Data Processing Agreement

Last updated 2026-07-17

This Data Processing Agreement ("DPA") forms part of the Terms of Service between AAG Ventures Ltd ("Processor") and the Customer ("Controller") and applies where we process personal data contained in Customer Data on the Controller's behalf.

1. Roles and scope

The Controller determines the purposes and means of processing Customer Data; the Processor processes it only to provide the Service and on the Controller's documented instructions (including these Terms). Subject matter: provision of the Service. Duration: the term of the account. Nature and purpose: hosting and processing business-operations data. Data subjects: the Controller's personnel, contacts, and customers. Data types: as determined by the Controller through its use of the Service.

2. Processor obligations

The Processor will: process only on the Controller's instructions and as required by law; ensure persons authorized to process are bound by confidentiality; implement appropriate technical and organizational security measures; and not sell Customer Data.

3. Sub-processors

The Controller authorizes the Processor to engage sub-processors to provide the Service, including hosting (Vercel), database/storage/auth (Supabase), email (Resend), AI processing (OpenAI), and payments (Stripe). The Processor remains responsible for its sub-processors' compliance and will impose equivalent obligations on them. The Processor will give notice of new sub-processors and the Controller may object on reasonable data-protection grounds.

4. Assistance, breach, and audits

Taking into account the nature of processing, the Processor will provide reasonable assistance with data-subject requests and with the Controller's security, breach-notification, and impact-assessment obligations. The Processor will notify the Controller without undue delay after becoming aware of a personal-data breach affecting Customer Data. The Processor will make available information reasonably necessary to demonstrate compliance and allow for audits on reasonable prior notice, subject to confidentiality.

5. Deletion and international transfers

On termination or on the Controller's request, the Processor will delete or return Customer Data within a reasonable period, except where retention is required by law. Where data is transferred internationally, the parties will rely on a lawful transfer mechanism as required by applicable law.

6. Liability

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service. In the event of a conflict on data-processing matters, this DPA controls; otherwise, the Terms of Service control.