Data Processing Addendum
The terms under which Asrar Studio SARL processes personal data on behalf of business customers, including security measures, subprocessors, breach notification and international transfers.
This Data Processing Addendum (the “DPA”) forms part of the Terms of Service (the “Agreement”) between Asrar Studio SARL (“Processor”, “Asrar”) and the customer that owns the workspace (“Customer”, “Controller”). It applies automatically when Asrar processes Customer Personal Data on the Customer’s behalf. A countersigned copy is available on request at legal@asrar.example.
1. Definitions
Data Protection Laws means all laws applicable to the processing of Customer Personal Data under the Agreement, including Regulation (EU) 2016/679 (“GDPR”), the UK GDPR, the Swiss FADP and Moroccan Law No. 09-08. Customer Personal Data means personal data contained in Customer Content that Asrar processes on behalf of Customer. Subprocessor, personal data breach, processing, controller, processor and data subject have the meanings given in the GDPR.
2. Roles and scope
2.1. Customer is the controller (or a processor acting for its own controller) and Asrar is the processor of Customer Personal Data.
2.2. Asrar processes Customer Personal Data only on Customer’s documented instructions, which consist of the Agreement, this DPA, and the configuration and use of the Service by Customer’s authorised users (including creating cards, running agents, connecting integrations and approving actions). Asrar will inform Customer if, in its opinion, an instruction infringes Data Protection Laws.
2.3. Details of the processing are set out in Annex 1.
3. Processor obligations
Asrar will:
- ensure that people authorised to process Customer Personal Data are bound by confidentiality;
- implement the technical and organisational measures described in Annex 2;
- not use Customer Personal Data to train or fine-tune AI models, and not sell it or use it for its own purposes;
- assist Customer, taking into account the nature of processing, in responding to data-subject requests and in complying with its obligations on security, breach notification, data protection impact assessments and prior consultation;
- make available the information necessary to demonstrate compliance with this DPA.
4. Subprocessors
4.1. Customer grants a general authorisation for Asrar to engage Subprocessors. The current list is published on the subprocessors page.
4.2. Asrar will give at least 30 days’ notice of a new Subprocessor by updating that page and emailing workspace owners who subscribed to updates. Customer may object on reasonable data-protection grounds within that period; the parties will discuss the objection in good faith and, failing resolution, Customer may terminate the affected Service and receive a refund of prepaid fees for it.
4.3. Asrar imposes data-protection obligations on each Subprocessor that are no less protective than this DPA and remains liable for its Subprocessors’ performance.
4.4. Third-party services that Customer chooses to connect (for example Slack, Notion, Google Drive, an email provider or a webhook endpoint) are not Subprocessors; data is sent to them at Customer’s direction.
5. Personal data breaches
Asrar will notify Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data, and will provide the information Customer reasonably needs to meet its own notification obligations, updating it as more becomes known. Notification is not an acknowledgement of fault.
6. Audits
Asrar will answer reasonable security questionnaires once per year and provide summaries of relevant third-party audit reports where available. If required by Data Protection Laws or a supervisory authority, Customer may conduct an audit on 30 days’ written notice, during business hours, at its own cost, subject to confidentiality and without access to other customers’ data.
7. International transfers
Asrar hosts the Service primarily in the European Union. Where Customer Personal Data is transferred to a country that does not provide an adequate level of protection, the parties agree that the European Commission’s Standard Contractual Clauses (Module 2 or Module 3, as applicable), together with the UK International Data Transfer Addendum and Swiss amendments where relevant, are incorporated by reference, with Asrar as data importer. Asrar applies supplementary measures including encryption in transit and at rest and a policy for challenging government access requests.
8. Deletion and return
Customer can export Customer Content at any time. Upon termination, or when a workspace is deleted, Asrar deletes Customer Personal Data from active systems within 30 days and from backups within a further 35 days, unless retention is required by law.
9. Liability and precedence
Each party’s liability under this DPA is subject to the limitations in the Agreement, except where Data Protection Laws do not allow such limitation. If there is a conflict, the Standard Contractual Clauses prevail over this DPA, and this DPA prevails over the Agreement.
Annex 1 — Details of processing
| Item | Description |
|---|---|
| Subject matter | Provision of the Dispatch service to Customer |
| Duration | For the term of the Agreement plus the deletion periods in section 8 |
| Nature and purpose | Hosting, storage, transmission, retrieval, AI processing (agent runs using the tools configured by Customer), rendering and export of Customer Content; support and security |
| Categories of data subjects | Customer’s authorised users; people whose data Customer includes in cards, attachments, comments, prompts and artifacts (for example Customer’s clients, leads, contacts and employees) |
| Categories of personal data | Identification and contact data; professional data; any personal data Customer chooses to include in Customer Content |
| Special categories | None intended. Customer will not submit special-category data without an appropriate legal basis and safeguards |
| Frequency | Continuous, as initiated by Customer’s use of the Service |
Annex 2 — Technical and organisational measures
- Encryption: TLS 1.2+ in transit; encryption at rest for databases, backups and object storage; integration secrets and custom-tool headers additionally encrypted with AES-256-GCM using keys that can be rotated.
- Access control: role-based workspace permissions; least-privilege staff access with multi-factor authentication; staff access to Customer Content is logged and limited to support, security and legal needs.
- Tenant isolation: every data query is scoped to the workspace at the data-access layer.
- Files: private storage buckets; downloads only through short-lived signed URLs after an authorisation check.
- Application security: input validation on every endpoint; rate limiting on authentication, API and run creation; protection of the fetch tools against private-network access (SSRF); dependency updates.
- Human oversight: approval gates before side-effecting actions; audit logs for administrative actions, approvals and tool executions.
- Availability: daily backups with 35-day retention; monitoring and alerting; documented incident response.
- Organisation: confidentiality commitments for staff; security awareness; vendor assessment for Subprocessors.