Draft template, not a signable document. This outlines the real clauses a Data Processing Agreement with us would contain. It needs our Terms of Service finalized and counsel review before either party can rely on it — if you need a signed DPA today, contact us through your account's support channel to start that process.

Data Processing Agreement

Governs how PinkyAI, as processor, handles personal data on your behalf as controller.

1. Parties & scope

You (controller) and PinkyAI, Inc. (processor). Scope is limited to the data listed on our Privacy policy page — account email/name, org membership, and telemetry if you opt in.

2. Processing instructions

We process data only to provide the service and per your documented instructions — no independent use beyond that.

3. Sub-processors

AWS, Auth0, and Sentry are our only sub-processors today. We'll give reasonable notice before adding a new one, and you can object.

4. Security measures

See our Security & trust page for the architecture and controls this DPA relies on.

5. Data subject requests

We assist you in fulfilling access/deletion requests. Account deletion is a real, working mechanism, not a stated intention.

6. Breach notification

See our data-breach notification runbook for the timeline we commit to.

7. International transfers

None today — all processing described above happens in AWS's US regions.

8. Term & deletion on termination

Data is deleted or returned within a stated window after contract end — the exact window is a business term, set per contract.

See also: Privacy policy, Terms of Service.