Skip to content
Customer Login Support Partners

Data Processing Addendum

Applies to aisqad.com and the AIWRKR platform.

1 · Overview

When an enterprise customer uses the aisqad-aiwrkr platform to process personal data of their own customers, end users, or employees, the customer acts as the data controller and aisqad-aiwrkr acts as a data processor. The DPA is the contractual document that defines our obligations as a processor and your rights as a controller.

The DPA is structured to satisfy the requirements of:

  • EU General Data Protection Regulation (GDPR) — Article 28
  • UK General Data Protection Regulation and Data Protection Act 2018
  • India Digital Personal Data Protection Act 2023 (DPDP)
  • California Consumer Privacy Act / California Privacy Rights Act (CCPA / CPRA)
  • Singapore Personal Data Protection Act (PDPA)

2 · Roles and responsibilities

  • Customer (Controller) — determines the purposes and means of processing personal data. Responsible for the lawful basis of processing and obtaining any required consents from data subjects.
  • aisqad-aiwrkr (Processor) — processes personal data only on the documented instructions of the customer, in accordance with the DPA and the enterprise agreement.
  • Sub-processors — third parties we engage to assist in providing the platform (cloud infrastructure, email delivery, analytics). All sub-processors are bound by data protection terms equivalent to the DPA.

3 · Categories of data and data subjects

Categories of personal data processed depend on the customer’s use case but typically include:

  • Customer voice recordings and transcripts
  • Customer chat conversations and message content
  • Customer identification data (names, account numbers, contact details)
  • Transaction data and account history accessed by AI Workers
  • Special category data (health, financial) where the customer’s use case involves it — handled under additional safeguards

Categories of data subjects: the customer’s end customers, prospects, employees, and other individuals who interact with the customer’s contact-centre operations.

4 · Processing purposes

We process personal data only for the purposes set out in the enterprise agreement:

  • Providing the aisqad-aiwrkr platform services
  • Operating AI Workers configured by the customer
  • Providing technical support to the customer’s authorised users
  • Ensuring platform security and integrity
  • Complying with legal obligations applicable to the processor

We do not use personal data for AI model training, advertising, or any purpose outside the agreed scope.

5 · Security measures

We maintain organisational, technical, and physical security measures appropriate to the risk, including:

  • Encryption of personal data in transit (TLS 1.3) and at rest (AES-256-GCM)
  • Tenant isolation enforced at the database layer
  • Role-based access control with least-privilege defaults
  • Multi-factor authentication for all administrative access
  • Continuous monitoring, intrusion detection, and vulnerability management
  • Annual third-party penetration testing
  • SOC 2 Type II audit programme (in progress)
  • ISO 27001 alignment

For Sovereign deployments, additional safeguards apply, including customer-controlled encryption keys and physical isolation of inference workloads.

6 · Sub-processors

We engage sub-processors to assist in providing the platform. Sub-processors are bound by written agreements imposing data protection obligations equivalent to those in the DPA. Our current sub-processor list is available on request and is updated when material changes occur. Customers may object to new sub-processors per the terms of the DPA.

7 · Data subject rights assistance

We assist the customer in responding to data subject requests (access, rectification, erasure, restriction, portability, objection). Where a data subject contacts aisqad-aiwrkr directly, we will direct them to the customer (controller) unless legally required to respond directly.

8 · International transfers

We rely on the following mechanisms for international data transfers where required:

  • EU Standard Contractual Clauses (SCCs) 2021/914
  • UK International Data Transfer Addendum to the EU SCCs
  • India DPDP-compliant transfer notifications and consents
  • Customer-region data residency commitments where contractually agreed

9 · Audit rights

The customer has the right to audit our compliance with the DPA, exercised through:

  • Review of our independent audit reports (SOC 2 Type II once issued, ISO 27001, penetration test summaries)
  • Annual questionnaire response
  • On-site audit on reasonable prior notice for Sovereign deployments

10 · Breach notification

If we become aware of a personal data breach affecting customer data, we will notify the customer without undue delay and in any event within 24 hours of confirmation. Notifications include the nature of the breach, categories and approximate number of data subjects and records affected, likely consequences, and mitigation measures taken or proposed.

11 · Term and termination

The DPA continues for the term of the underlying enterprise agreement. On termination, we will, at the customer’s choice, return or securely delete personal data within 30 days, subject to legal retention requirements.

12 · Requesting the full DPA

For the full executable Data Processing Addendum, contact legal@aisqad.com or your aisqad-aiwrkr account manager. We can typically provide the executed DPA within one business day.