LEGAL · DATA

Data Processing Terms

Terms that apply when AuraGrid processes personal data in Customer Content on a customer's behalf.

These Data Processing Terms (the "DPA") form part of the agreement between AuraGrid Labs LLC and the Customer. They apply to personal data in Customer Content that AuraGrid processes as the Customer's processor or service provider. A countersigned copy is available on request.

1. Roles and instructions

The Customer is the controller (or business) and AuraGrid is the processor (or service provider). AuraGrid processes personal data only on the Customer's documented instructions, which are the agreement, the Customer's configuration of the Services, and its lawful written requests. If AuraGrid believes an instruction violates law, it will tell the Customer and may pause the affected processing.

The Customer is responsible for having a lawful basis, giving notices, obtaining consents and having authority to share personal data with AuraGrid and to have it used to contact people.

2. Confidentiality and personnel

AuraGrid ensures that people authorized to process personal data are bound by confidentiality duties and receive appropriate training, and limits access to those who need it.

3. Security measures

AuraGrid maintains technical and organizational measures appropriate to the risk. The measures include those in Annex 2. AuraGrid may update them provided the overall level of protection is not reduced.

4. Sub-processors

The Customer gives general authorization for AuraGrid to use sub-processors. The current list is on the Sub-processors page. AuraGrid will update it and give at least 30 days' notice, by e-mail to the Customer's administrator or by notice in the workspace, before a new sub-processor processes Customer personal data. The Customer may object on reasonable data-protection grounds within that period, and the parties will work in good faith on a solution, failing which the Customer may terminate the affected Services without penalty. AuraGrid imposes data-protection obligations on sub-processors that are no less protective than these terms and remains responsible for their performance.

5. Assistance with individuals' requests

AuraGrid will, taking account of the nature of the processing, provide reasonable assistance so that the Customer can respond to requests to exercise data-subject rights. If AuraGrid receives such a request about Customer personal data, it will direct the individual to the Customer and will not respond itself unless required by law.

6. Personal data breaches

AuraGrid will notify the Customer without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting Customer personal data. The notice will describe, as far as known, the nature of the breach, the data and individuals affected, likely consequences and measures taken or proposed. AuraGrid will cooperate with the Customer's investigation and with notifications to authorities and individuals.

7. Impact assessments and consultation

AuraGrid will provide reasonable information and assistance for the Customer's data-protection impact assessments and consultations with authorities relating to the Services.

8. Return and deletion

After the Services end, AuraGrid will, at the Customer's choice made within 30 days, return or delete the personal data, and will delete remaining copies within 90 days, except where law requires retention. Backups are deleted on their normal rotation, and are protected until then.

9. Audits and information

AuraGrid will make available information reasonably needed to show compliance with this DPA, such as policies, summaries of independent test results where they exist, and completed security questionnaires. If that is not sufficient, the Customer may, on reasonable notice and no more than once a year (or after a breach), carry out or commission a confidentiality-bound audit during business hours that does not unreasonably disrupt operations or expose other customers' data. Each party bears its own costs unless the audit shows a material breach by AuraGrid.

10. International transfers

AuraGrid may process personal data in the United States and other countries where it or its sub-processors operate. For transfers of personal data from the European Economic Area, the United Kingdom or Switzerland to a country without an adequacy decision, the parties agree to the Standard Contractual Clauses (Module Two, controller to processor, and Module Three where the Customer is itself a processor), the UK International Data Transfer Addendum, and the Swiss amendments, which are incorporated by reference, with the details in the Annexes. For transfers from other countries such as Bangladesh, India or Brazil, the parties will use the mechanism that local law allows, and AuraGrid will sign additional terms the law requires.

11. US state-law terms

To the extent California or other US state privacy laws apply, AuraGrid acts as a service provider or processor. It will not sell or share personal information, will not retain, use or disclose it outside the direct business relationship or for any purpose other than the business purposes in the agreement, will not combine it with other personal information except as the law allows, will comply with applicable obligations and give the same level of protection, will tell the Customer if it can no longer meet them, and allows the Customer to take reasonable steps to stop and remediate unauthorized use.

12. Liability and precedence

The liability limits in the Terms of Service apply to this DPA to the extent the law permits. If there is a conflict between this DPA and other terms about the processing of personal data, this DPA prevails, and the Standard Contractual Clauses prevail over everything else where they apply.

Annex 1. Description of processing

Data exporter (controller)
The Customer
Data importer (processor)
Subject matter
Providing the AuraGrid Services described in the agreement
Duration
The term of the agreement plus the return and deletion period
Nature and purpose
Hosting, storage, analysis with AI, classification, drafting, routing, reminders, orchestration with connected systems, audit logging and support
Categories of data subjects
The Customer's prospects, leads, customers, representatives, employees and contractors, and other people who communicate with the Customer
Types of personal data
Names, contact details, company and role, conversation and message content, call transcripts or recordings if enabled, consent and suppression status, invoice and payment-status information, product and order information, user account details and audit events
Sensitive data
None intended. Not to be submitted unless agreed in writing
Frequency
Continuous while the Services are used
Competent authority
The authority of the Customer's establishment, or as stated in the Order Form

Annex 2. Security measures

Data protection
Asia, including Bangladesh
Company
Postal address