Last updated: July 6, 2026
Data Processing Agreement
This Data Processing Agreement (“DPA”) forms Schedule B of the Master AI Platform Subscription and Services Agreement (the “Agreement”) between:
InteractiveAI Ltd., an Irish company with registration number 790653, having its registered office at 31-32 Leeson Street Lower, Dublin 2, Ireland, henceforth “Interactive AI”;
And
Customer (as defined in the Agreement);
Under which the Processor provides the Controller with the software and services (the “Services”).
The Controller and the Processor are individually referred to as a “Party” and collectively as the “Parties”. The Parties seek to implement this DPA to comply with the requirements of EU GDPR (defined hereunder) in relation to Processor's processing of Personal Data (as defined under the EU GDPR) as part of its obligations under the Agreement. This DPA shall apply to Processor's processing of Personal Data, provided by the Controller as part of Processor's obligations under the Agreement. Except as modified below, the terms of the Agreement shall remain in full force and effect.
1. Definitions
Terms not otherwise defined herein shall have the meaning given to them in the EU GDPR or the Agreement. The following terms shall have the corresponding meanings assigned to them below:
“data protection laws” means Regulation (EU) 2016/679 (the “EU GDPR”) and any other applicable legislation of the European Union, the European Economic Area, or any Member State thereof relating to the protection of personal data, in each case as amended, supplemented, or replaced from time to time;
“data transfer” means a transfer of the Personal Data from the Controller to the Processor, or between two establishments of the Processor, or with a Sub-processor by the Processor;
“EU GDPR” means Regulation (EU) 2016/679 (EU GDPR) and any other applicable legislation of the European Union, the European Economic Area, or any Member State thereof relating to the protection of personal data;
“standard contractual clauses” means the contractual clauses attached hereto as Schedule 1 pursuant to the European Commission's Implementing Decision (EU) 2021/914 of 4 June 2021 on Standard Contractual Clauses for the transfer of Personal Data to processors established in third countries which do not ensure an adequate level of data protection;
“controller” means the Customer;
“processor” means InteractiveAI Limited;
“sub-processor” means any processor engaged by the Processor to process Personal Data on behalf of the Controller, subject to a written contract that imposes data protection obligations in accordance with Article 28(4) of the GDPR;
“zero data retention” or “ZDR” means that the relevant Sub-processor processes Personal Data in transit only, does not persist, store, or log the content of requests or responses beyond what is strictly necessary to complete the processing operation, does not use such data for any other purpose, including model training or improvement, and is contractually bound to such obligations, which are subject to appropriate technical and organisational verification measures. For clarity, ZDR does not preclude the retention of metadata strictly necessary for security, billing, or error logging purposes, provided such metadata does not contain the substantive content of Personal Data.
2. Purpose of this Agreement
This DPA sets out various obligations of the Processor in relation to the Processing of Personal Data and shall be limited to the Processor's obligations under the Agreement.
If there is a conflict between the provisions of the Agreement and this DPA, this DPA shall prevail with respect to the processing of Personal Data. For all other matters, including commercial terms, fees, and limitations of liability, the provisions of the Agreement shall prevail. This order of precedence is consistent with and subject to the hierarchy set out in Recital D of the Agreement.
In the event of any conflict between this DPA and the Standard Contractual Clauses set out in Schedule 1, the Standard Contractual Clauses shall prevail to the extent of such conflict.
3. Categories of Personal Data and Data Subjects
The Controller authorises permission to the Processor to process the Personal Data to the extent of which is determined and regulated by the Controller. The current nature of the Personal Data is specified in Annex I to Schedule 1 to this DPA.
4. Purpose of Processing
The objective of Processing of Personal Data by the Processor shall be limited to the Processor's provision of the Services to the Controller and or its Client, pursuant to the Agreement.
5. Duration of Processing
The Processor will Process Personal Data for the duration of the Agreement, unless otherwise agreed upon in writing by the Controller.
6. Controller's Obligations
The Controller warrants that it has all necessary rights to provide the Personal Data to the Processor for the Processing to be performed in relation to the Services.
To the extent required by Data Protection Laws, the Controller is responsible for ensuring that it provides such Personal Data to the Processor based on an appropriate legal basis allowing lawful processing activities, including that any necessary Data Subject consents to this Processing are obtained, and for ensuring that a record of such consents is maintained. The Controller shall indemnify the Processor against all costs, claims, damages, and expenses arising from or in connection with any processing carried out by the Processor in accordance with the Controller's Instructions, to the extent that such costs, claims, damages, or expenses arise from the Controller's breach of Data Protection Laws or this DPA.
