Data Processing Addendum.
The agreement under which AutoOps processes personal data on your behalf, including Standard Contractual Clauses where applicable.
Last updated: July 23, 2026
1. Parties & scope
This Data Processing Addendum ("DPA") forms part of the Terms of Service between AutoOps AI ("Processor") and the customer ("Controller"). It applies whenever we process Personal Data contained in Customer Data on the customer's behalf. This page is the operative document — no signature is needed for it to apply. If your procurement process requires a countersigned copy, email contact@autopsai.com with your organization name, billing email, and a data-protection contact; we aim to return a signed copy within a few business days.
2. Definitions
"Personal Data", "Processing", "Data Subject", and "Sub-processor" have the meanings given in applicable data protection laws — the GDPR, UK GDPR, and CCPA as applicable ("Data Protection Laws"). "Customer Data" has the meaning given in the Terms.
3. Roles
The customer is the controller of Personal Data in Customer Data; AutoOps is its processor. For account and billing data, AutoOps is an independent controller and the Privacy Policy governs.
4. Details of processing
| Subject matter | Provision of the AutoOps AI Services |
| Duration | The term of the agreement, plus the deletion window in Section 10 |
| Nature & purpose | Hosting, SAP synchronization, AI-assisted chat and report generation, support |
| Data subjects | The customer's users and personnel; individuals appearing in uploaded files or synced SAP records |
| Data categories | Names, business contact details, user-generated content, identifiers in SAP records, IP addresses in audit logs |
5. Our obligations as processor
- Instructions. We process Personal Data only on the customer's documented instructions — the Terms plus your in-product configuration are those instructions.
- Confidentiality. Everyone authorized to process Personal Data is bound by confidentiality obligations.
- Security. We maintain the technical and organizational measures described on the security page: bcrypt-12 password hashing, AES-256-GCM encryption at rest for SAP credentials, org-scoped RBAC, private storage buckets with short-lived signed URLs, HTTPS in transit, and append-only audit logging.
- Assistance. We provide reasonable assistance with data-subject requests and with the controller's security and impact-assessment obligations — start at contact@autopsai.com.
6. Sub-processors
The customer grants general written authorization to engage the sub-processors listed at /legal/sub-processors. We provide operational change notice before a new sub-processor handles Customer Data. The method and period are stated in a signed DPA or order form once a subscriber process is operating. You may object on reasonable data-protection grounds; if we can't resolve the objection, you may terminate the affected service. Each sub-processor is bound by its own data-processing terms.
7. Personal data breach
If we become aware of a personal data breach affecting Customer Data, we notify the controller without undue delay, with the information available to us: the nature of the breach, categories and approximate volumes of data affected, and the measures taken.
8. International transfers
The current posture is US-first. This page does not execute or complete the EU Standard Contractual Clauses or UK Addendum. Before accepting EEA/UK customer data, the parties must complete the relevant SCC annexes, transfer assessment, and UK Addendum with provider and transfer details.
9. Audits & information
We make available the information reasonably necessary to demonstrate compliance with this DPA: the security page, our security one-pager, and written responses to reasonable security questionnaires. Honest limit: at our current size we don't support on-site audits.
10. Return & deletion
Customer Data can be returned and deleted self-serve at any time, in Settings → Account (JSON export with time-limited file links; account deletion). On termination of the Services, upon request made within 30 days, we also return and/or delete Customer Data on your behalf, and then delete remaining copies — except where law requires us to retain them.
11. Liability & precedence
Liability under this DPA is subject to the limitation of liability in the Terms. If this DPA conflicts with the Terms on data protection, this DPA prevails.
12. Execution
To request a counsel-reviewed, countersigned DPA and its completed processing details, email contact@autopsai.com with your organization name, billing email, and a contact for data protection matters.