| Document field | Value |
|---|---|
| Version | 1.0 |
| Effective date | 27 August 2026 |
| Canonical URL | https://trust.asailabs.com/dpa |
| Processor | ASAI LABS POLAND SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ |
This Data Processing Agreement, including its Schedules (the DPA), forms part of the agreement governing the Customer's use of the ASAI Labs Services (the Customer Agreement).
1. Electronic acceptance and parties
1.1 ASAI. The service provider and Processor is ASAI LABS POLAND SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, with its registered office at ul. Złota 7, lok. 28, 00-019 Warszawa, Poland, KRS 0001236627 (ASAI).
1.2 Customer. The Customer is the legal entity identified as the customer or Organization in the applicable order, account registration, or Customer Agreement. If no legal entity is identified, the Customer is the person who accepts this DPA and controls the relevant ASAI account.
1.3 Acceptance. ASAI shall make the current DPA available through a clear link presented with the acceptance control before acceptance. By clicking “Accept Data Processing Agreement”, “I accept”, or an equivalent affirmative control during onboarding or account administration, the person accepting this DPA:
- confirms that they are authorized to bind the Customer;
- accepts this DPA for and on behalf of the Customer; and
- instructs ASAI to Process Customer Personal Data as described in this DPA.
If the person does not have authority to bind the Customer, they must not accept this DPA or submit Personal Data to the Services on the Customer's behalf.
1.4 Effective date and record. This DPA becomes binding when the Customer's authorized representative accepts the version presented in the Services. No handwritten or separate electronic signature is required. ASAI shall retain an electronic record of the Customer account, accepting user, acceptance time, acceptance method, and accepted DPA version and shall make a copy of the accepted version available to the Customer on reasonable request. Article 28(9) GDPR expressly permits a controller-processor contract to be in electronic form.
1.5 Priority. If this DPA conflicts with the Customer Agreement concerning the protection of Customer Personal Data, this DPA prevails. The Customer Agreement otherwise remains in force.
2. Definitions
2.1 Applicable Data Protection Law means Regulation (EU) 2016/679 (the GDPR) and binding EU or EEA Member State data-protection law applicable to the Processing under this DPA.
2.2 Controller, Data Subject, Personal Data, Personal Data Breach, Processing, and Processor have the meanings given in Articles 4(1), 4(2), 4(7), 4(8), and 4(12) GDPR.
2.3 Customer Personal Data means Personal Data that ASAI Processes on behalf of the Customer through the Services, as described in Schedule 1.
2.4 Services means the hosted applications, APIs, workflows, storage, notification features, image processing, reporting, support, and related services ASAI provides under the Customer Agreement.
2.5 Subprocessor means another Processor engaged by ASAI to Process Customer Personal Data on the Customer's behalf (Article 28(2) and (4) GDPR).
2.6 Restricted Transfer means a transfer of Customer Personal Data, including remote access, to a country outside the EEA that requires a safeguard under Chapter V GDPR.
3. Roles and scope
3.1 The Customer is the Controller and ASAI is the Processor for Customer Personal Data (Article 4(7) and (8) GDPR). If the Customer Processes Customer Personal Data on behalf of another Controller, the Customer is a Processor and ASAI is its Subprocessor; the Customer confirms that the relevant Controller has authorized ASAI's appointment and the instructions in this DPA (Article 28(2) and (4) GDPR).
3.2 This DPA applies only to Customer Personal Data. ASAI acts as a separate Controller for limited account administration, authentication, direct support, service security, fraud prevention, legal-compliance, and privacy-case records where ASAI determines the purposes and means (Article 4(7) GDPR). Those activities are governed by ASAI's applicable privacy notice and are not Customer instructions under this DPA.
3.3 ASAI shall not reclassify the Customer's operational content as separate-Controller data merely because ASAI can technically access that content while providing, securing, or supporting the Services.
3.4 The Customer is responsible for:
- the lawfulness, fairness, and transparency of its Processing;
- giving required notices to Data Subjects;
- ensuring that Customer Personal Data is adequate, relevant, accurate, and limited to what is necessary; and
- identifying a lawful basis under Article 6 GDPR and, where applicable, a condition under Article 9(2) GDPR,
in accordance with Articles 5(1), 6, 9, 12–14, and 24 GDPR. ASAI does not select or warrant the Customer's lawful basis.
