Legal

Data Processing Addendum

This Data Processing Addendum (“DPA”) forms part of the agreement between AEER Platform Inc. (“Processor”, “we”) and the customer using the FG platform (“Customer”, “Controller”) and applies to Processing of Customer Personal Data under the EU/UK GDPR.

AEER Platform Inc., a Delaware corporation · 8 The Green, STE A, Dover, DE 19901, USA · privacy@fg-platform.com

1. Definitions

“GDPR”, “Controller”, “Processor”, “Sub-processor”, “Personal Data”, “Processing”, “Data Subject”, and “Personal Data Breach” have the meanings given in the GDPR. “Customer Personal Data” means Personal Data that we Process on the Customer’s behalf in providing the FG platform — primarily conversation transcripts, messages, lead details, and session context of the Customer’s end-users.

2. Roles and scope

As between the parties, the Customer is the Controller and AEER is the Processor of Customer Personal Data. We Process Customer Personal Data only on the Customer’s documented instructions, including as set out in the agreement, this DPA, and the Customer’s configuration and use of the Service, unless required by law (in which case we will inform the Customer unless legally prohibited).

3. Nature, purpose, and duration

We Process Customer Personal Data to provide the FG platform: transcribing speech, generating and synthesizing assistant responses, storing conversations and leads for the Customer’s review, and metering usage. Details are set out in Annex I. Processing continues for the term of the agreement and until deletion or return under Section 9.

4. Processor obligations

5. Personal Data Breach

We will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and provide information reasonably available to us to help the Customer meet its notification obligations.

6. Sub-processors

The Customer provides a general authorization for AEER to engage the Sub-processors listed in Annex III. We impose data-protection obligations on each Sub-processor that are substantially the same as those in this DPA, and we remain responsible for their performance. We will give the Customer prior notice of any intended addition or replacement of a Sub-processor and a reasonable opportunity to object on reasonable, data-protection grounds.

7. Data Subject requests

Taking into account the nature of the Processing, we will assist the Customer with appropriate technical and organizational measures, insofar as possible, to fulfill the Customer’s obligations to respond to requests from Data Subjects exercising their rights. The Service includes tooling to retrieve and delete individual conversations. If we receive a request directly from a Data Subject, we will refer it to the Customer.

8. International transfers

Our primary hosting and database are in the EU (Frankfurt). Where Processing by a U.S. Sub-processor involves a transfer of Customer Personal Data outside the EEA/UK, such transfer is made subject to appropriate safeguards, in particular the European Commission’s Standard Contractual Clauses (Module Three, processor-to-sub-processor, where applicable) and the UK International Data Transfer Addendum, which are incorporated by reference where they apply.

9. Deletion or return

On expiry or termination of the agreement, we will, at the Customer’s choice, delete or return Customer Personal Data and delete existing copies, unless retention is required by law. The Service also lets the Customer delete conversations and configure a retention period at any time.

10. Audit

We will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior written notice and subject to confidentiality, allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, no more than once per year unless required by a supervisory authority.

11. Liability, precedence, and governing law

Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the agreement. In case of conflict, this DPA prevails over the agreement with respect to the subject matter here; the Standard Contractual Clauses prevail over this DPA to the extent of any conflict. Except where the Standard Contractual Clauses specify their own governing law, this DPA is governed by the law of the State of Delaware, USA, without prejudice to mandatory data-protection law.

Annex I — Details of Processing

Categories of Data Subjects

End-users and visitors who interact with the Customer’s FG-powered assistant (e.g. website visitors, prospects, support contacts).

Categories of Personal Data

  • Conversation content: voice (transcribed to text) and text messages exchanged with the assistant.
  • Lead details submitted by the Data Subject (typically name and email).
  • Session context: originating website/page, language, timestamps, and a randomly generated session/visitor identifier.

Special categories

None intended. Customers instruct their end-users not to submit sensitive data through the assistant.

Frequency and nature

Continuous, for the duration of the agreement; automated Processing to deliver real-time voice/chat responses and to store conversations and leads for the Customer.

Purpose

Providing the FG platform to the Customer: transcription, language-model responses, speech synthesis, storage and display of conversations and leads, and usage metering.

Retention

As configured by the Customer (retention period and on-demand deletion); otherwise for the term of the agreement, then deleted or returned per Section 9.

Annex II — Technical and Organizational Measures

  • Encryption in transit (TLS) between the Data Subject, the Service, and sub-processors.
  • Encryption at rest for the managed database.
  • Tenant isolation via row-level security so one Customer cannot access another’s data.
  • Credential protection: salted password hashing; hashed storage of session tokens and API keys; least-privilege service credentials.
  • Access control: authenticated console access; administrative access restricted to authorized personnel.
  • Abuse prevention: rate limiting, per-account quotas, and email verification.
  • Monitoring and logging of errors and security-relevant events, with alerting on critical failures.
  • Backups of the managed database with defined retention.
  • Data minimization: transcripts are not written to application logs; secrets are kept out of source control.

Annex III — Authorized Sub-processors

Sub-processorFunctionRegion
SupabaseManaged databaseEU (Frankfurt)
RenderApplication hostingEU (Frankfurt)
CloudflareCDN and network securityGlobal edge
GroqSpeech-to-textUnited States
AnthropicLanguage-model responsesUnited States
CartesiaText-to-speechUnited States
Jina AIWebsite rendering during assistant setupUnited States
ResendTransactional emailUnited States

The current list is maintained here; Customers receive prior notice of material changes as set out in Section 6.

Last updated: 16 July 2026
← Privacy Policy