GDPR-compliant data processing terms for enterprise customers
Last Updated: January 10, 2025 | Version 2.1
Data Processing Agreement Overview
This Data Processing Agreement ("DPA") supplements our Terms of Service and governs the processing of personal data by Adaapt.AI on behalf of enterprise customers in accordance with GDPR, CCPA, and other applicable privacy laws.
Full compliance with EU General Data Protection Regulation
California Consumer Privacy Act compliance
Healthcare data protection via Business Associate Agreement
Audited security and availability controls
This DPA applies to processing activities subject to:
As Data Controller, you are responsible for:
As Data Processor, Adaapt.AI will:
Special Category Data:
Processing of sensitive personal data (health, biometric, genetic data, etc.) requires explicit written agreement and additional safeguards. Contact our legal team for sensitive data processing requirements.
Adaapt.AI may engage the following categories of sub-processors:
All sub-processors must:
We will provide 30 days' notice of new sub-processors. Customers may object to new sub-processors with legitimate reasons related to data protection compliance.
Adaapt.AI will assist the Controller in responding to data subject rights requests, including:
Incident Response Timeline:
Breach notifications will include:
Upon breach detection, we will:
Data deletion procedures include:
Upon termination, we can provide data in commonly used formats including JSON, CSV, or XML, as specified in the service agreement.
Controllers may audit Adaapt.AI's compliance through:
Available compliance documentation includes:
International data transfers are protected through:
We conduct Transfer Impact Assessments (TIAs) to ensure adequate protection levels in destination countries, considering:
For questions about this DPA or data processing matters:
This DPA is automatically incorporated into your service agreement upon execution.