Acira AI Logo
PricingFeaturesCompareFor Agencies
Login

Data Processing Addendum

DATA PROCESSING ADDENDUM

Last updated: October 6, 2026


This Data Processing Addendum ("DPA") forms part of the Terms of Service ("Agreement") between Acira AI LLC ("Processor," "we," "us") and the user of the Services ("Controller," "you") and supplements the Agreement with respect to the processing of personal data.

This DPA applies when you use the Services to create, host, and publish websites that collect or process personal data of individuals located in the European Economic Area ("EEA"), the United Kingdom ("UK"), or Switzerland, or where otherwise required by applicable data protection laws.

This DPA may be translated into other languages for your convenience. In the event of any conflict or inconsistency between the English version and any translated version, the English version shall prevail, except where applicable law requires that the translated version apply or prevail, or that any inconsistency be resolved in your favor. For users located in Québec, the French version governs.


TABLE OF CONTENTS

  1. DEFINITIONS
  2. SCOPE AND ROLES
  3. DATA PROCESSING DETAILS
  4. OBLIGATIONS OF THE PROCESSOR
  5. OBLIGATIONS OF THE CONTROLLER
  6. SUBPROCESSORS
  7. INTERNATIONAL DATA TRANSFERS
  8. DATA SUBJECT RIGHTS
  9. DATA SECURITY
  10. DATA BREACH NOTIFICATION
  11. AUDITS AND COMPLIANCE VERIFICATION
  12. DATA RETENTION AND DELETION
  13. TERM AND TERMINATION
  14. LIMITATION OF LIABILITY
  15. CONTACT US

1. DEFINITIONS

"Applicable Data Protection Law" means all laws and regulations applicable to the processing of personal data under this DPA, including (as applicable) the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR, the Swiss Federal Act on Data Protection ("FADP"), and the California Consumer Privacy Act ("CCPA").

"Controller" means the natural or legal person which determines the purposes and means of the processing of personal data — in this context, you, the user of the Services who operates a website through the platform.

"Data Subject" means an identified or identifiable natural person whose personal data is processed.

"Personal Data" means any information relating to a Data Subject that is processed through the Services.

"Processing" means any operation performed on personal data, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, restriction, erasure, or destruction.

"Processor" means a natural or legal person which processes personal data on behalf of the Controller — in this context, Acira AI LLC.

"Subprocessor" means any third party engaged by the Processor to process personal data on behalf of the Controller.

"Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission, in the modules that apply under this DPA (see Sections 2.7 and 7.1).


2. SCOPE AND ROLES

2.1 Processing Relationship

When you use the Services to create and operate a website that collects personal data from your website visitors (through forms, user accounts, comments, reviews, or other interactive features), you act as the Controller and we act as the Processor of that visitor personal data.

2.2 Our Role as Controller

We act as an independent Controller for personal data we collect for our own purposes, including: your account information, billing data, usage analytics, general website characteristics derived from your website content (such as industry or business type), and platform operation data. The processing of such data is governed by our Privacy Policy and is outside the scope of this DPA.

Payment provider (Merchant of Record). Payments for paid Services are handled by a third-party payment provider that acts as the Merchant of Record — the seller of record — for your transaction, currently Sold through Link, LLC ("Link"), an affiliate of Stripe. In that capacity, the provider determines the purposes and means of processing the payment details you submit at checkout and therefore acts as an independent controller in its own right, not as our subprocessor. Its processing is governed by its own terms and privacy notice and falls outside the scope of this DPA. We receive only limited transaction and billing data from it, which we process as an independent Controller as described above.

2.3 Platform Analytics

We collect basic, privacy-friendly analytics on website visitors (as described in the Agreement). For analytics data, we act as a joint controller with you. We have designed our analytics to minimize personal data collection — we do not store raw IP addresses, and visitor identifiers are pseudonymous (see Section 3.3). The respective responsibilities of each joint controller are as follows:

  • Acira AI (Joint Controller): Determines the technical means of analytics collection, including what data points are collected, how visitor identifiers are computed, and how data is aggregated. We are responsible for the security and integrity of the analytics infrastructure and for responding to general inquiries about how analytics work on the platform.
  • You (Joint Controller): Operate the website on which analytics data is collected (analytics are provided as an integral part of the Services on all hosted websites). You are responsible for disclosing the collection of analytics data in your website's privacy policy and for responding to Data Subject requests from your website visitors regarding their analytics data.
  • Point of contact for Data Subjects: Data Subjects may contact you (the website owner) regarding analytics data collected on your website. If we receive a request from a Data Subject regarding analytics data, we will direct them to you unless you instruct us otherwise. For general platform inquiries, Data Subjects may contact us at legal@acira.ai.

