AIDevPortal legal and trust
Data Processing Agreement
This Data Processing Agreement (DPA) forms part of the agreement between Tech Innovation Hub LLC, doing business as AIDevPortal, and the customer using the AIDevPortal services. It applies when AIDevPortal processes personal data on the customer's behalf.
1. Roles and instructions
The customer is the controller or business responsible for customer data. AIDevPortal is the processor or service provider, except where it processes limited account, billing, security, and service analytics data for its own legitimate business purposes.
AIDevPortal processes customer personal data only to provide, secure, support, and improve the contracted services; comply with documented customer instructions; or meet applicable law. The subscription agreement, workspace configuration, support requests, and authorized workflow actions constitute documented instructions.
2. Processing details
Processing may include collection, storage, organization, retrieval, transmission, analysis, generation, logging, export, and deletion. The duration is the subscription term plus the documented retention and deletion period.
- Data subjects may include customer employees, contractors, users, prospects, clients, and other people whose data the customer submits.
- Data may include identity and contact details, account records, documents, prompts, model outputs, connected-system content, workflow data, support content, and audit events.
- Customers must not submit regulated data unless the order form expressly permits it and required agreements are in place.
3. Confidentiality and access
AIDevPortal limits access to personnel and service providers who need it to operate or support the service. Those people are subject to confidentiality obligations and access controls appropriate to their role.
4. Security measures
AIDevPortal maintains reasonable technical and organizational measures designed to protect customer data, including encryption in transit and at rest, tenant-scoped authorization, role-based access, audit logging, credential protection, change control, monitoring, and backup procedures.
Security measures evolve with the service and risk. AIDevPortal will not materially reduce the overall security of the service during a subscription term.
5. Subprocessors
The customer gives general authorization for the subprocessors listed in the public subprocessor register. AIDevPortal remains responsible for their processing obligations to the extent required by applicable data protection law.
AIDevPortal will publish material additions before they begin processing customer data where practicable. A customer with a reasonable data-protection objection may contact [email protected] to discuss an alternative.
6. International transfers
Where personal data is transferred across borders, AIDevPortal uses an appropriate legal transfer mechanism, such as adequacy decisions or applicable standard contractual clauses. Contract-specific residency commitments apply only when stated in an order form.
7. Data-subject requests
Taking into account the nature of processing, AIDevPortal will provide reasonable assistance so the customer can respond to requests to access, correct, export, restrict, object to, or delete personal data. AIDevPortal will direct requests about customer-controlled workspace data to the customer unless law requires a direct response.
8. Security incidents
AIDevPortal will notify the customer without undue delay after confirming a security incident involving customer personal data and will provide information reasonably available for the customer's assessment and reporting obligations. Notification is not an admission of fault.
9. Return and deletion
During an active subscription, authorized users may use available export features or request reasonable export assistance. After termination, AIDevPortal deletes or de-identifies customer data according to the published data-rights process, except where retention is legally required or data remains in protected backup cycles.
10. Information and review
On reasonable request and subject to confidentiality, AIDevPortal will provide available security documentation needed to demonstrate compliance. If that information is insufficient, the parties may agree to a narrowly scoped review that avoids exposing other customers' data or creating security risk.
11. Enterprise processing annex
This public DPA is the baseline agreement. An Enterprise order may include a negotiated processing annex after legal, security, and technical review. No enhanced control, region, regulated-data permission, recovery objective, or audit right applies unless it is written into the executed agreement.
Contact [email protected] to request the current annex package. Applicable Standard Contractual Clauses and transfer-impact materials are supplied for execution when the proposed processing requires them; this page does not itself execute those clauses.
- Processing subject matter, duration, purpose, data categories, data subjects, and customer restrictions
- Technical and organizational measures, approved regions, approved AI providers, and subprocessor notice terms
- Incident-notification contacts and timing, assistance obligations, audit evidence, and review boundaries
- Return, deletion, backup-cycle treatment, portability, and termination assistance
- Applicable transfer mechanism, Standard Contractual Clauses, and transfer-impact assessment
- Contracted availability, support, recovery objectives, and any regulated-data requirements
12. Order of precedence
If this DPA conflicts with the subscription terms on personal-data processing, this DPA controls. An executed order form or negotiated DPA controls over this public DPA for the same subject.