— DATA PROCESSING AGREEMENT · v1.0 · EFFECTIVE MAY 1, 2026
Plain-English DPA. What we process. How. Where. On whose authority.
Yeh page DPA ka plain-language version hai. The signed PDF (MSA-grade language, lawyer-readable) is one click below. Read this first; sign that second. If anything in the PDF contradicts this page, the PDF wins legally — but we’ll fix the page.
VERSIONv1.0 · MAY 2026
DATA CONTROLLERYou (the customer)
DATA PROCESSORAliens (us)
JURISDICTIONIndia + EEA + UK
01Parties & scope.
This DPA forms part of the agreement between Aliens (the “Processor”) and you (the “Controller”) under which Aliens provides A’nil Cyborg services. It governs the processing of personal data carried out by the Processor on behalf of the Controller.
Applies wherever the Controller processes personal data of subjects in the EEA / UK (GDPR), India (DPDP Act 2023), or jurisdictions that recognise “adequate protection” standards.
02What we process.
The personal data the Processor handles depends entirely on what the Controller authorises the Cyborg to access. We do not collect data on our own initiative.
Identity data — names, work email addresses, internal IDs of teammates the Cyborg interacts with via Slack, Teams, GitHub, etc.
Operational data — documents, codebases, design files, tickets, chat threads that the Controller explicitly grants the Cyborg access to.
Usage logs — timestamps, request traces, action audit logs from the Cyborg’s own VM (kept for security and SLA accounting).
We do NOT process: payment-card data (Stripe / Razorpay handle that directly), end-customers’ data unless the Controller routes it to the Cyborg as part of the role, biometric data, special-category data unless explicitly authorised in a separate addendum.
03How we process.
Processing happens on the Controller’s dedicated VM (see /concept/dedicated-machine) in the agreed region. One Cyborg, one VM, one customer. No multi-tenant inference. No cross-customer fine-tuning. Inference calls hit a stateless GPU pool that retains nothing per request.
Personal data leaves the VM only when the Controller explicitly authorises an outbound action (e.g., the Cyborg replies to a customer ticket, opens a PR on the Controller’s repo). All such egress is logged and exportable.
04Sub-processors.
We use a small number of sub-processors. Each is contracted under DPA terms equivalent to or stricter than this one. Adding or changing a sub-processor triggers a 30-day prior-notice email; you can object before the change takes effect.
Sub-processor
Purpose
Region
AWSEC2 · S3
VM hosting + storage for Cyborg infrastructure
ap-south-1 (Mumbai) by default
Anthropic / OpenAI[per plan]
Stateless inference calls; no data retention agreed contractually
The Controller is the “decision maker” over personal data. We act under your documented instructions only.
Access: request a structured export of any personal data we process for you — delivered within 7 days.
Rectification: ask us to correct or update any record — we act within 5 business days.
Erasure: request deletion of personal data — cryptographic wipe + certificate of destruction within 30 days, unless legal retention applies.
Portability: get the data in a structured, common, machine-readable format (JSON / CSV).
Objection: object to a sub-processor change before it takes effect (30-day window).
Audit: request an audit of our processing activities once per year, with 30-day notice. We accept SOC 2 Type II reports as evidence in lieu of on-site audits where applicable.
06Security measures.
Aliens implements technical + organisational measures appropriate to the risk:
Encryption at rest: AES-256, per-customer key, key never leaves the VM.
Encryption in transit: TLS 1.3 minimum on all internal + external traffic.
Access controls: Aliens engineers cannot access customer VMs without a customer-side approval workflow (break-glass mode, fully logged).
Audit logs: every API call, every action, every config change — logged and customer-exportable.
If Aliens becomes aware of a personal-data breach affecting Controller data, we notify the Controller without undue delay and in any case within 72 hours. Notification includes:
Nature + scope of the breach (records affected, data categories).
Likely consequences for data subjects.
Measures taken or proposed to address the breach.
Contact point for further information.
The Controller remains responsible for notifying its own data subjects and supervisory authorities where applicable; Aliens supports those notifications in good faith.
08International transfers.
We default to in-region processing (Indian customers in ap-south-1; EU customers in eu-central-1; UK customers in eu-west-2). Cross-border transfer of personal data, where unavoidable, relies on Standard Contractual Clauses (EU SCCs 2021/914) or equivalent UK / India safeguards.
09Term & termination.
This DPA is effective from the date the Controller signs the master agreement and remains in force as long as Aliens processes personal data on the Controller’s behalf.
On termination: 7-day cooling-off period → structured export (if requested) → cryptographic wipe of customer data → certificate of destruction issued. Backups age out within 12 months and are wiped at retention end.
10Liability & indemnity.
Liability under this DPA is governed by the master agreement, capped per the limits there, with the standard exception that breach of confidentiality obligations and gross negligence in security measures are not capped.
11Governing law.
For Indian customers: governed by Indian law; courts of Mumbai have exclusive jurisdiction. For EEA / UK customers: governed by Irish law; courts of Dublin have exclusive jurisdiction. The Controller and Processor agree this DPA is sufficient to satisfy GDPR Art. 28(3) requirements.
Want the signed PDF?
Reply with your company name + a signing email; we send the executed counterpart within 1 business day. PDF is human-readable, lawyer-passed, and matches this page exactly.