This document is an unsigned Data Processing Agreement template for business customers. It becomes an agreement only when the parties complete the identification and processing schedule and accept it in writing. Contact [legal@individu.ai](mailto:legal@individu.ai) for an executable copy. Publishing this template does not constitute a signed DPA or an independent compliance certification.

## 1. Parties and scope

**Controller:** the customer’s registered legal name, business address, registration number, authorized representative and privacy contact, to be completed in the signed copy.

**Processor:** Individu, the registered trade name in the Netherlands, KVK 97860891, VAT NL005293287B03. The registered business address, underlying operator details where required and authorized signatory must be completed and verified before signature. Privacy contact: [privacy@individu.ai](mailto:privacy@individu.ai).

This DPA applies when Individu processes personal data on the Controller’s behalf to provide the agreed assistant services. It does not cover processing for Individu’s own account administration, fraud prevention or legally required billing records, described separately in the [privacy policy](/privacy). If this DPA conflicts with general service terms about processing covered here, this DPA takes precedence.

## 2. Processing schedule

- **Subject matter and duration:** providing the contracted Individu assistant during the subscription, followed by agreed deletion and any strictly necessary retention.
- **Nature and purpose:** retrieving authorized information, storing selected content, summarizing, generating drafts and briefings, managing requested tasks and automations, and executing actions approved or configured by the Controller.
- **Data subjects:** the Controller’s staff, customers, prospects, suppliers, contacts and people appearing in authorized communications or documents.
- **Data types:** contact details, message and email content, attachments, meeting notes, calendar events, task details, property and transaction context, account identifiers and integration authorization data.
- **Sensitive data:** processing is limited to the Controller’s documented instructions. Special-category or criminal-offence data is not an intended default input. Any necessary processing requires an agreed scope and appropriate safeguards.
- **Connected services:** the specific accounts and enabled integrations selected by the Controller. The signed schedule identifies any restrictions, selected WhatsApp chats and authorized automations.

## 3. Instructions and confidentiality

Individu will process covered personal data only on the Controller’s documented instructions, including instructions made through authorized settings and actions. The Controller determines lawful purposes, access permissions and any required notices to data subjects. Individu will notify the Controller if it considers an instruction to infringe applicable data protection law and may suspend that instruction while the parties resolve it.

Where law requires processing beyond those instructions, Individu will inform the Controller before processing unless that law prohibits notice. Personnel permitted to access covered data must be bound by confidentiality and receive access appropriate to their duties. Covered content will not be used to train Individu’s models or selected third-party AI models.

## 4. Technical and organizational measures

The agreed baseline consists of TLS in transit, hashed account passwords, encrypted integration credentials, account-scoped authorization, private WhatsApp media storage, access-controlled media delivery, explicit MCP consent, revocable MCP access and restricted write actions. Operational access is limited to people who need it to maintain or support the service.

The signed security schedule will identify backup and log retention, access administration, incident contacts and any customer-specific measures. Individu does not currently claim an ISO 27001 certification or SOC 2 report. Provider certifications do not certify Individu itself.

### 4.1 WhatsApp and retention

WhatsApp uses a linked-device session. WhatsApp can still deliver data to that device. In selected-chat mode, Individu discards excluded messages before inbox persistence, media downloads and AI processing. Changing the selection removes excluded content from the active inbox cache, but does not erase prior copies saved in conversations, tasks or memory.

WhatsApp inbox content and cached WhatsApp media are subject to a 30-day retention limit. Daily cleanup removes expired cached data. Saved conversations, notes, tasks and memory follow their separate retention and deletion controls. Disconnecting removes the linked session and inbox state. It does not automatically delete every saved output derived from that connection.

### 4.2 AI and file storage

AI Gateway requests require no-training providers. Language, structured decision and video processing also require zero data retention support. Image generation, transcription and embeddings are not covered by that zero data retention guarantee.

General file uploads, profile images and generated images currently use URL-accessible storage. The private WhatsApp media control does not make these other files private. The Controller should agree appropriate file handling before uploading confidential attachments through these paths.

## 5. Sub-processors

The Controller grants general authorization for the sub-processors identified in the signed schedule, based on the current [provider register](/subprocessors). Individu will bind each processor to appropriate obligations for its processing and remains responsible for its sub-processor obligations under this DPA.

Under the signed agreement, Individu will notify the Controller at least 30 days before appointing or replacing a sub-processor for covered data, giving information needed to assess the change. The Controller may raise a reasoned data protection objection within that period. The parties will seek a practical alternative. If they cannot resolve the objection, the Controller may terminate the affected service before the change applies and receive a refund of unused prepaid fees for that service. The notification contact is specified in the signed schedule.

## 6. International transfers

The current service uses infrastructure and AI providers outside the EEA, including the United States. EU-only hosting and processing are not offered by this configuration. Using newer models and responsive infrastructure does not replace the requirement for lawful transfer safeguards.

Before processing under this DPA begins, the signed schedule must identify the applicable transfer mechanism and supporting provider agreements for each relevant transfer. Depending on the recipient, this may involve an applicable adequacy decision or the European Commission’s international transfer Standard Contractual Clauses with the appropriate module and supplementary measures. This template does not claim that a complete transfer assessment has already been performed or that signatures on this DPA alone establish those safeguards.

## 7. Assistance and incidents

Individu will reasonably assist the Controller with data-subject requests, security obligations, impact assessments and regulatory consultation, considering the nature of processing and information available. Individu will refer requests concerning the Controller’s data to the Controller rather than independently deciding the response, unless required by law.

Individu will notify the Controller without undue delay after becoming aware of a personal data breach affecting covered data. Available information will include the nature of the breach, affected data and people, likely consequences, measures taken and a contact for follow-up. Information may be provided in stages as facts become available. The Controller remains responsible for any required notifications to authorities and data subjects.

## 8. Return, deletion and review

At the end of the service, the Controller may request return of covered saved content in the available JSON export and deletion of covered data, subject to legally required retention. The signed schedule must state the deletion timetable for active systems and backups. Retained data will remain protected and will not be used for unrelated purposes. JSON export is not a complete archive of every attachment’s original binary file.

Individu will provide information reasonably necessary to demonstrate performance of this DPA and permit proportionate audits or inspections by the Controller or an authorized auditor, with reasonable notice and confidentiality safeguards. An urgent regulatory or incident-related request will be handled promptly. Costs and practical arrangements must not prevent the Controller from exercising mandatory rights.

## 9. Signature and annexes

The executable copy includes completed party details, effective date, service scope, privacy and incident contacts, security and retention schedule, authorized processor schedule and applicable transfer documentation.

**For the Controller:** name, title, signature and date.

**For Individu’s registered operator:** name, title, signature and date.

This template is intended to support the written arrangement required by Article 28 GDPR. The European Commission distinguishes controller-processor clauses from international-transfer clauses in its [SCC guidance](https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/new-standard-contractual-clauses-questions-and-answers-overview_en). The parties must complete the relevant agreement and schedules before relying on this document.
