Data Processing Agreement
For Team Customers
This agreement applies to Team customers. When your organization puts personal data it controls into Ainna, you are the controller and we are your processor. This document sets out how we handle that data on your instructions, as GDPR Article 28 requires. It supplements our Terms of Service and Privacy Policy; it does not replace them. Ainna is an AI system: its analysis is a starting point for your judgment, not a substitute for it, and it is built to help you bring in the experts you trust before you decide.
1. Scope and Application
Who this agreement is for and when it applies
1.1 Who This Applies To
This Data Processing Agreement ("DPA") applies where you use Ainna on a Team plan and, through it, provide us with personal data that your organization controls, for example personal data contained in your Inputs, or personal data about your Members. In this DPA, "you" and "Customer" mean the account holder of the Team plan.
1.2 When It Does Not Apply
This DPA does not apply to the Starter or Pro plans, where you use Ainna as an individual and we are the controller of your personal data under our Privacy Policy. It also does not apply to Ainna Enterprise, which is governed by its own written agreement.
1.3 Relationship to Our Other Terms
This DPA forms part of, and is subject to, our Terms of Service. You accept it when you subscribe to a Team plan. Where this DPA conflicts with the Terms of Service or Privacy Policy on the subject of our processing of Customer Personal Data as your processor, this DPA prevails. On all other matters, the Terms of Service prevail.
1.4 Controller and Processor
For personal data within scope of this DPA, you are the controller and Innovation Mode Limited is the processor, as those terms are defined in the GDPR. You determine why and how that data is processed; we process it on your behalf, on your instructions, to provide the Service.
Questions about scope? See How to Contact Us.
2. Definitions
Key terms used in this agreement
Terms defined in our Terms of Service have the same meaning here. In addition:
"GDPR" means Regulation (EU) 2016/679, and any equivalent United Kingdom data protection law where it applies to your use of the Service.
"Data Protection Law" means the GDPR and any other data protection or privacy law that applies to the processing under this DPA.
"Customer Personal Data" means personal data within your Inputs, or otherwise provided by you or your Members through a Team plan, that we process on your behalf as your processor.
"Data Subject," "Controller," "Processor," "Personal Data Breach," and "Processing" have the meanings given in the GDPR.
"Subprocessor" means a third party we engage to process Customer Personal Data on our behalf.
"Standard Contractual Clauses" ("SCCs") means the clauses approved by the European Commission for transfers of personal data to countries outside the European Economic Area that do not have an adequacy decision.
Questions about these definitions? See How to Contact Us.
3. Details of the Processing
What we process, why, and for how long
Article 28 of the GDPR requires us to record the nature of the processing we carry out for you. For a Team plan:
Subject matter: our processing of Customer Personal Data to provide the Ainna Service under the Terms of Service.
Duration: for as long as your Team plan is active, and thereafter as described in Section 9 (Return and Deletion) and the retention rules in our Privacy Policy.
Nature and purpose: hosting, storing, and processing Customer Personal Data so that Members can frame, assess, and document product opportunities; generating Outputs and, on demand, Documents; enabling collaboration within your Workspace and, where you use it, the Panel; and providing related support and security.
Types of personal data: the personal data your Members choose to include in Inputs (which is under your control and should be minimized, see Section 4.3), together with account and profile data for your Members (such as name and email address) and any names and email addresses you provide to invite Panelists.
Categories of data subjects: your Members, any Panelists you invite, and any individuals your Members choose to reference within Inputs.
Special categories: we do not require, and ask you not to include, special categories of personal data (Section 4.3).
Questions about the details of processing? See How to Contact Us.
4. Our Obligations as Processor
What we commit to when processing your data
4.1 Process Only on Your Instructions
We process Customer Personal Data only on your documented instructions, including as set out in this DPA, the Terms of Service, and your use of the Service's features, unless a law we are subject to requires otherwise, in which case we will tell you before processing unless that law prohibits it. Your instructions must comply with Data Protection Law. If we believe an instruction breaches Data Protection Law, we will tell you.
4.2 No Use for Our Own Purposes
We do not sell Customer Personal Data, we do not use it for our own purposes, and, consistent with our Privacy Policy, we do not use it to train, fine-tune, or improve any AI model.
4.3 Data Minimization Is Shared
You control what Members enter into Inputs. You are responsible for not including personal data that the analysis does not need, and for not including special categories of personal data, payment card numbers, health records, or similar sensitive data. We provide the tools; you decide what goes in.
4.4 Confidentiality
We ensure that people authorized to process Customer Personal Data are bound by appropriate confidentiality obligations, and we limit access to those who need it to provide the Service.
4.5 Security
We implement appropriate technical and organizational measures to protect Customer Personal Data, as described in our Privacy Policy, including encryption in transit and at rest, access controls, and least-privilege access. You are responsible for your own security practices, including managing your Members' access and keeping their sign-in secure.
Questions about our obligations? See How to Contact Us.
5. Subprocessors
The third parties who help us process your data
5.1 Your Authorization
You authorize us to engage subprocessors to process Customer Personal Data to provide the Service. We remain responsible to you for our subprocessors' processing of Customer Personal Data.
5.2 Terms with Subprocessors
Before a subprocessor processes Customer Personal Data, we impose on it data protection obligations that are, in substance, no less protective than those in this DPA, including the obligation not to use the data to train or improve its own services.
5.3 Our Current Subprocessors
Our subprocessors for the Service are the same providers listed in our Privacy Policy:
• Microsoft Azure — cloud hosting, in EU data centres
• OpenAI — conversational AI processing (United States); its API terms prohibit training on your content
• Stripe — payment processing
• LinkedIn — optional sign-in (identity verification only; we send LinkedIn no Customer Data, and receive only name, email, and profile picture)
Some of these subprocessors in turn rely on their own sub-processors to provide their services; OpenAI, for example, relies principally on Microsoft. Each is bound by the no-training and data-protection obligations described above, and OpenAI maintains its own current sub-processor list at platform.openai.com/subprocessors.
