Data Processing Agreement
Last updated: 28 September 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between the customer ("Controller") and Muhammad Usman, sole proprietor, Pakistan, operating ProofMyAI ("Processor"). It applies whenever ProofMyAI processes personal data on the Customer's behalf and meets the requirements of Article 28 of the EU GDPR and the UK GDPR.
1. Subject matter, nature and purpose
The Processor provides quality monitoring of the Controller's AI chatbots, AI agents and automation workflows: storing, masking, analysing and reporting on the data the Controller uploads or sends, and sending the alerts and reports the Controller configures. The Processor processes personal data only for this purpose and for the duration of the agreement.
2. Types of data and data subjects
- Data subjects: the Controller's customers and website visitors who talk to its chatbots; the Controller's staff who use ProofMyAI.
- Personal data: contents of chat conversations and AI agent runs as sent by the Controller (which may include names, contact details, vehicle, order or account details and complaint text), metadata such as timestamps and conversation IDs, and the account details of the Controller's users.
- Special category data: the Controller should not send it. If a conversation contains it, the Processor handles it under this DPA and the Controller should use masking, results-only mode and short retention.
3. Processor obligations
- Process personal data only on the Controller's documented instructions, which are the Terms, this DPA and the Controller's settings in ProofMyAI, and tell the Controller if an instruction appears to break data protection law.
- Ensure anyone with access is bound by confidentiality.
- Apply the technical and organisational measures described in the Trust Center, including encryption in transit, encryption of stored credentials, hashed passwords, access control, masking and logging of administrative actions.
- Help the Controller respond to data subject requests (access, correction, deletion, export) and with data protection impact assessments, as far as reasonably possible.
- Notify the Controller of a personal data breach without undue delay and in any case within 72 hours of becoming aware of it, with the information needed to meet the Controller's own obligations.
- Make available the information needed to demonstrate compliance with this DPA and allow reasonable audits, normally through written answers and documentation, with at least 30 days' notice and at the Controller's cost.
4. Sub-processors
The Controller authorises the sub-processors listed in the Trust Center. The Processor imposes data protection terms on each that are no less protective than this DPA, remains responsible for them, and gives at least 30 days' notice by email before adding or replacing a sub-processor that handles customer data. The Controller may object on reasonable grounds and, if no solution is found, end the service with a pro-rata refund of prepaid fees.
5. International transfers
Where personal data is transferred outside the UK or EEA to a country without an adequacy decision, including to the Processor's own location, the parties rely on the EU Standard Contractual Clauses (Module 2, controller to processor, or Module 3 for sub-processors) and the UK International Data Transfer Addendum, which are incorporated into this DPA by reference.
6. Controller responsibilities
The Controller is responsible for having a lawful basis for the processing, for informing its customers (for example in its privacy notice) that conversations are quality-checked by a service provider, and for choosing appropriate settings (masking, retention, results-only mode and whether AI checking is used).
7. Deletion and return
The Controller can delete data at any time in the dashboard, set automatic deletion per project, and export results as CSV. When the account is deleted, personal data is deleted from the live database immediately and from backups within 30 days, unless the law requires otherwise.
8. Liability and order of precedence
Liability under this DPA is subject to the limits in the Terms, except where the law does not allow limitation. If this DPA conflicts with the Terms, this DPA prevails for the processing of personal data.
Accept this DPA
Log in to accept this DPA online for your account, or email contact@usmanabbas.dev for a copy signed by both parties.