Data Processing Addendum
Applies to aisqad.com and the AIWRKR platform.
1 · Overview
When an enterprise customer uses the aisqad-aiwrkr platform to process personal data of their own customers, end users, or employees, the customer acts as the data controller and aisqad-aiwrkr acts as a data processor. The DPA is the contractual document that defines our obligations as a processor and your rights as a controller.
The DPA is structured to satisfy the requirements of:
- EU General Data Protection Regulation (GDPR) — Article 28
- UK General Data Protection Regulation and Data Protection Act 2018
- India Digital Personal Data Protection Act 2023 (DPDP)
- California Consumer Privacy Act / California Privacy Rights Act (CCPA / CPRA)
- Singapore Personal Data Protection Act (PDPA)
2 · Roles and responsibilities
- Customer (Controller) — determines the purposes and means of processing personal data. Responsible for the lawful basis of processing and obtaining any required consents from data subjects.
- aisqad-aiwrkr (Processor) — processes personal data only on the documented instructions of the customer, in accordance with the DPA and the enterprise agreement.
- Sub-processors — third parties we engage to assist in providing the platform (cloud infrastructure, email delivery, analytics). All sub-processors are bound by data protection terms equivalent to the DPA.
3 · Categories of data and data subjects
Categories of personal data processed depend on the customer’s use case but typically include:
- Customer voice recordings and transcripts
- Customer chat conversations and message content
- Customer identification data (names, account numbers, contact details)
- Transaction data and account history accessed by AI Workers
- Special category data (health, financial) where the customer’s use case involves it — handled under additional safeguards
Categories of data subjects: the customer’s end customers, prospects, employees, and other individuals who interact with the customer’s contact-centre operations.
4 · Processing purposes
We process personal data only for the purposes set out in the enterprise agreement:
- Providing the aisqad-aiwrkr platform services
- Operating AI Workers configured by the customer
- Providing technical support to the customer’s authorised users
- Ensuring platform security and integrity
- Complying with legal obligations applicable to the processor
We do not use personal data for AI model training, advertising, or any purpose outside the agreed scope.
5 · Security measures
We maintain organisational, technical, and physical security measures appropriate to the risk, including:
- Encryption of personal data in transit (TLS 1.3) and at rest (AES-256-GCM)
- Tenant isolation enforced at the database layer
- Role-based access control with least-privilege defaults
- Multi-factor authentication for all administrative access
- Continuous monitoring, intrusion detection, and vulnerability management
- Annual third-party penetration testing
- SOC 2 Type II audit programme (in progress)
- ISO 27001 alignment
For Sovereign deployments, additional safeguards apply, including customer-controlled encryption keys and physical isolation of inference workloads.
6 · Sub-processors
We engage sub-processors to assist in providing the platform. Sub-processors are bound by written agreements imposing data protection obligations equivalent to those in the DPA. Our current sub-processor list is available on request and is updated when material changes occur. Customers may object to new sub-processors per the terms of the DPA.
7 · Data subject rights assistance
We assist the customer in responding to data subject requests (access, rectification, erasure, restriction, portability, objection). Where a data subject contacts aisqad-aiwrkr directly, we will direct them to the customer (controller) unless legally required to respond directly.
8 · International transfers
We rely on the following mechanisms for international data transfers where required:
- EU Standard Contractual Clauses (SCCs) 2021/914
- UK International Data Transfer Addendum to the EU SCCs
- India DPDP-compliant transfer notifications and consents
- Customer-region data residency commitments where contractually agreed
9 · Audit rights
The customer has the right to audit our compliance with the DPA, exercised through:
- Review of our independent audit reports (SOC 2 Type II once issued, ISO 27001, penetration test summaries)
- Annual questionnaire response
- On-site audit on reasonable prior notice for Sovereign deployments
10 · Breach notification
If we become aware of a personal data breach affecting customer data, we will notify the customer without undue delay and in any event within 24 hours of confirmation. Notifications include the nature of the breach, categories and approximate number of data subjects and records affected, likely consequences, and mitigation measures taken or proposed.
11 · Term and termination
The DPA continues for the term of the underlying enterprise agreement. On termination, we will, at the customer’s choice, return or securely delete personal data within 30 days, subject to legal retention requirements.
12 · Requesting the full DPA
For the full executable Data Processing Addendum, contact legal@aisqad.com or your aisqad-aiwrkr account manager. We can typically provide the executed DPA within one business day.