Skip to main content

Data-processing procurement

Use an account-specific DPA, not an unverified public template.

This page is not a signed Data Processing Addendum and does not become one by using the site. Processing scope, providers, retention, security measures, transfers, and notification obligations must match the purchased service and executed customer agreement.

What the executed package should settle

01

Roles and instructions

Identify the controller, processor, any independent-controller activity, permitted purposes, documented instructions, and prohibited uses.

02

Data and people

List the exact account, customer, prospect, property, contact, communication, recording, billing, and usage data in scope—and the affected people.

03

Providers and transfers

Confirm the account-specific providers, purpose, location, contractual chain, cross-border mechanism, and change-notice process.

04

Security measures

Attach the technical and organizational measures that can be evidenced for the exact environment rather than relying on a generic marketing list.

05

Retention and deletion

Define schedules by data class and provider, export behavior, backup limitations, legal holds, deletion verification, and post-termination handling.

06

Rights and incidents

Define request intake, identity verification, assistance, notification triggers, timing, cooperation, audit evidence, and responsibility boundaries.

Current public assurance boundary

AI-STORMS does not publish a universal subprocessor annex, fixed retention schedule, certification, audit report, recovery target, or breach-notification SLA on this page. Those claims require current evidence and an executed agreement scoped to the customer environment.