Data Processing Agreement
Last updated: July 17, 2026
1. Purpose and Scope
This Data Processing Agreement (“DPA”) describes how AIQENprocesses personal data on behalf of an organization (“Customer”) using the AI Workforce platform (“the Platform”), where Customer acts as data controller and AIQEN acts as data processor, in support of the EU General Data Protection Regulation (GDPR), UK GDPR, and comparable data protection laws. This DPA supplements, and forms part of, our Terms of Service. Enterprise customers who require a countersigned, standalone DPA (including EU Standard Contractual Clauses as an exhibit) can request one at hello@aiqen.co; absent a countersigned version, this page governs.
2. Roles of the Parties
- Customer is the controller of personal data it submits to, or collects through, the Platform (for example, CRM contacts, campaign recipients, ticket submitters, and Customer’s own team members).
- AIQEN is the processor of that data, acting only on Customer’s documented instructions as expressed through Customer’s configuration and use of the Platform, except where we are required to process it otherwise by law.
- For account, billing, and website data collected directly from Customer’s personnel, AIQEN acts as controller, as described in our Privacy Policy.
3. Nature and Purpose of Processing
We process personal data submitted to the Platform for the purpose of providing the Platform’s features to Customer: hosting and displaying CRM and support data, sending emails and messages Customer configures, running AI employees and workflow automations against Customer’s data, generating analytics, and enabling the connected integrations Customer authorizes. Categories of data subjects typically include Customer’s team members, and Customer’s own customers, leads, and contacts. Categories of data depend entirely on what Customer chooses to enter into the Platform, and may include names, contact details, communication content, and — if Customer chooses to include it — other categories Customer is responsible for having a lawful basis to process.
4. Sub-Processors
Customer authorizes AIQEN to engage the sub-processors listed in Section 6 of our Privacy Policy, plus any specific third-party integration Customer itself elects to connect via the Integrations Hub. We remain responsible for our sub-processors’ compliance with data-protection obligations equivalent to those in this DPA. We will provide reasonable advance notice at hello@aiqen.co (on request) of any material change in sub-processors used for core infrastructure, and Customer may object on reasonable data-protection grounds.
5. Security Measures
We maintain the technical and organizational measures described in our Security Policy, including encryption in transit and at rest, row-level multi-tenant data isolation, role-based administrative access, rate limiting, and audit logging of sensitive actions.
6. Data Subject Requests
Where a data subject contacts AIQEN directly with a request concerning data Customer controls, we will refer the request to Customer promptly and provide reasonable assistance for Customer to respond, including through Platform features that allow Customer to access, export, and delete records it controls.
7. Personal Data Breach Notification
We will notify Customer without undue delay after becoming aware of a confirmed personal data breach affecting Customer’s data, and provide information reasonably available to us to help Customer meet its own notification obligations to regulators and affected individuals.
8. International Transfers
Where personal data is transferred outside the EEA, UK, or Switzerland to a sub-processor, we rely on an adequacy decision or appropriate safeguards, such as the European Commission’s Standard Contractual Clauses, incorporated by reference into our agreements with those sub-processors.
9. Deletion and Return of Data
On termination of Customer’s subscription, we will delete or anonymize Customer’s personal data within the retention window described in our Privacy Policy, except where we are required by law to retain it, or as retained in encrypted backups pending our standard backup rotation.
10. Audit Rights
On reasonable request, no more than once per 12-month period absent a security incident, we will make available information reasonably necessary to demonstrate compliance with this DPA, such as summaries of relevant security documentation. Enterprise customers with specific audit requirements should contact hello@aiqen.co to discuss terms.
11. Contact
Questions about this DPA, or requests for a countersigned version, can be sent to hello@aiqen.co.