Hi — I'm Aigenta 👋 Need an appointment or have a question? I can help right here.
Legal

Data Processing Addendum

Our standard DPA, the sub-processors we use, and how to execute the agreement.

Effective: June 1, 2026 Version 1.8

Executing the DPA

Our standard DPA is incorporated by reference into your Aigenta subscription. For a signed copy with your company name on it, email [email protected] with your legal entity name and signing contact. We use HelloSign and turn around requests within two business days.

The DPA includes Standard Contractual Clauses (Commission Decision 2021/914/EU) for transfers to processors outside the EEA.

Roles

You are the controller of personal data processed through your assistant. Aigenta is the processor. For the website analytics on aigenta.app itself, Aigenta is the controller.

Sub-processors

We engage the following sub-processors to deliver the service. We notify customers 30 days before adding a new one — subscribe at [email protected].

Sub-processor Purpose Location
Amazon Web ServicesHosting, storage, KMSEU (Frankfurt), US (Virginia)
Anthropic, PBCLLM inference (zero retention)US
Stripe, Inc.Payment processingUS, EU (Ireland)
ResendTransactional emailUS
CloudflareCDN, DDoS protection, DNSGlobal edge
TwilioSMS notifications (opt-in)US, EU (Ireland)
LinearInternal task tracking (no customer data)US
NotionInternal docs (no customer data)US

Data categories & subjects

  • Subjects: account holders, end users of customer websites.
  • Categories: identification (name, email), contact (phone if shared), interaction (chat messages, timestamps, IP for rate-limiting), technical (browser, locale).

Technical & organizational measures

Detailed in Annex II of the DPA: encryption (in transit and at rest), access controls (RBAC + JIT), backups, business continuity, incident response, and personnel training. Full text on request.

International transfers

EU customer data is hosted in eu-central-1 (Frankfurt). Where transfers to third countries occur (e.g., LLM inference, payments), they're governed by SCCs and transfer impact assessments are available.

Audit rights

Once per twelve-month period, customers may audit Aigenta's compliance with the DPA. In practice, we satisfy audit obligations with our SOC 2 Type II report (available under NDA).

Term & deletion

The DPA applies for the duration of your subscription. On termination, we delete customer personal data within 90 days unless retention is required by law (e.g., billing records under tax law).