Data Processing Addendum
Last updated: July 14, 2026
This Data Processing Addendum ("DPA") is a pilot-stage review draft. It does not become an executed agreement unless Edvin.ai and the customer agree to it in writing. Obtain qualified legal review before relying on it.
1. Roles and scope
For customer personal data processed to provide the Service, the customer acts as controller and Edvin.ai acts as processor, unless applicable law assigns different roles.
Processing is limited to documented customer instructions, the Service configuration, and actions a customer authorizes through Edvin.
2. Processing details
The subject matter is the operation of an AI-assisted workspace. Processing may include hosting, retrieval, generation, summarization, classification, connected-account access, file handling, durable task execution, audit logging, support, and security operations.
Data subjects may include customer personnel, customers, prospects, suppliers, and other people whose information the customer lawfully provides. Data may include account details, business communications, files, task context, generated outputs, usage records, and integration metadata.
Customers must not provide special-category or highly sensitive personal data unless the parties have expressly agreed appropriate safeguards.
3. Confidentiality and security
Edvin.ai will limit personnel access to people who need it for support, security, legal obligations, or service operation and who are subject to confidentiality obligations.
Current technical and organizational measures are described on the Security & Data Handling page. No security control eliminates all risk.
4. Subprocessors
The current, configuration-backed list is published on the Subprocessors page. The customer authorizes those subprocessors for the purposes described there. Material changes should be communicated through the Service or the customer's registered contact where practicable.
5. Assistance and incidents
Taking into account the nature of processing, Edvin.ai will provide reasonable assistance with verified data-subject requests, security inquiries, and legally required assessments.
Edvin.ai will notify the customer without undue delay after confirming a personal-data breach affecting customer data and will share available information needed for the customer's response. A contractual notification deadline must be agreed in an executed DPA; this draft does not invent one.
6. Return, export, and deletion
Workspace owners and admins can export supported workspace data and request deletion through Settings. Limited records may be retained where required for security, billing, disputes, abuse prevention, or law.
7. International transfers
Where a subprocessor processes data outside the EEA and a transfer mechanism is required, the parties should use an applicable lawful safeguard, such as an adequacy decision or standard contractual clauses. Exact transfer terms must be confirmed during legal review.
8. Audit information
Edvin.ai will make reasonable security and processing information available to pilot customers. On-site audits, certifications, and specialized regulatory commitments require a separate written agreement.
9. Priority and contact
If an executed DPA conflicts with the Terms of Service regarding processing of customer personal data, the executed DPA controls for that conflict.
Questions and execution requests: [email protected]