encrypted at rest and in transit.

Standard Contractual Clauses

By entering into this DPA, the parties agree to abide by the Standard Contractual Clauses for the transfer of personal data to processors established in third countries, as approved by the European Commission. The full SCCs are incorporated by reference and available upon request.