Should such consent be revoked by the Data Subject, the Controller is responsible for communicating the fact of such revocation to the Processor without undue delay.
The Controller shall provide all natural persons from whom it collects Personal Data with the relevant privacy notice.
The Controller warrants that it will not provide the Processor with special categories of personal data (as defined in Article 9 of the GDPR) without prior written notice and without having ensured that appropriate safeguards are in place. The Controller acknowledges that the Processor's technical and organisational measures are designed for the categories of data described in Annex I and may not be adequate for special categories of data absent such prior arrangement. The Controller shall indemnify and hold harmless the Processor from any claims, losses, or penalties arising from the Controller's failure to comply with this warranty.
The Controller shall request the Processor to purge Personal Data when required by the Controller or any Data Subject from whom it collects Personal Data, unless the Processor is otherwise required to retain the Personal Data by applicable law.
The Controller shall immediately advise the Processor in writing if it receives or learns of any:
- Complaint or allegation indicating a violation of Data Protection Laws regarding Personal Data;
- Request from one or more individuals seeking to access, correct, or delete Personal Data;
- Inquiry or complaint from one or more individuals relating to the collection, processing, use, or transfer of Personal Data; and
- Any regulatory request, search warrant, or other legal, regulatory, administrative, or governmental process seeking Personal Data.
7. Processor's Obligations
The Processor will follow written and documented instructions received from the Controller with respect to the Processing of Personal Data (each, an “Instruction”). Instructions may only be issued by persons duly authorised by the Controller, whose identity shall be notified to the Processor in writing. The Processing described in the Agreement and the related documentation shall be considered as Instructions from the Controller.
The Processor shall provide reasonable assistance to the Controller, taking into account the nature of processing and the information available to the Processor, to the extent required under applicable Data Protection Laws. Where such assistance requires material effort beyond the scope of the Services, it shall be provided on a time-and-materials basis in accordance with Clause 7.6 of the Agreement.
At the Controller's documented instruction, the Processor shall provide reasonable assistance to the Controller in fulfilling the Controller's obligations under Data Protection Laws regarding consent and Data Subject notification.
If the Processor considers that an instruction from the Controller violates the GDPR or any other applicable data protection law, the Processor shall promptly inform the Controller and shall be entitled to suspend the execution of the relevant instruction until the Controller confirms or amends it. The Processor shall not be liable for any delay or non-performance resulting from such suspension. Any such suspension shall not constitute a breach of this DPA or the Agreement and shall not give rise to any right of the Controller to terminate the Agreement or claim damages.
Taking into account the nature of the processing and the information available to it, the Processor shall assist the Controller in conducting any necessary Data Protection Impact Assessments (DPIAs), as required under the GDPR. Such assistance shall be provided in accordance with Clause 7.6 of the Agreement, on a time-and-materials basis as therein described.
8. Data Secrecy
The Processor will regularly train individuals having access to Personal Data in data security and data privacy in accordance with accepted industry practice and shall ensure that all Personal Data is kept strictly confidential. The Processor will maintain appropriate technical and organisational measures for protection of the security, confidentiality, and integrity of the Personal Data as per the standards mutually agreed in writing by the Parties. The obligations in this section are in addition to and without prejudice to the confidentiality obligations set out in Clause 11 of the Agreement.
9. Audit Rights
Upon Controller's reasonable request, the Processor will make available to the Controller, information as is reasonably necessary to demonstrate Processor's compliance with its obligations under the EU GDPR.
The Processor may satisfy the Controller's audit request by providing a copy of a current third-party audit report or equivalent independent assessment. The Controller shall accept such report in lieu of an on-site audit, unless the Controller demonstrates, in writing, a specific and reasonable ground for an on-site inspection not covered by the report.
When the Controller wishes to conduct an on-site audit (by itself or through a representative) at Processor's site, it shall provide at least thirty (30) days' prior written notice to the Processor. The Processor will provide reasonable cooperation and assistance in relation to such audit. The Controller shall bear the expense of such an audit. Any on-site audit shall not exceed five (5) business days and shall be conducted during the Processor's normal business hours, in a manner that minimises disruption to the Processor's operations.