5.4 Changes to Subprocessors
If we intend to add or replace a subprocessor that processes Customer Personal Data, we will give you notice through the Service or by email. If you have a reasonable, data-protection-based objection, tell us within 30 days of the notice and we will work with you in good faith to address it; if we cannot, you may stop using the affected feature or terminate the Team plan as your remedy.
Questions about subprocessors? See How to Contact Us.
6. Assisting with Data Subject Requests
How we help you respond to the people whose data you control
6.1 Requests Come to You
As the controller, you are responsible for responding to requests from data subjects (for example, requests for access, correction, or deletion) relating to Customer Personal Data. If we receive such a request directly, we will not respond to it ourselves except to confirm that it should be directed to you, and we will forward it to you without undue delay where we can identify that it relates to your account.
6.2 Our Assistance
Taking into account the nature of the processing, we will help you respond to data subject requests by providing the self-service tools in the Service and, where those are not sufficient, reasonable assistance on request. Many requests can be met using the workspace controls available to your Administrator, including viewing, correcting, and deleting content.
Questions about data subject requests? See How to Contact Us.
7. Personal Data Breaches
What we do if data is compromised
7.1 Notice to You
We will notify you without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.
7.2 What We Will Tell You
Our notice will describe, to the extent known, the nature of the breach, the likely consequences, and the measures we have taken or propose to take. We will provide further information as it becomes available.
7.3 Your Responsibility
As the controller, you are responsible for any notification to a supervisory authority or to affected data subjects that Data Protection Law requires of you. We will provide reasonable assistance to help you meet those obligations.
Questions about breach notification? See How to Contact Us.
8. International Transfers
How data is protected when it leaves the EEA
8.1 Storage in the EU
We store Customer Personal Data in EU data centres, as described in our Privacy Policy.
8.2 Processing Outside the EEA
Some processing occurs outside the European Economic Area, in particular AI processing by OpenAI in the United States. Where we, or a subprocessor, transfer Customer Personal Data outside the EEA to a country without an adequacy decision, the transfer is made under appropriate safeguards, primarily the Standard Contractual Clauses, together with the data minimization and encryption described in our Privacy Policy.
8.3 SCCs
Where the SCCs apply to a transfer under this DPA, they are incorporated by reference and take precedence over this DPA to the extent of any conflict on the subject of that transfer.
Questions about transfers? See How to Contact Us.
9. Return and Deletion of Data
What happens to your data when the plan ends
9.1 On Termination
When your Team plan ends, you can, for the period your account remains accessible, generate and download Documents and export the text content of your Opportunities, as described in our Terms of Service and Privacy Policy.
9.2 Deletion
After that, we delete or return Customer Personal Data in accordance with the retention rules in our Privacy Policy, unless Data Protection Law requires us to retain it. When data is deleted, it is removed from our active systems immediately; encrypted disaster-recovery backups age out on their normal cycle, and we do not use them to restore deleted content.
9.3 Your Control
At any time while your plan is active, your Administrator can delete Opportunities and workspace content, and can close the account, as described in the Terms of Service.
Questions about return and deletion? See How to Contact Us.
10. Audit and Information
How you can verify our compliance
10.1 Information We Provide
On reasonable written request, we will make available the information reasonably necessary to demonstrate our compliance with this DPA, including a description of our technical and organizational security measures and our current subprocessors.
10.2 Audits
Where Data Protection Law gives you a right to audit, we will satisfy that right primarily by providing the information described above and any certifications or third-party reports we or our subprocessors hold. If that is not sufficient to meet a specific, documented requirement of Data Protection Law, we will work with you in good faith to agree a reasonable, proportionate way to verify compliance, at your cost, without disrupting the Service or compromising the confidentiality or security of other customers' data.
Questions about audit and information? See How to Contact Us.
11. Liability and General Terms
How this agreement fits with the rest
11.1 Liability
Each party's liability under or in connection with this DPA is subject to the limitations and exclusions of liability in our Terms of Service, and this DPA does not increase those limits.
11.2 Duration
This DPA takes effect when you subscribe to a Team plan and continues for as long as we process Customer Personal Data on your behalf.
11.3 Changes
We may update this DPA in line with the change process in our Terms of Service. Where a change would reduce your rights or increase your obligations, we will give you notice as set out there.
11.4 Governing Law
This DPA is governed by the law of Ireland and subject to the jurisdiction and dispute-resolution provisions of the Terms of Service.
11.5 Precedence
On the subject of our processing of Customer Personal Data as your processor, this DPA prevails over the Terms of Service and Privacy Policy; where SCCs apply to a transfer, they prevail over this DPA to the extent of any conflict. On all other subjects, the Terms of Service prevail.
Questions about these terms? See How to Contact Us.
AI and Judgment
A note that applies to all use of Ainna
Ainna's outputs are generated by AI and are a starting point for judgment, not a substitute for it. Whoever uses them is responsible for verifying what matters before relying on them. This applies to Members and to anyone your organization involves through the Service. See our Terms of Service, Section 11.
Questions? See How to Contact Us.
12. How to Contact Us
How to reach us about this agreement
For any question about this DPA, our role as your processor, or a data protection matter relating to a Team plan:
Email privacy@ainna.ai
Our Details
Innovation Mode Limited
Company Registration Number: 785034
Registered Office: 51 Bracken Road Dublin 18, D18 CV48, DUBLIN
Ireland
This DPA should be read together with our Terms of Service and Privacy Policy.
