Skip to content
← Back

Data Processing Addendum

This Data Processing Addendum ("DPA") applies to the processing of personal data by airays on behalf of a Business Customer, where such processing is subject to the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the UK GDPR, the Swiss Federal Act on Data Protection, or equivalent laws of other jurisdictions ("Data Protection Laws").

This DPA is incorporated by reference into the Business Supplement and takes effect when the Business Customer accepts the Business Supplement or begins using the airays Business tier. Terms used but not defined here have the meanings in the applicable Data Protection Law.

1. Roles

  • The Business Customer is the "controller" (or equivalent) of the personal data submitted to airays by its Administrators and End Users.
  • airays is the "processor" (or equivalent) that processes that personal data on the Business Customer's documented instructions.
  • For personal data airays collects independently as controller (account registration, billing), airays acts as controller and the airays Privacy Policy applies.

2. Scope and duration

Subject matter: processing of Customer Data as necessary to provide the airays Business tier per the Business Supplement.

Duration: for the duration of the Business Customer's subscription, plus the 30-day post-termination export window described in Business Supplement Section 16.

Nature and purpose of processing: storage, transmission, encryption, indexing, delivery, AI-model inference, safety classification, and other operations necessary to provide the service as described in the Terms of Service, Privacy Policy, and Business Supplement.

Types of personal data: as submitted by Administrators and End Users. May include names, email addresses, message content, voice recordings, images, videos, generated AI content, and any other categories the Business Customer elects to submit.

Categories of data subjects: Business Customer's Administrators, End Users, and any third parties whose personal data is submitted by Business Customer's Administrators or End Users (recipients of messages, subjects of shared content, etc.).

3. Business Customer instructions

airays processes Customer Data on the documented instructions of the Business Customer. The Business Customer's acceptance of the Business Agreement (Business Supplement + this DPA + Terms of Service + AUP + SLA) constitutes those documented instructions.

Additional instructions may be given via the airays Business admin dashboard (retention settings, policy configuration, connector permissions) or in writing to legal@airays.ai. airays may reject instructions that (a) violate applicable law or (b) require material changes to airays operations unless a separate paid engagement is agreed.

If airays believes an instruction infringes applicable Data Protection Law, airays will notify the Business Customer without undue delay.

4. Confidentiality

airays ensures that all persons authorized to process Customer Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

5. Security

airays implements appropriate technical and organizational measures to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures include:

  • Encryption of Customer Data at rest (per-conversation encryption keys derived from a master secret held in a secure enclave)
  • Encryption of Customer Data in transit (TLS 1.2+)
  • Access controls: MFA required for personnel access to production systems; principle of least privilege; access logging and audit
  • Software-development lifecycle: mandatory code review; automated security testing; dependency vulnerability scanning
  • Application-layer controls: authentication (Clerk), session management, entitlement enforcement
  • Log fingerprinting: message content never enters application logs; IP addresses fingerprinted before storage
  • Sub-processor oversight: sub-processors selected for their equivalent security posture; contractual data-protection commitments in place
  • Incident detection and response: 24/7 automated monitoring; documented incident-response procedures

Current details of security measures are available on request under an appropriate NDA. Business Customers may audit airays's compliance with this DPA once per calendar year with 30 days notice, at their own expense; airays may satisfy audit requests by providing SOC 2 or ISO 27001 attestation reports once available.

6. Sub-processors

The Business Customer grants airays general authorization to engage sub-processors, subject to this Section 6. The current list of sub-processors is maintained in the Privacy Policy Section 7.

airays imposes on each sub-processor data-protection obligations no less protective than those in this DPA.

Change notification. airays notifies Business Customers at least 30 days before adding or replacing a sub-processor. Business Customers may object on reasonable grounds within 15 days; if the parties cannot resolve the objection, the Business Customer may terminate the affected subscription with a pro-rata refund of prepaid unused fees.

7. Data subject rights

airays provides mechanisms for the Business Customer and its End Users to exercise data-subject rights under Data Protection Laws:

  • Access — via Settings → Account → Export my data (delivered as signed download link within 24 hours)
  • Correction — via Settings profile editing
  • Deletion — via Settings → Account → Delete account (see Privacy Policy §11 for the deletion cascade)
  • Restriction / objection — via memory settings, feature toggles, or by email to privacy@airays.ai
  • Portability — export delivered in machine-readable format

Where a data subject contacts airays directly regarding Business Customer's Customer Data, airays will (unless legally prohibited) redirect them to the Business Customer and notify the Business Customer.

