Data Processing Agreement (DPA)
187N — Processor Terms Version: [FILL: v1.0] · Last updated: [FILL: date]
Draft for review — must be reviewed by counsel before offering to clients. This DPA is the agreement 187N enters into as a processor when it processes personal data on behalf of a client (the controller) while delivering AI agents, automation, and related services. It is the document linked from the footer and the security page. It is not the website privacy policy (see privacy-policy.md).
This Data Processing Agreement ("DPA") forms part of the Master Services Agreement or order ("Agreement") between the Client ("Controller") and 187N ([FILL: legal entity name], "Processor"). Where 187N processes personal data on the Controller's behalf, this DPA applies and prevails over conflicting terms in the Agreement on the subject of data protection.
1. Definitions
Terms such as "personal data", "processing", "controller", "processor", "data subject", and "sub-processor" have the meanings given in the GDPR (Regulation (EU) 2016/679).
2. Roles and scope of processing
The Controller determines the purposes and means of processing; 187N processes personal data only on the Controller's documented instructions. The subject matter, duration, nature, and purpose of processing, the types of personal data, and the categories of data subjects are set out in Annex 1.
3. 187N's obligations
187N shall:
a. process personal data only on the Controller's documented instructions, including for transfers, unless required by law (in which case it will inform the Controller unless legally prohibited); b. ensure persons authorised to process the data are bound by confidentiality; c. implement the technical and organisational security measures in Annex 2 (Art. 32 GDPR); d. respect the conditions in Section 5 for engaging sub-processors; e. assist the Controller, by appropriate measures, in responding to data-subject requests (access, rectification, erasure, etc.); f. assist the Controller with security, breach notification, data protection impact assessments, and prior consultation (Arts. 32–36); g. at the Controller's choice, delete or return all personal data at the end of the services and delete existing copies, unless retention is required by law; and h. make available information necessary to demonstrate compliance and allow for and contribute to audits, as set out in Section 7.
4. Personal data breach
187N will notify the Controller without undue delay, and in any case within [FILL: e.g. 48] hours, after becoming aware of a personal data breach affecting the Controller's data, with the information reasonably available to support the Controller's own notification obligations.
5. Sub-processors
The Controller provides general written authorisation for 187N to engage sub-processors, provided 187N (a) imposes data-protection obligations on each sub-processor equivalent to this DPA, and (b) remains liable for their performance. The current sub-processors are listed in Annex 3. 187N will inform the Controller of intended changes and give the Controller a chance to object on reasonable data-protection grounds.
6. International transfers
187N will not transfer personal data outside the EEA except under an appropriate safeguard (e.g. Standard Contractual Clauses, an adequacy decision, or the EU–US Data Privacy Framework). [FILL: note any transfer to the Dubai entity and the safeguard relied upon.]
7. Audits
187N will make available the information necessary to demonstrate compliance with Art. 28 GDPR and allow for audits, including inspections, by the Controller or an auditor it mandates, on reasonable notice, no more than [FILL: once] per year (or following a breach), subject to confidentiality and 187N's security policies.
8. Liability and term
The liability of each party under this DPA is subject to the limitations of liability in the Agreement. This DPA remains in effect for as long as 187N processes personal data on the Controller's behalf.
Annex 1 — Details of processing
- Subject matter: [FILL: e.g. delivery and operation of AI agents and automation workflows for the Controller]
- Duration: for the term of the Agreement
- Nature & purpose: [FILL: e.g. ingesting, classifying, generating, and routing data through AI agents]
- Types of personal data: [FILL: e.g. names, business contact details, support-ticket content, etc.]
- Categories of data subjects: [FILL: e.g. the Controller's customers, leads, and employees]
Annex 2 — Security measures
See 187N's security overview at https://187n.ai/security, including: encryption in transit and at rest, role-based access control, least-privilege, logging and monitoring, secure development practices, vendor due diligence, and incident response. [FILL: align with the controls actually described on /security.]
Annex 3 — Approved sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| [FILL: e.g. Vercel] | Hosting / infrastructure | [FILL] |
| [FILL: model/API providers, e.g. Anthropic] | AI model inference | [FILL] |
| [FILL: …] | [FILL] | [FILL] |