Last updated: July 15, 2026
Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the Aivius Terms of Service (the "Agreement") and is entered into between Aivius, Inc. ("Aivius," "Processor," or "we") and the customer entity that has agreed to the Agreement ("Customer," "Controller," or "you"). This DPA reflects the parties' agreement with respect to the processing of personal data under the GDPR, the UK GDPR, the Swiss Federal Act on Data Protection (FADP), and, where applicable, the CCPA/CPRA.
Applicability: This DPA applies to Aivius's processing of personal data on behalf of Enterprise and Agency customers who have signed an order form or subscription agreement that references it. Customers on Free, Starter, and Pro plans may rely on this DPA as a reference for our data protection practices but are not required to sign it; their processing is governed by our Privacy Policy and Terms of Service.
Capitalized terms not defined in this DPA have the meanings given in the GDPR or, if not defined there, in the Agreement. In the event of a conflict between this DPA and the Agreement, this DPA controls with respect to the processing of personal data.
Definitions
For the purposes of this DPA:
- "GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
- "UK GDPR" means the GDPR as it forms part of the law of the United Kingdom by virtue of the European Union (Withdrawal) Act 2018.
- "CCPA/CPRA" means the California Consumer Privacy Act, as amended by the California Privacy Rights Act of 2020.
- "Personal Data" has the meaning given in the GDPR and includes "personal information" as defined in the CCPA/CPRA.
- "Controller" means the entity that determines the purposes and means of processing personal data. "Processor" means the entity that processes personal data on behalf of the Controller.
- "Data Subject" means an identified or identifiable natural person to whom personal data relates.
- "Subprocessor" means a third party engaged by Aivius to process personal data on behalf of the Customer.
- "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission under Implementing Decision (EU) 2021/914.
- "Supervisory Authority" means an independent public authority established by an EU/EEA member state pursuant to GDPR Article 51.
- "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed.
Roles and Parties
The parties acknowledge and agree that:
- Customer is the Controller (or, where Customer processes personal data on behalf of its own clients, Customer acts as a Processor and Aivius acts as a Subprocessor). Customer determines the purposes and means of processing personal data submitted to the Service.
- Aivius is the Processor. Aivius processes personal data only on documented instructions from Customer, in accordance with the Agreement, this DPA, and applicable law.
- Where Aivius processes personal data subject to the CCPA/CPRA, Aivius acts as a "service provider" (as defined in CCPA) and processes personal information solely to perform the services described in the Agreement. Aivius does not sell or share personal information processed under this DPA and does not combine it with personal information from other sources except as permitted by the CCPA/CPRA.
Customer warrants that it has obtained all necessary consents and provided all necessary notices to Data Subjects required to authorize Aivius's processing of personal data on Customer's behalf.
Processing of Personal Data
Aivius processes the following categories of personal data on behalf of Customer, for the following purposes, for the duration of the Agreement:
- Account and contact data: names and email addresses of Customer's authorized users, processed to administer accounts and provide support.
- Brand and domain configuration data: brand names, domains, and competitor names configured by Customer, processed to perform AI engine citation queries.
- Citation and visibility data: text snippets, source URLs, and sentiment tags returned by AI engines, processed to generate visibility reports for Customer.
- Usage data: in-app events and feature usage, processed to deliver and improve the Service for Customer.
The categories of Data Subjects are limited to Customer's authorized users (employees, contractors, and agents) and, indirectly, individuals mentioned in AI engine responses (e.g., authors cited by AI engines). Aivius does not process special categories of personal data (GDPR Article 9) or criminal conviction data (GDPR Article 10).
Aivius processes personal data only on Customer's documented instructions, including with regard to transfers of personal data to a third country, unless required to do so by law. Aivius will inform Customer if it cannot comply with an instruction due to a legal requirement, without delay.
Aivius will not (a) sell or share personal data, (b) retain, use, or disclose personal data for any purpose other than providing the Service, (c) retain, use, or disclose personal data outside of the direct business relationship between the parties, or (d) combine personal data with personal information received from or on behalf of any other person, except as permitted by CCPA.
Subprocessors
Customer grants Aivius general authorization to engage subprocessors to process personal data on Customer's behalf, provided that Aivius enters into a written agreement with each subprocessor imposing data protection obligations no less protective than those in this DPA.
