AffinityAI legal
Data Processing Addendum
This DPA applies where Forito processes personal data in Customer Content on behalf of a Customer and forms part of the applicable service agreement.
1. Roles, scope and instructions
The Customer is controller and Forito is processor unless law requires otherwise. Forito processes personal data only on documented instructions in the agreement, configured use and support requests, unless legally required to do otherwise.
2. Confidentiality and security
Forito ensures authorized personnel are bound by confidentiality and uses measures appropriate to risk, including access control, encryption in transit, tenant isolation, logging controls, deletion barriers and recovery procedures.
3. Subprocessors
The Customer authorizes the subprocessors on the current Subprocessors page. Forito remains responsible for their processing obligations and provides notice of material changes with an opportunity to object on reasonable data-protection grounds.
4. Requests, incidents and assessments
Taking account of the nature of processing, Forito assists with data-subject requests, breach obligations, data-protection impact assessments and regulatory consultations. Forito will notify the Customer without undue delay after becoming aware of a Personal Data Breach.
5. Deletion and return
A commercial downgrade or the end of paid entitlement does not itself instruct Forito to delete Customer Personal Data. Commercial feature restrictions are distinct from retention and deletion. On termination of processing services, Forito deletes or returns Customer Personal Data as instructed under the agreement, unless applicable law requires limited retention.
An authorized permanent-deletion request starts access blocking immediately and ordinarily completes active-system deletion within 30 days, unless law requires limited retention. The Customer may provide deletion or return instructions through the supported account or privacy-request process.
6. Audit and compliance information
Forito provides information reasonably necessary to demonstrate compliance. Audits must be proportionate, protect other customers and avoid unnecessary disruption. Existing certifications and documentation should be used first where reasonable.
7. International transfers
Where required, the parties use the European Commission Standard Contractual Clauses and applicable UK addendum or equivalent mechanism. Forito will provide relevant transfer information reasonably available to it.
8. Processing details
Subject matter: operating AffinityAI. Duration: the service term plus agreed retention and deletion periods. Nature: collection, storage, retrieval, organization, analysis, generation, transmission and deletion. Data subjects may include authorized users, invitees, participants, customer personnel and business contacts.
9. Contact
privacy@affinityai.app