The Controller shall bear the expense of such an audit.
The Controller may conduct no more than one (1) audit per calendar year, unless a Personal Data Breach has occurred or the Processor is in material breach of this DPA.
Any third-party auditor must execute a non-disclosure agreement with the Processor prior to the audit, and the Processor may refuse an auditor who is an employee of a competitor.
The Processor shall not be required to give access to commercially sensitive information, information subject to confidentiality obligations towards third parties, or information relating to other controllers.
The Controller shall deliver a copy of the audit results to the Processor within a reasonable period. In the event of non-compliance, the Processor shall propose corrective measures within thirty (30) days from receipt of the audit report.
The Controller's audit rights under this section are without prejudice to the information rights set out in Section 6 of Schedule A to the Agreement, subject to the confidentiality obligations of Clause 11 of the Agreement.
10. Mechanism of Data Transfers
Any Data Transfer for the purpose of Processing by the Processor in a country outside the European Economic Area (the “EEA”) shall only take place in compliance with Schedule 1 to this DPA. Where the Standard Contractual Clauses have not been executed at the same time as this DPA, the Processor shall not unduly withhold the execution of such clauses, where the transfer of Personal Data outside of the EEA is required for the performance of the Agreement. Any transfer of Personal Data outside the EEA shall be made in accordance with Schedule 1, including the Standard Contractual Clauses attached thereto, and the Processor shall ensure that any recipient of such data is under contractual obligations to protect such Personal Data to the same or higher standards as those imposed under this DPA and Data Protection Laws.
11. Sub-processors
The Controller acknowledges and agrees that the Processor may engage a third-party Sub-processor(s) in connection with the performance of the Services, provided such Sub-processor(s) take technical and organisational measures to ensure confidentiality of Personal Data shared with them. The current Sub-processors engaged by the Processor and approved by the Controller are listed in Annex III of Schedule 1 hereto. The Processor shall notify the Controller at least thirty (30) calendar days in advance of any intended changes or additions to its Sub-processors listed in Annex III by emailing notice of the intended change to Customer.
In accordance with Article 28(4) of the GDPR, the Processor shall remain liable to Controller for any failure on behalf of a Sub-processor to fulfil its data protection obligations under the DPA in connection with the performance of the Services.
If the Controller has a concern that the Sub-processor(s) Processing of Personal Data is reasonably likely to cause the Controller to breach its data protection obligations under the GDPR, the Controller may object to Processor's use of such Sub-processor and the Processor and Controller shall confer in good faith to address such concern. If the Parties are unable to resolve the Controller's objection within fifteen (15) calendar days of the Controller's notice, the Controller may terminate this DPA and the affected Services upon thirty (30) days' written notice, without prejudice to fees due for services already performed.
The obligations set out in this section are without prejudice to and supplement Clause 19.3 of the Agreement.
12. Personal Data Breach Notification
The Processor shall maintain defined procedures in case of a Personal Data Breach (as defined under the GDPR) and shall without undue delay, and in any event within forty-eight (48) hours of becoming aware, notify the Controller if it becomes aware of any Personal Data Breach, unless such Data Breach is unlikely to result in a risk to the rights and freedoms of natural persons. Such notification is without prejudice to the incident notification obligations set out in Section 5 of Schedule A to the Agreement.
The Processor shall provide the Controller with all reasonable assistance to comply with the notification of Personal Data Breach to Supervisory Authority and/or the Data Subject, to identify the cause of such Data Breach and take such commercially reasonable steps as reasonably required to mitigate and remedy such Data Breach.
Processor's notification of or response to a Personal Data Breach under this DPA will not be construed as an acknowledgement by Processor of any fault or liability with respect to the data incident.
Such notification shall include information reasonably available to the Processor regarding the nature of the Personal Data Breach, its likely consequences, and any measures taken or proposed to address it.
13. Return and Deletion of Personal Data
The Processor shall delete or return Personal Data upon termination of the Services in accordance with the Controller's instructions and may retain data where required by applicable law.
The Processor shall return such Personal Data in a commonly used format or in the current format in which it was stored at discretion of the Controller, as soon as reasonably practicable following receipt of Controller's notification.
In any case, the Processor shall delete Personal Data including all the copies of it as soon as reasonably practicable following the end of the Agreement.
