Skip to main content
← Back to home

Data Processing Agreement

Version 1.2 · Last updated 19 July 2026

This Data Processing Agreement ("DPA") forms part of the Terms & Conditions between Shpat Radoniqi B.I. ("AIA", "we", "us") and the customer ("you"), and governs how we process personal data on your behalf when you use the AIA platform. It applies automatically to every workspace — no signature is required. It is written to satisfy Article 28(3) of the General Data Protection Regulation (GDPR).

1. Scope and roles

This DPA applies where we process personal data on your behalf as a processor — the "Customer Data": the messages and their metadata, contacts, knowledge-base content, and workflow or agent configuration content that you connect to or create in the platform. For that data, you are the controller (or a processor acting for another controller) and we are your processor. Annex 1 describes the processing in detail.

We remain an independent controller for your account data — registration details, contact information, and usage and security logs — as described in our Privacy Policy. That processing is outside the scope of this DPA.

2. Processing on your documented instructions

We process Customer Data only on your documented instructions, including with regard to international transfers, unless applicable law requires us to process it otherwise — in which case we will inform you before processing, unless the law prohibits us from doing so. The Terms, this DPA, and the configuration choices you make in the product (which accounts you connect, which agents and workflows you enable) together constitute your complete documented instructions.

We will inform you if, in our opinion, an instruction infringes the GDPR or other applicable data-protection law.

3. Confidentiality

We ensure that every person we authorise to process Customer Data is bound by a contractual or statutory obligation of confidentiality.

4. Security

We implement and maintain the technical and organisational measures described in Annex 2, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the processing (Article 32 GDPR). We may update these measures over time, provided the overall level of protection is not reduced.

5. Sub-processors

You give us your general written authorisation to engage sub-processors to help provide the service. The current list is published at /subprocessors, which also describes the safeguards each sub-processor is bound by.

We will update that page and notify account owners by email at least 30 days before a new or replaced sub-processor starts processing Customer Data. If you object on reasonable data-protection grounds, you may terminate the affected services before the change takes effect. We remain fully liable to you for the performance of each sub-processor's data-protection obligations.

6. International transfers

Where Customer Data is transferred to a country outside the Republic of Kosovo or the European Economic Area that has not been found to provide an adequate level of protection, we ensure appropriate safeguards are in place, such as the European Commission Standard Contractual Clauses or an adequacy decision, as described in our Privacy Policy and on the sub-processor page.

7. Assistance with data-subject requests

Taking into account the nature of the processing, we assist you with appropriate technical and organisational measures, insofar as this is possible, in fulfilling your obligation to respond to data-subject requests under Chapter III of the GDPR (access, rectification, erasure, restriction, portability, and objection). If a data subject contacts us directly about Customer Data, we will forward the request to you without undue delay and will not respond on your behalf, except to direct them to you.

8. Personal-data breach

If we become aware of a personal-data breach affecting Customer Data, we will notify you without undue delay, and in any event within 48 hours of becoming aware of it. The notification will include the information reasonably available to us at the time — the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed — and we will supplement it as further information becomes available. We will document breaches and cooperate with you so you can meet your own notification obligations.

9. Assistance with security, impact assessments, and prior consultation

Taking into account the nature of the processing and the information available to us, we provide reasonable assistance with your obligations under Articles 32 to 36 of the GDPR, including data-protection impact assessments and prior consultation of a supervisory authority, where they relate to our processing of Customer Data.

10. Deletion and return of data

During the term, you can export Customer Data using the product's export features, and you can disconnect any integration at any time, which stops further collection from that source.

When the agreement ends — you delete your workspace, close your account, or the Terms are terminated — we delete the Customer Data within 60 days, unless applicable law requires us to retain some of it. Data we must retain stays protected under this DPA and is deleted as soon as the legal requirement ends.

11. Audits

We make available to you the information necessary to demonstrate compliance with Article 28 GDPR — primarily through documentation: this DPA, the sub-processor page, descriptions of our security measures, and written answers to reasonable security questionnaires.

Where that documentation is not sufficient, you (or an independent auditor you mandate, who may not be a competitor of ours) may audit our compliance with this DPA: no more than once in any 12 months, with at least 30 days' written notice, during normal business hours, at your cost, and in a way that does not access other customers' data or endanger the security or proper operation of the platform.

12. Precedence and liability

This DPA is part of the Terms. If this DPA and the Terms conflict regarding the processing of personal data, this DPA prevails. The limitations and exclusions of liability in the Terms apply to this DPA.

13. Duration

This DPA applies for as long as we process Customer Data under the Terms. The obligations regarding deletion, confidentiality, and cooperation survive until all Customer Data has been deleted.

14. Contact

Questions about this DPA can be sent to info@aiaplatform.ai. If your organisation requires a countersigned copy of this DPA, email us and we will provide one.

Annex 1 — Description of processing

ParticularDescription
Subject matterProvision of the AIA platform: unified inbox, AI-assisted classification and response drafting, workflow automation, and knowledge base.
DurationThe term of the agreement, plus the 60-day deletion window after termination.
Nature and purposeIngestion, storage, display, classification, AI-assisted response drafting, workflow automation, and search of the messages and content the customer connects to the platform.
Categories of data subjectsThe customer's users, and the individuals who communicate with the customer through connected channels (message senders, recipients, and contacts).
Categories of personal dataMessage content and metadata, names and contact details, calendar and scheduling data, lead and invoice data extracted from messages, and knowledge-base content the customer uploads.
Special categoriesNot intended. The service is not designed for special-category data, although message content sent by the customer's correspondents may incidentally contain it.
FrequencyContinuous, for as long as integrations remain connected.
RetentionFor the term of the agreement; deleted within 60 days of termination (see the deletion clause).

Annex 2 — Technical and organisational measures

Access control and tenant isolation

  • Authentication with short-lived access tokens and refresh tokens (JWT).
  • Role-based access control within each workspace (Owner, Admin, Member, Viewer), with a separate platform-administrator distinction for operator access.
  • Multi-tenant data isolation: every customer-facing query is scoped to the workspace it belongs to.

Encryption

  • All traffic encrypted in transit (TLS/HTTPS).
  • Passwords stored only as salted hashes (bcrypt), never in plain text.
  • OAuth credentials for connected accounts encrypted at rest (AES-256-GCM).
  • Managed database storage with provider-level disk encryption.

Logging and monitoring

  • Audit logging of message access and administrative actions.
  • Authentication and consent events recorded, including the legal version accepted at signup.
  • Health checks and operational monitoring of the platform.

Network and infrastructure

  • The platform is fronted by a CDN and security provider with bot protection, and human verification on the sign-in, sign-up, and password-reset pages.
  • Tiered rate limiting to protect against brute force and abuse.
  • Hosted on managed cloud infrastructure with database backups.

Organisational measures

  • Least-privilege OAuth scopes requested from connected platforms.
  • Data processing agreements with every sub-processor (see the sub-processor page).
  • A breach-response commitment of notification within 48 hours of awareness.
  • Versioned legal documents with recorded consent.

Annex 3 — Sub-processors

The authorised sub-processors, the safeguards each is bound by, and our 30-day change notice are published on the Sub-processors page, which forms part of this DPA.

See also: Privacy Policy · Terms & Conditions · Imprint · Cookie Policy · Sub-processors