Data Processing Agreement
Last updated: 13 August 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between the customer (“Controller”) and OneAI (“Processor”) for the provision of the Services. Where the Services process personal data on behalf of the Controller, this DPA applies.
1. Definitions
Terms defined in Regulation (EU) 2016/679 (“GDPR”) have the same meaning here.
2. Subject matter and duration
Processor processes Personal Data on behalf of Controller only for the duration and purposes set out in the underlying agreement.
3. Nature and purpose of processing
Processor processes Personal Data to provide the Services, including monitoring, case management, RFI automation, MID governance, reporting, and related functions.
4. Categories of data subjects and Personal Data
- Controller's users and administrators (identifiers, contact data, role, activity logs).
- Controller's merchants (business details, MID, descriptors, contact data).
- End customers of Controller's merchants (transaction-related identifiers).
5. Processor obligations
- Process Personal Data only on documented instructions from Controller.
- Ensure persons authorised to process Personal Data are bound by confidentiality.
- Implement appropriate technical and organisational measures (Annex II).
- Assist Controller with data subject requests and Article 32–36 obligations.
- Delete or return Personal Data at the end of the Services, subject to legal retention.
- Make available all information necessary to demonstrate compliance and allow audits.
6. Sub-processors
Controller grants general authorisation for the sub-processors listed on the Security page. Processor will notify Controller of any changes and allow objection within 30 days.
7. International transfers
Where Personal Data is transferred outside the EEA/UK, the parties rely on Standard Contractual Clauses and supplementary measures as applicable.
8. Security
Processor maintains a security programme aligned with recognised industry standards, including encryption in transit and at rest, access controls, logging and monitoring, and incident response. Full details are available on the Security page.
9. Breach notification
Processor will notify Controller without undue delay after becoming aware of a Personal Data breach, with sufficient information for Controller to meet its obligations under GDPR Article 33.
10. Liability
The parties' liability under this DPA is subject to the limitations set out in the underlying agreement.
Annex I — Details of processing
See sections 3–4 above. Frequency: continuous during the term of the Services.
Annex II — Security measures
Documented on the Security page, updated as the programme evolves. Highlights: TLS 1.3, AES-256 at rest, field-level encryption for PII/PAN, RBAC, SSO/SAML, SCIM, audit logging, and quarterly access reviews.
Contact
DPA enquiries: sales@oneaialert.com.