Data Processing Agreement

Effective: August 2026

For institutional and enterprise customers. This Data Processing Agreement supplements our Terms of Service and Privacy Policy for organizations that require formal data processing documentation under GDPR, CCPA, or other applicable regulations.

If your institution requires a signed DPA before using ProofInk.AI, please contact us at [email protected] and we will provide a completed agreement for your review.

1. Scope and Parties

This DPA applies between ProofInk.AI ("Processor") and the subscribing institution ("Controller") and governs the processing of personal data that the Controller submits to ProofInk.AI in connection with the use of our services.

2. Definitions

3. Data Processing Details

4. Processor Obligations

ProofInk.AI shall:

5. Sub-processors

The Controller authorizes ProofInk.AI to engage the sub-processors listed on our Subprocessors page. ProofInk.AI will notify the Controller before adding or replacing a sub-processor, providing the Controller an opportunity to object. Each sub-processor is bound by data protection obligations no less protective than those in this DPA.

6. International Transfers

Personal data is processed in the United States. For transfers of personal data from the EU/EEA/UK to the United States, ProofInk.AI relies on Standard Contractual Clauses (SCCs) as approved by the European Commission (Decision 2021/914) and the UK International Data Transfer Agreement (IDTA), or other lawful transfer mechanisms as applicable. For transfers from Switzerland, ProofInk.AI relies on the Swiss-approved version of SCCs. For transfers from Canada, ProofInk.AI ensures a comparable level of protection as required under PIPEDA. The Controller may request a copy of the applicable transfer mechanism by contacting ProofInk.AI.

7. Data Breach Notification

ProofInk.AI will notify the Controller without undue delay (and in any event within 72 hours) after becoming aware of a personal data breach affecting the Controller's data. The notification will include the nature of the breach, the categories of data affected, and the measures taken or proposed to address it.

8. Data Retention and Deletion

9. Security Measures

ProofInk.AI implements the following security measures:

10. Audit Rights

The Controller may, upon reasonable written notice and no more than once per year, request information or conduct an audit (directly or through a third-party auditor bound by confidentiality) to verify ProofInk.AI's compliance with this DPA. ProofInk.AI will cooperate with such audits and provide reasonable access to relevant information and systems.

11. Governing Law

This DPA is governed by the laws of the Commonwealth of Massachusetts, United States, except where mandatory data protection laws of the Controller's jurisdiction require otherwise.

Contact

To request a signed DPA or discuss institutional data protection requirements, email [email protected].