Skip to content
πŸ“‹ Legal

Data Processing Addendum

This DPA governs how Aegis Firma processes personal data on behalf of customers. It supplements the Terms of Service and reflects the GDPR Article 28 processor requirements.

Last updated: 2026-04-20Effective immediately upon account creation

Data processing model: Customer-as-controller, Aegis Firma-as-processor

You (the customer) determine the purposes and means of processing personal data in Aegis Firma. We process that data only according to your instructions. You remain responsible for ensuring your use of Aegis Firma complies with applicable data protection law.

1. Parties and Definitions

Controller: The customer entity that has entered into the Aegis Firma Terms of Service. The Controller determines the purposes and means of processing Personal Data.

Processor: Aegis Firma (operated by Aegis Digital Systems). The Processor processes Personal Data on behalf of the Controller according to the Controller's instructions.

Personal Data: Any information relating to an identified or identifiable natural person that the Controller submits to the Service.

Processing: Any operation performed on Personal Data, including collection, storage, retrieval, use, disclosure, erasure, or destruction.

Sub-processor: Any third party engaged by the Processor to process Personal Data on the Controller's behalf.

2. Processor Obligations

Aegis Firma, as Processor, undertakes to:

  • Process Personal Data only on documented instructions from the Controller (i.e., to provide the Service as described in the Terms of Service)
  • Ensure persons authorized to process Personal Data are bound by confidentiality obligations
  • Implement appropriate technical and organizational security measures (see our Security Posture)
  • Respect the conditions for engaging sub-processors as set out in Section 5
  • Assist the Controller in responding to data subject rights requests, taking into account the nature of the processing
  • Assist the Controller with security, breach notification, DPIAs, and prior consultation obligations
  • Delete or return all Personal Data at the end of the service relationship, at the Controller's choice
  • Provide all information necessary to demonstrate compliance with Article 28 GDPR, and allow for audits and inspections

3. Controller Obligations and Compliance Responsibility

Important: You remain the Controller. You own compliance decisions.

Aegis Firma generates documentation tools and workflows. We are your data processor β€” not your compliance officer, legal counsel, or regulator. You are solely responsible for determining whether your use of the Service (and the outputs generated) satisfies your applicable legal obligations.

The Controller represents and warrants that:

  • It has a lawful basis for transferring Personal Data to Aegis Firma for processing
  • It has provided all required notices to data subjects about the processing
  • It has the authority to enter into this DPA on behalf of the Controller entity
  • It will not submit Personal Data to the Service that requires a higher level of protection than our standard security measures provide (e.g., special categories of data) without first obtaining our written agreement

4. Subject Matter, Nature, and Purpose of Processing

Subject matter: Personal data submitted by the Controller to use the Aegis Firma Service, including organization profile data, employee data, AI tool usage data, and compliance documentation.
Nature of processing: Collection, storage, retrieval, use in AI-powered document generation and analysis, disclosure to authorized users within the Controller's organization, and deletion.
Purpose: To provide the Aegis Firma Service β€” AI compliance documentation, evidence collection, workflow management, and regulatory monitoring β€” as described in the Terms of Service.
Duration: For the duration of the Service agreement, plus any retention period required by law (e.g., billing records for 7 years per applicable tax law) or until the Controller requests deletion.
Types of Personal Data: Name, email, job title, organization details, and any personal data included in documents or assessments submitted by the Controller.
Categories of data subjects: The Controller's employees, contractors, officers, and any individuals whose data the Controller submits to the Service.

5. Sub-processors

By entering into this DPA, the Controller provides general written authorization for Aegis Firma to engage sub-processors. Current authorized sub-processors:

Sub-processorPurposeLocation
SupabaseDatabase and authenticationEU (West Europe)
LemonSqueezyPayment processing (Merchant of Record)USA
ResendTransactional emailUSA
CloudflareCDN, DDoS protection, DNSGlobal edge

We will notify you of new sub-processors by updating this page. You may object to a new sub-processor within 30 days of notification. If we cannot accommodate your objection, you may terminate the Service.

6. International Data Transfers

Where Personal Data is transferred from the European Economic Area (EEA) or UK to countries without an adequacy decision, we rely on Standard Contractual Clauses (SCCs) as the transfer mechanism. Our primary data store (Supabase) is located in the EU. Transfers to US-based sub-processors (Resend, LemonSqueezy, Cloudflare) are made under appropriate safeguards including SCCs or their US equivalents.

7. Security Measures

We implement technical and organizational measures appropriate to the risk, including:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256)
  • Row-level security on all database tables (no customer can access another customer's data)
  • Multi-factor authentication available for all accounts
  • Regular dependency vulnerability scanning
  • Content Security Policy blocking unauthorized data exfiltration
  • Tamper-evident audit log for all data access events

Full security posture: aegisfirma.com/security/posture

8. Data Subject Rights Assistance

Where a data subject exercises their rights (access, erasure, restriction, portability, objection) and those rights apply to data processed by Aegis Firma on your behalf, we will assist you in responding. You can export all data for a user via the Settings page. Account deletion permanently removes all associated Personal Data, subject to legal retention requirements.

9. Breach Notification

In the event of a Personal Data breach, we will notify the Controller without undue delay and no later than 72 hours after becoming aware of the breach, where feasible. We will provide sufficient information to allow the Controller to meet its own breach notification obligations under applicable law.

10. Audit Rights

The Controller may conduct audits of our data processing activities or commission third-party auditors to do so, subject to 30 days' written notice and agreement on audit scope and cost allocation. We may satisfy audit requests by providing documentation of our security controls and certifications in lieu of on-site visits.

11. Return and Deletion of Data

On termination of the Service agreement, or on the Controller's request, we will delete or return all Personal Data. You may export all your data at any time from the Settings page. Account deletion is permanent and immediate. We retain only what is legally required (e.g., billing records for 7 years per applicable tax law).

12. Contact

Questions about this DPA? Contact us via in-app feedback (sign in required). We aim to respond within 48 hours on business days.