2.4 Essence of the Joint Controller Arrangement

In accordance with Article 26(2) of the GDPR, the essence of this joint controller arrangement for analytics data is as follows: We (Acira AI) determine the technical means and data points collected; you (the website operator) operate the website on which analytics data is collected and are responsible for disclosing the collection to your visitors. We are each responsible for our respective obligations under Applicable Data Protection Law. You are the primary point of contact for your website visitors regarding analytics data. A summary of this arrangement is made available to Data Subjects through this DPA and at https://www.acira.ai/dpa.

2.5 CCPA Service Provider Designation

To the extent that we process personal information subject to the California Consumer Privacy Act ("CCPA") on your behalf, we are your "service provider" as defined in Cal. Civ. Code § 1798.140(ag). We shall not:

  • Sell or share (as those terms are defined under the CCPA) any personal information you provide to us;
  • Retain, use, or disclose personal information for any purpose other than the business purposes specified in this DPA and the Agreement, or as otherwise permitted by the CCPA;
  • Retain, use, or disclose personal information outside of the direct business relationship between you and us;
  • Combine personal information received from you with personal information that we receive from or on behalf of another person or that we collect from our own interactions with consumers, except as permitted by the CCPA.

We may derive general, non-identifying business characteristics (such as industry classification) from your website content for the purpose of providing relevant product recommendations, as described in Section 2.2. This limited use does not constitute selling, sharing, or combining personal information within the meaning of the CCPA.

We certify that we understand and will comply with these restrictions.

2.6 Representative Designations

We designate a data protection representative in each jurisdiction where applicable law requires us to do so, and we identify any such representative in our Privacy Policy. We assess our processing activities against the representative-designation thresholds of the jurisdictions relevant to our Services — including Article 14 of the Swiss Federal Act on Data Protection (FADP).

2.7 Agency-Managed Websites

Where a website is created or operated through our Agency Program, an agency ("Agency") uses the Services to build and manage the website on behalf of its own client ("End Client"). In that arrangement:

  • The End Client (or, where the Agency operates the website for its own purposes, the Agency) is the Controller of visitor personal data collected through the managed website.
  • Where the Agency acts as a processor for its End Client, we act as a subprocessor engaged by the Agency, and the processor-to-subprocessor Standard Contractual Clauses (Module Three) apply to that link in addition to the modules described in Section 7. Where the Agency is itself the Controller, we act as its Processor as described in this DPA.
  • The Agency is responsible for entering into a data processing agreement with each End Client on terms consistent with this DPA, and for ensuring it has authority to instruct us on the End Client's behalf.
  • Agency staff granted access to a managed website may access visitor personal data stored for that website (including form submissions, session data, and user-table records) in order to build, manage, and operate the website. The Agency is responsible for restricting and supervising such access in accordance with Applicable Data Protection Law.

The terms of the Agency Program, including the Agency's obligations, are set out in the Acira AI Agency Terms at https://www.acira.ai/agency-terms.


3. DATA PROCESSING DETAILS

3.1 Subject Matter and Duration

The processing of personal data under this DPA is performed for the purpose of providing the Services as described in the Agreement and will continue for the duration of the Agreement.

3.2 Nature and Purpose of Processing

We process personal data to:

