Data Processing Addendum

Ameena AI, Inc.

Effective upon incorporation into or execution with the applicable Agreement

This Data Processing Addendum ("DPA") forms part of the Terms of Service, order form, enterprise agreement, or other written agreement governing Customer's use of the Ameena.ai services (the "Agreement") between Ameena AI, Inc. ("Ameena AI") and the customer identified in the Agreement ("Customer"). For self-service plans, this DPA is incorporated into the Agreement by reference when Customer accepts the applicable Terms. For Enterprise customers, this DPA may be executed separately or attached as an exhibit to a negotiated agreement. Capitalized terms not defined in this DPA have the meanings given in the Agreement.

1. Scope and Roles

1.1 This DPA applies only to personal data contained in Customer Data that Ameena AI processes on behalf of Customer in providing the Service ("Customer Personal Data"). As between the parties, Customer is the controller or business and Ameena AI is the processor, service provider, or contractor, as those terms are defined by Applicable Data Protection Law, except where the law requires a different characterization.

1.2 This DPA does not govern personal data Ameena AI processes for its own independent purposes, including account administration, direct billing, website analytics, security, fraud prevention, legal compliance, and other activities for which Ameena AI determines the purposes and means of processing. Those activities are addressed by the Ameena AI Privacy Policy and other applicable terms.

1.3 "Applicable Data Protection Law" means privacy, data protection, and data security laws applicable to the processing of Customer Personal Data under the Agreement, including, where applicable, the EU General Data Protection Regulation 2016/679 ("EU GDPR"), the UK GDPR, and applicable U.S. state privacy laws.

2. Processing Instructions

2.1 Ameena AI will process Customer Personal Data only on Customer's documented instructions, including as necessary to provide, secure, maintain, support, and improve the Service for Customer, to perform the Agreement, and as otherwise documented by Customer through its configuration and use of the Service.

2.2 Customer instructs Ameena AI to process Customer Personal Data as described in Schedule 1 and to disclose Customer Personal Data to authorized subprocessors as described in this DPA.

2.3 If Ameena AI is required by applicable law to process Customer Personal Data other than on Customer's instructions, Ameena AI will inform Customer of that legal requirement before processing unless the law prohibits such notice. Ameena AI will promptly inform Customer if, in Ameena AI's opinion, a Customer instruction infringes Applicable Data Protection Law.

2.4 Customer is responsible for the lawfulness of its instructions, Customer Personal Data, and the means by which Customer obtained the data, including providing any required notices and obtaining any required consents or other legal bases.

3. Confidentiality

Ameena AI will ensure that personnel authorized to process Customer Personal Data, including employees and contractors, are subject to appropriate confidentiality obligations, are granted access on a least-privilege basis, and access Customer Personal Data only as necessary to provide the Service, including troubleshooting at Customer's request or addressing security matters. Authorized personnel and subprocessors may process Customer Personal Data from locations where Ameena AI or the applicable subprocessor operates, subject to this DPA and any transfer mechanism required by Applicable Data Protection Law.

4. Security

4.1 Taking into account the nature of the processing, the state of the art, implementation costs, and the risks to individuals, Ameena AI will maintain reasonable and appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.

4.2 The current measures are summarized in Schedule 2. Customer acknowledges that security measures may evolve as the Service develops, provided Ameena AI does not materially reduce the overall level of protection for Customer Personal Data during the term of the Agreement.

4.3 Ameena AI does not represent that it holds any security certification unless expressly stated in a separate written agreement.

5. Customer-Selected Models and BYOK

5.1 Certain plans may allow Customer to connect a supported third-party AI model or provider using Customer's own API key, account, or credentials (a "Customer-Selected Model"). Current supported Customer-Selected Model options may include Anthropic/Claude and OpenAI/ChatGPT where enabled in the Service. Customer instructs Ameena AI to transmit Customer Personal Data to the Customer-Selected Model as necessary to provide the requested functionality.

5.2 Ameena AI remains responsible for its own processing of Customer Personal Data, including routing data through the Service to the Customer-Selected Model on Customer's instruction. Customer is responsible for selecting and configuring its provider account, including the provider's retention, privacy, security, and model-training settings.

