Last updated: 2026-08-21
Processing is limited to storing, replicating and returning the data the Customer's own myAI instance pushes to its hosted brain remote, plus operating the account/billing surface — solely to provide the subscribed service, for the duration of the subscription, and never for advertising, profiling, resale, or model training.
Where the Vendor processes personal data on the Customer's behalf, the Vendor will:
The Customer generally authorises the subprocessors on the maintained subprocessor list. The Vendor gives at least 30 days' notice before adding or replacing a subprocessor (the list page records the change and its date); the Customer may object on reasonable data-protection grounds, and if the objection cannot be resolved, may terminate the affected service and receive a pro-rata refund. Integrations the Customer configures with their own credentials (LLM providers, messaging bots, error tracking) are the Customer's own vendors, not subprocessors — see the list page.
Hosted brain remotes are provisioned in the region chosen at provisioning time and are not moved without the notice in Section 5. Where a transfer outside the Customer's jurisdiction is unavoidable (e.g. the payment processor), it relies on the subprocessor's Standard Contractual Clauses or an equivalent lawful transfer mechanism, referenced per-vendor on the subprocessor list.
Self-hosted data never left the Customer's hands, so deletion is entirely the Customer's operation. For hosted surfaces: the Customer can deprovision a hosted brain at any time, and on account closure the Vendor deletes or anonymises hosted personal data within 30 days, except billing records retained to meet legal and tax obligations. Export is available first — the platform's export tooling (myai memory export, context export) returns the data in portable form.
myAI is source-available: the security-relevant implementation (auth, tenancy, hashing, retention jobs) is inspectable in the repository, which serves as the primary audit artifact. The Vendor will additionally answer reasonable written security questionnaires, no more than once per year absent a genuine incident, at the Customer's expense for extraordinary effort.
Liability under this DPA is subject to the limitations in the Terms of Service. If this DPA conflicts with the Terms on data-protection matters, this DPA prevails.
This published DPA applies automatically to hosted subscriptions from the “Last updated” date above. Enterprise customers who need a countersigned copy (or their own DPA template reviewed) can open a private thread via the repository or email the maintainer listed in the repo profile. Material changes are posted on this page with an updated date.
This document is a plain-language addendum, not legal advice; have your counsel adapt it to your jurisdiction before relying on it commercially.