legal for your compliance team
Data Processing Addendum
last updated May 12, 2026 · effective June 11, 2026 · definable ai technologies pvt. ltd., gurugram, india
This DPA governs how Definable processes personal data on behalf of customers. It is incorporated into our Terms of Service and applies automatically — accepting the Terms is deemed execution of this DPA, no signature required. If your procurement process needs a countersigned copy, email [email protected] and we will return one within two business days.
01 Definitions and roles
in short You are the controller of your workspace data; Definable is the processor. Definitions track GDPR and the DPDP Act.
“Customer Data” means personal data that Customer or its users submit to the Services — prompts, files, knowledge bases, workflow inputs and outputs, and data from integrations Customer connects. “Data Protection Laws” means all laws applicable to the processing of Customer Data, including the EU and UK GDPR, the Digital Personal Data Protection Act, 2023 (India), and US state privacy laws. “Subprocessor” means a third party engaged by Definable to process Customer Data.
For Customer Data, Customer is the controller (or data fiduciary, or a processor acting for another controller) and determines the purposes and means of processing; Definable is the processor (or data processor) acting on Customer’s behalf. For data about Customer’s account and billing relationship, Definable is an independent controller, and our Privacy Policy governs. Under the CCPA, Definable is a “service provider” and does not sell or share Customer Data, retain it except as permitted, or combine it with other data except to provide the Services.
02 Scope of processing
in short We process your data only on your documented instructions — the Terms, your configuration, and your use of the product.
Definable will process Customer Data only in accordance with Customer’s documented, lawful instructions, which consist of: the Agreement (Terms of Service and any order form), this DPA, Customer’s configuration of the Services (including integrations enabled and agent permissions granted), and Customer’s use of the Services’ features. Additional instructions require mutual written agreement.
If Definable becomes aware or believes that an instruction violates Data Protection Laws, we will notify Customer and may suspend the affected processing until the instruction is confirmed or modified. Definable will not process Customer Data for its own purposes, will never use Customer Data to train AI models, and will not permit its Subprocessors to do so.
Details of processing — subject matter, duration, nature, categories of data subjects and personal data — are set out in Annex 1.
03 Subprocessors
in short You authorise the vendors in Annex 3. We give 30 days’ notice before adding one; you can object, and termination is the remedy if we can’t resolve it.
Customer provides general authorisation for Definable to engage the Subprocessors listed in Annex 3. Each Subprocessor is bound by a written agreement imposing data protection obligations no less protective than this DPA, and Definable remains fully liable for its Subprocessors’ performance.
We will give Customer at least 30 days’ notice before adding or replacing a Subprocessor (by email to workspace owners and by updating Annex 3). Customer may object on reasonable data-protection grounds within 30 days of notice; the parties will work in good faith to resolve the objection (for example by region pinning or feature configuration), and if no resolution is possible, Customer may terminate the affected Services and receive a pro-rated refund of prepaid, unused fees.
04 Security
in short Audited technical and organisational measures: encryption, tenant isolation, access controls. Full list in Annex 2.
Definable implements and maintains the technical and organisational measures described in Annex 2, including encryption of Customer Data in transit (TLS 1.2+) and at rest (AES-256), tenant isolation, role-based access on a need-to-know basis, logging and monitoring, and personnel confidentiality undertakings. Measures are reviewed against SOC 2 Type II and ISO/IEC 27001 audit cycles and will not materially degrade during a subscription term.
Definable ensures that personnel authorised to process Customer Data are bound by confidentiality obligations and receive security and privacy training.
05 Assistance and data subject requests
in short Rights requests that reach us get redirected to you; the product gives you the tools to answer them yourself.
Taking into account the nature of the processing, Definable will assist Customer, through the Services’ features (export, deletion, access controls, audit logs) and reasonable additional cooperation, in fulfilling Customer’s obligations to respond to data-subject requests and in meeting its obligations regarding security, breach notification, data protection impact assessments, and prior consultation with supervisory authorities.
If a data subject sends a request directly to Definable concerning Customer Data, we will not respond substantively (except to acknowledge and redirect) and will promptly forward the request to Customer. If a public authority demands Customer Data, we will review the demand, challenge or narrow it where reasonably possible, disclose only what we are legally compelled to, and notify Customer before disclosure unless legally prohibited.
06 Personal data breach
in short If a breach affects your data, we notify you within 48 hours of becoming aware, with what we know and what we’re doing.
Definable will notify Customer in writing without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Data. The notification will describe, to the extent known: the nature of the breach, categories and approximate volumes of data and data subjects affected, likely consequences, measures taken or proposed, and a contact point. We will provide timely updates as the investigation progresses and reasonably cooperate with Customer’s own notification obligations.
Notification of or response to a breach is not an acknowledgement of fault or liability.
07 Audits
in short Our SOC 2 Type II report and ISO 27001 certificate answer most audits. Genuine need beyond that: on-site audit, once a year, under NDA.
Definable will make available information reasonably necessary to demonstrate compliance with this DPA, including its then-current SOC 2 Type II report, ISO/IEC 27001 certificate, and penetration test summaries, under NDA via [email protected]. The parties agree these materials satisfy Customer’s audit rights in the first instance.