4. Documented instructions and purpose limitation
4.1 The Customer instructs ASAI to Process Customer Personal Data only to provide, secure, support, and delete the Services as described in the Customer Agreement, this DPA, the Customer's authorized configuration and use of the Services, and additional written instructions accepted by ASAI.
4.2 ASAI shall Process Customer Personal Data only on the Customer's documented instructions, including instructions concerning Restricted Transfers, unless Union or Member State law requires Processing. If legally permitted, ASAI shall inform the Customer of that legal requirement before Processing (Article 28(3)(a) GDPR).
4.3 ASAI shall immediately inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law. ASAI may suspend only the affected instruction while the parties resolve the issue (Article 28(3), final subparagraph, GDPR).
4.4 The Customer's instructions do not authorize ASAI to:
- sell Customer Personal Data or use it for advertising or unrelated marketing profiling;
- perform face recognition, unique identification, face matching, biometric templates, or sensitive-trait inference from Protocol Images;
- train ASAI's or a third party's general-purpose AI model on Customer Personal Data;
- use exact submission Location for background tracking, advertising, or unrelated worker profiling; or
- disclose Customer Personal Data to an unlisted recipient except where required by law and handled under Section 13.
4.5 If ASAI determines the purposes and means of Processing contrary to the Customer's instructions, ASAI shall be treated as a Controller for that Processing to the extent required by Article 28(10) GDPR.
4.6 If ASAI becomes aware that Customer Personal Data is inaccurate or outdated, ASAI shall inform the Customer without undue delay so the Customer can apply Articles 5(1)(d), 16, and 19 GDPR.
5. Confidentiality and authorized personnel
5.1 ASAI shall limit access to Customer Personal Data to personnel who need access to provide or secure the Services and shall apply least-privilege access appropriate to their responsibilities (Articles 28(3)(b), 29, and 32(4) GDPR).
5.2 ASAI shall ensure that authorized personnel are bound by contractual or statutory confidentiality obligations, receive appropriate data-protection and security instructions, and Process Customer Personal Data only as directed unless law requires otherwise (Articles 28(3)(b) and 29 GDPR).
5.3 Confidentiality obligations continue after access ends and after termination of the Customer Agreement.
6. Security of Processing
6.1 Taking account of the state of the art, implementation costs, the nature, scope, context, and purposes of Processing, and the risks to Data Subjects, ASAI shall maintain the technical and organisational measures in Schedule 2 to provide security appropriate to risk (Articles 28(3)(c) and 32 GDPR).
6.2 ASAI may update the measures to reflect technical development, risk, and service changes, provided that an update does not materially reduce the overall protection of Customer Personal Data during the term.
6.3 On reasonable request, ASAI shall provide information necessary for the Customer to assess the measures. ASAI may protect other customers' data, privileged material, confidential information, and security-sensitive details.
7. Subprocessors
7.1 By accepting this DPA, the Customer gives general written authorization for ASAI to use the Subprocessors listed in Schedule 3A for the purposes stated there (Article 28(2) GDPR).
7.2 ASAI shall give the Customer at least 30 calendar days' notice before adding or replacing a Subprocessor that will Process Customer Personal Data. ASAI may give notice through the Services or to the Customer's account or privacy contact. The notice shall identify the provider, service, data involved, Processing location where known, and applicable transfer mechanism.
7.3 The Customer may object within 15 calendar days after notice on reasonable, documented data-protection grounds by emailing [email protected]. The parties shall work in good faith on a reasonable alternative. If no alternative is available, the Customer may stop the affected feature or terminate the affected part of the Services without requiring ASAI to stop unrelated Processing.
7.4 Before a Subprocessor Processes Customer Personal Data, ASAI shall bind it by written terms imposing materially the same data-protection obligations that apply to ASAI under this DPA, including confidentiality, security, assistance, deletion, audit information, breach notification, and transfer safeguards (Article 28(3)(d) and (4) GDPR).
7.5 ASAI remains fully liable to the Customer for a Subprocessor's performance of its data-protection obligations to the extent required by Article 28(4) GDPR.
7.6 On reasonable request, ASAI shall provide a copy of the relevant data-protection terms binding a Subprocessor. ASAI may redact commercial terms and confidential information that is not necessary to demonstrate compliance with Article 28(4) GDPR.
7.7 Schedule 3B identifies downstream recipients that may not act as Subprocessors, such as browser-selected push services or user-directed navigation services. Their classification does not remove either party's transparency, minimisation, security, or Chapter V obligations.
