Back to home

Data Processing Agreement

Effective Date: January 1, 2026 Last Updated: January 1, 2026

This Data Processing Agreement (this "DPA") is entered into between AICSUITE, LLC, a Delaware limited liability company ("Processor" or "AICSUITE"), and the customer identified in the applicable order or account ("Controller" or "Customer"). This DPA forms part of, and is incorporated by reference into, the Terms of Service between the parties.

This DPA applies to AICSUITE's processing of Personal Data on behalf of Customer in connection with the Services and is intended to comply with Article 28 of the EU General Data Protection Regulation (Regulation (EU) 2016/679, the "GDPR"), the UK GDPR, the California Consumer Privacy Act (as amended by the CPRA, the "CCPA"), and other comparable data-protection laws.

1. Definitions

Capitalized terms not defined here have the meaning given in the GDPR or the applicable Data Protection Law. The following terms apply throughout this DPA:

  • "Personal Data" means any information relating to an identified or identifiable natural person that AICSUITE processes on behalf of Customer in connection with the Services.
  • "Data Subject" means the natural person to whom Personal Data relates (such as Customer's employees, contractors, or clients).
  • "Data Protection Law" means all applicable data protection and privacy laws, including the GDPR, UK GDPR, CCPA/CPRA, and similar laws.
  • "Processing" has the meaning given in the GDPR.
  • "Subprocessor" means any third party engaged by AICSUITE to process Personal Data on AICSUITE's behalf.
  • "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.

2. Scope and Purpose of Processing

AICSUITE will process Personal Data only on behalf of and in accordance with the documented instructions of Customer (which include this DPA, the Terms of Service, and Customer's configuration and use of the Services), except where required to do otherwise by applicable law. The subject matter, nature, purpose, duration, types of Personal Data, and categories of Data Subjects are described in Annex 1.

Customer is the controller of Personal Data submitted to the Services and is responsible for the lawfulness of collection, the legal basis for processing, and obtaining all necessary notices and consents from Data Subjects.

3. Obligations of the Processor

AICSUITE will:

  • Process Personal Data only on Customer's documented instructions;
  • Ensure that personnel authorized to process Personal Data are bound by written confidentiality obligations and receive appropriate training;
  • Implement and maintain the technical and organizational measures described in Annex 2;
  • Provide reasonable assistance to Customer with: (a) responding to Data Subject requests; (b) ensuring the security of processing; (c) notifying Personal Data Breaches; (d) carrying out data-protection impact assessments; and (e) consulting with supervisory authorities, taking into account the nature of processing and the information available to AICSUITE;
  • Make available all information reasonably necessary to demonstrate compliance with this DPA and Article 28 GDPR;
  • Promptly inform Customer if, in AICSUITE's opinion, an instruction infringes applicable Data Protection Law.

4. Sub-processing

Customer grants AICSUITE general written authorization to engage Subprocessors to process Personal Data, subject to the following:

  • AICSUITE will maintain an up-to-date list of Subprocessors at aicsuite.com/en/legal/subprocessors;
  • AICSUITE will impose contractual obligations on each Subprocessor that are no less protective than those in this DPA;
  • AICSUITE will provide reasonable advance notice of new Subprocessors (no less than thirty (30) days where practicable), and Customer may object on reasonable data-protection grounds. If the parties cannot resolve the objection, Customer may terminate the affected portion of the Services;
  • AICSUITE remains responsible to Customer for the acts and omissions of its Subprocessors.

5. Data Subject Rights

AICSUITE will, taking into account the nature of the processing, provide reasonable assistance to Customer (by appropriate technical and organizational measures) in fulfilling Customer's obligation to respond to requests from Data Subjects exercising their rights under Data Protection Law. If AICSUITE receives a request directly from a Data Subject regarding Personal Data, AICSUITE will, without undue delay, forward the request to Customer and will not respond except as required by law or instructed by Customer.

6. Security Measures (Technical and Organizational Measures)

AICSUITE has implemented and will maintain the security measures described in Annex 2, designed to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, the nature, scope, context, and purposes of processing, and the risks to the rights and freedoms of Data Subjects.

7. Personal Data Breach Notification

AICSUITE will notify Customer without undue delay, and in any event within seventy-two (72) hours of becoming aware of a Personal Data Breach affecting Customer's Personal Data. Each notification will include, to the extent known at the time:

  • The nature of the Personal Data Breach;
  • Categories and approximate number of Data Subjects and records affected;
  • The likely consequences of the breach;
  • Measures taken or proposed to address the breach and mitigate possible adverse effects;
  • The contact point for further information.