5.3 Ameena AI does not control and does not make representations regarding a Customer-Selected Model provider's independent downstream processing, policies, account settings, or practices. Customer's use of a Customer-Selected Model is also subject to that provider's applicable terms.

6. Subprocessors

6.1 Customer grants Ameena AI general written authorization to engage subprocessors to process Customer Personal Data in connection with the Service. Ameena AI will impose data protection obligations on each subprocessor that are no less protective in substance than the obligations applicable to Ameena AI under this DPA, to the extent required by Applicable Data Protection Law.

6.2 Ameena AI's current subprocessors are listed in Schedule 3. Customer grants Ameena AI general authorization to add or replace subprocessors as the Service evolves. Ameena AI will ordinarily provide at least thirty (30) days' advance notice of a new subprocessor that will materially process Customer Personal Data. Notice may be provided by email, in-app notification, or by posting an updated subprocessor list or updates page made available by Ameena AI. Ameena AI may provide a shorter notice period where reasonably necessary to address an urgent security or business-continuity issue, outage, vendor discontinuation, or material provider policy change.

6.3 Customer may object to a new subprocessor on reasonable data protection grounds by written notice within ten (10) days after receiving notice. The parties will work in good faith to address the objection. If they cannot reasonably resolve it, Ameena AI may provide an alternative if commercially reasonable or Customer may discontinue the affected feature or Service.

6.4 Ameena AI remains responsible for the performance of its subprocessors to the extent required by Applicable Data Protection Law. For clarity, a third-party provider connected as a Customer-Selected Model under Section 5, including Anthropic/Claude or OpenAI/ChatGPT when connected using Customer's own API key, account, or credentials, is a customer-directed integration and is not a subprocessor engaged by Ameena AI under this Section solely by virtue of that Customer-selected use. Ameena AI remains responsible for its own processing and routing of Customer Personal Data as described in Section 5.

7. Data Subject Requests

Taking into account the nature of the processing, Ameena AI will provide reasonable assistance to Customer, through appropriate technical and organizational measures where feasible, to help Customer respond to requests by individuals exercising rights under Applicable Data Protection Law. If Ameena AI receives a request relating to Customer Personal Data for which Customer is responsible, Ameena AI will promptly forward or refer the request to Customer, generally within five (5) business days, unless prohibited by law. Requests concerning personal data that Ameena AI processes for its own independent purposes, such as user account or billing-contact information, will be handled by Ameena AI under its Privacy Policy and applicable law.

8. Personal Data Breaches

8.1 Ameena AI will notify Customer without undue delay after becoming aware of a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data ("Personal Data Breach").

8.2 To the extent reasonably available, the notice will describe the nature of the Personal Data Breach, the categories of affected data, likely consequences, and measures taken or proposed to address it. Ameena AI may provide information in phases as it becomes available.

8.3 Ameena AI's notification of a Personal Data Breach is not an acknowledgment of fault or liability.

9. Assistance with Compliance

Taking into account the nature of the processing and information available to Ameena AI, Ameena AI will provide reasonable assistance to Customer with Customer's obligations relating to security, breach notifications, data protection impact assessments, and prior consultation with supervisory authorities, to the extent required by Applicable Data Protection Law. Additional assistance that is materially beyond the ordinary operation of the Service may be subject to reasonable fees if permitted by law.

10. Return and Deletion

10.1 During the term, Customer may retrieve or export Customer Data using the export functionality then available in the Service. Customer is responsible for completing any desired retrieval or export before deletion. Ameena AI does not commit to provide a bespoke, complete, or post-termination export beyond the functionality then available in the Service. Upon Customer's deletion of its account, or within thirty (30) days after termination or expiration of the Agreement, Ameena AI will delete Customer Personal Data from its production systems, unless applicable law requires continued storage.

10.2 Residual copies of Customer Personal Data in backup systems will be deleted through Ameena AI's standard backup rotation and, in any event, within two hundred ten (210) days after deletion from production systems. Until deletion, backup copies will remain encrypted and subject to this DPA and will not be used for any purpose other than disaster recovery, security, or legal compliance. If a backup containing data scheduled for deletion is restored, Ameena AI will re-apply the applicable deletion. Customer Personal Data held by subprocessors will be deleted in accordance with the applicable subprocessor's contractual obligations and standard retention practices.

