Data Processing Agreement

Effective Date: 1 July 2026 · Last Updated: 10 August 2026

This DPA forms part of the agreement between AAAecommerce INC (“Processor”) and the Customer (“Customer”) concerning processing of personal data through AiEngage.

1. Roles

For Customer Data processed through the Services:

  • Customer: determines the lawful purpose and instructions for processing, subject to applicable law.
  • AiEngage: processes such personal data on Customer’s documented instructions and as necessary to provide the Services, except where applicable law requires otherwise.

2. Processing Details

Subject Matter

Provision of CRM, communication, automation, AI and related Services.

Duration

For the duration of the Services plus applicable retention periods.

Purpose

Including:

  • CRM management
  • Lead management
  • Customer communication
  • Marketing automation
  • Sales automation
  • AI processing
  • Analytics
  • Customer support
  • Platform security

Data Subjects

May include:

  • Prospects
  • Leads
  • Customers
  • Employees
  • Vendors
  • Partners
  • Customer representatives

Data Types

May include:

  • Identity information
  • Contact details
  • CRM records
  • Conversation data
  • Call information
  • Transaction-related information
  • Lead attributes
  • Customer-supplied custom fields

3. Customer Instructions

AiEngage will process Customer Personal Data according to Customer’s documented instructions, including instructions expressed through Customer’s configuration and use of the Services.

If AiEngage reasonably believes an instruction violates applicable law, it may inform Customer and, where legally appropriate, suspend the affected processing.

4. Customer Responsibilities

Customer is responsible for:

  • Lawful collection;
  • Required notices;
  • Consent where required;
  • Data accuracy;
  • Communication permissions;
  • Handling individual requests as required;
  • Lawful instructions; and
  • Compliance with industry-specific obligations.

5. Confidentiality

Persons authorized by AiEngage to process Customer Personal Data will be subject to appropriate confidentiality obligations.

6. Security

AiEngage will maintain reasonable technical and organizational measures appropriate to the nature of the Services and processing risks.

Measures may include, as appropriate:

  • Access controls;
  • Authentication;
  • Encryption in transit;
  • Logging;
  • Monitoring;
  • Backup controls;
  • Vulnerability management;
  • Employee access restrictions;
  • Incident-response procedures.

7. Subprocessors

Customer authorizes AiEngage to engage subprocessors necessary to provide the Services.

These may include providers of:

  • Cloud infrastructure;
  • AI;
  • Messaging;
  • WhatsApp;
  • Telephony;
  • Email;
  • SMS;
  • Analytics;
  • Support;
  • Security.

AiEngage will impose appropriate data-protection obligations on subprocessors as required by applicable law and contract.

8. International Transfers

Where personal data is processed internationally, AiEngage will take measures required by applicable law.

9. Data Subject Requests

Where legally and technically appropriate, AiEngage will reasonably assist Customer in responding to requests relating to Customer Personal Data.

AiEngage may direct an individual to the relevant Customer where Customer controls the relevant data.

10. Security Incidents

If AiEngage becomes aware of a personal-data breach affecting Customer Personal Data that requires notification under applicable law or contract, AiEngage will notify Customer without undue delay as required by the applicable framework.

Customer remains responsible for its own regulatory and individual notifications unless applicable law assigns that obligation otherwise.

11. Deletion or Return

Upon termination, AiEngage will delete or return Customer Personal Data in accordance with the agreement, applicable retention practices and legal obligations.

Backup copies may remain temporarily until overwritten according to standard backup cycles.

12. Audits

AiEngage may provide reasonable information necessary to demonstrate compliance with this DPA.

Audits must:

  • Be reasonable;
  • Protect other customers;
  • Protect AiEngage confidential information;
  • Avoid unreasonable disruption; and
  • Be subject to appropriate confidentiality.

Customer may be responsible for extraordinary audit costs where permitted by the agreement.

13. Liability

Liability under this DPA is subject to the liability provisions of the primary agreement unless expressly agreed otherwise.

WhatsApp