  • Host and serve your website content
  • Store and manage data submitted through your website's forms and interactive features
  • Maintain user accounts and sessions for your website's protected areas
  • Deliver email communications on your behalf
  • Forward emails received at your custom domain email addresses
  • Perform AI inference requested by your website's own code (requests and responses are not persisted)
  • Generate AI-powered descriptions and metadata for uploaded files
  • Convert uploaded files into web-optimized formats
  • Provide visitor analytics
  • Process your website's records with the AI assistant when you ask it to read or act on them
  • Generate PDF documents from your website's templates
  • Run background jobs, scheduled tasks, and automations you configure
  • Make outbound network requests initiated by your website's own code (such as webhooks and calls to external APIs)
  • Capture screenshots of your website's pages for design review and content-policy enforcement
  • Detect and prevent spam and abuse (including automated bot protection)
  • Perform content moderation on uploaded files
  • Review website content during publication for compliance with platform content policies
  • Manage email opt-out preferences for your website's email recipients
  • Facilitate real-time channel communications on your website via WebSocket connections (messages are ephemeral and not persisted)
  • Provide programmatic access to your website content and data through the command-line interface (CLI) and other programmatic APIs, at your direction (including retrieval and export of content to your local environment)
  • Maintain error and diagnostic logs for platform reliability and troubleshooting (platform error logs may include IP addresses and request metadata; retention is set out in Section 12.1)

3.3 Types of Personal Data

The types of personal data processed depend on what you collect through your website, which may include:

  • Names and contact information
  • Email addresses
  • Messages and form submissions
  • File uploads submitted by website visitors (such as images and documents)
  • User account credentials (stored in hashed form)
  • Session data
  • IP addresses (not stored: an address is used in transit to route the request, determine country and region, and for bot protection. Where an identifier must persist — analytics and rate limiting — only a keyed, per-website hash is kept, and analytics identifiers rotate daily. Form submissions record country and region, not the address. Your own page code can read a visitor's IP address; anything you choose to store is your own collection, for which you are the controller)
  • Browser and device information
  • Location data (country and region-level, derived from IP)
  • Email opt-out records (the recipient's email address and what they opted out of, available to you so that you can honor and manage your website's opt-out list)
  • Spam classification results (whether a submission was determined to be spam)
  • Error and diagnostic log data (request paths, error details and, in platform error logs, IP addresses; retention is set out in Section 12.1)

3.4 Categories of Data Subjects

  • Your website visitors
  • Users who create accounts on your website
  • Users who submit forms on your website
  • Users who submit comments, reviews, or other contributions on your website

4. OBLIGATIONS OF THE PROCESSOR

We shall:

  1. Process personal data only on your documented instructions, unless required to do so by applicable law (in which case we will inform you of that legal requirement before processing, unless prohibited by law);
  2. Ensure that persons authorized to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
  3. Implement appropriate technical and organizational security measures as described in Section 9;
  4. Comply with the conditions for engaging subprocessors as set out in Section 6;
  5. Assist you, taking into account the nature of the processing, in responding to requests from Data Subjects exercising their rights under Applicable Data Protection Law;
  6. Assist you in ensuring compliance with your obligations under Articles 32-36 of the GDPR (security, breach notification, data protection impact assessments, and prior consultation), taking into account the nature of processing and the information available to us. Where your use of the Services involves high-risk processing that may require a Data Protection Impact Assessment (DPIA), we will provide you with information about our processing activities, technical and organizational measures, and subprocessors to support your assessment;
  7. Assist you in fulfilling your obligations under Article 22 of the GDPR (automated individual decision-making) by providing information about any automated processing carried out on your behalf, including content moderation, spam detection, and bot protection, and by facilitating human review of automated decisions upon request;
  8. Inform you if, in our opinion, an instruction from you infringes Applicable Data Protection Law;
  9. At your choice, delete or return all personal data after the end of the provision of Services, and delete existing copies unless storage is required by applicable law;
  10. Make available to you all information necessary to demonstrate compliance with the obligations laid down in this DPA and allow for and contribute to audits, including inspections, as described in Section 11.

5. OBLIGATIONS OF THE CONTROLLER

You shall:

  1. Ensure that your collection and processing of personal data through your website complies with Applicable Data Protection Law;
  2. Provide appropriate privacy notices to your website visitors describing your data collection practices, including disclosure of platform-level analytics, spam detection, and bot protection;
  3. Obtain all necessary consents or establish another lawful basis for the processing of personal data through your website;
  4. Ensure that your instructions to us regarding the processing of personal data comply with Applicable Data Protection Law;
  5. Be responsible for the accuracy, quality, and legality of personal data provided to us through your website.

By using the Services, you instruct us to perform the following processing activities on your behalf as part of standard platform operations: content moderation of uploaded files, content policy review of published website content, spam detection on form submissions (including AI-based screening of their contents, unless you turn it off), and automated bot protection. These activities are documented instructions under Article 28(3)(a) of the GDPR.


