DoAIRight
Legal

Data Processing Addendum

This DPA forms part of the agreement between you (the Customer, acting as data controller) and Halyon Tech LLP (operating DoAIRight, acting as data processor) for the processing of personal data in the course of providing the Service.

Last updated · 5 August 2026

1. Roles of the parties

For personal data you submit to the Service, you are the data controller (or processor acting for your own customers) and Halyon Tech LLP is the data processor. We process personal data only to provide the Service and only on your documented instructions, which include this DPA and your use of the Service's features.

2. Subject matter, nature & duration

  • Subject matter: provision of the DoAIRight AIMS application and readiness assessment.
  • Nature & purpose: hosting, storing, and processing your AIMS records and account data so you can build and operate an ISO/IEC 42001 management system.
  • Duration: for the term of your subscription and any limited wind-down period, after which data is deleted or returned.

3. Categories of data & data subjects

  • Data subjects: your authorized users, teammates, and any individuals referenced within the records you create.
  • Personal data: names, work email addresses, role/organization, authentication data, and any personal data you choose to include in documents, risks, actions or notes.
  • We do not require or request special-category data; you should avoid placing it in free-text fields.

4. Our obligations as processor

  • Process personal data only on your documented instructions, including for international transfers, unless required by law (in which case we notify you where permitted).
  • Ensure personnel authorized to process data are bound by confidentiality.
  • Implement appropriate technical and organizational security measures (see our Trust Center).
  • Assist you, taking into account the nature of processing, in responding to data-subject requests.
  • Assist you with security, breach notification, and data protection impact assessments.
  • Make available information necessary to demonstrate compliance and allow for audits (Section 8).

5. Security measures

We maintain per-tenant database isolation with row-level security, encryption in transit, least-privilege access, salted-hash credential storage, signed and verified billing webhooks, and rate limiting. Our current technical measures are described on our Trust Center and may be updated as security practices evolve, provided protection is not materially reduced.

6. Sub-processors

You provide general authorization for us to engage the sub-processors below to process personal data. Each is bound by data-protection obligations no less protective than this DPA. We will inform you of intended changes and give you the opportunity to object on reasonable data-protection grounds.

RailwayApplication hosting & managed database
United States / EU
Google (Gemini)AI model inference (on request)
United States
GroqAI model inference (on request)
United States
RazorpaySubscription billing & payments
India
ResendTransactional & reminder email
United States
S3-compatible object storageDocument & evidence storage
Configurable region

7. International transfers

Where personal data is transferred across borders (including outside India), we rely on appropriate safeguards permitted by applicable law and on our sub-processors' contractual protections. We do not transfer personal data to any jurisdiction restricted by an applicable government notification.

8. Audits

On reasonable prior written request, and subject to confidentiality, we will provide information reasonably necessary to demonstrate compliance with this DPA. Where an on-site audit is required by law, the parties will agree on scope, timing and cost in advance so as not to disrupt the Service or other customers.

9. Return & deletion

On termination, you may export your data in a machine-readable format from within the Service (Settings → Data & privacy). After a limited wind-down period we delete your data, except where retention is required by law.

10. Order of precedence

In case of conflict between this DPA and the Terms of Service, this DPA prevails for matters relating to the processing of personal data.

Executing this DPA

Need a countersigned copy for your records or vendor-risk file? Send your company details and any specific requirements to [email protected] and we'll return an executed DPA. For security documentation, contact [email protected].