8. Data Subject rights and compliance assistance
8.1 Taking account of the nature of Processing, ASAI shall assist the Customer through appropriate technical and organisational measures, insofar as possible, to respond to requests under Articles 12–22 GDPR (Article 28(3)(e) GDPR).
8.2 If ASAI receives a request from a Data Subject concerning Customer Personal Data, ASAI shall promptly forward it to the Customer's account or privacy contact and shall not respond substantively unless instructed by the Customer or required by law.
8.3 Taking account of the nature of Processing and the information available to ASAI, ASAI shall reasonably assist the Customer with:
- security assessments under Article 32 GDPR;
- Personal Data Breach investigation and notifications under Articles 33–34 GDPR;
- data protection impact assessments under Article 35 GDPR;
- prior consultation under Article 36 GDPR; and
- information needed for the Customer's records of processing under Article 30(1) GDPR,
as required by Article 28(3)(f) GDPR.
8.4 ASAI shall maintain the records required of a Processor by Article 30(2) GDPR and cooperate with competent supervisory authorities in accordance with Article 31 GDPR.
8.5 Assistance available through ordinary service functionality is included in the Services. ASAI may charge reasonable, documented costs for exceptional assistance caused by the Customer's instructions unless the assistance is required because ASAI breached this DPA.
9. Personal Data Breaches
9.1 ASAI shall notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data (Article 33(2) GDPR). ASAI shall send notice to the Organization owner, designated account contact, or privacy contact recorded in the Services.
9.2 As information becomes available, the notice shall include information reasonably needed for the Customer's Article 33(3) and Article 34 assessments, including:
- the nature of the breach and affected data and Data Subject categories;
- the approximate scale, where known;
- likely consequences;
- containment, investigation, and remediation measures; and
- ASAI's incident contact.
9.3 ASAI may provide information in phases and shall keep the Customer informed of material developments. Notification is not an admission of fault or liability.
9.4 ASAI shall document relevant facts, effects, and remedial action and provide the information reasonably needed for the Customer to meet Article 33(5) GDPR, as part of the assistance required by Article 28(3)(f) GDPR.
10. International transfers
10.1 ASAI shall not make a Restricted Transfer unless it is documented in Schedule 3, otherwise authorized by the Customer, or required by law, and a valid Chapter V mechanism is in place (Articles 44–49 GDPR).
10.2 Depending on the destination and recipient, the mechanism may include an adequacy decision under Article 45 GDPR or appropriate safeguards under Article 46 GDPR. Where required, ASAI shall use the applicable module of the 2021 EU Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914.
10.3 The Customer authorizes ASAI, acting as data exporter in its own capacity where applicable, to enter into the appropriate 2021 EU Standard Contractual Clauses with a Subprocessor. ASAI shall assess transfer circumstances and implement supplementary measures where necessary to provide the protection required by Articles 44–46 GDPR.
10.4 Remote access from a third country is treated as a transfer for this Section. ASAI shall record relevant support and Subprocessor access countries in its vendor and transfer records.
10.5 If a transfer mechanism becomes invalid or ineffective, ASAI shall inform the Customer and suspend the affected transfer or implement a lawful alternative. Where reasonably possible, unrelated EEA Processing shall remain available.
10.6 This DPA is drafted for the EU/EEA GDPR. A Customer that requires a United Kingdom, Swiss, or other jurisdiction-specific transfer addendum should contact [email protected] before submitting data subject to that regime.
11. Return and deletion
11.1 ASAI shall retain Customer Personal Data only for the duration and purposes in Schedule 1 and delete or return it as described in Schedule 4, subject to a shorter documented Customer instruction and any Union or Member State law requiring retention (Articles 5(1)(e), 17, and 28(3)(g) GDPR).
11.2 During the term, the Customer may use available service functionality or contact [email protected] to request an export, correction, restriction, or deletion.
11.3 After termination, ASAI shall make a standard export available for 30 days where the Services support export, then delete active production copies within 30 days after the export period ends. If the Customer instructs ASAI to delete without return, ASAI shall begin deletion without an additional export period.
11.4 Where immediate removal from a protected backup is not technically feasible, ASAI shall isolate the data from ordinary use, retain it only for recovery, prevent access except where recovery is necessary, and reapply deletion records after any restore before returning the restored system to ordinary use. Protected recovery copies shall expire within the period in Schedule 4.
