Data Processing Addendum
This DPA forms part of the agreement between you (the Customer, acting as data controller) and Halyon Tech LLP (operating DoAIRight, acting as data processor) for the processing of personal data in the course of providing the Service.
1. Roles of the parties
For personal data you submit to the Service, you are the data controller (or processor acting for your own customers) and Halyon Tech LLP is the data processor. We process personal data only to provide the Service and only on your documented instructions, which include this DPA and your use of the Service's features.
2. Subject matter, nature & duration
- Subject matter: provision of the DoAIRight AIMS application and readiness assessment.
- Nature & purpose: hosting, storing, and processing your AIMS records and account data so you can build and operate an ISO/IEC 42001 management system.
- Duration: for the term of your subscription and any limited wind-down period, after which data is deleted or returned.
3. Categories of data & data subjects
- Data subjects: your authorized users, teammates, and any individuals referenced within the records you create.
- Personal data: names, work email addresses, role/organization, authentication data, and any personal data you choose to include in documents, risks, actions or notes.
- We do not require or request special-category data; you should avoid placing it in free-text fields.
4. Our obligations as processor
- Process personal data only on your documented instructions, including for international transfers, unless required by law (in which case we notify you where permitted).
- Ensure personnel authorized to process data are bound by confidentiality.
- Implement appropriate technical and organizational security measures (see our Trust Center).
- Assist you, taking into account the nature of processing, in responding to data-subject requests.
- Assist you with security, breach notification, and data protection impact assessments.
- Make available information necessary to demonstrate compliance and allow for audits (Section 8).
5. Security measures
We maintain per-tenant database isolation with row-level security, encryption in transit, least-privilege access, salted-hash credential storage, signed and verified billing webhooks, and rate limiting. Our current technical measures are described on our Trust Center and may be updated as security practices evolve, provided protection is not materially reduced.
6. Sub-processors
You provide general authorization for us to engage the sub-processors below to process personal data. Each is bound by data-protection obligations no less protective than this DPA. We will inform you of intended changes and give you the opportunity to object on reasonable data-protection grounds.
7. International transfers
Where personal data is transferred across borders (including outside India), we rely on appropriate safeguards permitted by applicable law and on our sub-processors' contractual protections. We do not transfer personal data to any jurisdiction restricted by an applicable government notification.
8. Audits
On reasonable prior written request, and subject to confidentiality, we will provide information reasonably necessary to demonstrate compliance with this DPA. Where an on-site audit is required by law, the parties will agree on scope, timing and cost in advance so as not to disrupt the Service or other customers.
9. Return & deletion
On termination, you may export your data in a machine-readable format from within the Service (Settings → Data & privacy). After a limited wind-down period we delete your data, except where retention is required by law.
10. Order of precedence
In case of conflict between this DPA and the Terms of Service, this DPA prevails for matters relating to the processing of personal data.
Executing this DPA
Need a countersigned copy for your records or vendor-risk file? Send your company details and any specific requirements to [email protected] and we'll return an executed DPA. For security documentation, contact [email protected].