1. Parties, scope and priority
This DPA forms part of an accepted Service agreement between the Customer identified in its account or order and the unincorporated business trading as My Companies AI. It applies when we process personal data on the Customer's behalf. The Customer is the controller and we are the processor; where the Customer is itself a processor, we act as its subprocessor and the Customer warrants that it has the controller's authority.
"Data Protection Law" means the UK GDPR and Data Protection Act 2018 as amended, and the EU GDPR, Swiss Federal Act on Data Protection or other privacy law to the extent it applies to the relevant processing. "Personal Data" means personal information processed for the Customer through the Service. Terms such as controller, processor, breach and processing take their meaning from applicable law.
Mandatory international-transfer clauses prevail over this DPA; this DPA prevails over conflicting general terms on processing. Neither party's statutory responsibilities nor an individual's enforceable rights are reduced. Our separate controller activities are explained in the Privacy notice.
2. Instructions and Customer responsibilities
We will process Personal Data only on documented instructions to deliver, maintain, secure and support the Service, as set out in the agreement, this DPA, authorised workspace settings and further agreed written instructions. Instructions cover the processing and disclosures described in the schedules. We will not use that data for our own advertising, sell it, or train a shared model for our own purposes.
If law binding on us requires other processing, we will inform the Customer before doing it unless legally prohibited. We will promptly flag an instruction we reasonably believe infringes Data Protection Law and suspend the affected processing while it is clarified. Instructions cannot require us to break the law or expose another customer's information.
The Customer is responsible for a lawful basis, appropriate notices, data accuracy and minimisation, the authority to appoint us and approve subprocessors, and lawful access and use by its Users. It must evaluate whether the Service's security and international arrangements meet its needs and provide any additional instructions needed for compliance. It must not submit restricted data outside the agreed scope.
3. Confidentiality and security
We will restrict access to personnel who need it for an authorised purpose and are subject to enforceable confidentiality obligations. We will maintain technical and organisational measures appropriate to the risk, taking account of the nature, scope, context and purpose of processing. The current measures and material limitations are in Schedule B.
We will review controls, address identified vulnerabilities according to risk and maintain processes for confidentiality, integrity, availability and recovery. Measures may evolve, but we will not materially reduce the agreed overall level of protection without notifying the Customer and resolving the effect on its processing. Security is a shared responsibility; Customer-managed permissions and devices remain the Customer's responsibility.
4. Subprocessor authorisation
The Customer gives general written authorisation for the subprocessors and services identified in Schedule C: provider register, only for the listed purposes. We will assess their suitability and ensure that a binding agreement imposes materially equivalent data-protection obligations appropriate to their processing. We remain responsible to the Customer for our subprocessors' performance of those obligations.
We will give at least 30 days' advance notice to the Customer's account contact of a proposed additional or replacement subprocessor that will receive Personal Data. The Customer may object on reasonable data-protection grounds within that period. We will seek an alternative or other reasonable solution. If none is practicable, either party may end the affected processing before the new provider is used; we will refund prepaid fees for the unused affected period. A necessary urgent security replacement will be notified as early as possible, with equivalent protection and a reasonable objection process.
Listing a provider describes its involvement; it is not a substitute for executing a necessary provider contract or transfer safeguard. A payment provider or authority may act as an independent controller for some purposes rather than as our subprocessor.
5. International transfers
Primary application storage and local backups are in Scotland, UK. The Customer instructs the international processing described in Schedule C only to the extent permitted by Data Protection Law. We will not make a restricted transfer unless a valid legal mechanism and any required assessment or supplementary protection cover that transfer.
Adequacy may be used only while it applies to the destination and recipient. Where contractual safeguards are needed, the parties must complete and enter into the applicable EU Standard Contractual Clauses, UK IDTA or UK Addendum and, where needed, Swiss adaptations before the relevant transfer. The correct module, parties, descriptions, competent authority, security measures and assessment must reflect the actual arrangement. An EU clause reference alone does not satisfy UK transfer requirements.
This published DPA is not an independently completed international-transfer instrument and does not certify any provider's eligibility for an adequacy framework. We will provide information reasonably needed to verify the relevant safeguards and cooperate in completing required instruments. If a mechanism becomes invalid or protections cannot be maintained, we will stop the affected transfer until it is lawfully resolved and discuss an alternative or termination. Additional local restrictions remain applicable.
6. Rights requests and compliance assistance
We will promptly notify the Customer of a request relating to Personal Data for which it is responsible. Unless authorised or legally required, we will not substantively answer it on the Customer's behalf. Taking account of the processing, we will provide appropriate technical and organisational assistance with access, correction, erasure, restriction, portability, objections and other applicable rights, within a time that enables the Customer to meet its obligations.
We will also reasonably assist with security assessments, breach notifications, data-protection impact assessments, prior regulatory consultation and transfer assessments, taking account of the information available to us. We may agree reasonable charges in advance for exceptional assistance beyond the ordinary Service, but charges must not prevent mandatory assistance, audits or statutory rights. Assistance required because of our breach is at our cost.
7. Personal-data incidents
We will notify the Customer without undue delay after becoming aware of a Personal Data breach affecting its data. An initial notification will not be delayed until every fact is known. As information becomes available, we will provide the nature of the incident, affected categories and approximate numbers where known, likely consequences, containment and remedial steps, and a contact for follow-up.