11.5 On reasonable request, ASAI shall provide written confirmation that deletion required by this Section has been completed. Any legal hold must be documented, limited to specified records and purposes, access-restricted, and released when its legal basis expires.
12. Information and audits
12.1 ASAI shall make available information reasonably necessary to demonstrate compliance with Article 28 GDPR and this DPA, including relevant policies, architecture descriptions, test evidence, Subprocessor information, and independent assurance reports if available (Article 28(3)(h) GDPR).
12.2 The Customer may conduct one audit in any 12-month period on at least 30 days' written notice. The parties shall use a proportionate sequence: existing documentation and remote review first, followed by a scoped inspection only where the earlier evidence is insufficient.
12.3 The frequency and notice limits do not apply following a material Personal Data Breach, where evidence gives reasonable grounds to suspect material non-compliance, or where a competent supervisory authority requires an audit.
12.4 Audits shall occur during normal business hours, minimize disruption, comply with reasonable security and confidentiality rules, and avoid access to other customers' data. The Customer bears its audit costs unless the audit identifies ASAI's material breach of this DPA.
12.5 ASAI shall cooperate with audits and inspections by the Customer or an auditor mandated by the Customer as required by Article 28(3)(h) GDPR. An auditor must be independent, qualified, non-competitive with ASAI, and bound by confidentiality.
13. Government and legal requests
13.1 Unless prohibited by law, ASAI shall notify the Customer before disclosing Customer Personal Data in response to a binding government or law-enforcement demand.
13.2 ASAI shall review the lawfulness and scope of the demand, challenge it where there are reasonable grounds, seek confidential treatment, and disclose only the minimum data legally required. These measures support Articles 5(1)(a) and (c), 32, and 44–49 GDPR.
14. Liability
14.1 Liability between ASAI and the Customer is governed by the Customer Agreement, subject to Article 82 GDPR and any rule of Applicable Data Protection Law that cannot lawfully be limited.
14.2 Nothing in this DPA excludes or limits a Data Subject's statutory rights, a supervisory authority's powers, or either party's direct statutory liability.
15. Term, non-compliance, and termination
15.1 This DPA remains in force while ASAI Processes Customer Personal Data.
15.2 ASAI shall inform the Customer if ASAI cannot comply with this DPA. If ASAI materially or persistently breaches this DPA, the Customer may instruct ASAI to suspend the affected Processing until compliance is restored or terminate the affected Services. Suspension should be limited to the affected Processing where lawful and reasonably possible.
15.3 If the Customer insists on an instruction after ASAI has informed it under Section 4.3 that the instruction infringes Applicable Data Protection Law, ASAI may terminate the affected Processing on written notice.
15.4 Confidentiality, deletion, audit, transfer, and liability provisions survive until Customer Personal Data has been deleted or returned as required.
16. Notices and contact
16.1 The Customer's operational privacy and incident contact is the Organization owner, account contact, or other privacy contact designated in the Services. The Customer is responsible for keeping that contact current.
16.2 Notices to ASAI concerning this DPA, Data Subject requests, Subprocessor objections, or security incidents must be sent to [email protected].
16.3 Contractual notices otherwise follow the Customer Agreement.
17. Online publication, versions, and changes
17.1 The canonical DPA is published at https://trust.asailabs.com/dpa. ASAI shall identify the version and effective date at the top of the document and retain prior versions for compliance evidence.
17.2 ASAI may make non-material updates to reflect legal terminology, contact details, service descriptions, or improved technical and organisational measures. A non-material update must not materially reduce Customer Personal Data protection and becomes effective when published.
17.3 ASAI shall give at least 30 days' notice of a material DPA change through the Services or to the Customer's account contact. ASAI shall require the Customer to click-accept a materially changed DPA before that version binds the Customer, unless an earlier change is required by law. The previously accepted version continues to govern until the replacement becomes effective or the affected Services terminate.
17.4 Subprocessor changes are governed by Section 7 and do not require separate re-acceptance where ASAI follows the notice and objection procedure.
18. General terms
18.1 This DPA, the Customer Agreement, and documented instructions accepted by ASAI comprise the parties' agreement concerning ASAI's Processing of Customer Personal Data. Customer purchase-order or portal terms do not amend this DPA unless ASAI expressly accepts them in writing.
18.2 If a provision is invalid or unenforceable, it shall be interpreted or replaced to preserve its lawful purpose as closely as possible without reducing Data Subject protections. The remaining provisions continue in effect.