6. SUBPROCESSORS

6.1 Authorized Subprocessors

You provide general authorization for us to engage subprocessors to assist in providing the Services. Our current subprocessors are listed below and at https://www.acira.ai/dpa.

6.2 Current Subprocessor List

Subprocessor Purpose Location
Amazon Web Services (AWS) Cloud infrastructure, compute, storage, database, email delivery, domain registration, content moderation, language detection, and AI inference (which may run models developed by AWS or by third parties on AWS infrastructure). For EU-resident website operators, see Section 7.1. United States and European Union (Stockholm)
Cloudflare Edge hosting, CDN, DNS, SSL, website delivery, persistent storage, analytics, bot protection, AI-based spam detection (which executes third-party models on Cloudflare's own infrastructure), and website screenshot capture (Browser Rendering). For EU-resident website operators, see Section 7.1. Global (with EU-jurisdictioned storage for EU accounts)
Fireworks AI AI text generation, conversational AI, content creation, and AI inference requested by your website's own code. Visitor personal data is not sent to Fireworks AI or xAI, except to Fireworks AI where your website's own code includes it in an AI inference request, or where you ask the AI assistant to read or act on your website's records; in either case, Fireworks AI processes it at your direction. Processed under terms that prohibit use for training and limit retention. United States and other locations where the provider operates
xAI (SpaceXAI LLC) AI image generation and editing (text prompts and, for edits, the source images you provide). Processed under terms that prohibit use for training and limit retention. United States and other locations where the provider operates
BrightData Public web data collection (to assist the user during website creation, and to retrieve web pages the AI assistant is asked to read), SERP keyword tracking (for applicable plans) Israel / Global
CloudConvert (Lunaweb GmbH, Germany) File format conversion United States (Virginia)

Payment processing is performed by our Merchant of Record (Link, an affiliate of Stripe), which acts as an independent controller rather than a subprocessor and is therefore not listed above; see Section 2.2.

6.3 Changes to Subprocessors

Changes to the subprocessor list are made only under this Section 6.3; they are not changes to this DPA under Section 13. We will provide notice of any intended changes to the subprocessor list for Services you currently use at least fifteen (15) days before the new subprocessor begins processing personal data, by updating the subprocessor list at https://www.acira.ai/dpa and, if you have subscribed to subprocessor notifications, by email. You may subscribe to receive subprocessor-change notifications by emailing legal@acira.ai with the subject line "Subprocessor Notifications." When we introduce new features or services that involve additional subprocessors, those subprocessors will be disclosed at the time the feature or service becomes available; your use of the new feature or service constitutes acceptance of its disclosed subprocessors. Where we must replace a subprocessor urgently for security or continuity reasons, we will notify you as soon as practicable. If you have a reasonable objection to a new subprocessor processing data for existing Services, you may notify us in writing within fifteen (15) days of the notice. We will work with you in good faith to address your concerns. If we cannot resolve the objection to your reasonable satisfaction, you may terminate the Agreement by providing written notice.

6.4 Subprocessor Obligations

We will enter into written agreements with each subprocessor that impose data protection obligations no less protective than those set out in this DPA. We remain liable for the acts and omissions of our subprocessors to the same extent we would be liable if performing the services directly.


7. INTERNATIONAL DATA TRANSFERS

7.1 Transfer Mechanisms

The Services are hosted primarily in the United States. Personal data processed through the Services may be transferred to and processed in the United States and other countries where our subprocessors operate. Our AI inference providers (Fireworks AI and xAI) and our file conversion provider (CloudConvert) process data in the United States, and our AI inference providers may also process data in other locations where they operate. BrightData may process data in Israel and other locations globally. Cloudflare processes data at edge locations worldwide.

