Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of the agreement between AEER Platform Inc. (“Processor”, “we”) and the customer using the FG platform (“Customer”, “Controller”) and applies to Processing of Customer Personal Data under the EU/UK GDPR.
1. Definitions
“GDPR”, “Controller”, “Processor”, “Sub-processor”, “Personal Data”, “Processing”, “Data Subject”, and “Personal Data Breach” have the meanings given in the GDPR. “Customer Personal Data” means Personal Data that we Process on the Customer’s behalf in providing the FG platform — primarily conversation transcripts, messages, lead details, and session context of the Customer’s end-users.
2. Roles and scope
As between the parties, the Customer is the Controller and AEER is the Processor of Customer Personal Data. We Process Customer Personal Data only on the Customer’s documented instructions, including as set out in the agreement, this DPA, and the Customer’s configuration and use of the Service, unless required by law (in which case we will inform the Customer unless legally prohibited).
3. Nature, purpose, and duration
We Process Customer Personal Data to provide the FG platform: transcribing speech, generating and synthesizing assistant responses, storing conversations and leads for the Customer’s review, and metering usage. Details are set out in Annex I. Processing continues for the term of the agreement and until deletion or return under Section 9.
4. Processor obligations
- Process Customer Personal Data only on documented instructions.
- Ensure persons authorized to Process the data are bound by confidentiality.
- Implement the technical and organizational measures in Annex II.
- Respect the conditions for engaging Sub-processors in Section 6.
- Taking into account the nature of Processing, assist the Customer by appropriate measures to respond to Data Subject requests (Section 7).
- Assist the Customer with security, breach notification, data-protection impact assessments, and prior consultation, taking into account the information available to us.
- Delete or return Customer Personal Data as set out in Section 9.
- Make available information reasonably necessary to demonstrate compliance and allow for audits as set out in Section 10.
5. Personal Data Breach
We will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and provide information reasonably available to us to help the Customer meet its notification obligations.
6. Sub-processors
The Customer provides a general authorization for AEER to engage the Sub-processors listed in Annex III. We impose data-protection obligations on each Sub-processor that are substantially the same as those in this DPA, and we remain responsible for their performance. We will give the Customer prior notice of any intended addition or replacement of a Sub-processor and a reasonable opportunity to object on reasonable, data-protection grounds.
7. Data Subject requests
Taking into account the nature of the Processing, we will assist the Customer with appropriate technical and organizational measures, insofar as possible, to fulfill the Customer’s obligations to respond to requests from Data Subjects exercising their rights. The Service includes tooling to retrieve and delete individual conversations. If we receive a request directly from a Data Subject, we will refer it to the Customer.
8. International transfers
Our primary hosting and database are in the EU (Frankfurt). Where Processing by a U.S. Sub-processor involves a transfer of Customer Personal Data outside the EEA/UK, such transfer is made subject to appropriate safeguards, in particular the European Commission’s Standard Contractual Clauses (Module Three, processor-to-sub-processor, where applicable) and the UK International Data Transfer Addendum, which are incorporated by reference where they apply.
9. Deletion or return
On expiry or termination of the agreement, we will, at the Customer’s choice, delete or return Customer Personal Data and delete existing copies, unless retention is required by law. The Service also lets the Customer delete conversations and configure a retention period at any time.
10. Audit
We will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior written notice and subject to confidentiality, allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, no more than once per year unless required by a supervisory authority.
11. Liability, precedence, and governing law
Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the agreement. In case of conflict, this DPA prevails over the agreement with respect to the subject matter here; the Standard Contractual Clauses prevail over this DPA to the extent of any conflict. Except where the Standard Contractual Clauses specify their own governing law, this DPA is governed by the law of the State of Delaware, USA, without prejudice to mandatory data-protection law.
Annex I — Details of Processing
Categories of Data Subjects
End-users and visitors who interact with the Customer’s FG-powered assistant (e.g. website visitors, prospects, support contacts).
Categories of Personal Data
- Conversation content: voice (transcribed to text) and text messages exchanged with the assistant.
- Lead details submitted by the Data Subject (typically name and email).
- Session context: originating website/page, language, timestamps, and a randomly generated session/visitor identifier.
Special categories
None intended. Customers instruct their end-users not to submit sensitive data through the assistant.
Frequency and nature
Continuous, for the duration of the agreement; automated Processing to deliver real-time voice/chat responses and to store conversations and leads for the Customer.
Purpose
Providing the FG platform to the Customer: transcription, language-model responses, speech synthesis, storage and display of conversations and leads, and usage metering.
Retention
As configured by the Customer (retention period and on-demand deletion); otherwise for the term of the agreement, then deleted or returned per Section 9.
Annex II — Technical and Organizational Measures
- Encryption in transit (TLS) between the Data Subject, the Service, and sub-processors.
- Encryption at rest for the managed database.
- Tenant isolation via row-level security so one Customer cannot access another’s data.
- Credential protection: salted password hashing; hashed storage of session tokens and API keys; least-privilege service credentials.
- Access control: authenticated console access; administrative access restricted to authorized personnel.
- Abuse prevention: rate limiting, per-account quotas, and email verification.
- Monitoring and logging of errors and security-relevant events, with alerting on critical failures.
- Backups of the managed database with defined retention.
- Data minimization: transcripts are not written to application logs; secrets are kept out of source control.
Annex III — Authorized Sub-processors
| Sub-processor | Function | Region |
|---|---|---|
| Supabase | Managed database | EU (Frankfurt) |
| Render | Application hosting | EU (Frankfurt) |
| Cloudflare | CDN and network security | Global edge |
| Groq | Speech-to-text | United States |
| Anthropic | Language-model responses | United States |
| Cartesia | Text-to-speech | United States |
| Jina AI | Website rendering during assistant setup | United States |
| Resend | Transactional email | United States |