Skip to content
Return home

Data Processing Addendum

Effective Date:
Last Updated:

This Data Processing Addendum (“DPA”) forms part of the Customer Agreement (SaaS) or other written agreement between Plasma AI Inc. (“Plasma AI”) and the customer identified in such agreement (“Customer”) governing Customer’s use of the Plasma AI Product (the “Agreement”). This DPA is incorporated into the Agreement by reference and applies to the extent Plasma AI processes Personal Data contained in Customer Data that is subject to Data Protection Legislation on Customer’s behalf in providing the Plasma AI Product. Capitalized terms used but not defined in this DPA have the meanings given in the Agreement. In the event of a conflict between this DPA and the Agreement with respect to the processing of Personal Data, this DPA will control.

1. Definitions

“Customer Data” has the meaning given in the Agreement, i.e., any data, content or materials that Customer (including its Users) submits to its Plasma AI Product accounts, including from Third-Party Platforms.

“Data Protection Legislation” means all data protection and privacy laws applicable to the processing of Personal Data under the Agreement, including, as applicable: (a) Regulation (EU) 2016/679 (the “GDPR”) and the GDPR as incorporated into the laws of the United Kingdom (the “UK GDPR”); (b) the Swiss Federal Act on Data Protection; (c) the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020, and its implementing regulations (the “CCPA”); and (d) other applicable U.S. state privacy laws, in each case as amended, superseded or replaced from time to time.

“Personal Data” means any information contained in Customer Data that relates to an identified or identifiable natural person, or that is otherwise defined as “personal data,” “personal information” or a similar term under applicable Data Protection Legislation, that Plasma AI processes on Customer’s behalf in providing the Plasma AI Product.

“controller,” “processor,” “data subject,” “processing” (and its cognates), “supervisory authority” and similar terms have the meanings given in applicable Data Protection Legislation. For purposes of the CCPA, “controller” includes “business” and “processor” includes “service provider.”

“Security Incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data processed by Plasma AI on Customer’s behalf.

“Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of personal data to third countries approved by European Commission Implementing Decision (EU) 2021/914, as amended or replaced from time to time.

“Subprocessor” means a third party engaged by Plasma AI to process Personal Data on Customer’s behalf in connection with the Plasma AI Product.

“System Data” has the meaning given in the Agreement, i.e., data collected by Plasma AI regarding the Plasma AI Product that may be used to generate logs, statistics or reports regarding the performance, availability, usage, integrity or security of the Plasma AI Product.

2. Roles and Scope of Processing

As between the parties, Customer is the controller (or, where Customer acts on behalf of a third-party controller, a processor) and Plasma AI is a processor (or subprocessor, as applicable) with respect to Personal Data. Each party will comply with its obligations under applicable Data Protection Legislation. The subject matter, duration, nature and purpose of the processing, and the types of Personal Data and categories of data subjects, are described in Annex I.

3. Processing Instructions

Plasma AI will process Personal Data only on Customer’s documented instructions, including with regard to transfers of Personal Data to a third country, unless required to do otherwise by applicable law (in which case Plasma AI will inform Customer of that legal requirement before processing, unless the law prohibits doing so). The Agreement, this DPA and Customer’s use and configuration of the Plasma AI Product constitute Customer’s documented instructions. Plasma AI will inform Customer if, in its opinion, an instruction infringes applicable Data Protection Legislation.

4. Confidentiality

Plasma AI will ensure that persons it authorizes to process Personal Data are subject to appropriate obligations of confidentiality, whether contractual or statutory.

5. Security

Plasma AI will implement and maintain appropriate technical and organizational measures designed to protect Personal Data against Security Incidents, including the measures described in Annex II and on the Plasma AI Security Page at plasma.ai/security (as updated from time to time in a manner that does not materially decrease the protections described therein). Plasma AI may update such measures as security practices evolve, provided the updates do not materially decrease the overall protection of Personal Data.

6. Subprocessors

Customer generally authorizes Plasma AI to engage Subprocessors, including those listed in Annex III. Plasma AI will (a) impose on each Subprocessor data protection obligations that are materially as protective as those in this DPA; (b) remain responsible for each Subprocessor’s performance of such obligations; and (c) provide Customer at least ten (10) days’ prior notice (which may be by email or by posting to plasma.ai/dpa or a successor page) before authorizing a new Subprocessor to process Personal Data. Customer may object in writing to a new Subprocessor on reasonable data protection grounds within such notice period, in which case the parties will discuss in good faith a resolution; if none can be reached within thirty (30) days, Customer may terminate the affected Order Form upon written notice and receive a pro rata refund of prepaid fees for the terminated portion of the subscription term.