The Processor may retain Personal Data where required by applicable law or for legitimate compliance or evidentiary purposes, such data shall remain subject to this DPA and the Processor shall inform the Controller of the specific data retained and the legal basis for such retention.
Without prejudice to the foregoing, the Controller may request export of Personal Data in a commonly used, machine-readable format in accordance with Clause 15.6(f) of the Agreement.
14. Technical and Organisational Measures
Having regard to the state of technological development and the cost of implementing any measures, the Processor will take appropriate technical and organisational measures in accordance with applicable Data Protection Laws to ensure a level of security appropriate to the risk against the unauthorised or unlawful processing of Personal Data and against the accidental loss or destruction of, or damage to, Personal Data to ensure a level of security appropriate to: (a) the harm that might result from unauthorised or unlawful processing or accidental loss, destruction or damage; and (b) the nature of the data to be protected, including the measures stated in Annex II of Schedule 1.
The Processor may update the technical and organisational measures from time to time, provided that any such update does not materially diminish the overall level of security afforded to the Personal Data. The Processor shall make the updated measures available to the Controller upon reasonable request.
15. Limitation of Liability
The aggregate liability of the Processor under or in connection with this DPA, whether in contract, tort (including negligence), breach of statutory duty, or otherwise, shall be subject to the limitations and exclusions of liability set out in the Agreement. This DPA shall not be construed to create any liability for the Processor in excess of the caps set out in the Agreement.
In no event shall the Processor be liable under this DPA for any indirect, incidental, consequential, special, or punitive damages, including but not limited to loss of profits, revenue, goodwill, data (other than Personal Data), or business opportunity, regardless of the legal theory upon which the claim is based and even if the Processor has been advised of the possibility of such damages. This exclusion shall not apply to the extent prohibited by applicable law.
Nothing in this clause shall limit either Party's liability to Data Subjects under Articles 79 and 82 of the GDPR, or any liability that cannot be excluded or limited by applicable law.
16. Third-Party and Government Requests
If the Processor receives a request from a Data Subject, supervisory authority, law enforcement body, or any other third party in relation to the Processing of Personal Data under this DPA, the Processor shall promptly refer such request to the Controller and shall not respond to the request without the Controller's prior written instructions, unless required by applicable law to respond directly.
Where the Processor is legally compelled to disclose Personal Data, it shall, to the extent permitted by law:
- notify the Controller in advance of such disclosure, providing details of the request and the Personal Data to be disclosed;
- limit disclosure to the minimum extent required by law; and
- cooperate with the Controller to challenge or narrow the scope of the request where lawfully possible.
17. Term and Survival
This DPA shall come into effect on the date the Agreement is executed and shall remain in force for the duration of the Agreement.
Upon termination or expiry of the Agreement, the following sections of this DPA shall survive for so long as the Processor retains any Personal Data: Data Secrecy, Return Export and Deletion of Personal Data, Technical and Organisational Measures, Limitation of Liability, Controller Indemnification, and Governing Law and Jurisdiction.
For the avoidance of doubt, the termination or expiry of this DPA shall not release the Controller from any obligation or liability that has accrued prior to such termination or expiry.
18. Amendments
This DPA may be amended only by a written instrument signed by both Parties except for cases already expressly permitted by the agreement itself.
Notwithstanding the foregoing, where amendments are required to reflect changes in Data Protection Laws, regulatory guidance, or binding decisions of a competent supervisory authority, the Parties shall negotiate such amendments in good faith and without undue delay. Neither Party shall unreasonably withhold its consent to such amendments.
No amendment shall be effective unless it expressly states that it amends this DPA and identifies the specific provisions to be amended.
19. Governing Law
This DPA shall be governed by the law and dispute resolution provisions set out in Clause 23 of the Agreement.
20. Severability
If any provision of this DPA is found by any court or administrative body of competent jurisdiction to be invalid or unenforceable, the invalidity or unenforceability of such provision shall not affect the other provisions of this DPA, which shall remain in full force and effect.
The Parties shall negotiate in good faith to replace any invalid or unenforceable provision with a valid and enforceable provision that achieves, to the greatest extent possible, the economic, legal, and commercial objectives of the invalid or unenforceable provision.
Schedule 1
Annex I
List of parties
Data exporter(s)
Name: Customer (as set forth in the relevant Order Form).
Address: As set forth in the relevant Order Form.
Contact person: As set forth in the relevant Order Form.