AICSUITE will cooperate with Customer's reasonable investigation and remediation activities. Customer remains responsible for notifying supervisory authorities and Data Subjects as required by applicable law.

8. International Data Transfers

To the extent Personal Data of Data Subjects in the EEA, UK, or Switzerland is transferred outside those jurisdictions to a country without an adequacy decision, the parties agree that the EU Standard Contractual Clauses (Module 2: Controller to Processor, and Module 3: Processor to Processor where applicable), together with the UK International Data Transfer Addendum or UK IDTA where applicable, are incorporated by reference and apply to such transfers. AICSUITE will provide the executed clauses upon written request.

9. Audits

AICSUITE will, no more than once per twelve (12) month period (except following a material Personal Data Breach or as required by a supervisory authority), make available to Customer copies of relevant third-party audit reports, security certifications (when obtained), and policies, sufficient to allow Customer to verify AICSUITE's compliance with this DPA. Customer may request an on-site audit at its expense subject to reasonable advance notice, scope, confidentiality protections, and not unreasonably interfering with AICSUITE's business operations.

10. Term and Termination

This DPA takes effect on the Effective Date and remains in force as long as AICSUITE processes Personal Data on behalf of Customer under the Terms of Service. Provisions which by their nature should survive termination will survive.

11. Return or Deletion of Personal Data

Upon termination of the Services, Customer may export Personal Data for thirty (30) days. Thereafter, AICSUITE will delete or anonymize all Personal Data within sixty (60) days, except to the extent retention is required by applicable law or backups, in which case the data will remain encrypted, isolated, and subject to deletion within ninety (90) days following the next backup-rotation cycle.

12. Liability

Each party's liability under this DPA is subject to the limitations of liability set forth in the Terms of Service.


Annex 1 — Description of Processing

A. Subject Matter and Duration

AICSUITE processes Personal Data to provide the Services for the duration of the Customer's subscription, plus a limited wind-down period following termination as described in this DPA.

B. Nature and Purpose of Processing

Collection, recording, organization, structuring, storage, retrieval, consultation, use, disclosure by transmission, restriction, erasure, and destruction of Personal Data for the purpose of providing the Services (workforce management, payroll calculation, scheduling, invoicing, and related operational features).

C. Categories of Data Subjects

  • Customer's authorized users (Administrators, Managers, Staff);
  • Customer's workforce members (Employees and Contractors managed in the Services);
  • Customer's clients and contacts whose data is entered into the Services;
  • Other natural persons whose data is included in Customer Data submitted to the Services.

D. Categories of Personal Data

  • Identification and contact data (name, email, phone, address);
  • Sensitive identifiers: Social Security Numbers and other government identifiers (encrypted at rest using AES-256);
  • Employment and engagement data (worker classification, role, hire/start date, status);
  • Compensation and payroll data (rates, hours, deductions, banking details for direct deposit, where applicable);
  • Scheduling, assignment, and job-related data;
  • Communication and audit-log data;
  • Authentication and account credentials (passwords as salted hashes only).

E. Frequency

Continuous, throughout the term of the Services.


Annex 2 — Technical and Organizational Measures (TOMs)

A. Confidentiality

  • Role-based access control with a least-privilege, five-tier role model (Administrator, Manager, Staff, Contractor, User);
  • Row-Level Security (RLS) at the PostgreSQL database layer to enforce tenant isolation;
  • Encryption at rest using AES-256 for sensitive identifiers (e.g., SSNs) and banking data;
  • Encryption in transit using TLS 1.2 or higher;
  • Personnel bound by written confidentiality obligations and access only on a need-to-know basis.

B. Integrity

  • Input validation and parameterized database queries;
  • Audit logging of administrative and data-modifying actions;
  • Change management and code review for production changes.

C. Availability and Resilience

  • Managed cloud infrastructure (AWS, Cloudflare, Supabase);
  • Regular automated backups with monitored restore procedures;
  • Monitoring and alerting on availability and error rates.

D. Authentication

  • Salted, hashed password storage;
  • JWT-based session tokens;
  • Multi-factor authentication available for accounts (recommended for Administrators and Managers).

E. Vendor Management

Written agreements with each Subprocessor that impose data-protection obligations no less protective than this DPA.

F. Incident Response

Documented incident-response process with defined roles, escalation paths, and 72-hour breach-notification commitment to Customers.

G. Compliance Roadmap

AICSUITE is actively pursuing SOC 2 Type II attestation. See the Security Overview for current status.


Contact

For DPA execution, supervisory-authority correspondence, or related inquiries, contact:

Questions about this document?

Email us at legal@aicsuite.com

AICSUITE, LLC · A Delaware limited liability company