18.3 The governing law and forum in the Customer Agreement apply. If the Customer Agreement does not specify them, Polish law applies and the competent courts in Warsaw, Poland have jurisdiction, without limiting rights and powers granted to Data Subjects and supervisory authorities by the GDPR.
18.4 The English version controls if ASAI publishes a convenience translation.
Schedule 1 — Details of Processing
A. Parties
| Party | Details |
|---|---|
| Customer | The person or legal entity identified in the Customer Agreement, applicable order, or ASAI account and bound through the electronic acceptance described in Section 1. |
| Customer role | Controller, or Processor acting for another Controller, as described in Section 3.1. |
| Customer contact | Organization owner, account contact, or privacy contact designated in the Services. |
| ASAI | ASAI LABS POLAND SPÓŁKA Z OGRANICZONĄ ODPOWIEDZIALNOŚCIĄ, ul. Złota 7, lok. 28, 00-019 Warszawa, Poland, KRS 0001236627. |
| ASAI role | Processor, or Subprocessor where the Customer is a Processor, except for the separate-Controller activities in Section 3.2. |
| ASAI contact | [email protected] |
| ASAI supervisory authority | Prezes Urzędu Ochrony Danych Osobowych (UODO), Poland. |
B. Processing description
| Article 28 element | Description |
|---|---|
| Subject matter | Hosting, operation, security, support, and deletion of the Customer's ASAI Labs environment and customer-directed workflows. |
| Duration | The term of the Customer Agreement plus the export, deletion, protected recovery, and lawful legal-hold periods in Section 11 and Schedule 4. |
| Nature and operations | Receive, collect, validate, sanitize, transmit, store, structure, organize, retrieve, query, display, compare, calculate distance, schedule, notify, blur faces, generate advisory analysis, support human review, log authorized actions, export, restrict, erase, and destroy. These are Processing operations under Article 4(2) GDPR. |
| Purposes | Administer customer Organizations, locations, Stores, Store Contacts, users, regions, schedules, inspections or Protocols; request and receive submissions; sanitize and blur submitted images; verify submission proximity; present authorized maps and evidence; provide human-reviewed operational analytics; deliver customer-configured email, SMS, and Web Push notifications; provide integrations and APIs; preserve proportionate customer accountability; secure the Services; and comply with documented rights and deletion instructions. |
| Frequency | Continuous while the Services are active, including scheduled workflows and event-driven submissions, analysis, and notifications. |
| Geographic scope | Primary application storage is configured in the EEA. Approved Subprocessors and downstream recipients may Process data outside the EEA as described in Schedule 3 and Section 10. |
| Instructions | The Customer Agreement, this DPA, authorized service configuration and use, requests submitted through the Services, and additional written instructions accepted by ASAI. |
| Lawful basis | Determined and documented by the Customer under Article 6 GDPR and, where applicable, Article 9(2) GDPR. |
C. Categories of Data Subjects
- Customer personnel, account users, administrators, managers, reviewers, and integration users.
- Store Contacts and other people responsible for a location, Store, inspection, Protocol, or submission.
- Store workers, managers, and other personnel whose actions or Location evidence relate to a customer workflow.
- People incidentally captured in submitted images, including workers, customers, bystanders, and potentially children.
- Recipients of customer-directed email, SMS, or Web Push notifications.
- Other people whose Personal Data the Customer chooses to submit within the documented scope of the Services.
D. Categories of Customer Personal Data
- Identity and business contact data: name, role, email address, telephone number, Organization or Store association, region, and communication preferences.
- Customer location and configuration data capable of relating to people: Store or site name, address, coordinates, opening times, external identifiers, schedules, assignments, and operating settings.
- Workflow and submission data: identifiers, associations, status, timestamps, comments, failure details, and submission history.
- Images and derivative data: raw and sanitized image content, blurred images, object identifiers, annotations, comments, hashes, quality flags, operational estimates, confidence intervals, human review decisions, and reviewer identifiers.
- Location evidence: configured site coordinates; submission latitude and longitude; capture time; calculated distance; and proximity or suspicious-location result.
- Notification data: recipient address or number, push endpoint and keys, message variables and links, delivery status, provider identifiers, error categories, opt-in or revocation state, and timestamps.
- Customer operational audit data: actor and entity identifiers, action, outcome, approved changed values, timestamps, and accountability metadata.
- Online and device data used for customer-directed accountability: IP address, user agent or browser class, session and credential metadata, pseudonymous identifiers, and access timestamps.
