Data Processing Terms
Terms that apply when AuraGrid processes personal data in Customer Content on a customer's behalf.
These Data Processing Terms (the "DPA") form part of the agreement between AuraGrid Labs LLC and the Customer. They apply to personal data in Customer Content that AuraGrid processes as the Customer's processor or service provider. A countersigned copy is available on request.
1. Roles and instructions
The Customer is the controller (or business) and AuraGrid is the processor (or service provider). AuraGrid processes personal data only on the Customer's documented instructions, which are the agreement, the Customer's configuration of the Services, and its lawful written requests. If AuraGrid believes an instruction violates law, it will tell the Customer and may pause the affected processing.
The Customer is responsible for having a lawful basis, giving notices, obtaining consents and having authority to share personal data with AuraGrid and to have it used to contact people.
2. Confidentiality and personnel
AuraGrid ensures that people authorized to process personal data are bound by confidentiality duties and receive appropriate training, and limits access to those who need it.
3. Security measures
AuraGrid maintains technical and organizational measures appropriate to the risk. The measures include those in Annex 2. AuraGrid may update them provided the overall level of protection is not reduced.
4. Sub-processors
The Customer gives general authorization for AuraGrid to use sub-processors. The current list is on the Sub-processors page. AuraGrid will update it and give at least 30 days' notice, by e-mail to the Customer's administrator or by notice in the workspace, before a new sub-processor processes Customer personal data. The Customer may object on reasonable data-protection grounds within that period, and the parties will work in good faith on a solution, failing which the Customer may terminate the affected Services without penalty. AuraGrid imposes data-protection obligations on sub-processors that are no less protective than these terms and remains responsible for their performance.
5. Assistance with individuals' requests
AuraGrid will, taking account of the nature of the processing, provide reasonable assistance so that the Customer can respond to requests to exercise data-subject rights. If AuraGrid receives such a request about Customer personal data, it will direct the individual to the Customer and will not respond itself unless required by law.
6. Personal data breaches
AuraGrid will notify the Customer without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting Customer personal data. The notice will describe, as far as known, the nature of the breach, the data and individuals affected, likely consequences and measures taken or proposed. AuraGrid will cooperate with the Customer's investigation and with notifications to authorities and individuals.
7. Impact assessments and consultation
AuraGrid will provide reasonable information and assistance for the Customer's data-protection impact assessments and consultations with authorities relating to the Services.
8. Return and deletion
After the Services end, AuraGrid will, at the Customer's choice made within 30 days, return or delete the personal data, and will delete remaining copies within 90 days, except where law requires retention. Backups are deleted on their normal rotation, and are protected until then.
9. Audits and information
AuraGrid will make available information reasonably needed to show compliance with this DPA, such as policies, summaries of independent test results where they exist, and completed security questionnaires. If that is not sufficient, the Customer may, on reasonable notice and no more than once a year (or after a breach), carry out or commission a confidentiality-bound audit during business hours that does not unreasonably disrupt operations or expose other customers' data. Each party bears its own costs unless the audit shows a material breach by AuraGrid.
10. International transfers
AuraGrid may process personal data in the United States and other countries where it or its sub-processors operate. For transfers of personal data from the European Economic Area, the United Kingdom or Switzerland to a country without an adequacy decision, the parties agree to the Standard Contractual Clauses (Module Two, controller to processor, and Module Three where the Customer is itself a processor), the UK International Data Transfer Addendum, and the Swiss amendments, which are incorporated by reference, with the details in the Annexes. For transfers from other countries such as Bangladesh, India or Brazil, the parties will use the mechanism that local law allows, and AuraGrid will sign additional terms the law requires.
11. US state-law terms
To the extent California or other US state privacy laws apply, AuraGrid acts as a service provider or processor. It will not sell or share personal information, will not retain, use or disclose it outside the direct business relationship or for any purpose other than the business purposes in the agreement, will not combine it with other personal information except as the law allows, will comply with applicable obligations and give the same level of protection, will tell the Customer if it can no longer meet them, and allows the Customer to take reasonable steps to stop and remediate unauthorized use.
12. Liability and precedence
The liability limits in the Terms of Service apply to this DPA to the extent the law permits. If there is a conflict between this DPA and other terms about the processing of personal data, this DPA prevails, and the Standard Contractual Clauses prevail over everything else where they apply.
Annex 1. Description of processing
- Data exporter (controller)
- The Customer
- Data importer (processor)
- Subject matter
- Providing the AuraGrid Services described in the agreement
- Duration
- The term of the agreement plus the return and deletion period
- Nature and purpose
- Hosting, storage, analysis with AI, classification, drafting, routing, reminders, orchestration with connected systems, audit logging and support
- Categories of data subjects
- The Customer's prospects, leads, customers, representatives, employees and contractors, and other people who communicate with the Customer
- Types of personal data
- Names, contact details, company and role, conversation and message content, call transcripts or recordings if enabled, consent and suppression status, invoice and payment-status information, product and order information, user account details and audit events
- Sensitive data
- None intended. Not to be submitted unless agreed in writing
- Frequency
- Continuous while the Services are used
- Competent authority
- The authority of the Customer's establishment, or as stated in the Order Form
Annex 2. Security measures
- Separation of customer workspaces with tenant-scoped authorization and least-privilege access.
- Strong authentication for administrative access and prompt removal of access that is no longer needed.
- Encryption of data in transit and protection of stored credentials and secrets.
- Controlled tools and approval gates for consequential actions, with audit records of decisions and actions.
- Logging and monitoring for security events, and a process for responding to incidents.
- Secure development practices, dependency updates and review of changes before release.
- Backups and recovery planning, and secure deletion at end of life.
- Confidentiality commitments and security awareness for personnel.
- Vendor review for sub-processors.
- Data protection
- Asia, including Bangladesh
- Company
- Postal address