← Legal

Data Processing Agreement

Effective date: July 1, 2026

This DPA applies to customers who are subject to GDPR, UK GDPR, or similar data protection laws and who process personal data using the Annex AI Service. It supplements the Terms of Service and forms part of the agreement between you and Annex AI.

1. Definitions

  • Controller — the Customer, who determines the purposes and means of processing personal data
  • Processor — Annex AI, who processes personal data on behalf of the Controller
  • Data Subject — the individual whose personal data is being processed
  • Personal Data — any information relating to an identified or identifiable natural person
  • Processing — any operation performed on personal data
  • Standard Contractual Clauses (SCCs) — the European Commission's approved clauses for international data transfers

2. Roles and Scope

The Customer acts as the Controller and Annex AI acts as the Processor with respect to personal data processed through the Service. Annex AI processes personal data only on documented instructions from the Customer, as set out in these Terms and the ToS, unless required by applicable law.

The personal data processed by Annex AI on behalf of the Customer includes:

  • Employee account information pulled from connected identity providers (email addresses, names, MFA enrollment status, last login timestamps)
  • Repository and infrastructure metadata from connected developer tools and cloud providers
  • Any personal data included in compliance notes, policy content, or AI system descriptions entered by the Customer

3. Processing Instructions

Annex AI will process personal data only for the purposes described in the Terms of Service — specifically, to perform automated compliance checks, generate compliance documentation, and provide the compliance platform features. Annex AI will promptly notify the Customer if it believes any instruction violates applicable data protection law.

4. Confidentiality

Annex AI ensures that personnel authorized to process personal data are bound by appropriate confidentiality obligations. Annex AI will not disclose personal data to any third party except as authorized under this DPA or required by law.

5. Security Measures

Annex AI implements and maintains appropriate technical and organizational measures to protect personal data against unauthorized access, disclosure, alteration, or destruction. These measures include:

  • Encryption of sensitive credentials at rest using AES-256-GCM
  • Encryption of data in transit using TLS 1.2 or higher
  • Access controls limiting data access to authorized personnel
  • Use of minimum-privilege integration credentials (read-only scopes)
  • Automated daily database backups with a 14-day retention period
  • Audit logging of administrative actions

6. Sub-processors

The Customer provides general authorization to Annex AI to engage sub-processors. Annex AI currently uses the following sub-processors:

Sub-processorPurposeLocation
Vercel Inc.Application hosting and deliveryUnited States
Neon Inc.Database (PostgreSQL)United States
Anthropic PBCAI policy generationUnited States
Trigger.dev Ltd.Scheduled background tasksUnited States / EU

Annex AI will provide 14 days' advance notice of any new sub-processors via email or in-app notification. If the Customer objects, it may terminate the affected service components within the notice period.

7. Data Subject Rights

Annex AI will assist the Customer in responding to requests from Data Subjects exercising their rights under applicable data protection law (access, correction, deletion, portability, objection). The Customer is primarily responsible for responding to Data Subject requests. Annex AI will cooperate with reasonable requests for assistance within 5 business days.

8. Data Breach Notification

Annex AI will notify the Customer without undue delay — and in any event within 72 hours of becoming aware — of any personal data breach that may affect Customer data. The notification will include the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed to address the breach.

9. International Transfers

Personal data is processed in the United States. For transfers of personal data from the EEA, UK, or Switzerland to the US, the parties rely on the Standard Contractual Clauses (Module 2: Controller to Processor) issued by the European Commission under Decision 2021/914, which are hereby incorporated by reference. A copy of the applicable SCCs is available upon request at contact@annexai.in.

10. Audit Rights

Annex AI will provide the Customer with information reasonably necessary to demonstrate compliance with this DPA. The Customer may conduct audits or inspections with 30 days' written notice, at the Customer's expense, no more than once per year, provided that audits do not interfere with Annex AI's operations or compromise the security or privacy of other customers.

11. Return or Deletion of Data

Upon termination of the Service, Annex AI will, at the Customer's election, return or delete all personal data within 30 days, except where retention is required by applicable law. Annex AI will provide written confirmation of deletion upon request.

12. Contact

For questions about this DPA or to request the Standard Contractual Clauses, contact us at contact@annexai.in.