EU Data Residency: For websites whose country of operation, set when the website is created and before it goes live, is a member state of the European Union ("EU-resident website operators"; other EEA countries, the United Kingdom, and Switzerland are not included), we apply the following data residency measures to minimize transfers of visitor personal data outside the European Union:

  • Storage: Visitor data in persistent edge storage — including form submissions, session data, and user table data — is jurisdictionally restricted to, and stored in, the European Union.
  • Automated visitor-facing processing: Operations triggered automatically by visitor activity — including notifications about new website database records, transactional email delivery, and machine translation of website database content into the site's additional languages — are processed in the European Union (Stockholm).
  • Platform management access: When you access your website's visitor data through the platform dashboard, the conversational interface (including when you ask the AI assistant to read or act on your website's records, which are then processed by our AI inference provider, Fireworks AI, in the United States), or the command-line interface (CLI) or other programmatic APIs (for example, viewing form submissions, managing user records, or exporting content to your local environment), this data may be processed through our US-based infrastructure to fulfill your request, and — where you use the CLI or a programmatic interface — may be transmitted to and stored in the environment where you run those tools. These transfers are on-demand, initiated by you (the Controller), and protected by the transfer mechanisms and supplementary measures described below to the extent the data remains within our infrastructure. Once you export or retrieve personal data to your own environment (such as a local machine or a third-party development tool), you are responsible for its security and lawful handling; our jurisdictional-residency and other technical measures do not extend to personal data after it leaves our infrastructure.
  • Diagnostic logs: Error and console logs produced by your website — the diagnostic output shown to you on the platform's Logs page — are retained on our US-based infrastructure for the period set out in Section 12.1. These are operational records kept for your own review and are not intended to contain visitor personal data; you control what your website's own code writes to them.
  • AI inference requested by your website: When your website's own code requests AI inference, the request passes through our infrastructure in the European Union (Stockholm) and is processed by our AI inference provider, Fireworks AI, in the United States; EU-restricted processing is not available for this feature. You control what your website's code sends, including any visitor personal data, and these transfers are subject to the transfer mechanisms below.
  • Other processing outside the EU: Analytics data and data processed by our US-based cloud infrastructure for content moderation and AI inference may still be transferred to the United States, and file conversion is performed in the United States. AI-based spam classification of form submissions runs on Cloudflare's global network and is not restricted to the EU. These transfers are subject to the transfer mechanisms below.

For transfers of personal data from the EEA, UK, or Switzerland to countries not recognized as providing an adequate level of data protection, we rely on:

  1. Standard Contractual Clauses (SCCs): We incorporate the European Commission's Standard Contractual Clauses into this DPA by reference: Module One (Controller to Controller) for analytics data where we act as joint controller (see Section 2.3), and Module Two (Controller to Processor) for all other personal data processed on your behalf. The SCCs are available at https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en.
  2. UK International Data Transfer Addendum: For transfers from the UK, the UK Addendum to the EU SCCs applies.
  3. Swiss Data Transfer Mechanisms: For transfers from Switzerland, the SCCs apply with the modifications required by the Swiss FADP.

For the purposes of the SCCs, the parties agree that: (a) the data exporter is you and the data importer is Acira AI LLC; (b) Annex I.B (description of the transfer) is completed by Section 3 of this DPA; (c) Annex II (technical and organisational measures) is completed by Sections 7.2 and 9 of this DPA; (d) for Clause 9, Option 2 (general written authorisation) applies, with the notice period set out in Section 6.3; (e) the optional docking clause (Clause 7) is not used; (f) for Clause 17 (governing law) and Clause 18 (choice of forum), the SCCs are governed by the law of, and disputes arising from them are resolved before the courts of, Ireland; and (g) the competent supervisory authority in Annex I.C is determined in accordance with Clause 13 of the SCCs. For the purposes of the UK International Data Transfer Addendum, Tables 1 to 3 are deemed completed with the corresponding information set out in this DPA and the SCC elections above, and for Table 4, neither party may end the UK Addendum as set out in Section 19 of the UK Addendum.

7.2 Supplementary Measures

We implement the following supplementary measures to protect transferred personal data:

  • Encryption of data in transit (TLS/SSL) and at rest
  • Access controls and authentication mechanisms
  • Periodic review of our security measures and our providers' security documentation
  • Data minimization practices (e.g., pseudonymous visitor identifiers instead of raw IP storage)
  • Jurisdictional data residency for EU-resident website operators (persistent storage and automated visitor-facing processing restricted to the EU)
  • EU-based compute and email infrastructure for automated visitor-facing operations (notifications about new website database records and transactional email delivery processed in the European Union for EU-resident website operators)

7.3 Transfer Impact Assessment

These supplementary measures are informed by our assessment of the laws and practices of the destination countries, taking into account the nature of the data transferred, the transfer mechanism relied upon, and the technical and organizational safeguards in place. We have assessed that the supplementary measures described above, together with the commitments in the SCCs, provide an adequate level of protection for the personal data transferred. Our transfer impact assessment is available on request from legal@acira.ai, and we will make it available to a competent supervisory authority on request.

