Data Processing Addendum
Last Updated: February 10, 2026
This Data Processing Addendum ("DPA") supplements the Customer Agreement between RunAI Inc ("RunAI", "Processor") and the Customer ("Controller") and governs the processing of personal data by RunAI on behalf of the Customer.
1. Roles and Scope
1.1 Roles
| Party | Role | Responsibilities |
|---|---|---|
| Customer | Data Controller | Determines the purposes and means of processing personal data |
| RunAI | Data Processor | Processes personal data only on documented instructions from the Controller |
1.2 Categories of Data Subjects
- Customer's employees and contractors
- Customer's authorized users of the Service
1.3 Types of Personal Data
- Account data (name, email, employee ID, role)
- Communications data (messages, files, reactions)
- Usage data (login times, feature usage, IP addresses)
- Device data (browser type, OS, screen resolution)
1.4 Processing Activities
- Storage, retrieval, and delivery of messages and files
- User authentication and access management
- System monitoring and security logging
- Generating aggregated, de-identified analytics
2. GDPR Compliance
2.1 Processor Obligations
RunAI shall:
- Process personal data only on documented instructions from the Controller, including with respect to transfers of personal data to a third country, unless required to do so by applicable law.
- Ensure that persons authorized to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk (see Section 3).
- Assist the Controller in fulfilling its obligations to respond to data subject requests.
- Assist the Controller in ensuring compliance with security, breach notification, data protection impact assessments, and prior consultation obligations.
- At the choice of the Controller, delete or return all personal data to the Controller after the end of the provision of services, and delete existing copies unless applicable law requires storage.
- Make available to the Controller all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits.
2.2 Controller Obligations
The Controller shall:
- Ensure it has a lawful basis for processing personal data through the Service.
- Provide clear and documented processing instructions to RunAI.
- Inform its employees and users about the processing in accordance with applicable law.
- Respond to data subject requests in a timely manner.
3. Security Measures
RunAI implements and maintains the following technical and organizational measures:
3.1 Encryption
- Data in transit: TLS 1.2 or higher for all connections.
- Data at rest: AES-256 encryption for stored data.
3.2 Access Controls
- Role-based access control (RBAC) for all internal systems.
- Multi-factor authentication for RunAI personnel accessing production systems.
- Principle of least privilege applied to all access grants.
- Regular access reviews and prompt deprovisioning.
3.3 Infrastructure
- Production systems hosted in SOC 2-compliant data centers.
- Network segmentation and firewalls.
- Automated vulnerability scanning and patch management.
- DDoS mitigation.
3.4 Organizational
- Security awareness training for all employees.
- Background checks for employees with access to customer data.
- Incident response plan maintained and tested regularly.
- Regular third-party security assessments.
4. Sub-processors
4.1 Authorization
The Controller provides general written authorization for RunAI to engage sub-processors. RunAI shall:
- Maintain an up-to-date list of sub-processors, available upon request.
- Notify the Controller at least 30 days before adding or replacing a sub-processor.
- Enter into written agreements with sub-processors imposing data protection obligations no less protective than those in this DPA.
4.2 Objection
If the Controller objects to a new sub-processor, the parties will work in good faith to find a resolution. If no resolution is reached within 30 days, the Controller may terminate the affected Service by providing written notice.
4.3 Liability
RunAI remains fully liable to the Controller for the performance of its sub-processors' obligations.
5. Data Breach Notification
5.1 Notification Timeline
RunAI shall notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Controller's data.
5.2 Notification Content
The notification shall include, to the extent available:
- A description of the nature of the breach, including categories and approximate number of data subjects and records affected.
- The name and contact details of RunAI's point of contact for further information.
- A description of the likely consequences of the breach.
- A description of the measures taken or proposed to address the breach, including measures to mitigate its adverse effects.
5.3 Cooperation
RunAI shall cooperate with the Controller and take reasonable steps to assist in the investigation, mitigation, and remediation of the breach.
6. International Transfers
To the extent that processing involves the transfer of personal data outside the European Economic Area, the parties agree to the EU Standard Contractual Clauses (Module Two: Controller to Processor), which are incorporated by reference into this DPA.
7. Audit Rights
Upon reasonable notice (no less than 30 days), and no more than once per year, the Controller may audit RunAI's compliance with this DPA. Audits shall be conducted during normal business hours, at the Controller's expense, and subject to reasonable confidentiality obligations.
RunAI may satisfy audit requests by providing relevant certifications, audit reports (e.g., SOC 2), or other documentation demonstrating compliance.
8. Term and Termination
This DPA remains in effect for the duration of the Customer Agreement. Obligations relating to data deletion, confidentiality, and cooperation with audits survive termination.