Data Processing Agreement
Standard contractual clauses for GDPR-compliant data processing.
Scope and Purpose
This Data Processing Agreement (DPA) applies when AIwithFiaz processes personal data on behalf of a client (Data Controller) under GDPR Article 28. It covers all services where we act as Data Processor.
Data Categories
We may process: contact details, identification data, project information, technical logs, and communication records. Special category data is only processed with explicit consent.
Processor Obligations
AIwithFiaz will: process data only on documented instructions, ensure confidentiality, implement security measures, assist with data subject rights, notify breaches within 72 hours, and delete/return data after service completion.
Sub-processors
We use sub-processors for hosting (AWS/Vercel), analytics (Google), payments (Stripe), and email (SendGrid). Sub-processor list is available on request. Clients may object to new sub-processors.
International Transfers
Data may be processed in the USA. We rely on Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework for adequacy.
Audit Rights
Controller may audit Processor's compliance with reasonable notice. Audit costs are borne by Controller unless significant non-compliance is found.
This policy is effective as of the date listed above. We may update it periodically. Continued use of our services constitutes acceptance of the updated policy. For questions, contact us at hello@aiwithfiaz.com