Activities relevant to the data transferred: Recipient of the Services provided by InteractiveAI Limited in accordance with the Agreement.
Signature and date: Set out in the Agreement.
Role: Controller
Data importer(s)
Name: InteractiveAI Limited
Address: 31-32 Leeson Street Lower, Dublin 2, Dublin, Ireland
Contact person: Rafael Cifuentes, Data Protection Officer, dpo@interactive.ai
Activities relevant to the data transferred: Provision of the Services to the Customer in accordance with the Agreement.
Signature and date: Set out in the Agreement.
Role: Processor
Description of transfer
Categories of data subjects whose personal data is transferred: Customer's authorised users of the Services, organisation members, and end users of AI agents deployed through the Platform.
Categories of personal data transferred: Email address, full name, avatar/image URL, organisation membership and roles, billing information (billing name, billing email, company name, company address, VAT/GST number), invoice records, AI agent conversation content (user inputs, AI model outputs), AI trace and generation data (model inputs/outputs, evaluation results), support ticket content, and user session metadata.
Sensitive data transferred (if applicable): No sensitive data (as defined under GDPR Article 9) is collected or processed. AI trace and conversation data may contain content provided by the Controller's end users; the Controller is responsible for ensuring no sensitive personal data is included unless appropriate safeguards are in place.
Frequency of transfer: Continuous basis.
Nature of the processing: Collection, storage, organisation, structuring, retrieval, consultation, use, alignment, combination, and erasure of personal data for the purpose of providing AI observability, agent management, trace analytics, billing, and support services through the Interactive Platform.
Purpose(s) of the data transfer and further processing: The purpose of the transfer is to facilitate the performance of the Services more fully described in the Agreement and accompanying order forms.
Retention period: The period for which the Customer Personal Data will be retained is more fully described in the Agreement, Addendum, and accompanying order forms. In general: user account data is retained until account deletion; billing and invoice data is retained for 7 years (legal/tax obligation); AI trace, generation, and conversation data is retained until explicit deletion by the Controller; support tickets are retained until explicit deletion.
For transfers to (sub-)processors: The subject matter, nature, and duration of the Processing are more fully described in the Agreement, Addendum, and accompanying order forms.
Competent supervisory authority: The data exporter is established in an EEA country. The competent supervisory authority is as determined by application of Clause 13 of the EU SCCs.
Annex II
Technical and organisational measures, including measures to ensure the security of the data, implemented by InteractiveAI Limited as the data processor/data importer to ensure an appropriate level of security, taking into account the nature, scope, context, and purpose of the processing, and the risks for the rights and freedoms of natural persons.
Security management system
- Organisation: InteractiveAI Limited designates qualified security personnel whose responsibilities include development, implementation, and ongoing maintenance of the Information Security Program.
- Policies: Management reviews and supports all security-related policies to ensure the security, availability, integrity and confidentiality of Customer Personal Data. These policies are updated at least once annually.
- Assessments: InteractiveAI Limited engages a reputable independent third-party (Scrut Automation) to perform risk assessments and compliance audits of all systems containing Customer Personal Data at least once annually.
- Risk treatment: InteractiveAI Limited maintains a formal and effective risk treatment program that includes vulnerability management and patch management to identify and protect against potential threats to the security, integrity or confidentiality of Customer Personal Data.
- Vendor management: InteractiveAI Limited maintains an effective vendor management program with documented vendor assessments and Data Processing Agreements for all sub-processors.
- Incident management: InteractiveAI Limited reviews security incidents regularly, including effective determination of root cause and corrective action.
- Standards: InteractiveAI Limited is pursuing certification against ISO/IEC 42001:2023 (AI Management System) and GDPR compliance, audited by Scrut Automation.
Personnel security
- InteractiveAI Limited personnel are required to conduct themselves in a manner consistent with the company's guidelines regarding confidentiality, business ethics, appropriate usage, and professional standards.
- Personnel are required to execute a confidentiality agreement in writing at the time of hire and to protect Customer Personal Data at all times. Personnel must acknowledge receipt of, and compliance with, InteractiveAI Limited's confidentiality, privacy and security policies.
- Personnel are provided with privacy and security training on how to implement and comply with the Information Security Program. Personnel handling Customer Personal Data are required to complete additional requirements appropriate to their role.
- InteractiveAI Limited's personnel will not process Customer Personal Data without authorisation.
