Last updated: September 25, 2026
This Data Processing Agreement ("DPA") forms part of the agreement between AirComply, Inc., a Delaware corporation ("AirComply"), and the customer identified in the applicable order, account registration, or agreement ("Customer") governing Customer's use of AirComply's services (the "Agreement"). For customers who purchase online, this DPA is incorporated by reference into the AirComply Terms of Service and applies automatically. It reflects the parties' agreement with regard to the processing of Personal Data within Customer Data.
Customer is the controller (or a processor acting on behalf of a third-party controller) of Personal Data; AirComply is a processor acting on Customer's documented instructions.
AirComply will process Customer Data only on Customer's documented instructions, including as set out in the Agreement and this DPA, unless required otherwise by applicable law (in which case AirComply will inform Customer unless legally prohibited). AirComply will promptly inform Customer if, in its opinion, an instruction infringes Applicable Data Protection Laws.
No AI training: Customer Data is never used to train AI models, by AirComply or by its AI subprocessors, as described in Section 7.
AirComply ensures that persons authorized to process Customer Data are bound by confidentiality obligations, whether contractual or statutory.
AirComply implements and maintains appropriate technical and organizational measures, including:
Details are maintained on our Security page.
Customer provides general authorization for AirComply to engage the subprocessors listed below. AirComply will update this page at least 15 days before adding or replacing a subprocessor that processes Customer Data; Customer may object on reasonable data protection grounds within that period. AirComply remains responsible for its subprocessors' performance.
Taking into account the nature of processing, AirComply will assist Customer by appropriate technical and organizational measures in fulfilling Customer's obligations to respond to data subject requests (access, correction, deletion, portability). If AirComply receives a request directly from a data subject relating to Customer Data, it will promptly forward the request to Customer and will not respond except to direct the data subject to Customer, unless legally required.
AirComply will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data breach affecting Customer Data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, likely consequences, and measures taken or proposed. AirComply will cooperate with Customer and take reasonable steps to mitigate and remediate.
Customer may request a full export of Customer Data at any time, and AirComply will provide it in standard formats without undue delay; in-application self-serve export is on the product roadmap. Upon termination of the Agreement, AirComply provides a 30-day window for export, after which Customer Data is deleted from production systems within 30 days and from backups through routine backup rotation within 90 days, unless retention is required by applicable law. AirComply is not an archival or backup service; Customer is responsible for retaining independent copies of source documents and any records required to meet its legal and regulatory retention obligations.
AirComply will make available information reasonably necessary to demonstrate compliance with this DPA, including summaries of third-party certifications of its infrastructure providers (SOC 2 Type II; ISO 27001 where held). Where Applicable Data Protection Laws grant Customer an audit right that cannot be satisfied by such information, Customer may conduct an audit no more than once per year, on 30 days' written notice, during business hours, without disrupting operations, at Customer's expense, subject to confidentiality obligations.
AirComply stores and processes Customer Data in the United States. Where Personal Data subject to the GDPR or UK GDPR is transferred to AirComply or its subprocessors in the United States, the parties rely on the EU Standard Contractual Clauses (Module 2: Controller to Processor), which are incorporated by reference into this DPA, and on subprocessor safeguards including Data Privacy Framework certifications where held (Anthropic is DPF-certified).
Each party's liability arising out of or related to this DPA is subject to the exclusions and limitations of liability set out in the Agreement.
This DPA remains in force for the term of the Agreement and for as long as AirComply processes Customer Data. In case of conflict between this DPA and the Agreement regarding the processing of Personal Data, this DPA prevails. AirComply may update this DPA as required by changes in Applicable Data Protection Laws, with notice via this page.
Questions about this DPA: legal@aircomply.com. Enterprise customers may request a countersigned copy of this DPA, and the current subprocessor list, at the same address.