We will investigate, take reasonable steps to mitigate harm, preserve relevant evidence and cooperate with the Customer. The Customer determines its own notification obligations to people and regulators; we will not make notices on its behalf without authority unless the law requires it. No contractual incident timetable replaces a shorter mandatory deadline. A notice does not itself admit liability.
8. Information and audit rights
We will make available information reasonably necessary to demonstrate compliance and allow and contribute to audits, including inspections by the Customer or its mandated independent auditor. Documentary review should normally be used first. Inspections should have reasonable notice, occur during agreed hours and protect confidentiality, safety and other customers' data.
Routine audits may normally be coordinated annually, but this does not prevent additional proportionate audits after a relevant incident, a credible compliance concern or a regulator's request. We will not use confidentiality or a commercial condition to frustrate a legally required audit. The parties will agree practical safeguards and reasonable allocation of extraordinary costs in advance.
9. Return, deletion and duration
This DPA lasts for the processing, including necessary return or deletion after the Service ends. At the Customer's choice, we will return Personal Data in a reasonably usable format or delete it, and delete remaining copies unless law requires retention. Request export before closing the workspace; an immediate deletion instruction can remove the opportunity to export.
On a verified instruction following termination, we will arrange the return or deletion of active-service Personal Data within 30 days unless a shorter legal deadline applies or the Customer agrees a different timetable. Without a choice from the Customer we will contact its authorised administrator to arrange deletion, rather than treat an expired subscription as permission to retain data indefinitely.
Routine backup copies age out on the current 14-day rolling schedule. Separately held migration, deployment and incident-recovery copies require an operator deletion action; we will include them in the closure process and remove them within 90 days of the verified deletion instruction, unless legally required retention applies. During that period copies are isolated from ordinary use, used only for recovery or compliance, and deletion instructions must be reapplied after any restoration. We will confirm completion on request and explain any legally required exception.
Necessary records for which we independently act as controller, such as accounting and proportionate security records, follow the Privacy notice and applicable law rather than being reused as Customer knowledge.
Schedule A — Processing details
| Subject matter | Provision of a company knowledge and AI question-answering service for the Customer's workspace. |
|---|---|
| Duration and frequency | On an ongoing or on-demand basis during the agreement, followed by authorised return/deletion and restricted backup retention described above. |
| Operations and purposes | Receipt, storage, malware scanning, extraction, analysis, indexing, retrieval, generation of replies, permission checks, communication, export, support, security monitoring, backup and deletion for the Service. |
| People | Customer personnel, contractors, authorised users, business contacts, and individuals whose information the Customer lawfully includes in approved company knowledge. Children's data is outside the standard scope. |
| Information | Names, work contact and role details; business-document text and related identifiers; questions, replies and feedback; access, approval and usage records; and other ordinary business personal data submitted within the agreed scope. |
| Restricted categories | Special-category and criminal-offence data, regulated health records and other high-risk or classified information are excluded unless a separate written arrangement defines the lawful instructions and required safeguards before processing. |
| Customer contact and rights | The authorised administrator/account contact identifies the Customer and gives instructions, sets permissions, obtains assistance and exercises the audit and return/deletion rights in this DPA. |
| Processor contact | My Companies AI. Privacy and processing requests: privacy@mycompaniesai.com. Formal contracts: legal@mycompaniesai.com. |
Schedule B — Security measures and deployment limits
- Company isolation and document permissions checked on the server; restricted original/citation access; explicit document approval before answers use the knowledge.
- Individual accounts, password hashing, MFA controls, protected recovery processes and privileged-action checks; service-account and filesystem permissions restrict access.
- Public HTTPS through the network gateway; encrypted external API and outbound mail connections. The Service needs readable content to process requests and is not end-to-end encrypted.
- Upload type/size checks, malware scanning, quarantine/failure handling and restricted publication; rate, concurrency, question and processing-budget controls.
- Audit and operational records, health and worker monitoring, process recovery, daily local backups and restore verification. Backups are currently on the same VM and do not constitute an off-site disaster-recovery guarantee.
- Data minimisation through authorised retrieval and bounded requests. Customer content is not an advertising dataset or a shared-model training dataset operated by us.
Original documents and database content currently lack application-level document encryption. The standard deployment does not promise a dedicated tenant, immutable backups, guaranteed data residency at external providers, zero AI-provider retention, or a particular security certification. The Customer must assess these limits before processing information with heightened requirements. Additional agreed measures must be documented, not assumed from a plan name.
Schedule C and regional requirements
The provider register forms Schedule C. The notice and objection process in section 4 applies to relevant changes.
Where US state privacy law applies to our role as a service provider or processor, we will process Customer Personal Data only for the specified business purposes, will not sell it or share it for cross-context behavioural advertising, and will not retain, use, disclose or combine it outside the direct business relationship except as expressly permitted by that law. We will provide the same level of protection required by that law, notify the Customer if we cannot comply, and allow reasonable steps to verify compliance and stop and remedy unauthorised use.
Where Swiss or other applicable local law requires additional safeguards, the parties will document them before the relevant processing. This DPA is a set of contractual obligations, not a certification of worldwide compliance or a substitute for a necessary local agreement.
You can use your browser's Print or Save as PDF option to keep a copy. For an earlier accepted version, contact legal@mycompaniesai.com.