Where Data Protection Laws grant Customer a mandatory audit right that the materials above do not satisfy, Customer may conduct (itself or through an independent auditor that is not a competitor of Definable) an audit of Definable’s relevant controls: on at least 30 days’ written notice, during business hours, no more than once per 12-month period (except after a material breach), under confidentiality obligations, without access to other customers’ data, and at Customer’s expense.
08 International transfers
in short Your workspace stays in your chosen region. Where data must cross borders, SCCs and equivalents apply automatically.
Customer Data is hosted in the region Customer selects (India, US, or EU) and is not moved from it except as necessary to provide the Services (for example, routing a request to a model provider Customer has chosen to use) or as Customer instructs.
Where processing involves a transfer of personal data out of the EEA, the EU Standard Contractual Clauses (2021/914) are incorporated into this DPA by reference — Module 2 (controller-to-processor) or Module 3 (processor-to-processor) as applicable, with Definable as data importer, the option in Clause 9(a) set to general authorisation with 30 days’ notice, the governing law and forum being Ireland, and Annexes I–III completed by Annexes 1–3 of this DPA. For UK transfers, the UK International Data Transfer Addendum applies; for Swiss transfers, the Clauses are adapted as required by the FDPIC. Transfers of personal data outside India comply with the DPDP Act, 2023 and rules notified under it.
09 Return and deletion
in short Export everything for 30 days after termination; then we delete, production within 30 days, backups within 90.
During the subscription term, Customer can export Customer Data at any time through the Services. For 30 days following termination or expiry, Definable will continue to make Customer Data available for export in machine-readable formats. Thereafter, Definable will delete Customer Data from production systems within 30 days and from encrypted backups within 90 days, unless retention is required by applicable law — in which case the data remains protected under this DPA and is deleted when the requirement lapses. On written request, we will confirm deletion.
10 Liability and order of precedence
in short The liability cap in the Terms covers this DPA too. If documents conflict on data protection, this DPA wins.
Each party’s liability arising out of or related to this DPA is subject to the limitations and exclusions of liability in the Agreement, applied in aggregate across the Agreement and this DPA together. In the event of conflict regarding the processing of personal data, the order of precedence is: the Standard Contractual Clauses (where they apply), then this DPA, then the Agreement. This DPA terminates automatically when Definable ceases to process Customer Data.
11 Annex 1 — Details of processing
| Item | Description |
|---|---|
| Subject matter | Provision of the Definable multi-agent workflow platform and related support |
| Duration | The subscription term plus the export and deletion windows in Section 9 |
| Nature and purpose | Hosting, orchestration of AI agents and workflows, routing to AI model providers, syncing with integrations Customer enables, storage, retrieval, support |
| Data subjects | Customer’s users; Customer’s own customers, employees, suppliers and other persons whose data Customer submits |
| Categories of data | Any personal data contained in Customer Data — typically identifiers, contact details, professional information, and communications content. Customer agrees not to submit health data, payment-card numbers, or other special categories requiring heightened safeguards (see Terms, Acceptable Use) |
| Frequency | Continuous, as driven by Customer’s use |
12 Annex 2 — Technical and organisational measures
- — Encryption: TLS 1.2+ for all data in transit; AES-256 at rest, with managed key rotation.
- — Tenant isolation: logical separation of customer workspaces at the application and storage layers; no cross-tenant mixing during AI processing.
- — Access control: SSO and mandatory 2FA for personnel; role-based access on least-privilege; production access gated, logged, and reviewed quarterly.
- — Network security: VPC segregation, firewalling, hardened bastion access, no direct database exposure.
- — Monitoring: centralised logging, anomaly alerting, 24/7 on-call rotation.
- — Secure development: code review on every change, dependency scanning, secrets management, CI-enforced static analysis.
- — Testing: independent penetration tests at least annually; continuous automated vulnerability scanning; coordinated disclosure programme (see /legal/security/).
- — Resilience: multi-AZ deployments, encrypted backups on a rolling 90-day window, disaster-recovery plan tested annually (RPO 24h, RTO 24h).
- — Personnel: background checks where lawful, confidentiality undertakings, annual security and privacy training, immediate access revocation on departure.
- — AI-specific: zero-data-retention or no-training agreements with model providers; agent actions gated by customer-configured permissions with full audit trails.
- — Certifications: SOC 2 Type II and ISO/IEC 27001, audited annually.
13 Annex 3 — Subprocessors
in short Current as of the date above. Subscribe to change notices at [email protected].
| Subprocessor | Purpose | Region |
|---|---|---|
| Amazon Web Services | Cloud infrastructure and storage | India / US / EU (per customer selection) |
| OpenAI | AI model inference (zero data retention) | US |
| Anthropic | AI model inference (zero data retention) | US |
| Google Cloud | AI model inference (no training, per DPA) | US / EU |
| Mistral AI | AI model inference (no training, per DPA) | EU |
| Stripe | Payment processing | US / India |
| Razorpay | Payment processing (India) | India |
| Postmark | Transactional email delivery | US |
| Plain | Customer support tooling | US / EU |
Model providers receive Customer Data only when a workflow routes a task to that provider’s model, and only the content needed for that task. Customers can restrict which model providers their workspace uses in settings.