Data Processing Addendum

Last updated: 2026-08-21

This Data Processing Addendum (“DPA”) forms part of the agreement between the customer (“Customer”) and the myAI maintainers (“Vendor”) whenever the Vendor processes personal data on the Customer's behalf. In myAI's default self-hosted configuration this DPA has almost nothing to govern: the working context — agent memory, sessions, handoffs, the recall corpus — is processed on the Customer's own hardware and never transmitted to the Vendor (see Security & Data Locality). It applies to the hosted surfaces only: the account/billing service, optional hosted brain remotes, and support.

1. Roles and scope

  • Self-hosted deployment (default): the Customer is the controller and operates the processing themselves, on their own infrastructure. The Vendor receives no personal data and is neither controller nor processor for the Customer's working context.
  • Hosted account & billing: the Vendor acts as an independent controller for the minimal account data described in the Privacy Policy (email, hashed credentials, subscription state).
  • Hosted brain remote (optional, per-tenant): when the Customer provisions a hosted brain, the Vendor acts as a processor for the content the Customer chooses to sync there. This is the surface the obligations below govern.

2. Subject matter, duration, nature and purpose

Processing is limited to storing, replicating and returning the data the Customer's own myAI instance pushes to its hosted brain remote, plus operating the account/billing surface — solely to provide the subscribed service, for the duration of the subscription, and never for advertising, profiling, resale, or model training.

3. Categories of data and data subjects

  • Account data — email address, display name, hashed credentials, tenant identifiers (data subjects: the Customer’s named users).
  • Billing data — customer reference, plan tier, subscription status; card data is held by the payment processor, never by the Vendor.
  • Hosted brain content — whatever the Customer’s instance syncs (session atoms, compiled briefs). Its contents are determined entirely by the Customer; the Customer is responsible for what they choose to sync.
  • Support correspondence — whatever the Customer sends when asking for help.

4. Vendor (processor) obligations

Where the Vendor processes personal data on the Customer's behalf, the Vendor will:

  • Process it only on the Customer’s documented instructions — the subscription itself and the sync operations the Customer’s instance issues — unless required otherwise by law, in which case the Vendor informs the Customer unless legally barred.
  • Ensure persons authorised to process the data are bound by confidentiality.
  • Apply the technical and organisational measures published on the Security & Data Locality page and in version-controlled SECURITY.md — hashed credentials, SHA-256-hashed API keys with constant-time comparison, per-tenant isolation, and loopback-bound defaults.
  • Engage subprocessors only as listed on the Subprocessors page, under written terms no less protective than this DPA, with advance notice of changes (Section 5).
  • Assist the Customer, taking into account the nature of the processing, in responding to data-subject requests (access, rectification, erasure, portability) and in meeting its security, breach-notification and impact-assessment obligations.
  • Notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer’s data, with the detail needed for the Customer’s own art. 33/34 obligations.
  • Delete or return the data at the end of the service (Section 7).
  • Make available the information necessary to demonstrate compliance, and allow for audits as described in Section 8.

5. Subprocessors

The Customer generally authorises the subprocessors on the maintained subprocessor list. The Vendor gives at least 30 days' notice before adding or replacing a subprocessor (the list page records the change and its date); the Customer may object on reasonable data-protection grounds, and if the objection cannot be resolved, may terminate the affected service and receive a pro-rata refund. Integrations the Customer configures with their own credentials (LLM providers, messaging bots, error tracking) are the Customer's own vendors, not subprocessors — see the list page.

6. International transfers

Hosted brain remotes are provisioned in the region chosen at provisioning time and are not moved without the notice in Section 5. Where a transfer outside the Customer's jurisdiction is unavoidable (e.g. the payment processor), it relies on the subprocessor's Standard Contractual Clauses or an equivalent lawful transfer mechanism, referenced per-vendor on the subprocessor list.

7. Deletion and return

Self-hosted data never left the Customer's hands, so deletion is entirely the Customer's operation. For hosted surfaces: the Customer can deprovision a hosted brain at any time, and on account closure the Vendor deletes or anonymises hosted personal data within 30 days, except billing records retained to meet legal and tax obligations. Export is available first — the platform's export tooling (myai memory export, context export) returns the data in portable form.

8. Audit

myAI is source-available: the security-relevant implementation (auth, tenancy, hashing, retention jobs) is inspectable in the repository, which serves as the primary audit artifact. The Vendor will additionally answer reasonable written security questionnaires, no more than once per year absent a genuine incident, at the Customer's expense for extraordinary effort.

9. Liability and order of precedence

Liability under this DPA is subject to the limitations in the Terms of Service. If this DPA conflicts with the Terms on data-protection matters, this DPA prevails.

10. Executing this DPA

This published DPA applies automatically to hosted subscriptions from the “Last updated” date above. Enterprise customers who need a countersigned copy (or their own DPA template reviewed) can open a private thread via the repository or email the maintainer listed in the repo profile. Material changes are posted on this page with an updated date.

This document is a plain-language addendum, not legal advice; have your counsel adapt it to your jurisdiction before relying on it commercially.

Data Processing Addendum — myAI