7.4 Canadian Data Transfers

For transfers of personal data from Canada, we rely on the following safeguards to ensure that personal data transferred outside of Canada receives a comparable level of protection as required under the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation (including Alberta's PIPA, British Columbia's PIPA, and Quebec's Act respecting the protection of personal information in the private sector):

  1. Contractual protections: Written data processing agreements with each subprocessor that impose obligations to protect personal data to a standard consistent with Canadian privacy law, including requirements for appropriate security safeguards, use limitations, breach notification, and data subject access.
  2. Technical safeguards: The same encryption, pseudonymization, access control, and data minimization measures described in Section 7.2 apply to Canadian data transfers.
  3. Organizational safeguards: Subprocessor due diligence, confidentiality obligations for personnel, and documented incident response procedures as described in this DPA.

8. DATA SUBJECT RIGHTS

8.1 Assistance with Requests

We will assist you in responding to requests from Data Subjects exercising their rights under Applicable Data Protection Law, including rights of access, rectification, erasure, restriction, portability, and objection.

8.2 Notification

If we receive a request or a data protection complaint directly from a Data Subject regarding personal data processed on your behalf, we will promptly escalate it to you and will not respond to the request or complaint without your instructions, unless required by applicable law. As the Controller, you are responsible for handling and responding to such Data Subject complaints, including any complaints-handling obligations that apply to you under Applicable Data Protection Law (such as Section 164A of the UK Data Protection Act 2018).

8.3 Platform Tools

We provide tools within the Services to help you fulfill Data Subject requests, including:

  • Access to and management of data stored in your website's databases
  • Deletion of individual records from your website's databases
  • Upon request, we can provide data exports in a structured, machine-readable format to assist with data portability obligations

9. DATA SECURITY

9.1 Security Measures

We implement and maintain appropriate technical and organizational measures to protect personal data against unauthorized or unlawful processing and against accidental loss, destruction, or damage. These measures include:

  • Encryption: Data encrypted in transit via TLS/SSL and at rest using industry-standard encryption
  • Access Control: Role-based access controls, least-privilege access policies, and authentication required for all account and administrative access
  • Infrastructure Security: Managed cloud infrastructure with automated security patching and DDoS protection at the network edge
  • Data Isolation: Per-website data isolation through dedicated storage instances
  • Monitoring: Automated monitoring and alerting with structured logging
  • Credential Security: All API keys and secrets stored in dedicated secrets management services; user passwords hashed using strong cryptographic algorithms with per-user salts
  • Bot Protection: Automated bot protection to prevent automated abuse

9.2 Confidentiality

We ensure that all personnel authorized to process personal data are bound by confidentiality obligations.


10. DATA BREACH NOTIFICATION

10.1 Notification to Controller

We will notify you without undue delay after becoming aware of a personal data breach affecting personal data processed on your behalf. Notification will be sent to the contact information associated with your account.

10.2 Notification Content

Our breach notification will include, to the extent available:

  1. A description of the nature of the breach, including categories and approximate number of Data Subjects and records concerned;
  2. The name and contact details of our data protection contact;
  3. A description of the likely consequences of the breach;
  4. A description of the measures taken or proposed to address the breach and mitigate its effects.

10.3 Your Obligations

You are responsible for notifying the relevant supervisory authority and affected Data Subjects of a personal data breach as required by Applicable Data Protection Law. We will cooperate with you and provide reasonable assistance to help you comply with your breach notification obligations.


11. AUDITS AND COMPLIANCE VERIFICATION

11.1 Compliance Documentation

To demonstrate our compliance with this DPA, we will make available to you, upon reasonable written request (up to once per year), the following:

  1. Relevant third-party audit reports, certifications, or summaries of security assessments;
  2. A summary of our current technical and organizational security measures;
  3. Information about our processing activities, subprocessors, and data protection practices.

Where we rely on third-party infrastructure providers (such as AWS and Cloudflare), their security certifications and compliance documentation are available through their respective trust and compliance programs.

