Effective date: February 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Agreements.ai ("Processor", "we", "us") and the customer ("Controller", "you") who has agreed to the Terms of Service. This DPA reflects the parties' agreement on the processing of personal data in accordance with applicable data protection laws, including the General Data Protection Regulation (EU) 2016/679 ("GDPR").
The Processor processes Personal Data solely for the purpose of providing the Agreements.ai platform services as described in the Terms of Service. This includes contract creation, analysis, storage, e-signatures, and related AI-powered legal document services.
Personal Data will be processed for the duration of the service agreement. Upon termination, the Processor will delete or return all Personal Data within 90 days, unless retention is required by applicable law.
The Controller authorizes the Processor to engage the following sub-processors. The Processor will notify the Controller of any changes to this list and provide the Controller an opportunity to object.
| Sub-processor | Purpose | Location |
|---|---|---|
| Google Cloud Platform / Firebase | Cloud infrastructure, data storage, authentication | United States / EU |
| OpenAI | AI-powered contract analysis and generation | United States |
| Resend | Transactional email delivery | United States |
| Stripe | Payment processing and billing | United States |
| Vercel | Application hosting and edge delivery | Global |
The Processor will assist the Controller in fulfilling Data Subject requests under applicable data protection law, including rights of access, rectification, erasure, restriction, portability, and objection. The Processor will promptly notify the Controller of any Data Subject request received directly.
The Processor implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk. These measures are described in detail on our Security & Trust page and include encryption at rest and in transit, access controls, regular security assessments, and employee training.
The Processor will notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach. The notification will include the nature of the breach, categories and approximate number of Data Subjects affected, likely consequences, and measures taken or proposed to address the breach.
Where Personal Data is transferred outside the European Economic Area (EEA), the Processor ensures that appropriate safeguards are in place, including the European Commission's Standard Contractual Clauses (SCCs) for international data transfers. The Processor will comply with any additional requirements under applicable data protection law regarding cross-border transfers.
The Processor will make available to the Controller all information necessary to demonstrate compliance with this DPA and applicable data protection law. The Processor will allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller, subject to reasonable notice and scope.
Upon termination of the service agreement, the Processor will, at the Controller's choice, delete or return all Personal Data and delete existing copies within 90 days, unless applicable law requires storage of the Personal Data. The Controller may export their data at any time during the term of the agreement.
For questions about this DPA or to exercise your rights, contact us at one@agreements.ai.
Streamline your legal workflow with AI-powered contract analysis and creation. Upload, analyze, and create contracts in minutes.