The current list of subprocessors, including their name, location, and purpose, is set out below. Aivius will update this list and notify Customer of any addition or replacement of a subprocessor at least 30 days in advance, giving Customer the right to object in writing if the new subprocessor does not meet Customer's data protection requirements. If Customer objects and the parties cannot resolve the objection within 30 days, Customer may terminate the affected portion of the Service with a pro-rata refund.
| Subprocessor | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure: application servers, databases, object storage | United States (US-East region) |
| Paddle | Merchant of Record: subscription billing, tax collection, invoicing | United Kingdom / United States |
| Resend | Transactional email delivery (receipts, security notices, support replies) | United States |
| Google (Google Analytics) | Aggregate, pseudonymized website analytics (no cross-site tracking) | United States |
| OpenAI | AI engine API: ChatGPT citation queries (sent prompts and brand names) | United States |
| Perplexity | AI engine API: Perplexity citation queries | United States |
| Google (AI Overviews / Gemini) | AI engine API: Google AI Overviews and Gemini citation queries | United States |
| Anthropic | AI engine API: Claude citation queries | United States |
| Microsoft | AI engine API: Microsoft Copilot citation queries | United States |
| Meta | AI engine API: Meta AI citation queries | United States |
| Amazon | AI engine API: Amazon Rufus citation queries | United States |
| Apple | AI engine API: Apple Intelligence citation queries | United States |
When prompts and brand names are sent to AI engine APIs (rows 5-12 above), those AI engine providers act as independent controllers of the data they receive, governed by their own terms and privacy policies. Aivius cannot guarantee the data protection practices of these third-party controllers and recommends that Customer review their policies before tracking brands in regions with strict data protection requirements.
To subscribe to subprocessor change notifications, email dpa@aivius.ai with "Subprocessor notifications" in the subject line.
Security Measures
Aivius implements and maintains appropriate technical and organizational measures designed to ensure a level of security appropriate to the risk, including, at minimum, the measures described in GDPR Article 32. These measures include:
- Encryption: personal data is encrypted in transit using TLS 1.2+ and at rest using AES-256.
- Access control: role-based access with least-privilege principle. Production access requires multi-factor authentication and is logged. Access reviews are conducted quarterly.
- Network security: firewalls, network segmentation, and intrusion detection. Production infrastructure is isolated in a private VPC with no direct internet access to databases.
- Application security: secure software development lifecycle, dependency scanning, regular penetration testing, and code review.
- Monitoring and logging: security event logging with centralized log management. Logs are retained for 90 days.
- Business continuity: daily encrypted backups with 30-day retention. Quarterly disaster recovery testing.
- Personnel security: background checks for employees with production access, confidentiality agreements, and annual security training.
- Vendor management: subprocessors are assessed before onboarding and reviewed annually.
- Data minimization: Aivius only collects and processes personal data that is necessary to deliver the Service. We do not collect special categories of personal data (GDPR Article 9) and have no need for such data.
- Data segregation: each Customer's personal data is logically segregated within the shared infrastructure through per-tenant identifiers. Cross-customer data access is prevented at the application layer.
- Secure deletion: when personal data is deleted at Customer's request, Aivius removes it from production systems within 30 days and from backups within 90 days. Backup media that cannot be selectively purged are encrypted and rotated out according to the standard backup retention schedule.
Aivius will not materially decrease the security of these measures during the term of the Agreement. On request, Aivius will provide Customer with a summary of our security practices (for example, a SOC 2 Type II report or equivalent) subject to a mutual non-disclosure agreement.
International Transfers
Where personal data is transferred from the EEA, UK, or Switzerland to a country that has not received an adequacy decision (including the United States), the transfer is made pursuant to the Standard Contractual Clauses (SCCs) as adopted by the European Commission under Implementing Decision (EU) 2021/914.
For transfers to the United States, the SCCs are supplemented by Aivius's participation in the EU-U.S. Data Privacy Framework (DPF), the UK Extension to the DPF, and the Swiss-U.S. DPF. Aivius's DPF certification can be verified at dataprivacyframework.gov.
For UK transfers, the UK International Data Transfer Addendum to the SCCs applies. For Swiss transfers, the SCCs are modified as required by the Swiss FDPIC.
