Data Processing Agreement
This Data Processing Agreement (“DPA”) forms part of the Terms of Service (the “Agreement”) between OurAI ApS (“Processor”, “OurAI”, “we”) and the customer organisation that has subscribed to the OurAI service (“Controller”, “Customer”, “you”).
This DPA applies only to Business Customers: organisations (including sole traders acting in a professional capacity) that use OurAI in the course of a business or professional activity. If you use OurAI as an Individual Customer for personal purposes, this DPA does not apply to you. Your data is governed solely by the Privacy Policy, and OurAI is the controller for the personal data you submit.
Scope
This DPA reflects the parties’ agreement on the processing of Personal Data by OurAI on Customer’s behalf in the course of providing the OurAI service, in compliance with the EU General Data Protection Regulation (“GDPR”) and the Danish Data Protection Act.
By accepting the Agreement, the Business Customer enters into this DPA on its own behalf and, to the extent required, on behalf of its affiliates that use the service. No separate signature is required.
Definitions
Capitalised terms not defined here have the meaning given in the Agreement or in the GDPR. “Personal Data”, “Processing”, “Data Subject”, “Controller”, “Processor”, “Sub-processor”, and “Personal Data Breach” have the meanings given in the GDPR.
“Customer Personal Data” means Personal Data that Customer or its authorised users submit to the service and that OurAI processes on Customer’s behalf.
Roles
- Customer is the Controller of Customer Personal Data. Customer determines the purposes and means of the processing and is responsible for ensuring that the processing it instructs OurAI to perform is lawful under the GDPR and the Danish Data Protection Act.
- OurAI is the Processor, acting only on Customer’s documented instructions.
- Where OurAI processes Personal Data for its own purposes (for example, account billing data and the contact details of Customer’s administrators), OurAI is an independent Controller and the Privacy Policy applies, not this DPA.
Subject matter and duration
OurAI processes Customer Personal Data for the duration of the Agreement, plus any post-termination period needed to return or delete it under the Return or deletion section.
Details of the processing
Subject matter. Provision of the OurAI service: a controlled, audited workspace for using large language models.
Nature and purpose. Hosting, transmitting, and processing prompts, conversations, files, and usage metadata on Customer’s instructions so that Customer’s authorised users can use AI models. Generating audit logs, billing data, and aggregated workspace insights.
Categories of Data Subjects. Customer’s authorised users (employees, contractors); and any individuals whose personal data is included in the content Customer’s users submit.
Categories of Personal Data. Identifiers (name, work email, user ID); authentication and session data; the content of prompts, conversations, and uploaded files, which may contain personal data chosen by Customer’s users; and usage metadata (model, token counts, timestamps, conversation ID).
Special-category data. Not requested by, and not required for, the service. Customer is responsible for ensuring that its users do not submit special-category data without an appropriate lawful basis.
Frequency of processing. Continuous, for as long as Customer uses the service.
Customer instructions
OurAI will process Customer Personal Data only on Customer’s documented instructions, including for transfers to a third country, unless processing is required by Union or Member State law to which OurAI is subject. In that case, OurAI will inform Customer of the legal requirement before processing, unless the law prohibits this on important grounds of public interest. The Agreement, this DPA, and Customer’s use of the product’s configuration controls (model permissions, retention settings, workspace policies) together constitute Customer’s documented instructions.
OurAI will inform Customer without undue delay if, in OurAI’s opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions.
Confidentiality
OurAI ensures that personnel authorised to process Customer Personal Data are bound by confidentiality obligations (contractual or statutory) and are trained on data-protection requirements. Only personnel who need access to Customer Personal Data in order to provide the service are authorised, and access is withdrawn without undue delay when the authorisation ends or is revoked. OurAI can demonstrate these confidentiality commitments to Customer on request.
Security
OurAI implements appropriate technical and organisational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. OurAI may update them from time to time, provided the level of security is not reduced. These measures include at least:
- Encryption in transit: TLS 1.2 or higher for all customer-facing endpoints and inter-service traffic.
- Encryption at rest: for databases, backups, and storage volumes holding Customer Personal Data.
- Access control: role-based access; least-privilege defaults; multi-factor authentication required for production access.
- Audit logging: administrative actions on production systems are logged and reviewed.
- Network segmentation: production environments are isolated from development and staging.
- Backups: daily backups stored within the EU; tested restores at least annually.
- Vulnerability management: dependency scanning, regular patching, periodic penetration testing.
- Incident response: documented playbook, defined on-call rotation, post-incident review.
- Personnel: confidentiality agreements; data-protection and security training; background checks where lawful and proportionate.
- Vendor management: written contracts with Sub-processors imposing equivalent protections.
- Data minimisation and retention: retention limits configurable by Customer in the product, with default and maximum periods documented.
Detailed evidence of these measures (e.g. certifications, audit reports) is available to Customer on reasonable request under the Audit section.
Sub-processors
General authorisation
Customer grants OurAI a general authorisation to engage the Sub-processors listed below.
New Sub-processors
OurAI will give Customer at least 30 days’ prior notice before adding or replacing a Sub-processor (by updating the list below and notifying Customer’s admin contact or via the product). Customer may object within that window on reasonable data-protection grounds. If the parties cannot resolve the objection, Customer may terminate the affected service for convenience and receive a pro-rata refund of pre-paid fees for the unused portion.
Sub-processor obligations
OurAI imposes on each Sub-processor data-protection obligations no less protective than those in this DPA, and remains liable to Customer for any breach by a Sub-processor. On Customer’s request, OurAI will provide a copy of its agreement with a Sub-processor; commercial terms that do not affect its data-protection content may be redacted.