8. Personal data breach notification

airays notifies the Business Customer of a personal data breach affecting Customer Data without undue delay, and in any event within 72 hours after becoming aware of the breach. Notification includes, to the extent known:

  • The nature of the breach, including categories and approximate number of data subjects and records affected
  • The likely consequences of the breach
  • The measures taken or proposed to address the breach and mitigate its adverse effects
  • The contact point for further information

airays cooperates with the Business Customer's own breach- response obligations, including any required notification to supervisory authorities or data subjects.

9. Data protection impact assessments

airays provides reasonable assistance to the Business Customer in carrying out data protection impact assessments (Article 35 GDPR) and prior consultations with supervisory authorities (Article 36 GDPR) where required by law, taking into account the nature of the processing and the information available to airays.

10. Return or deletion at end of service

On termination of the Business subscription, airays deletes or returns Customer Data as follows:

  • For 30 days after termination, the Business Customer may export Customer Data via the standard export mechanism
  • After 30 days, all Customer Data is deleted from active systems within 24 hours
  • Encrypted backups are eligible for deletion in the next 30-day backup cycle, after which they are permanently removed

Retention beyond the standard period requires a separate written agreement (e.g., legal-hold retention as a paid add- on). airays does not retain Customer Data for any purpose after the deletion window.

11. International transfers

airays operates on Cloudflare's global edge network. Customer Data may be transferred to and processed in the United States and other countries where sub-processors are located. airays complies with Chapter V of the GDPR (and equivalent requirements of other Data Protection Laws) for cross-border transfers.

For transfers from the EEA to countries not deemed adequate by the European Commission, the parties incorporate by reference the Standard Contractual Clauses adopted by the Commission Implementing Decision (EU) 2021/914 of 4 June 2021 ("EU SCCs"), Module Two (Controller to Processor), as follows:

  • Clause 7 (Docking) — optional; not opted in
  • Clause 9(a) (Sub-processor authorization) — option 2 selected (general written authorization); the time period for prior notice is 30 days per Section 6 above
  • Clause 11(a) (Redress option for data subjects) — optional independent dispute resolution not opted in
  • Clause 17 (Governing law) — law of Ireland
  • Clause 18 (Choice of forum and jurisdiction) — courts of Ireland
  • Annex I.A (Parties) — the Business Customer as data exporter (controller); airays as data importer (processor)
  • Annex I.B (Description of transfer) — as described in Section 2 above
  • Annex II (Technical and organizational measures) — as described in Section 5 above

For transfers from the UK, the parties incorporate the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner's Office (Version B.1.0). For transfers from Switzerland, the parties apply the EU SCCs with the modifications adopted by the Swiss Federal Data Protection and Information Commissioner (FDPIC).

Where the EU-US Data Privacy Framework or equivalent adequacy mechanism applies to a US-based sub-processor, that sub-processor is designated as a Data Privacy Framework participant.

12. AI-model processing (specific to airays)

airays uses third-party AI providers (currently Anthropic, OpenAI, Replicate, ElevenLabs, Deepgram — as listed in the Privacy Policy Section 7) to process Customer Data in generating AI Outputs. Each AI provider is engaged as a sub-processor under this DPA on the following basis:

  • API traffic is subject to enterprise / business-tier privacy terms with each provider (Anthropic Zero-Retention API, OpenAI Enterprise Privacy, ElevenLabs Business, Replicate Business, Deepgram Enterprise) that contractually prohibit training on Customer Data
  • Retention at each provider is either zero (for providers who offer it) or the minimum required for abuse detection (typically 30 days), as documented in each provider's terms
  • airays maintains agreements with each provider that require GDPR-equivalent data-protection measures

13. Liability

Liability under this DPA is subject to the limitations of liability in the Business Supplement Section 12.

14. Order of precedence

In case of conflict between this DPA and the Business Supplement, this DPA prevails on data-protection matters. In case of conflict between this DPA and the EU SCCs, the EU SCCs prevail.

15. Contact

Data protection contact for airays: privacy@airays.ai. For legal notices: legal@airays.ai.