7. Assistance; Data Subject Requests

Taking into account the nature of the processing, Plasma AI will assist Customer by appropriate technical and organizational measures, insofar as this is possible, in fulfilling Customer’s obligations to respond to requests from data subjects exercising their rights under Data Protection Legislation. If Plasma AI receives such a request directly and can identify Customer, it will promptly redirect the request to Customer and will not respond except to redirect it, unless required by law. Plasma AI will further provide reasonable assistance to Customer, taking into account the nature of the processing and the information available to Plasma AI, with Customer’s obligations regarding security, Security Incident notifications, data protection impact assessments and prior consultation with supervisory authorities.

8. Security Incident Notification

Plasma AI will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Security Incident, and will provide Customer with information reasonably available to Plasma AI to assist Customer in meeting its notification obligations under Data Protection Legislation. Plasma AI will take reasonable steps to contain, investigate and mitigate the Security Incident. Plasma AI’s notification of a Security Incident is not an acknowledgment of fault or liability.

9. Audits and Compliance Information

Plasma AI will make available to Customer information reasonably necessary to demonstrate compliance with this DPA, including, upon written request and no more than once per twelve (12) month period, summaries of Plasma AI’s then-current third-party audit reports or certifications (such as a SOC 2 report, when available), subject to confidentiality obligations. To the extent Customer’s audit rights under Data Protection Legislation cannot reasonably be satisfied through such documentation, Plasma AI will allow for and contribute to audits, including inspections, conducted by Customer or an independent auditor mandated by Customer (that is not a competitor of Plasma AI), upon reasonable prior written notice, during normal business hours, no more than once per twelve (12) month period (except following a Security Incident or where required by a supervisory authority), and in a manner that does not disrupt Plasma AI’s business or compromise the security of other customers.

10. International Transfers

Plasma AI processes Personal Data in the United States. To the extent Plasma AI processes Personal Data protected by the GDPR, UK GDPR or Swiss data protection law in a country that has not received an adequacy decision, the parties agree that such transfers are governed by the SCCs, which are incorporated into this DPA by reference as follows: Module Two (controller to processor) applies where Customer is a controller, and Module Three (processor to processor) applies where Customer is a processor; Customer is the “data exporter” and Plasma AI is the “data importer”; Clause 7 (docking) is included; under Clause 9, Option 2 (general authorization) applies with the notice period in Section 6 of this DPA; under Clause 11, the optional language is deleted; under Clauses 17 and 18, the governing law and forum are those of Ireland; and Annexes I and II to the SCCs are populated by Annexes I and II to this DPA. For transfers subject to the UK GDPR, the SCCs apply as modified by the UK International Data Transfer Addendum issued by the UK Information Commissioner, and for transfers subject to Swiss law, the SCCs apply with the adaptations required by the Swiss Federal Data Protection and Information Commissioner.

11. CCPA; U.S. State Privacy Laws

To the extent Personal Data is subject to the CCPA or other U.S. state privacy laws, Plasma AI acts as Customer’s “service provider” or “processor,” and: (a) Plasma AI will not sell or share Personal Data; (b) Plasma AI will not retain, use or disclose Personal Data for any purpose other than the business purposes specified in the Agreement and this DPA, or as otherwise permitted by applicable law, including not retaining, using or disclosing Personal Data outside of the direct business relationship between the parties; (c) Plasma AI will not combine Personal Data with personal information it receives from other sources, except as permitted by applicable law; (d) Plasma AI certifies that it understands and will comply with the restrictions in this Section; and (e) Plasma AI will notify Customer if it determines it can no longer meet its obligations under applicable Data Protection Legislation, in which case Customer may take reasonable and appropriate steps to stop and remediate unauthorized use of Personal Data.

12. No Training on Customer Data

Plasma AI will not use Customer Data, including Personal Data contained therein, to train or improve artificial intelligence or machine learning models. For clarity, nothing in this Section limits Plasma AI’s rights under the Agreement with respect to System Data or aggregated and anonymized information that does not identify Customer or any individual.

13. Deletion and Return

Upon expiration or termination of the Agreement or applicable Order Form, Plasma AI will, at Customer’s election, return or delete Personal Data in accordance with the Customer Data retrieval and deletion terms of the Agreement, unless retention is required by applicable law. Personal Data in backup media will be deleted in accordance with Plasma AI’s standard backup expiration cycle and will remain protected in accordance with this DPA until deleted.

