Data Processing Agreement
GDPR Article 28: controller and processor terms.
Last updated:
AM8’s Data Processing Agreement (DPA) forms part of our customer terms and sets out how we process personal data on your behalf as a processor, including security measures, sub-processor management, international transfer safeguards and assistance with data-subject requests.
Our DPA incorporates the EU Standard Contractual Clauses where relevant and references the current sub-processor list.
End of processing (Article 28(3)(g)). On deletion of your account we destroy the personal data we process on your behalf: your workspace record and the operational data under it, every member’s sign-in identity, every credential you stored with us, and the files we generated for you. A defined class of records is retained rather than deleted, because retaining it is a legal obligation under GDPR Article 17(3)(b) and the EU AI Act’s documentation duties: the audit trail, control test results, collected evidence, sign-offs, overrides, incident reports and the record of how each AI-generated verdict was reached. Control test results are kept 7 years; collected evidence 10. Those records are kept; the people named in them are not. Erasure removes the acting person’s identifier from every retained record that carried it, and destroys the key behind the pseudonym used in AI-decision records, which makes that pseudonym permanently unresolvable, by us included. The record survives intact: it still shows what happened and when, and no longer shows by whom.
Your AI assistant instructions (ARIA). ARIA accepts free text. Whatever your users type into it, you instruct us to process on your behalf, for the purpose of answering them. We do not inspect, classify or filter that text before processing it, and we do not screen it for special categories of personal data under Article 9 or criminal-offence data under Article 10. You should therefore treat ARIA as a general-purpose free-text field and instruct your users accordingly: it is not an appropriate place for health data, biometric data, data revealing racial or ethnic origin, political opinions, religious beliefs or trade union membership, or details of criminal offences, and it is not an appropriate place for personal data about people outside your organisation. Conversations are processed by Anthropic as our sub-processor under Standard Contractual Clauses, are retained under the periods set out in our privacy notice, and are included in your export.
To request a countersigned copy of the DPA, contact privacy@am8-ai-governance.tech.