Legal
Data Processing Addendum
Last updated 31 August 2026
This Data Processing Addendum (“DPA”) applies where ConsultAI LLC (“Processor”) processes personal data on behalf of a client (“Controller”) under an Engagement Document. It forms part of that Engagement Document. Where a client has its own DPA, the signed version prevails over this one.
1. Roles
The Controller determines the purposes and means of processing. The Processor processes personal data only on the Controller's documented instructions, including the Engagement Document itself. If the Processor believes an instruction infringes applicable data protection law, it will tell the Controller without undue delay.
2. Subject matter and duration
Subject matter: the provision of AI consulting and development services described in the Engagement Document.
Duration: the term of the Engagement Document, plus any agreed return or deletion period.
Nature and purpose: design, build, testing, evaluation, deployment and support of AI systems, and diagnostic work necessary to those activities.
3. Categories of data and data subjects
These are set out in the Engagement Document for each engagement. Typically they are limited to what the system under construction requires: for example customer contact details, transaction records, documents, images or audio processed by the system, and the Controller's own personnel who administer it.
The Processor does not require special-category data unless the engagement is expressly about it, in which case it is named in the Engagement Document along with the additional safeguards that apply.
4. Processor obligations
- process personal data only on documented instructions, including for international transfers
- ensure that people authorised to process the data are bound by confidentiality
- implement appropriate technical and organisational measures, as described in the Security Statement
- assist the Controller in responding to data subject requests, taking into account the nature of the processing
- assist the Controller with data protection impact assessments and prior consultations
- make available the information reasonably necessary to demonstrate compliance
5. Data minimisation in development
Wherever the work allows it, the Processor develops and tests against synthetic, anonymised or pseudonymised data rather than production personal data, and requests production data only when the engagement genuinely requires it. Access is scoped to the smallest set of records and the shortest period that will do.
6. Sub-processors
The Controller gives general authorisation for the Processor to engage sub-processors, typically cloud infrastructure, model providers and hosting used to deliver the engagement. The Processor will maintain a current list of sub-processors, give at least 30 days' notice before adding or replacing one, and impose data protection obligations on each that are no less protective than this DPA. The Controller may object on reasonable data protection grounds, and the parties will work in good faith to find an alternative.
7. Data subject requests
If a data subject contacts the Processor directly, the Processor will not respond substantively but will refer the request to the Controller without undue delay, and will assist the Controller in answering it.
8. Personal data breach
The Processor will notify the Controller without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting the Controller's data, and will provide the information the Controller needs to meet its own notification duties. The Processor will take reasonable steps to contain and remediate the breach.
9. Return and deletion
On termination or expiry, the Processor will, at the Controller's choice, return or delete the personal data and existing copies, within 30 days, unless law requires retention. The Processor will confirm deletion in writing on request.
10. Audit
The Processor will make available information necessary to demonstrate compliance with this DPA, and will allow and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates. Audits are limited to once per twelve months unless a breach has occurred or a supervisory authority requires more, must be given 30 days' notice, and must be conducted so as not to disrupt the Processor's operations or the confidentiality of other clients.
11. International transfers
Where the Processor transfers personal data out of the European Economic Area, the United Kingdom or Switzerland, it will do so under an approved transfer mechanism, ordinarily the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable), together with any supplementary measures required by the circumstances of the transfer.
12. Liability and precedence
Liability under this DPA is subject to the limitations in the Engagement Document and the Terms of Service. In case of conflict, the order of precedence is: a signed DPA, then this DPA, then the Engagement Document, then the Terms of Service.
13. Contact
Data protection enquiries: contact@globalconsultai.com.