Back to Policy Center
Legal Policy

Data Processing Agreement

Standard contractual clauses for GDPR-compliant data processing.

Last updated: December 15, 2025Version 1.0

Scope and Purpose

This Data Processing Agreement (DPA) applies when AIwithFiaz processes personal data on behalf of a client (Data Controller) under GDPR Article 28. It covers all services where we act as Data Processor.

Data Categories

We may process: contact details, identification data, project information, technical logs, and communication records. Special category data is only processed with explicit consent.

Processor Obligations

AIwithFiaz will: process data only on documented instructions, ensure confidentiality, implement security measures, assist with data subject rights, notify breaches within 72 hours, and delete/return data after service completion.

Sub-processors

We use sub-processors for hosting (AWS/Vercel), analytics (Google), payments (Stripe), and email (SendGrid). Sub-processor list is available on request. Clients may object to new sub-processors.

International Transfers

Data may be processed in the USA. We rely on Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework for adequacy.

Audit Rights

Controller may audit Processor's compliance with reasonable notice. Audit costs are borne by Controller unless significant non-compliance is found.

This policy is effective as of the date listed above. We may update it periodically. Continued use of our services constitutes acceptance of the updated policy. For questions, contact us at hello@aiwithfiaz.com