When it applies
Whenever an AIW system stores, retrieves, transmits, or generates output containing personal data on your behalf, you are the controller and AIW is the processor. Article 28 GDPR requires a written agreement for exactly that situation, so the DPA is annexed to the engagement and signed alongside it — it is not optional, and it is not something we negotiate at the end of a project.
It does not apply to personal data we process for our own purposes — an enquiry through the private access form, or invoicing — where AIW is the controller. That is covered by the Privacy Policy.
What it covers
- Processing only on your documented instructions, for the purposes in the statement of work.
- Confidentiality undertakings for everyone involved in delivery.
- Technical and organisational measures: access control, encryption in transit and at rest, environment segregation, logging, and AI-specific controls including no-training and minimal-retention provider settings where offered.
- Sub-processor governance with advance notice and an objection right — the current list is published at Sub-Processors.
- Assistance with data subject requests, DPIAs, and supervisory authority enquiries.
- Personal data breach notification without undue delay.
- Audit and information rights, and verifiable deletion or return at the end of the engagement.
- EEA-first processing, with EU Standard Contractual Clauses where a transfer is unavoidable.
Annexes
Annex 1 records the processing details, Annex 2 the security measures, and Annex 3 the sub-processors used for your specific engagement. Annex 1 and 3 are completed per client — the default set of sub-processors is already filled in and any addition requires notice under §5.
Download the agreement
The PDF below is the document we sign, with AIW's processor details completed and the controller fields left as fill-in lines. Send it back completed, or send us your own DPA and we will review it.
Privacy questions and data subject requests: admin@agentsiw.com