Data Processing Addendum
Last updated: October 1, 2026
This addendum applies where aisenn processes personal data on your behalf. It forms part of our Terms of Service and sits alongside our Privacy Policy and Security pages. If your organization requires this executed as a signed document, email support@aisenn.app and we will sign yours or ours.
1. Roles
You are the controller of the personal data you put into aisenn — your team members, the creators you work with, and the people you invite to review. aisenn is the processor, acting on your instructions. Where aisenn handles data about you as our own customer (billing, support, account administration), we are the controller of that, and the Privacy Policy governs it.
2. Subject matter and duration
We process your data for as long as your account is open, and for the retention periods set out on the Security page. On deletion of your account, data is purged after a 30-day grace period intended to let you recover from an accidental deletion.
3. Categories of data and data subjects
- Data subjects: your team members, creators engaged on your campaigns, agency staff on either side, and guests you invite to review by link.
- Categories: identity and contact data (name, email, profile image, social handles, and phone number where WhatsApp is used); content and work product (briefs, captions, uploaded media, comments, approvals); commercial terms (fees, usage rights, exclusivity); and technical data (session records, IP address for rate limiting, device push tokens).
- We do not request or require special category data, and aisenn has no feature that calls for it.
4. Our obligations
- Process personal data only on your instructions and as needed to run the service.
- Keep the technical and organizational measures described on the Security page, and not materially weaken them during the term.
- Restrict access to personnel who need it, under confidentiality obligations.
- Notify you without undue delay, and in any event within 72 hours, on becoming aware of a personal data breach affecting your data, with what we know at the time.
- Assist you with data subject requests, data protection impact assessments, and regulator enquiries, so far as the service makes that possible.
- Delete or return your data on termination, subject to the retention periods above and any legal obligation to retain.
5. Your obligations
You are responsible for having a lawful basis for the data you put into aisenn, for the accuracy of what you upload, for telling the people whose data it is, and for managing who in your organization holds which seat. Seats are how access is controlled — see the Security page — and keeping them current is yours to do.
6. Subprocessors
We engage the subprocessors below. Each is bound by terms no less protective than these, and each is engaged for a specific purpose rather than general access. We will give notice before adding a new subprocessor that handles customer data; if you object on reasonable data protection grounds, we will work with you or you may terminate.
Rows marked conditional process data only where the feature is used. If one is unacceptable to you, the corresponding feature can be left unused without affecting the rest of the product.
| Subprocessor | Purpose | Data processed |
|---|---|---|
| Netlify | Application hosting and CDN | All request and response data in transit |
| Neon | Managed PostgreSQL database | All application data: accounts, organizations, campaigns, deals, deliverables, captions, approvals, comments |
| Clerk | Authentication and identity | Name, email address, profile image, authentication factors, session records |
| Mux | Video storage, encoding and streaming | Uploaded video and its derived renditions and thumbnails |
| UploadThing | File storage | Non-video files: images, documents, contracts, attachments |
| Upstash | Rate limiting (Redis) and scheduled jobs (QStash) | Request IP addresses for rate limiting; record identifiers in job payloads |
| Pusher | Real-time updates in the workspace | Event payloads for live updates: identifiers, comment and approval events |
| Resend | Transactional email | Recipient name and email address, and the content of the notification |
| Sentry | Error reporting | Error traces, which may incidentally include a user identifier and the URL in use |
| Stripe | Payment processing | Billing name, email, and card details — collected and held by Stripe, never by aisenn |
| Anthropicconditional | AI document analysisOnly on explicit use of contract analysis or brief extraction | The specific document you submit for analysis, at the moment you invoke the feature |
| Google (Analytics) | Product usage measurement | Page views, feature events, device and browser information |
| Expoconditional | Mobile push notification deliveryOnly for accounts using the mobile app | Device push tokens and notification content, for users of the mobile app |
| Meta (WhatsApp Business)conditional | Approvals over WhatsApp during a campaign's live windowOnly where a campaign enables WhatsApp and a user connects their own number | Phone number and message content |
| Zernioconditional | Publishing approved content to connected social accountsOnly where a creator connects a social account | The post content, caption and schedule, plus the connected account's token |
| Waveconditional | InvoicingOnly where a creator connects their own Wave account | Invoice recipient name and email, line items and amounts |
Each subprocessor publishes its own hosting regions, onward subprocessors and attestations. We will confirm the specific regions in use for your account on request — ask rather than assume, since they depend on when the account was provisioned.
7. International transfers
aisenn and the subprocessors above are predominantly US-based. Where personal data of people in the UK, EU or Switzerland is transferred out of those territories, the transfer relies on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or a provider's certification under the EU–US Data Privacy Framework, as applicable. We will enter into the SCCs with you on request.
8. Audits
We will answer your security questionnaire, provide the information on the Security page in whatever format your process needs, and make the relevant people available to your security team. We do not currently hold a SOC 2 Type II report or ISO 27001 certification, and the Security page says so plainly rather than pointing you at our providers' certificates as if they were ours.
9. Contact
Data protection enquiries, data subject requests and breach notifications: support@aisenn.app.