This Data Processing Agreement (“DPA”) describes how afka processes personal data on your behalf when you use the Service. It forms part of, and is governed by, our Terms of Service, and reflects the requirements of GDPR Article 28 and similar laws.
This DPA applies where afka processes personal data on your behalf in providing the Service. For that data, you act as the controller (or, under some laws, business) and afka acts as the processor (or service provider). Where you process personal data on behalf of your own customers, you may be a processor and afka a sub-processor; this DPA applies accordingly. If there is a conflict between this DPA and the Terms regarding the processing of personal data, this DPA controls.
Capitalized terms not defined here have the meaning given in the Terms. “Applicable Data Protection Law” means privacy and data-protection laws that apply to the processing, including the EU GDPR, the UK GDPR, and U.S. state privacy laws such as the CCPA/CPRA. “Controller,” “Processor,” “Personal Data,” “Processing,” “Data Subject,” and “Personal Data Breach” have the meanings given in Applicable Data Protection Law. “Customer Personal Data” means personal data within your Content that afka processes on your behalf.
afka will process Customer Personal Data only on your documented instructions, including as set out in the Terms, this DPA, and your configuration and use of the Service, unless required to act otherwise by law (in which case afka will inform you, where legally permitted). The subject matter, duration, nature, purpose, types of personal data, and categories of data subjects are described in Annex I. You are responsible for ensuring you have a lawful basis to provide Customer Personal Data and that your instructions comply with Applicable Data Protection Law. afka will inform you if, in its opinion, an instruction infringes Applicable Data Protection Law.
afka ensures that personnel authorized to process Customer Personal Data are bound by appropriate confidentiality obligations and process that data only as needed to provide the Service.
afka implements and maintains appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the state of the art, the costs of implementation, and the nature of the processing. A description of these measures is set out in Annex II. afka may update its measures over time, provided the level of protection is not materially reduced.
You provide general written authorization for afka to engage sub-processors to process Customer Personal Data in order to provide the Service. afka imposes data-protection obligations on each sub-processor that are no less protective than those in this DPA, and remains responsible for each sub-processor's performance. The categories of sub-processors are listed in Annex III; a current list of named sub-processors is available on request. afka will give you reasonable notice of any intended addition or replacement of a sub-processor and an opportunity to object on reasonable data-protection grounds.
Taking into account the nature of the processing, afka will assist you with appropriate technical and organizational measures, insofar as possible, to respond to requests from data subjects exercising their rights under Applicable Data Protection Law. If afka receives such a request directly relating to your Customer Personal Data, it will, where legally permitted, direct the data subject to you rather than respond itself. Many requests can be fulfilled by you directly through the Service.
afka will notify you without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide information reasonably available to it to help you meet your notification obligations. afka's notification is not an acknowledgment of fault or liability.
afka and its sub-processors may process Customer Personal Data in the United States and other countries. Where afka transfers Customer Personal Data originating in the European Economic Area, the United Kingdom, or Switzerland to a country without an adequacy decision, the transfer is made under appropriate safeguards, such as the European Commission's Standard Contractual Clauses (and the UK Addendum, where applicable), which are incorporated by reference and will be made available on request.
afka will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. To the extent available, afka may satisfy audit requests by providing summaries of relevant third-party assessments or documentation of its security program, and audits will be conducted on reasonable prior notice, during business hours, subject to confidentiality, and no more than once per year unless required by a supervisory authority or following a Personal Data Breach.
On expiry or termination of the Service, afka will, at your choice, delete or return Customer Personal Data, and delete existing copies unless retention is required by law. afka will make Customer Personal Data available for export for a limited period following termination, after which it is deleted or de-identified, subject to routine backup cycles and legal requirements.
To the extent afka processes personal information subject to the CCPA/CPRA on your behalf, afka acts as a service provider. afka does not sell or share that personal information, does not retain, use, or disclose it for any purpose other than performing the Service (or as otherwise permitted by the CCPA), and does not combine it with personal information from other sources except as permitted. afka certifies that it understands and will comply with these restrictions.
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms. This DPA takes effect when you accept the Terms or begin using the Service and remains in effect for as long as afka processes Customer Personal Data on your behalf.
| Subject matter | afka's provision of the Service to you under the Terms. |
| Duration | For the term of the Service, plus any limited export and deletion period. |
| Nature & purpose | Hosting, processing, and transmitting Customer Personal Data to operate the Service and perform the tasks you delegate, including via your Connected Accounts. |
| Categories of personal data | Account and contact details; content you submit (tasks, prompts, files, artifacts); data accessed in Connected Accounts at your direction; usage and audit-log data. You control what data enters your Workspace. |
| Special categories | Not intended. You should not submit sensitive personal data except as necessary and lawful, and you are responsible for any such data you choose to provide. |
| Categories of data subjects | Your users, employees, customers, prospects, and other individuals whose data appears in your Content or Connected Accounts. |
| Frequency | Continuous, for the duration of the Service. |
afka maintains technical and organizational measures including:
afka engages sub-processors in the following categories to provide the Service:
A current list of named sub-processors, including the processing each performs, is available to customers on request at support@afka.ai.
This DPA applies automatically when you accept the Terms and use the Service. If your organization requires a countersigned copy or has specific data-protection requirements, contact support@afka.ai and we will be glad to help.
Afka, Inc.
2810 N Church St STE 89857
Wilmington, DE 19802
United States