- Integration data: external identifiers, import provenance, API credential metadata, and data supplied through customer-directed integrations or APIs.
E. Special-category, biometric, and children's data
The Services do not intentionally require special-category data under Article 9(1) GDPR or biometric data processed for unique identification under Article 4(14) GDPR. An image may nevertheless incidentally reveal characteristics such as apparent racial or ethnic origin, religion, health, disability, or union activity and may incidentally depict children. Face detection is used only to blur faces; ASAI does not perform recognition, matching, identification, embeddings, sensitive inference, training, or reuse.
The Customer must avoid intentional collection of Article 9 data unless the applicable Service expressly supports it and ASAI has accepted a written instruction covering an Article 9(2) condition, appropriate safeguards, and any required DPIA under Article 35 GDPR. ASAI may reject or suspend unsupported high-risk Processing.
Schedule 2 — Technical and Organisational Measures
1. Governance and access management
- Named operational privacy and security owners and a defined escalation contact.
- Access limited to authorized personnel with a business need and confidentiality obligations (Articles 28(3)(b), 29, and 32(4) GDPR).
- Role-based application access, including region-scoped permissions where supported.
- Organization context resolved per request and enforced in application queries; a session is rejected when its Organization does not match the requested Organization.
- Customer API keys generated using cryptographically secure randomness, stored as hashes, shown only when created, and revocable.
2. Authentication and credential protection
- Administrator passwords stored using bcrypt hashes; plaintext passwords are not stored.
- Session secrets and enrollment tokens stored as hashes; session tokens use cryptographically secure random values and expire or may be revoked.
- Secure production cookie settings and Organization-aware session scope.
- Authenticated and rate-limited API traffic, including a separate limit for write requests.
- Runtime secrets kept in restricted secret stores; plaintext environment and infrastructure operator files excluded from version control and tracked shared configuration encrypted.
3. Transmission and storage security
- HTTPS/TLS for production application and API interfaces and encrypted provider connections where supported.
- Provider-managed encryption controls for managed storage and database infrastructure.
- Primary Protocol Image storage configured in Cloudflare R2's EU jurisdiction and Eastern Europe location.
- Primary application database configured in Neon's Frankfurt AWS region.
- Storage credentials and internal service tokens restricted to the services that require them.
4. Organization isolation and minimisation
- Customer records scoped by Organization in the backend and integration APIs, with automated tests covering cross-Organization access paths.
- Procedure-specific audit allowlists and secret-field redaction. Audit records exclude passwords, login codes, tokens, API keys, signed URLs, raw image bytes, message bodies, whole request payloads, provider response bodies, and push secrets.
- Templated, low-cardinality, payload-free external telemetry that excludes direct contact details, submission links, image keys, exact coordinates, request bodies, and provider credentials.
- No product analytics, advertising, or marketing profiling of Customer Personal Data without a separately assessed and documented purpose.
5. Image, AI, and Location controls
- Image size, declared content type, and magic-byte validation before storage.
- Authenticated image sanitization through decoding and re-encoding, removing embedded non-image content and ordinarily stripping EXIF and other metadata.
- Application-level checks that prevent pending, failed, or sanitized-but-unblurred images from being displayed. Display routes verify the face-blurred marker and use private caching and security headers.
- Bounded, blurred previews for advisory fill-rate analysis; AI Gateway payload logging disabled; results remain review-required and may be confirmed, corrected, or rejected by a human.
- No face recognition, unique identification, matching, embeddings, sensitive inference, general-model training, or secondary image reuse.
- Exact Location collected only when a user initiates a submission and only for proximity verification, authorized review, maps, and proportionate dispute evidence. No background tracking or marketing reuse.
- Temporary browser Location persistence scoped to the relevant workflow: a local fallback expires after no more than two hours, and a session copy ends with the browser session.
6. Availability, monitoring, and recovery
- Structured customer operational audit records and payload-free server and workflow observability.
- Bounded retries and dead-letter queues for image and AI workflows; a failed processing path does not authorize display of an unblurred image.
- Time-bounded database recovery history and pre-deploy snapshots.
- Deletion records reapplied after a backup restore before restored data returns to ordinary use.
- Scoped, approved, access-restricted, and time-bounded legal holds.
7. Secure development and assurance
- Version-controlled changes with automated linting, type checking, unit tests, integration tests, and routed-flow tests proportionate to risk.