OurAI’s agreements with Sub-processors include Customer as a third-party beneficiary in the event of OurAI’s bankruptcy, so that Customer can invoke OurAI’s rights against the Sub-processor, for example to instruct it to delete or return Customer Personal Data.
Current sub-processors
We currently engage the following Sub-processors:
- Hetzner Online GmbH: primary hosting infrastructure for the managed deployment. Datacenter in Helsinki, Finland (EU); company seated in Germany (EU).
- OpenAI: AI model inference and image generation, where Customer’s workspace policy permits. Located in the United States.
- Anthropic: AI model inference, where Customer’s workspace policy permits. Located in the United States.
- Google (Gemini): AI model inference, where Customer’s workspace policy permits. Located in the United States.
- Mistral AI: AI model inference, where Customer’s workspace policy permits; additionally, automated content-safety moderation of prompts on every request, independent of workspace policy. Where Customer’s redaction policy is active, moderation reads the redacted text. Located in France (EU).
- xAI: AI model inference, where Customer’s workspace policy permits. Located in the United States.
- DeepSeek: AI model inference, where Customer’s workspace policy permits. Located in China.
- Alibaba Cloud (Qwen): AI model inference via Alibaba Cloud’s international endpoint, where Customer’s workspace policy permits. Located in Singapore.
- Moonshot AI: AI model inference, where Customer’s workspace policy permits. Located in Singapore.
- Brave Software: web search: when the web-search tool is enabled, search queries derived from Customer conversations are sent to Brave. Located in the United States.
- Postmark (ActiveCampaign): transactional email: verification, sign-in, and invitation messages to Customer’s users. Located in the United States.
- Sentry (Functional Software): error monitoring for the service’s backend and web applications. Located in the United States.
- Stripe: billing and payment processing.
- Proton: business email and document storage for business communications. Located in Switzerland.
Customer support is handled over email. No separate support-ticketing Sub-processor is engaged.
We will update this list before adding or replacing a Sub-processor, with the prior notice described above.
International transfers
Customer Personal Data is hosted in Helsinki, Finland (EU/EEA) by default. Where the Customer’s workspace configuration permits inference on AI models hosted outside the EU/EEA, the corresponding prompts and responses are transferred to the relevant provider for the duration of the inference call.
For transfers outside the EU/EEA, OurAI relies on:
- the EU–US Data Privacy Framework adequacy decision where the recipient is certified; or
- the European Commission’s Standard Contractual Clauses (SCCs), incorporated by reference into the agreement with the relevant Sub-processor; and
- supplementary technical and organisational measures (encryption in transit, contractual prohibitions on training, audit rights).
Customer authorises OurAI to enter into the SCCs (and any successor mechanism) with Sub-processors on Customer’s behalf.
Assistance to Controller
Taking into account the nature of the processing and the information available, OurAI will provide reasonable assistance to Customer to:
- respond to requests from Data Subjects exercising their rights under the GDPR;
- comply with its security, breach notification, data protection impact assessment (DPIA), and prior consultation obligations under the GDPR.
OurAI will pass on Data Subject requests it receives directly to Customer without responding to them itself (unless Customer instructs otherwise).
Personal Data Breach notification
OurAI will notify Customer without undue delay, and in any event within 48 hours, of becoming aware of a Personal Data Breach affecting Customer Personal Data (whether at OurAI or at a Sub-processor), so that Customer can meet its own 72-hour deadline for reporting to the supervisory authority. The notification will include the information the GDPR requires, to the extent then known, and will be supplemented as more information becomes available.
Return or deletion at the end of processing
On termination of the Agreement or on Customer’s written request, OurAI will, at Customer’s choice, return Customer Personal Data in a structured, machine-readable format, or delete it. Deletion will be completed within 30 days of the request or termination date, except where Union or Member State law requires longer retention (for example, Danish bookkeeping law for financial records, kept up to 5 years).
Audit
OurAI will make available to Customer all information reasonably necessary to demonstrate compliance with this DPA, and will allow for audits, including inspections, conducted by Customer or an independent auditor mandated by Customer, subject to reasonable confidentiality and operational safeguards.
To minimise disruption, OurAI may satisfy an audit request by providing recent third-party certifications (e.g. ISO 27001), penetration-test summaries, or completed security questionnaires, where these reasonably address Customer’s concerns. On-site audits are limited to once per year, conducted during business hours, with at least 30 days’ notice, and at Customer’s expense, except when prompted by a confirmed Personal Data Breach.
Audits of Sub-processors are as a rule performed through OurAI: on Customer’s reasonable request, OurAI will obtain and share documentation of a Sub-processor’s compliance with its data-protection obligations.
OurAI will give supervisory authorities that have a statutory right of access to Customer’s or OurAI’s facilities, or representatives acting on their behalf, access to OurAI’s physical facilities on presentation of appropriate identification.
Liability
The liability provisions of the Agreement apply to this DPA. The total combined liability of the parties under the Agreement and this DPA, taken together, is subject to the limitations in the Agreement.
Order of precedence
If there is a conflict between this DPA and the Agreement on the subject of personal data processing, this DPA controls. If there is a conflict between this DPA and the SCCs incorporated under International transfers, the SCCs control.
Contact
Notices and questions under this DPA can be sent to support@ourai.dk. OurAI directs notices to Customer’s admin contact. Each party will keep the other informed of changes to its contact point.
Governing law
This DPA is governed by the law specified in the Agreement (Danish law), without prejudice to mandatory provisions of the GDPR and any applicable Member State law.