← Back to AI Office

Data Processing Agreement (DPA)

(UK & EU GDPR Compliant)
Last Updated: 17 Nov 2025

This Data Processing Agreement ("Agreement") forms part of the Terms & Conditions between:

Controller: You (the customer using AI Office)
Processor: AI Office ("we", "us", "our")

This Agreement outlines how we process, store, and protect personal data on your behalf under the UK GDPR, EU GDPR, and Data Protection Act 2018.

1. Definitions

"Personal Data": Any information relating to an identifiable person.

"Processing": Any action performed on personal data (collection, storage, analysis, deletion).

"Controller": The person or business deciding how data is used (you).

"Processor": The organisation processing data on your behalf (AI Office).

"Sub-processor": A third party engaged by us to support processing.

2. Scope of Processing

We process personal data solely to provide the AI Office service, including:

We do not process data for any purpose unrelated to service delivery.

3. Duration of Processing

We process data for the duration of your subscription and according to retention rules defined in the Privacy Policy.

4. Types of Personal Data

We may process:

We do not collect sensitive data unless voluntarily provided by you.

5. Sub-processors

We use trusted GDPR-compliant vendors:

5.1 Infrastructure & Hosting

Hosting platforms (servers, storage)

5.2 Authentication & Database

Supabase – User authentication, database storage

5.3 Payment Processing

Stripe – Subscription billing

5.4 Analytics (optional)

Google Analytics (only if you accept cookies)

We remain responsible for the actions of our sub-processors.

6. Processor Obligations

We agree to:

7. Controller Obligations

You agree to:

8. Security Measures

We implement:

9. International Transfers

Where data is transferred outside the UK/EU, we ensure:

10. Data Subject Rights

We support the rights of individuals, including:

We will assist you in responding to any such requests.

11. Data Breach Notification

If we become aware of a breach affecting personal data, we will:

12. Return or Deletion of Data

Upon account closure or request, we will:

13. Liability

Liability is limited according to the Terms & Conditions.

14. Governing Law

This Agreement is governed by:

15. Contact Information

For data processing matters:
Email: support@aioffice.agency

End of Data Processing Agreement