- Regression coverage for Organization isolation, audit redaction, private-before-blur application delivery, upload rejection, and payload-free telemetry.
- Controlled deployment and encrypted secret workflows.
- Review of measures and risks when a new purpose, data category, vendor, country, monitoring feature, AI use, material scale increase, or material incident occurs (Articles 24(1), 25(1), and 32(1)(d) GDPR).
Schedule 3 — Subprocessors and Downstream Recipients
The list below is the authorized Subprocessor list for this DPA version. A provider name includes the relevant contracting entity or affiliate used under ASAI's provider account. ASAI will identify additional or replacement providers through the notice procedure in Section 7.
A. Authorized Subprocessors
| Provider | Service and purpose | Customer Personal Data | Primary location and transfer treatment |
|---|---|---|---|
| Cloudflare, Inc. | Pages, Workers, Containers, Durable Objects, R2, Queues, Images, Workers AI, and AI Gateway for application delivery, compute, storage, image processing, security, and advisory inference. | Potentially all Schedule 1 categories. | Primary configured storage in the EEA; approved global support and Subprocessors under Cloudflare's DPA, adequacy decisions, or 2021 EU SCCs as applicable. |
| Neon | Managed PostgreSQL, recovery history, snapshots, and authorized support. | Database categories in Schedule 1; no raw image bytes. | Primary database in AWS Europe (Frankfurt); approved remote support and Subprocessors under adequacy decisions or Article 46 safeguards as applicable. |
| Inngest | Workflow events, runs, step outputs, retries, scheduling, and workflow observability. | Workflow identifiers and state; step outputs may include Store, workflow, image-key, notification, and operational metadata. | United States-hosted service and approved Subprocessors; 2021 EU SCCs and supplementary measures where required. |
| Plus Five Five, Inc. (Resend) | Customer-directed transactional email and delivery state. | Recipient email address, Store or location title, workflow link, locale, schedule time, and delivery metadata. | United States and approved Subprocessors; adequacy or 2021 EU SCCs and supplementary measures where required. |
| Twilio | Customer-directed SMS and delivery state. | Recipient telephone number, workflow link, message content, delivery identifier, status, and error category. | Global communications infrastructure and approved Subprocessors; Twilio transfer safeguards, BCRs, adequacy, or 2021 EU SCCs as applicable. |
B. Downstream recipients not necessarily acting as Subprocessors
| Recipient or category | Limited disclosure and condition |
|---|---|
| Browser-selected Web Push provider, such as Apple, Google, or Mozilla | Encrypted push payload, endpoint, delivery metadata, and network data only after affirmative user subscription; revoked following opt-out or invalid endpoint. |
| OpenStreetMap tile infrastructure | Browser IP address, request metadata, and map-tile coordinates for an authorized map. Exact submission coordinates are not sent as a geocoding query. |
| Nominatim/OpenStreetMap geocoding | User-entered Store or site address and request metadata for address geocoding, not exact submission Location. |
| Google Maps | Coordinates disclosed only when an authorized user deliberately follows a labeled external navigation link; no hidden request before the click. |
| Telecommunications carriers | Destination number, routing data, message content, and delivery data necessary to deliver a customer-enabled SMS. |
Schedule 4 — Return and Deletion Timetable
| Stage or data copy | Default period and action |
|---|---|
| Active Services | Customer Personal Data is retained while needed for the Customer's configured service purposes and documented instructions. Customer-controlled deletion functions and accepted written instructions apply during the term. |
| Post-termination export | Where supported, a standard export remains available for 30 days after termination unless the Customer requests immediate deletion. |
| Active production deletion | ASAI deletes active production copies within 30 days after the export period ends, or within 30 days after an accepted delete-without-return instruction. |
| Protected recovery copies | Recovery copies expire within 90 days after active production deletion and remain isolated from ordinary use. Deletion records are reapplied after any restore. |
| Subprocessor copies | ASAI propagates applicable deletion instructions according to the provider contract and service capabilities. |
| Legal hold | Only identified records subject to a documented legal requirement are retained for the required period, access-restricted, and deleted when the legal basis expires. |
Legal References
- Regulation (EU) 2016/679 (GDPR), including Article 28
- Commission Implementing Decision (EU) 2021/915 — controller-to-processor standard contractual clauses
- Commission Implementing Decision (EU) 2021/914 — international-transfer standard contractual clauses
- EDPB Guidelines 07/2020 on Controller and Processor concepts