Data Processing Agreement
GDPR Article 28: controller and processor terms.
Last updated:
AM8’s Data Processing Agreement (DPA) forms part of our customer terms and sets out how we process personal data on your behalf as a processor, including security measures, sub-processor management, international transfer safeguards and assistance with data-subject requests.
Our DPA incorporates the EU Standard Contractual Clauses where relevant and references the current sub-processor list.
End of processing (Article 28(3)(g)). On deletion of your account we destroy the personal data we process on your behalf: your workspace record and the operational data under it, every member’s sign-in identity, every credential you stored with us, and the files we generated for you. A defined class of records is retained rather than deleted, because retaining it is a legal obligation under GDPR Article 17(3)(b) and the EU AI Act’s documentation duties: the audit trail, control test results, collected evidence, sign-offs, overrides, incident reports and the record of how each AI-generated verdict was reached. Control test results are kept 7 years; collected evidence 10. Those records are kept; the people named in them are not. Erasure removes the acting person’s identifier from every retained record that carried it, and destroys the key behind the pseudonym used in AI-decision records, which makes that pseudonym permanently unresolvable, by us included. The record survives intact: it still shows what happened and when, and no longer shows by whom.
Return or delete, at your choice (Article 28(3)(g)). When you close your account you may choose to have all personal data returned to you before any of it is destroyed. The complete export is delivered as part of the same closure request, so there is no separate step to remember and no window in which your account is gone and your data has not arrived. The export carries its own completeness statement, naming anything it could not include, so you can verify what you received rather than take our word for it. If we cannot return all of it, the deletion does not proceed and your account is left exactly as it was. The retained compliance evidence described above is unaffected by this choice: it is returned to you in the export, and it is also kept by us, because keeping it is a legal obligation rather than a preference.
If you stop paying rather than closing your account. Closing your account destroys your data straight away, and you may take the export first as described above. A lapsed subscription is different: we keep your workspace readable for 12 months from the end of your subscription, so that a billing failure or a lapsed renewal never costs you your compliance history. Before anything is deleted we email your workspace owners and administrators, and deletion happens only once that warning has been on the record for a further 30 days. You can export at any point in that window, and you can ask us to delete sooner.
Sub-processor changes (Article 28(2)). We give you at least 30 days’ notice by email, to your workspace owners and administrators, before we add a sub-processor or change what an existing one does. You may object during that period, and we will discuss it with you before the change takes effect. Removing a sub-processor happens as soon as we can do it and carries no notice period, because it narrows rather than widens who processes your data. Notices are also published on our sub-processor page, which is a second channel rather than the primary one: the email is the notice.
Your AI assistant instructions (ARIA). ARIA accepts free text. Whatever your users type into it, you instruct us to process on your behalf, for the purpose of answering them. We do not inspect, classify or filter that text before processing it, and we do not screen it for special categories of personal data under Article 9 or criminal-offence data under Article 10. You should therefore treat ARIA as a general-purpose free-text field and instruct your users accordingly: it is not an appropriate place for health data, biometric data, data revealing racial or ethnic origin, political opinions, religious beliefs or trade union membership, or details of criminal offences, and it is not an appropriate place for personal data about people outside your organisation. Conversations are processed by Anthropic as our sub-processor under Standard Contractual Clauses, are retained under the periods set out in our privacy notice, and are included in your export.
To request a countersigned copy of the DPA, contact privacy@am8-ai-governance.tech.