DRAFT: have a lawyer review before publishing.
Data Processing Agreement
This agreement applies whenever the Processor handles personal information on the Controller's behalf through the BuildAi platform, and forms part of the Terms of Service. It is written to satisfy GDPR Article 28, the CCPA/CPRA service-provider requirements and the accountability principles of the Trinidad and Tobago Data Protection Act 2011.
1. Roles
The Controller decides why and how its customers', leads' and visitors' personal information is used. The Processor handles it only on the Controller's documented instructions, which are: use of the platform's features, and these terms. The Processor must tell the Controller if an instruction appears to break the law.
2. What is processed (Annex A)
- Subject matter and purpose: providing marketing, messaging, website, advertising and reporting services.
- Duration: while the Controller has an account, plus up to 30 days to delete or return the data.
- People: the Controller's customers, prospects and contacts; people who chat with the Controller's assistants; visitors to the Controller's websites; the Controller's staff.
- Data: names, email addresses, phone numbers, messaging IDs, website and social handles, chat messages, email open/click activity, website visit activity, ad performance data.
3. Processor's obligations
- Keep the information confidential and make sure everyone with access is bound by confidentiality.
- Apply the security measures in Annex B.
- Use only the sub-processors in Annex C. Tell the Controller about changes in advance (by email or on the privacy page) so it can object; if the objection can't be resolved, the Controller may end the services.
- Help the Controller answer requests from people exercising their rights (access, correction, deletion, restriction, objection, portability), using the platform's export and deletion tools where possible.
- Tell the Controller without undue delay, and within 72 hours, of becoming aware of a personal data breach affecting its information, with the details it needs to meet its own duties.
- Help with impact assessments and consultations with authorities where reasonably required.
- Delete or return all personal information at the end of the services, within 30 days, unless the law requires it to be kept.
- Make available the information needed to show compliance and allow reasonable audits (on reasonable notice, no more than once a year unless there has been a breach).
4. Controller's obligations
- Have a lawful basis, and any required consent, for the information it uploads or collects, and for the messages it sends.
- Give people the notices the law requires. The platform adds an unsubscribe link to marketing email, tells chat users they are speaking to an AI assistant, and can create a privacy page for the Controller's website, but the Controller remains responsible for them being accurate.
- Not upload sensitive categories of personal information.
5. International transfers
The sub-processors below are mainly in the United States. Where the law requires a transfer mechanism, the parties rely on the standard contractual clauses (or the UK addendum) between the Processor and each sub-processor, which the Processor will provide on request.
6. Liability and governing law
Liability under this agreement is subject to the limits in the Terms of Service. It is governed by the laws of Trinidad and Tobago, except where mandatory data protection law of another place applies to the people concerned.
Annex B: Security measures
- Encrypted connections (HTTPS) for all apps and APIs; providers that encrypt stored data.
- Server-side administrator sign-in with hashed passwords, optional second factor, lockout after repeated failures and signed, expiring sessions.
- Client portal access restricted to confirmed, invited users, and to that client's own data only.
- Database access limited to the Processor's servers (row-level security on, no public access).
- Verified webhook signatures; rate limiting and abuse limits on public endpoints; checks on outbound web requests.
- Dependency vulnerability scanning and automated tests on every change.
- Logging of AI usage and security-relevant events, without storing secrets in logs.
Annex C: Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database, storage, client authentication | Region of the Processor's project |
| Railway | Application hosting | United States |
| Anthropic | AI text generation and chat assistants | United States |
| Resend | Email delivery | United States |
| Twilio | WhatsApp messaging | United States |
| Meta Platforms | Messenger/Instagram messaging, advertising | United States / Ireland |