Data Processing Agreement
Last updated: 14 June 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between invenios.ai ("Processor", "we") and the customer ("Controller", "you") and applies where we process personal data on your behalf in providing the platform. In this DPA, "personal data", "processing", "controller", "processor", and "data subject" have the meanings given in applicable data protection law, including the UK GDPR and, where applicable, the EU GDPR.
If there is a conflict between this DPA and the Terms of Service on the subject of data protection, this DPA prevails.
1. Roles of the parties
You are the controller (or a processor acting on behalf of a third-party controller) of the personal data processed through the platform. We act as your processor (or sub-processor). Each party will comply with its obligations under applicable data protection law.
2. Scope and instructions
We will process personal data only on your documented instructions, including as set out in this DPA and the Terms, and as necessary to provide and secure the platform, unless required to do otherwise by law (in which case we will inform you where legally permitted). You are responsible for the lawfulness of your instructions and for having a lawful basis for the processing.
3. Details of processing
The details of the processing are set out in Annex 1: the subject matter, duration, nature and purpose of the processing, the types of personal data, and the categories of data subjects.
4. Confidentiality
We will ensure that personnel authorised to process personal data are subject to appropriate confidentiality obligations and are trained in their data protection responsibilities.
5. Security
We will implement and maintain the technical and organisational measures described in Annex 2, appropriate to the risk, to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.
6. Sub-processors
You authorise us to engage sub-processors to process personal data, including those listed in Annex 3. We will impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain responsible for their performance. We will give you reasonable notice of any intended change to our sub-processors and an opportunity to object on reasonable data protection grounds.
7. Assistance to the controller
Taking into account the nature of the processing, we will assist you, by appropriate technical and organisational measures and insofar as possible, to respond to requests from data subjects exercising their rights and to meet your obligations relating to security, breach notification, data protection impact assessments, and prior consultation.
8. Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting personal data we process on your behalf, and will provide information reasonably available to us to help you meet your notification obligations.
9. Return and deletion
On termination of the service, we will, at your choice, delete or return the personal data we process on your behalf and delete existing copies, unless applicable law requires continued storage. We provide a limited period for export as described in our documentation.
10. Audits
We will make available information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, subject to reasonable notice, confidentiality, and frequency limits. We may satisfy this obligation by providing third-party certifications or reports where available.
11. International transfers
Where we transfer personal data outside the UK or EEA, we will ensure an appropriate transfer mechanism is in place, such as the UK International Data Transfer Agreement / Addendum or the EU Standard Contractual Clauses, together with any additional measures required.
12. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service.
Annex 1 — Details of processing
- Subject matter: provision of the invenios.ai platform.
- Duration: for the term of the agreement and any permitted retention period.
- Nature and purpose: hosting, storing, and processing personal data to create, configure, operate, and support AI assistants and related features.
- Types of personal data: account and contact data; usage and log data; and the content of assistant configurations and conversations, which may include any personal data that you or your end users include.
- Categories of data subjects: your personnel and authorised users; and the end users who interact with your assistants.
Annex 2 — Technical and organisational measures
Measures include: encryption of data in transit; access controls and authentication; logical separation (tenant isolation) of customer data; least-privilege access for personnel; logging and monitoring; secure development practices; backup and recovery processes; and an incident response process.
Annex 3 — Authorised sub-processors
- Amazon Web Services — cloud hosting and storage (primarily EU/Ireland).
- Clerk — authentication and identity management.
- Stripe — payment processing.
- AI model providers that you connect to your assistants.
- Email and analytics providers used to operate and improve the service.
For any question about this DPA, contact hello@invenios.ai.