11. Audits and Information

11.1 Ameena AI will make available information reasonably necessary to demonstrate compliance with the processor obligations applicable under this DPA. Customer will first use available documentation, questionnaires, and other remote means to assess compliance.

11.2 If Applicable Data Protection Law requires an audit and the available information is not reasonably sufficient, Customer may conduct or appoint an independent auditor to conduct an audit no more than once in any twelve-month period, except following a material Personal Data Breach or where a regulator requires otherwise. Audits must be conducted on reasonable prior written notice, during normal business hours, in a manner that avoids unreasonable disruption and protects other customers' confidential information.

11.3 Customer will bear its audit costs unless Applicable Data Protection Law requires otherwise. No audit may include penetration testing or access to another customer's data, source code, or systems unrelated to Customer without Ameena AI's prior written consent.

11.4 Responses provided by Ameena AI to security questionnaires, diligence requests, or similar informational materials are for informational purposes only and do not create binding security, service-level, warranty, or other contractual commitments unless expressly incorporated into a written order form, enterprise agreement, or addendum signed by Ameena AI.

12. U.S. State Privacy Requirements

To the extent Ameena AI processes Customer Personal Data as a service provider, contractor, or processor under applicable U.S. state privacy law, Ameena AI will: (a) process the data only for the limited and specified purposes described in the Agreement, this DPA, and Customer's documented instructions; (b) not sell or share Customer Personal Data for cross-context behavioral advertising; (c) not retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer except as permitted by law; (d) not combine Customer Personal Data with personal data received from or on behalf of another person except as permitted by applicable law; and (e) notify Customer if Ameena AI determines it can no longer meet an applicable statutory obligation. Customer may take reasonable and appropriate steps to help ensure Ameena AI uses Customer Personal Data consistently with applicable law and, upon reasonable prior written notice, to stop and remediate any unauthorized use of Customer Personal Data. Ameena AI certifies that it understands and will comply with the restrictions and obligations applicable to it under this Section.

13. GDPR and UK GDPR Terms

13.1 Where the EU GDPR or UK GDPR applies to Ameena AI's processing of Customer Personal Data, the parties intend this DPA to satisfy Article 28 requirements, including processing on documented instructions, confidentiality, security, subprocessors, assistance with data subject rights and controller obligations, deletion or return, and information and audit rights.

13.2 The standard Service and this DPA are offered for U.S.-based processing arrangements and do not themselves incorporate the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, or another international transfer mechanism. A non-U.S. Customer, or any Customer requiring a transfer mechanism for Customer Personal Data, must contact Ameena AI to enter into the applicable data transfer addendum or other agreed transfer terms before the relevant transfer.

13.3 Nothing in this DPA requires Ameena AI to process Customer Personal Data in a jurisdiction, permit access from a jurisdiction, or support a transfer mechanism that Ameena AI has not agreed to support in writing.

14. Order of Precedence; Liability

14.1 If this DPA conflicts with the Agreement regarding the processing or protection of Customer Personal Data, this DPA controls to the extent of that conflict. However, any security, privacy, or data-protection term expressly negotiated and included in a signed order form, enterprise agreement, or addendum will control to the extent it expressly states that it supersedes the applicable provision of this DPA. Security questionnaires, diligence responses, emails, or other informational materials do not amend this DPA unless expressly incorporated into a signed agreement. The Agreement otherwise remains in effect.

14.2 Except to the extent prohibited by Applicable Data Protection Law, each party's liability arising out of or relating to this DPA is subject to the exclusions, limitations, and caps in the Agreement.

15. Term

This DPA remains in effect for as long as Ameena AI processes Customer Personal Data on Customer's behalf under the Agreement. Provisions that by their nature should survive termination, including confidentiality, deletion, liability, and applicable audit or regulatory obligations, will survive.

