Transparency in how we handle your data.
This Data Processing Agreement (DPA) describes how Dainin AI processes personal data on behalf of its customers, and the measures in place to support GDPR compliance and data protection obligations.
Agreement Scope
This DPA covers the following areas of data processing performed by Dainin AI on behalf of the customer.
How personal data is processed on behalf of the customer.
Technical and organisational measures to protect personal data.
Third-party providers involved in data processing.
Supporting access, rectification, erasure, and portability requests.
Notification obligations in the event of a personal data breach.
Data retention periods and deletion upon termination.
GDPR Roles
Data Scope
Contact Information
Names, email addresses, job titles, company names
Account management and service delivery
Communication Data
Email metadata, calendar events, meeting transcripts (where enabled)
AI-powered analysis and workflow automation
Operational Data
CRM records, pipeline data, engagement metrics
Revenue operations and performance intelligence
Lawful Basis
Personal data is processed solely for the purpose of delivering the Dainin AI platform services as instructed by the customer.
Technical Controls
Dainin AI implements appropriate technical and organisational measures to ensure the security of personal data processed on behalf of its customers.
Encryption at rest and in transit (AES-256, TLS 1.2+)
Role-based access controls with least-privilege enforcement
Regular security assessments and vulnerability management
Audit logging and monitoring of data access
Incident detection, response, and notification procedures
Secure development lifecycle practices
Third Parties
Dainin AI may engage subprocessors to assist in delivering the platform services. All subprocessors are subject to equivalent data protection obligations.
Cross-Border
Where personal data is transferred outside the European Economic Area (EEA), appropriate safeguards are implemented in accordance with GDPR requirements.
Data Lifecycle
Personal data is retained only for as long as necessary to provide the services. Upon termination, data is deleted or returned in accordance with the agreement.
Individual Rights
Right to obtain confirmation of processing and access to personal data.
Right to correct inaccurate or incomplete personal data.
Right to request deletion of personal data where applicable.
Right to restrict processing in certain circumstances.
Right to receive personal data in a structured, machine-readable format.
Dainin AI assists the customer in responding to data subject requests. Requests should be directed to the customer as the data controller.
Breach Response
In the event of a personal data breach, Dainin AI will notify the customer without undue delay and provide the information necessary to fulfil regulatory obligations.
Related
Questions?
To request a signed copy of our DPA or for data protection inquiries, please contact our security team.
security@dainin.ai