Legal review required. This pilot-stage document is public for transparency, but it must be reviewed by qualified counsel before contractual reliance.

Data Processing Addendum

Last updated: July 14, 2026

This Data Processing Addendum ("DPA") is a pilot-stage review draft. It does not become an executed agreement unless Edvin.ai and the customer agree to it in writing. Obtain qualified legal review before relying on it.

1. Roles and scope

For customer personal data processed to provide the Service, the customer acts as controller and Edvin.ai acts as processor, unless applicable law assigns different roles.

Processing is limited to documented customer instructions, the Service configuration, and actions a customer authorizes through Edvin.

2. Processing details

The subject matter is the operation of an AI-assisted workspace. Processing may include hosting, retrieval, generation, summarization, classification, connected-account access, file handling, durable task execution, audit logging, support, and security operations.

Data subjects may include customer personnel, customers, prospects, suppliers, and other people whose information the customer lawfully provides. Data may include account details, business communications, files, task context, generated outputs, usage records, and integration metadata.

Customers must not provide special-category or highly sensitive personal data unless the parties have expressly agreed appropriate safeguards.

3. Confidentiality and security

Edvin.ai will limit personnel access to people who need it for support, security, legal obligations, or service operation and who are subject to confidentiality obligations.

Current technical and organizational measures are described on the Security & Data Handling page. No security control eliminates all risk.

4. Subprocessors

The current, configuration-backed list is published on the Subprocessors page. The customer authorizes those subprocessors for the purposes described there. Material changes should be communicated through the Service or the customer's registered contact where practicable.

5. Assistance and incidents

Taking into account the nature of processing, Edvin.ai will provide reasonable assistance with verified data-subject requests, security inquiries, and legally required assessments.

Edvin.ai will notify the customer without undue delay after confirming a personal-data breach affecting customer data and will share available information needed for the customer's response. A contractual notification deadline must be agreed in an executed DPA; this draft does not invent one.

6. Return, export, and deletion

Workspace owners and admins can export supported workspace data and request deletion through Settings. Limited records may be retained where required for security, billing, disputes, abuse prevention, or law.

7. International transfers

Where a subprocessor processes data outside the EEA and a transfer mechanism is required, the parties should use an applicable lawful safeguard, such as an adequacy decision or standard contractual clauses. Exact transfer terms must be confirmed during legal review.

8. Audit information

Edvin.ai will make reasonable security and processing information available to pilot customers. On-site audits, certifications, and specialized regulatory commitments require a separate written agreement.

9. Priority and contact

If an executed DPA conflicts with the Terms of Service regarding processing of customer personal data, the executed DPA controls for that conflict.

Questions and execution requests: [email protected]