Effective date: July 1, 2026
The Customer acts as the Controller and Annex AI acts as the Processor with respect to personal data processed through the Service. Annex AI processes personal data only on documented instructions from the Customer, as set out in these Terms and the ToS, unless required by applicable law.
The personal data processed by Annex AI on behalf of the Customer includes:
Annex AI will process personal data only for the purposes described in the Terms of Service — specifically, to perform automated compliance checks, generate compliance documentation, and provide the compliance platform features. Annex AI will promptly notify the Customer if it believes any instruction violates applicable data protection law.
Annex AI ensures that personnel authorized to process personal data are bound by appropriate confidentiality obligations. Annex AI will not disclose personal data to any third party except as authorized under this DPA or required by law.
Annex AI implements and maintains appropriate technical and organizational measures to protect personal data against unauthorized access, disclosure, alteration, or destruction. These measures include:
The Customer provides general authorization to Annex AI to engage sub-processors. Annex AI currently uses the following sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Vercel Inc. | Application hosting and delivery | United States |
| Neon Inc. | Database (PostgreSQL) | United States |
| Anthropic PBC | AI policy generation | United States |
| Trigger.dev Ltd. | Scheduled background tasks | United States / EU |
Annex AI will provide 14 days' advance notice of any new sub-processors via email or in-app notification. If the Customer objects, it may terminate the affected service components within the notice period.
Annex AI will assist the Customer in responding to requests from Data Subjects exercising their rights under applicable data protection law (access, correction, deletion, portability, objection). The Customer is primarily responsible for responding to Data Subject requests. Annex AI will cooperate with reasonable requests for assistance within 5 business days.
Annex AI will notify the Customer without undue delay — and in any event within 72 hours of becoming aware — of any personal data breach that may affect Customer data. The notification will include the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed to address the breach.
Personal data is processed in the United States. For transfers of personal data from the EEA, UK, or Switzerland to the US, the parties rely on the Standard Contractual Clauses (Module 2: Controller to Processor) issued by the European Commission under Decision 2021/914, which are hereby incorporated by reference. A copy of the applicable SCCs is available upon request at contact@annexai.in.
Annex AI will provide the Customer with information reasonably necessary to demonstrate compliance with this DPA. The Customer may conduct audits or inspections with 30 days' written notice, at the Customer's expense, no more than once per year, provided that audits do not interfere with Annex AI's operations or compromise the security or privacy of other customers.
Upon termination of the Service, Annex AI will, at the Customer's election, return or delete all personal data within 30 days, except where retention is required by applicable law. Annex AI will provide written confirmation of deletion upon request.
For questions about this DPA or to request the Standard Contractual Clauses, contact us at contact@annexai.in.