11.2 Additional Inquiries

If the documentation provided under Section 11.1 does not reasonably address your compliance concerns, you may submit specific written questions regarding our data protection practices, which we will respond to within a reasonable timeframe.

11.3 Audits and Inspections

Where the documentation provided under Sections 11.1 and 11.2 is insufficient to demonstrate our compliance with this DPA, or where an audit is required by a supervisory authority or by Applicable Data Protection Law, you (or an independent auditor bound by confidentiality obligations and not a competitor of ours) may audit our compliance with this DPA, including by inspection. Audits require at least thirty (30) days' prior written notice, may take place no more than once per year (unless required by a supervisory authority or following a personal data breach affecting your data), are conducted at your cost during normal business hours in a manner that minimizes disruption, and do not include access to other customers' data or to our subprocessors' facilities, for which we will instead provide the subprocessors' own audit reports and certifications.


12. DATA RETENTION AND DELETION

12.1 During the Agreement

We will retain personal data processed on your behalf for the duration of the Agreement and in accordance with your instructions through the Services. Specific retention periods for visitor data include:

  • Website database records (such as form submissions and other user-generated content): Retained for the duration of the associated website, unless you delete them earlier through the platform tools.
  • Session data for your website visitors: Automatically deleted after 30 days of inactivity.
  • Deleted visitor content (website database records, such as form submissions, comments, and other user-generated content): When you delete visitor content through the platform tools, it is moved to a soft-delete state and retained for up to thirty (30) days to support recovery. After this period, soft-deleted content is removed from your website's data.
  • Point-in-time recovery history: Changes to your website's stored data, including deletions, are kept in the website's point-in-time recovery history for up to thirty (30) days. Restoring your website to an earlier point reinstates the data as it stood at that point, including records deleted since; email opt-outs are preserved across any restore.
  • Notification history: When the Services notify you of new records in your website's databases, the notification is also kept in your in-app notification history for up to six (6) months. For EU-resident website operators, it holds a summary without the record's content.
  • Rate-limiting records for your website: The keyed per-visitor hashes described in Section 3.3, retained for up to three (3) days and then automatically purged.
  • Error and diagnostic logs: Platform error logs (which may include IP addresses) and your website's own diagnostic log, shown on its Logs page, are retained for up to ninety (90) days, including after the website is deleted, and then automatically purged.
  • Email opt-out records on your website: Retained for the duration of the associated website, unless the recipient re-subscribes. Opt-out records are deleted when the website is deleted.
  • Analytics data: Retained for the duration of the associated website. Plan-based retention limits, described on our pricing page, determine how much historical analytics data remains displayed and accessible.

12.2 Upon Termination

Upon termination of the Agreement, or upon your request, we will delete personal data processed on your behalf in accordance with the data retention practices described in the Agreement (including the grace period for account and website deletions described there). After the grace period, deletion is permanent and irreversible.

12.3 Exceptions

We may retain personal data to the extent required by applicable law, or where data has been anonymized and can no longer be linked to a Data Subject.


13. TERM AND TERMINATION

This DPA takes effect on the date you accept the Agreement and remains in effect for as long as we process personal data on your behalf. The obligations of confidentiality and data protection set forth in this DPA survive the termination of the Agreement.

Changes to this DPA. We may change this DPA in the same way as the Agreement (see "Changes to These Terms of Service" in the Agreement): we email a summary of a material change to the address associated with your account at least thirty (30) days before it takes effect, except where a change is required by law or is needed urgently for security, fraud, or abuse reasons, and non-material changes take effect when posted. Changes to the subprocessor list follow Section 6.3 instead. No change to this DPA modifies the Standard Contractual Clauses, which are incorporated without modification, or reduces the protection they provide.

An executed (countersigned) copy of this DPA, including the Standard Contractual Clauses incorporated by reference, is available upon written request to legal@acira.ai.


14. LIMITATION OF LIABILITY

The liability of each party under this DPA is subject to the limitations of liability set forth in the Agreement.


15. CONTACT US

For questions about this DPA or to exercise your rights, contact us at:

Acira AI LLC
Attn: Data Protection
11500 S Eastern Ave, Suite 150
Henderson, NV 89052
United States

Phone: 888-389-1189
Email: legal@acira.ai