Access controls
- Access management: InteractiveAI Limited maintains a formal access management process for the request, review, approval and provisioning of all personnel with access to Customer Personal Data. Access reviews are conducted periodically to ensure that only those personnel with access still require it.
- Infrastructure security personnel: InteractiveAI Limited maintains a security policy for its personnel and requires security training. Its infrastructure security personnel are responsible for ongoing monitoring of the security infrastructure, review of the Services, and responding to security incidents.
- Access control and privilege management: Administrators and end users must authenticate via a secure authentication system (credentials with bcrypt-hashed passwords, or OAuth 2.0 via Google/GitHub) in order to use the Services.
- Internal data access processes and policies: Designed to protect against unauthorised access, use, disclosure, alteration or destruction of Customer Personal Data, based on principles of “least privilege” and “need to know”. Role-Based Access Control (RBAC) is enforced at the API layer with organisation-level data isolation. The platform uses two separate PostgreSQL database users: one for runtime application access (least privilege) and one for database migrations only. API keys and secrets are stored separately and encrypted with pgcrypto (AES).
Data center and network security
- Infrastructure: InteractiveAI Limited uses Google Cloud Platform (GCP) as its cloud infrastructure provider, with resources hosted in the EU (europe-west1) region.
- Resiliency: The platform is deployed on Google Kubernetes Engine (GKE) with namespace-level isolation and pod redundancy to ensure high availability.
- Server operating systems: Servers are containerised and deployed via Kubernetes with hardened configurations. A code review process is employed to increase the security of the code used to provide the Services.
- Disaster recovery: Data is replicated using GCP's built-in redundancy mechanisms. Database backups are performed regularly with encryption at rest.
- Security logs: Systems have logging enabled to support security audits and monitor and detect actual and attempted attacks or intrusions.
- Vulnerability management: Regular vulnerability assessments are performed on all infrastructure components of the production environment. Vulnerabilities are remediated on a risk basis, with Critical, High and Medium security patches installed as soon as commercially possible.
Networks and transmission
- Data transmission: All data transmissions in the production environment are encrypted using HTTPS/TLS. All API communications use TLS 1.2 or higher.
- External attack surface: GCP firewall rules and Kubernetes network policies are in place for the production environment.
- Incident response: InteractiveAI Limited maintains incident management policies and procedures, including detailed security incident escalation procedures, monitors communication channels for security incidents, and security personnel react promptly to suspected or known incidents, mitigate harmful effects, and document such incidents and their outcomes.
- Encryption technologies: HTTPS encryption (TLS) is available for all data in transit. Passwords are hashed with bcrypt. Sensitive credentials and API keys are encrypted at rest using pgcrypto (AES). GCP Cloud Storage uses server-side encryption for stored files (invoice PDFs). OAuth state tokens use 32-byte cryptographically secure random values. Cookies are set with Secure, HttpOnly, and SameSite=Lax attributes.
Data storage, isolation, authentication, and destruction
- InteractiveAI Limited stores data on Google Cloud Platform servers in the EU region. Data and the Services database are backed by PostgreSQL with encryption at rest provided by GCP.
- InteractiveAI Limited logically isolates the data of different customers at the application level through organisation-level data isolation; all database queries are filtered by organisation ID, enforced at the API layer.
- A central authentication system (credentials + OAuth 2.0) is used across all Services to increase uniform security of data.
- InteractiveAI Limited ensures secure disposal of Customer Data through database-level deletion with cascading removal of all related records (billing, agents, conversations, support tickets) upon organisation or account deletion.
Annex III
List of sub-processors
The Controller has authorised the use of the following sub-processors:
| Sub-processor | Description of processing | Location |
|---|---|---|
| Google Cloud Platform (GCP) | Hosting the production environment, database infrastructure, cloud storage for invoice PDFs, and application secrets management | EU (europe-west1) |
| OpenRouter | LLM inference routing/processing AI model prompts and completions on behalf of platform users. Zero Data Retention (ZDR) is enabled. | EU |
| Resend | Transactional email delivery/sending verification emails, password resets, invitation emails, and support notifications | EU/US |
| Google Analytics | Website analytics, anonymised page views, user interactions, and session data for product improvement (subject to user consent) | EU/US |
This Data Processing Agreement is classified as Confidential and forms part of the Agreement between the Customer and InteractiveAI Limited.