Last updated: July 2026 · EverydAI, London, United Kingdom
This Data Processing Agreement ("DPA") forms part of every EverydAI client engagement and governs personal data we process on a client's behalf. The client is the controller; EverydAI is the processor. It is written to meet Article 28 UK GDPR, and it prevails over any conflicting term in the proposal on data protection matters.
1. Details of the processing
Subject matter and nature: operating AI systems and automations connected to the client's tools: reading, drafting, filing, scheduling and reporting on the client's instructions. Duration: the subscription term, plus the wind-down period in section 9. Categories of data: business contact details, correspondence, calendar entries, CRM records and documents the client connects. Data subjects: the client's staff, clients, prospects and suppliers. Special category data is not sought; if a client's records contain it incidentally, it is processed only as part of those records and under the same safeguards.
2. Instructions
We process personal data only on the client's documented instructions: the signed proposal, the agreed System configurations, and instructions given through the tuning process. If we believe an instruction breaches data protection law, we tell the client and pause that instruction. If law requires us to process otherwise, we tell the client first unless the law prevents it.
3. Confidentiality and personnel
Everyone who accesses client personal data is bound by confidentiality obligations, and access is limited to what operating the client's Systems requires.
4. Security
We apply technical and organisational measures appropriate to the risk, including: minimum-scope connections and read-only access wherever possible; encryption in transit; secrets held in managed environment stores, never in code; per-client separation of configurations; approval gates so nothing leaves the client's business without human sign-off; and logging of every System action with its reasoning. Our written security procedures are available to clients and form the security annex to this DPA.
5. Sub-processors
The client authorises the sub-processors listed in our privacy notice (currently Anthropic, Make, Google Workspace, Supabase and Vercel), each engaged under terms no less protective than this DPA, including the exclusion of client data from AI model training. We give at least 14 days' notice of any change, and the client may object on reasonable data protection grounds; if we cannot resolve an objection, the client may terminate the affected Systems without penalty. We remain fully liable for our sub-processors' performance.
6. International transfers
Where a sub-processor processes personal data outside the UK, the transfer is protected by the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, so that the level of protection is not materially lower than under UK GDPR.
7. Assisting the client
Taking into account the nature of the processing, we help the client meet its obligations: responding to data subject requests (we forward any request we receive within 2 working days and assist with retrieval), and supporting data protection impact assessments, security obligations and consultations with the ICO where relevant.
8. Personal data breaches
We notify the client without undue delay after becoming aware of a personal data breach affecting their data, and in any event within 48 hours, with what we know: the nature of the breach, categories and approximate numbers affected, likely consequences, and the measures taken. We then cooperate fully with the client's own notification obligations. Notifying the ICO or data subjects is the controller's decision; making it possible in time is ours.
9. Return and deletion
At the end of the engagement we return the personal data and outputs the Systems hold for the client in a common format on request, then delete personal data from our systems within 30 days, except what law requires us to retain (which stays protected under this DPA until deleted). Deletion covers sub-processors too.
10. Audit
We make available the information reasonably necessary to demonstrate compliance with this DPA, including our security procedures, records of processing and sub-processor terms. Once per year, or after a breach, the client may audit on 14 days' written notice, during business hours, in a way that does not expose other clients' data; third-party certifications and reports satisfy the audit where they cover the question asked.
11. Liability and term
Liability under this DPA is subject to the limitations in the terms of service, except where UK GDPR does not permit limitation. This DPA lasts as long as we process personal data for the client, and sections on confidentiality, return and deletion survive.