Data Breach Notification
Aivius will notify Customer without undue delay, and in any case within 72 hours after becoming aware of a Personal Data Breach affecting Customer's personal data, as required by GDPR Article 33. The notification will:
- Describe the nature of the breach, including, where possible, the categories and approximate number of data subjects and records concerned.
- Provide the name and contact details of Aivius's data protection contact (currently privacy@aivius.ai).
- Describe the likely consequences of the breach.
- Describe the measures taken or proposed to address the breach and mitigate its adverse effects.
Aivius will cooperate with Customer in handling the breach, including assisting Customer in notifying the competent Supervisory Authority and affected data subjects where required by GDPR Articles 33 and 34. Aivius will document all Personal Data Breaches, including the facts, effects, and remedial action taken.
Aivius's notification of or response to a Personal Data Breach is not an acknowledgment or admission of fault or liability.
Data Subject Rights
Aivius will assist Customer in fulfilling its obligations to respond to data subjects' requests to exercise their rights under GDPR Articles 15 to 22 (access, rectification, erasure, restriction, portability, objection) and under CCPA/CPRA (know, delete, correct, opt-out). Specifically:
- If Aivius receives a request from a data subject directly, Aivius will redirect the data subject to Customer and notify Customer without delay.
- Aivius will provide Customer with the ability to correct, export, or delete personal data within the Service through the dashboard or API.
- Where Aivius is required by law to respond directly to a data subject request (for example, a deletion request under CCPA), Aivius will notify Customer before responding, unless prohibited by law.
- Aivius will assist Customer with data protection impact assessments (DPIAs) where required by GDPR Article 35, to the extent the Service is part of the assessment scope.
Audit Rights
Customer may audit Aivius's compliance with this DPA, subject to the following conditions:
- Customer must give Aivius at least 30 days' written notice of the audit, unless a shorter notice is required by law or by a Supervisory Authority.
- The audit must be conducted during business hours, in a manner that does not interfere with Aivius's business operations or violate Aivius's security policies.
- Customer may conduct the audit itself or engage a qualified third-party auditor that is not a competitor of Aivius and that has signed a non-disclosure agreement.
- The audit must be limited to information and systems relevant to the processing of Customer's personal data.
- Customer is responsible for the cost of the audit, unless the audit reveals a material non-compliance by Aivius, in which case Aivius bears the cost.
In lieu of an on-site audit, Aivius may, at its discretion, provide Customer with a recent third-party audit report (such as a SOC 2 Type II report), security certification, or equivalent documentation. Where such documentation adequately addresses Customer's audit concerns, Customer agrees to accept it in lieu of conducting its own audit.
Aivius will contribute to audits or inspections conducted by Supervisory Authorities as required by GDPR Article 31.
Term and Termination
This DPA takes effect on the date Customer first uses the Service and remains in effect for the duration of the Agreement. Upon termination of the Agreement:
- Aivius will, at Customer's choice, return or delete all personal data processed on behalf of Customer, and delete existing copies, unless applicable law requires storage.
- Return or deletion will occur within 30 days of termination, except for personal data that Aivius is required to retain by law (for example, billing records retained for 7 years under US tax law). Such retained data will be minimized and protected in accordance with this DPA until it can be deleted.
- Aivius will provide written confirmation of deletion upon request.
Any provision of this DPA that by its nature should survive termination will survive, including the Confidentiality, Audit Rights, and Liability provisions.
Liability
Each party's liability arising out of or related to this DPA, whether in contract, tort, or under any other theory of liability, is subject to the limitations of liability in the Agreement, and any reference in the Agreement to a party's liability means the aggregate liability of that party under the Agreement and this DPA together.
Contact
For any question about this DPA, to sign a custom DPA, to subscribe to subprocessor change notifications, or to exercise audit rights, contact:
- Email: dpa@aivius.ai
- Privacy contact: privacy@aivius.ai
- Mailing address: Aivius, Inc., 123 Delaware Ave, Wilmington, DE 19801, United States
- Contact page: aivius.ai/contact
Aivius has not appointed a formal Data Protection Officer (DPO) because we are not required to under GDPR Article 37. Our privacy contact acts as the point of contact for Supervisory Authorities and data subjects under GDPR Article 38 and 39. We review this DPA at least annually and update it to reflect any changes in our subprocessor list, security practices, or applicable law. Customers will be notified of material changes at least 30 days before they take effect.