Schedule 1 — Details of Processing

Subject matterProvision of the Ameena.ai business-to-business AI marketing platform and related features, integrations, support, and account functionality.
DurationFor the term of the Agreement and any limited period afterward during which Customer Personal Data remains in the Service or backups as permitted by this DPA.
Nature and purposeHosting, storing, organizing, transmitting, analyzing, retrieving, displaying, securing, supporting, and otherwise processing Customer Personal Data to provide the Service and Customer-requested AI and integration functionality.
Data subjectsCustomer personnel, Customer prospects, leads, contacts, customers, and other individuals whose personal data Customer submits, uploads, connects, or otherwise makes available through the Service.
Types of personal dataBusiness contact information; CRM and campaign information; prompts, conversation content, images, files, and other user-submitted content; integration data; identifiers and metadata contained in Customer Data; and other personal data Customer chooses to process through the Service, subject to the Agreement's restricted-data provisions.
Special categories / sensitive dataCustomer must not submit special-category data, protected health information (PHI), payment-card data or financial account numbers, government identification numbers, children's data, or other highly sensitive or specially regulated personal data unless Ameena AI expressly agrees in writing. Ameena AI is not a HIPAA business associate and does not undertake HIPAA business associate obligations unless expressly agreed in a separate written agreement. Ameena AI does not use image-processing functionality to identify individuals.
Processing frequencyContinuous or as initiated by Customer and its authorized users through use of the Service.
Controller rights and obligationsAs set out in the Agreement, this DPA, Customer's documented instructions, and Applicable Data Protection Law.

Schedule 2 — Technical and Organizational Measures

The following summarizes Ameena AI's current measures relevant to Customer Personal Data. These measures may be updated as the Service evolves, subject to Section 4 of the DPA.

Encryption and transmission

  • Service traffic is transmitted over HTTPS/TLS.
  • Customer-provided AI provider keys used for BYOK functionality are encrypted before storage using AES-256-GCM authenticated encryption.

Hosting and network protection

  • The production database is not directly exposed to the public internet and is reachable through the application environment.
  • Application and database hosting are provided through third-party infrastructure.

Tenant isolation

  • Customer-owned records are logically scoped by organization within the application data model.
  • Customer content is not combined across organizations for cross-customer model training or customer-facing benchmarking.

Access controls

  • Production access is restricted to authorized personnel using individually issued credentials and least-privilege access principles.
  • Customer access is authenticated through account credentials and application-level authorization controls.

Backups

  • Automated database backups are maintained.
  • Backup archives are encrypted and stored off-site using Cloudflare R2.
  • Backups are maintained on a rotating daily, weekly, and monthly schedule.

Deletion

  • Organization-level account deletion functionality is designed to delete organization-scoped data from production systems through application/database cascade controls.
  • Residual backup copies are encrypted and deleted through ordinary backup rotation, with an outside retention period of 210 days as described in the DPA.

AI processing

  • Ameena AI uses Anthropic/Claude for hosted AI processing and currently supports Anthropic/Claude and OpenAI/ChatGPT as Customer-Selected Model options where enabled.
  • Customer content is not used by Ameena AI for cross-customer model training.

For clarity, Ameena AI does not represent in this DPA that it has completed SOC 2 or ISO 27001 certification, implemented SSO/SAML, maintains centralized infrastructure access logging, or completed a full end-to-end backup restore drill unless and until expressly confirmed in a later written update.

Schedule 3 — Current Subprocessors

ProviderPurposeApplicability / Notes
AnthropicPrimary hosted AI model processingUsed for AI processing on hosted plans.
ResendTransactional emailAccount verification, receipts, notifications, and related service communications.
HostingerApplication and database hostingHosts application and production database infrastructure.
Cloudflare R2Encrypted off-site backup storageUsed for backup storage; not in the ordinary live request path.

Customer-Selected Models, including Anthropic/Claude and OpenAI/ChatGPT when connected using Customer's own API key, account, or credentials, are addressed in Section 5 and are not included in this subprocessor list solely by virtue of Customer-selected use. Future subprocessors may be added or replaced in accordance with Section 6.

Questions? Contact support@ameena.ai. See also our Terms of Service.