aisenn

Data Processing Addendum

Last updated: October 1, 2026

This addendum applies where aisenn processes personal data on your behalf. It forms part of our Terms of Service and sits alongside our Privacy Policy and Security pages. If your organization requires this executed as a signed document, email support@aisenn.app and we will sign yours or ours.

1. Roles

You are the controller of the personal data you put into aisenn — your team members, the creators you work with, and the people you invite to review. aisenn is the processor, acting on your instructions. Where aisenn handles data about you as our own customer (billing, support, account administration), we are the controller of that, and the Privacy Policy governs it.

2. Subject matter and duration

We process your data for as long as your account is open, and for the retention periods set out on the Security page. On deletion of your account, data is purged after a 30-day grace period intended to let you recover from an accidental deletion.

3. Categories of data and data subjects

  • Data subjects: your team members, creators engaged on your campaigns, agency staff on either side, and guests you invite to review by link.
  • Categories: identity and contact data (name, email, profile image, social handles, and phone number where WhatsApp is used); content and work product (briefs, captions, uploaded media, comments, approvals); commercial terms (fees, usage rights, exclusivity); and technical data (session records, IP address for rate limiting, device push tokens).
  • We do not request or require special category data, and aisenn has no feature that calls for it.

4. Our obligations

  • Process personal data only on your instructions and as needed to run the service.
  • Keep the technical and organizational measures described on the Security page, and not materially weaken them during the term.
  • Restrict access to personnel who need it, under confidentiality obligations.
  • Notify you without undue delay, and in any event within 72 hours, on becoming aware of a personal data breach affecting your data, with what we know at the time.
  • Assist you with data subject requests, data protection impact assessments, and regulator enquiries, so far as the service makes that possible.
  • Delete or return your data on termination, subject to the retention periods above and any legal obligation to retain.

5. Your obligations

You are responsible for having a lawful basis for the data you put into aisenn, for the accuracy of what you upload, for telling the people whose data it is, and for managing who in your organization holds which seat. Seats are how access is controlled — see the Security page — and keeping them current is yours to do.

6. Subprocessors

We engage the subprocessors below. Each is bound by terms no less protective than these, and each is engaged for a specific purpose rather than general access. We will give notice before adding a new subprocessor that handles customer data; if you object on reasonable data protection grounds, we will work with you or you may terminate.

Rows marked conditional process data only where the feature is used. If one is unacceptable to you, the corresponding feature can be left unused without affecting the rest of the product.

SubprocessorPurposeData processed
NetlifyApplication hosting and CDNAll request and response data in transit
NeonManaged PostgreSQL databaseAll application data: accounts, organizations, campaigns, deals, deliverables, captions, approvals, comments
ClerkAuthentication and identityName, email address, profile image, authentication factors, session records
MuxVideo storage, encoding and streamingUploaded video and its derived renditions and thumbnails
UploadThingFile storageNon-video files: images, documents, contracts, attachments
UpstashRate limiting (Redis) and scheduled jobs (QStash)Request IP addresses for rate limiting; record identifiers in job payloads
PusherReal-time updates in the workspaceEvent payloads for live updates: identifiers, comment and approval events
ResendTransactional emailRecipient name and email address, and the content of the notification
SentryError reportingError traces, which may incidentally include a user identifier and the URL in use
StripePayment processingBilling name, email, and card details — collected and held by Stripe, never by aisenn
AnthropicconditionalAI document analysisOnly on explicit use of contract analysis or brief extractionThe specific document you submit for analysis, at the moment you invoke the feature
Google (Analytics)Product usage measurementPage views, feature events, device and browser information
ExpoconditionalMobile push notification deliveryOnly for accounts using the mobile appDevice push tokens and notification content, for users of the mobile app
Meta (WhatsApp Business)conditionalApprovals over WhatsApp during a campaign's live windowOnly where a campaign enables WhatsApp and a user connects their own numberPhone number and message content
ZernioconditionalPublishing approved content to connected social accountsOnly where a creator connects a social accountThe post content, caption and schedule, plus the connected account's token
WaveconditionalInvoicingOnly where a creator connects their own Wave accountInvoice recipient name and email, line items and amounts

Each subprocessor publishes its own hosting regions, onward subprocessors and attestations. We will confirm the specific regions in use for your account on request — ask rather than assume, since they depend on when the account was provisioned.

7. International transfers

aisenn and the subprocessors above are predominantly US-based. Where personal data of people in the UK, EU or Switzerland is transferred out of those territories, the transfer relies on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or a provider's certification under the EU–US Data Privacy Framework, as applicable. We will enter into the SCCs with you on request.

8. Audits

We will answer your security questionnaire, provide the information on the Security page in whatever format your process needs, and make the relevant people available to your security team. We do not currently hold a SOC 2 Type II report or ISO 27001 certification, and the Security page says so plainly rather than pointing you at our providers' certificates as if they were ours.

9. Contact

Data protection enquiries, data subject requests and breach notifications: support@aisenn.app.