Data Processing Agreement
For institutional and enterprise customers. This Data Processing Agreement supplements our Terms of Service and Privacy Policy for organizations that require formal data processing documentation under GDPR, CCPA, or other applicable regulations.
If your institution requires a signed DPA before using ProofInk.AI, please contact us at [email protected] and we will provide a completed agreement for your review.
1. Scope and Parties
This DPA applies between ProofInk.AI ("Processor") and the subscribing institution ("Controller") and governs the processing of personal data that the Controller submits to ProofInk.AI in connection with the use of our services.
2. Definitions
- Personal Data: any information relating to an identified or identifiable natural person, as defined under applicable data protection laws.
- Processing: any operation performed on personal data, including collection, storage, use, transmission, and deletion.
- Sub-processor: a third party engaged by ProofInk.AI to process personal data on behalf of the Controller. Current sub-processors are listed on our Subprocessors page.
3. Data Processing Details
- Categories of data subjects: researchers, faculty, students, and staff who use ProofInk.AI, whether through an individual account or an institutional arrangement.
- Types of personal data: name, email address, institutional affiliation, uploaded document content (which may incidentally contain personal data), and usage data.
- Purpose of processing: providing AI-powered feedback on grant proposals and research papers, managing user accounts and purchases, and supporting document Q&A features.
- Duration: personal data is processed for as long as the account remains active. Upon account deletion or termination, data is deleted in accordance with our Privacy Policy and the retention periods in Section 8 below.
4. Processor Obligations
ProofInk.AI shall:
- Process personal data only on documented instructions from the Controller and only for the purposes described above
- Ensure that persons authorized to process the personal data are subject to confidentiality obligations
- Implement appropriate technical and organizational security measures (as described in our Privacy Policy, section 6)
- Not engage additional sub-processors without prior notice to the Controller (current sub-processors are listed on our Subprocessors page)
- Assist the Controller in responding to data subject access requests
- Delete or return all personal data upon termination of the service, at the Controller's request
- Make available to the Controller all information necessary to demonstrate compliance with these obligations
5. Sub-processors
The Controller authorizes ProofInk.AI to engage the sub-processors listed on our Subprocessors page. ProofInk.AI will notify the Controller before adding or replacing a sub-processor, providing the Controller an opportunity to object. Each sub-processor is bound by data protection obligations no less protective than those in this DPA.
6. International Transfers
Personal data is processed in the United States. For transfers of personal data from the EU/EEA/UK to the United States, ProofInk.AI relies on Standard Contractual Clauses (SCCs) as approved by the European Commission (Decision 2021/914) and the UK International Data Transfer Agreement (IDTA), or other lawful transfer mechanisms as applicable. For transfers from Switzerland, ProofInk.AI relies on the Swiss-approved version of SCCs. For transfers from Canada, ProofInk.AI ensures a comparable level of protection as required under PIPEDA. The Controller may request a copy of the applicable transfer mechanism by contacting ProofInk.AI.
7. Data Breach Notification
ProofInk.AI will notify the Controller without undue delay (and in any event within 72 hours) after becoming aware of a personal data breach affecting the Controller's data. The notification will include the nature of the breach, the categories of data affected, and the measures taken or proposed to address it.
8. Data Retention and Deletion
- Uploaded documents in Lab Bundle, 3-Pack Lab Suite, and Lab Suite workspaces are retained for up to 1 year from the date of upload, after which they are automatically deleted. Documents uploaded through focused-review plans (Free, Professional) are ephemeral and are automatically deleted from active storage within approximately 2 days of upload, regardless of session state.
- Completed feedback reports are retained for up to 1 year from the date of creation, after which report content is automatically cleared. A minimal record (dates, review type, quota usage) is preserved for account integrity.
- Upon account deletion or Controller request, all personal data and documents are permanently deleted from active storage without waiting for the retention period to expire.
- A minimal account-history record is retained for internal audit purposes. This record includes the original name and email of the data subject (for fraud-prevention and audit-trail purposes), tier at deletion, dates of registration and last login, counts and dates of completed reviews, and total cost and tokens consumed. It does NOT contain the content of any uploaded documents or AI-generated reviews. This record is itself subject to deletion upon legitimate request under applicable law (e.g., GDPR Article 17).
- Encrypted system backups are retained for up to 14 days and then permanently deleted. Backups are used solely for disaster recovery. Upon account deletion, live data is removed immediately; backup copies are purged within 14 days as part of the normal backup rotation cycle.
9. Security Measures
ProofInk.AI implements the following security measures:
- Encryption at rest for our managed database and off-site backups, which we additionally encrypt with AES-256 before upload
- HTTPS/TLS encryption for all data in transit
- Password hashing using scrypt with per-user salt
- CSRF protection, rate limiting, and input sanitization
- Role-based access controls ensuring data isolation between users
- Regular security reviews and updates
10. Audit Rights
The Controller may, upon reasonable written notice and no more than once per year, request information or conduct an audit (directly or through a third-party auditor bound by confidentiality) to verify ProofInk.AI's compliance with this DPA. ProofInk.AI will cooperate with such audits and provide reasonable access to relevant information and systems.
11. Governing Law
This DPA is governed by the laws of the Commonwealth of Massachusetts, United States, except where mandatory data protection laws of the Controller's jurisdiction require otherwise.
Contact
To request a signed DPA or discuss institutional data protection requirements, email [email protected].