14. General

This DPA is subject to the limitations of liability set forth in the Agreement, and each party’s aggregate liability arising out of or related to this DPA is subject to the caps set forth therein. If any provision of this DPA is held invalid or unenforceable, the remainder will remain in full force and effect. This DPA will terminate automatically upon termination of the Agreement, except that it will continue to apply for as long as Plasma AI processes Personal Data on Customer’s behalf.

Annex I – Description of Processing

Subject matter and duration. The processing of Personal Data in connection with the provision of the Plasma AI Product under the Agreement, for the duration of the Agreement plus the retrieval and deletion periods described in the Agreement.

Nature and purpose. Hosting, storage, computation, transmission, agent orchestration and related processing necessary to provide, support, secure and maintain the Plasma AI Product and to perform Professional Services, as instructed by Customer through its use and configuration of the Plasma AI Product.

Categories of data subjects. Customer’s Users (e.g., employees, contractors and other personnel authorized by Customer) and any individuals whose Personal Data is contained in Customer Data submitted to the Plasma AI Product by Customer or its Users, as determined by Customer.

Types of Personal Data. User account and contact information (e.g., name, business email); usage and log data associated with Users; and any Personal Data contained in Customer Data, the scope of which is determined and controlled by Customer. Customer will not submit special categories of personal data (e.g., health data) unless the parties have agreed in writing.

Frequency. Continuous, for the duration described above.

Annex II – Technical and Organizational Measures

Plasma AI maintains the technical and organizational measures described on the Plasma AI Security Page at plasma.ai/security, which include, at a minimum, measures in the following areas:

  • Physical access control: hosting in third-party cloud data centers with controlled facility access, surveillance and monitoring; restricted office access; processes for revoking physical access when no longer required.
  • System access control: unique user accounts; multi-factor authentication for production and critical systems; centrally managed, least-privilege access subject to approval; prompt revocation on role change or departure; no guest or shared accounts on systems processing Personal Data.
  • Data access control: encryption of Personal Data in transit (TLS 1.2+) and at rest (AES-256); access to Personal Data limited to personnel with a business need; logging of access where supported by the relevant system.
  • Disclosure control: encrypted transmission of Personal Data; audit trails of data transfers; multi-factor authenticated, encrypted remote access for administration.
  • Input control: logging of user and administrative activity on systems processing Personal Data, including records of what data was entered, changed or removed, when, and by whom.
  • Availability control: automated encrypted backups; redundancy across our cloud providers’ infrastructure; business continuity and disaster recovery procedures; anti-malware and firewall protections.
  • Segregation control: logical separation of each customer’s data; segregation of production from testing and development environments; no use of Personal Data in test environments, except with Customer’s authorization or after appropriate de-identification.
  • Organizational measures: confidentiality obligations for all personnel; security and privacy training; background checks where permitted by law; documented incident response procedures; vendor security review for Subprocessors.

Annex III – Subprocessors

Plasma AI currently engages the following Subprocessors in the provision of the Plasma AI Product:

Amazon Web Services, Inc.PurposeCloud hosting and infrastructureLocationUnited States
AnthropicPurposeThird-party foundation models (API)LocationUnited States
OpenAIPurposeThird-party foundation models (API)LocationUnited States
OpenRouterPurposeModel routing for third-party modelsLocationUnited States
MongoDB (Atlas)PurposeProduct databaseLocationUnited States
NeonPurposeProduct database (Postgres)LocationUnited States
ModalPurposeCompute for product workloadsLocationUnited States
RailwayPurposeBackend hostingLocationUnited States
VercelPurposeApplication hostingLocationUnited States
CloudflarePurposeCDN, DNS and network securityLocationUnited States
SentryPurposeError monitoringLocationUnited States
ResendPurposeTransactional emailLocationUnited States
WorkOSPurposeEnterprise authentication (SSO, SAML, directory sync)LocationUnited States
ComposioPurposeIntegrations connecting the Plasma AI Product to third-party tools and APIsLocationUnited States
DatadogPurposeInfrastructure monitoring and observability (logs, metrics)LocationUnited States
GCP (Google Cloud Platform)PurposeCloud hosting and infrastructureLocationUnited States
Fly.ioPurposeApplication hosting and computeLocationUnited States

For clarity, providers of Customer-Provided Resources that Customer procures directly are not Plasma AI Subprocessors.