aitonomy← Back to legal

Data Processing Agreement

Effective 3 September 2026 · Version 1.1

This is the Data Processing Agreement (the “DPA”) for the Aitonomy platform and for Aitonomy’s services, between Baby Elephant B.V., a private limited company having its registered office at Emmastraat 23, 2282 AM Rijswijk, The Netherlands, registered with the Dutch Chamber of Commerce under number 27299029, trading under the name Aitonomy and in this DPA referred to as “Aitonomy”, and the Customer.

This DPA forms an integral part of the SaaS Terms and Conditions, of the Services Terms and Conditions, or of both, whichever apply to the Agreement, and of the Agreement itself. Words written with a capital that are not defined in this DPA have the meaning given in the applicable Terms.

1. Definitions

1.1 In this DPA the following terms have the following meaning, and words written with a capital that are not defined here have the meaning given in the Terms. Where a word is defined in only one of the Terms, that definition applies:

1.1.1 Controller: the party that determines the purposes and means of the processing of Personal Data.

1.1.2 Processor: the party that processes Personal Data on behalf of the Controller.

1.1.3 Data Subject: an identified or identifiable natural person to whom Personal Data relates.

1.1.4 Personal Data Breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.

1.1.5 Sub-processor: a third party engaged by Aitonomy to process Personal Data in connection with the Services.

1.1.6 Supervisory Authority: the competent data protection supervisory authority, which in the Netherlands is the Autoriteit Persoonsgegevens.

1.1.7 Services: the Aitonomy service (agents as a service) as defined in the SaaS Terms and Conditions, the advisory, assessment, design and implementation services as defined in the Services Terms and Conditions, or both, as applicable to the Agreement.

1.1.8 Terms: the SaaS Terms and Conditions, the Services Terms and Conditions, or both, whichever apply to the Agreement.

2. Roles and scope

2.1 This DPA applies to the processing of Personal Data by Aitonomy on the Customer’s behalf under the Agreement, whether that Agreement concerns the platform, the services, or both. Neither requires Personal Data to function. However, the Customer Data and Customer Materials that the Customer connects to or makes available (documents, records, tickets, code, prompts, and the process and system documentation drawn from the systems the Customer connects), together with the account data of the Customer’s Users, may contain Personal Data.

2.2 To the extent Aitonomy processes Personal Data in connection with the Services, Aitonomy acts as Processor and the Customer as Controller within the meaning of the GDPR. The Customer determines the purposes and means of the processing.

2.3 Where the Agreement includes the platform and the Order Form specifies a hosted deployment, Aitonomy processes Personal Data on the Customer’s behalf within the platform. Where the Order Form specifies an in-client deployment, Customer Data remains within the Customer Environment, and Aitonomy’s processing is limited to what is reasonably necessary for configuration, Support and any Service Metrics export agreed in the Order Form. Where the Agreement concerns services only, there is no platform deployment, and Aitonomy’s processing is limited to what is reasonably necessary to perform the Assignment described in the Order Form.

2.4 This DPA forms an integral part of the Agreement, and the liability arrangements in the Terms apply to it. In the event of a conflict between this DPA and the Terms in respect of the processing of Personal Data, this DPA prevails.

2.5 This DPA does not cover processing for which Aitonomy is an independent controller, including the Personal Data of the Customer’s personnel and other participants that Aitonomy records in the course of an Assignment, such as contact details, meeting notes, recordings and transcripts. That processing is described in clause 8.8 of the Services Terms and Conditions.

3. Processing of Personal Data

3.1 Aitonomy processes Personal Data only to provide and support the Services and on the documented instructions of the Customer. The Agreement, the Order Form, and the Customer’s configuration and use of the Services constitute the Customer’s documented instructions. Aitonomy will inform the Customer if, in its opinion, an instruction infringes the GDPR or other data protection law, unless prohibited from doing so by law.

3.2 The subject matter of the processing is the provision of the Services. The nature and purpose of the processing is the governance, execution, review and measurement of Agents and the related operation of the platform and, where the Agreement includes services, the assessment, design and implementation work described in the Order Form. The processing continues for the duration of the Agreement.

3.3 The types of Personal Data processed are determined by the Customer and may include the names, business contact details and role of the Customer’s Users, and any Personal Data incidentally contained in Customer Data or Customer Materials that the Customer chooses to make available to the Services.

3.4 The categories of Data Subjects are determined by the Customer and may include the Customer’s Users and employees, and any individuals whose Personal Data is incidentally contained in Customer Data.

3.5 Special categories of personal data within the meaning of Article 9 of the GDPR, and personal data relating to criminal convictions and offences within the meaning of Article 10 of the GDPR, are processed only where the Order Form, or an annex to it, expressly provides for that processing. Absent such a provision, the Customer will not make such data available to the Services.

3.6 Where the Order Form provides for the processing of such data, the parties record in it, for each process concerned: the categories of data involved, the purpose, the legal basis on which the Customer relies, the retention period, and the additional safeguards that apply. Those safeguards include in any event that the processing takes place within the European Economic Area, that only the fields required for the relevant processing step are transferred, that access is restricted to named personnel, and that the data are not used to train AI models.

3.7 In a Scan as defined in the Services Terms and Conditions, no such data are processed. Where they are relevant to a process under assessment, they are described as a data flow only.

4. Confidentiality and security

4.1 Aitonomy ensures that the persons authorised to process Personal Data under its responsibility are bound by an appropriate duty of confidentiality.

4.2 Aitonomy implements and maintains the technical and organisational measures set out in Schedule 1 to protect Personal Data against loss and against unlawful processing, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of the processing, and the risks to Data Subjects.

4.3 The Customer may request Aitonomy to implement additional security measures. Aitonomy may charge the reasonable costs of implementing measures requested by the Customer. Aitonomy does not guarantee that the security measures are effective in all circumstances.

5. Sub-processors

5.1 The Customer grants Aitonomy general authorisation to engage Sub-processors for the processing of Personal Data. A current list of Sub-processors is available at joinaitonomy.ai/legal/sub-processors.

5.2 Aitonomy imposes on each Sub-processor, by contract, data protection obligations that are in substance the same as those set out in this DPA. Aitonomy remains responsible to the Customer for the performance of each Sub-processor’s obligations.

5.3 Aitonomy will inform the Customer of any intended addition or replacement of a Sub-processor through its website or otherwise in writing. The Customer may object on reasonable data protection grounds within five (5) Business Days of the notice, in which case the parties will discuss a solution in good faith, failing which the Customer may terminate the affected part of the Services.

5.4 Where Aitonomy engages a third party provider of AI models to process Customer Data or Customer Materials through the Services, Aitonomy engages that provider under terms that prohibit the use of Customer Data and Personal Data to train the provider’s models. Aitonomy does not use Personal Data to train AI models.

6. International transfers

6.1 Aitonomy processes Personal Data within the European Economic Area.

6.2 Aitonomy will not transfer Personal Data to a country outside the European Economic Area unless a valid transfer mechanism under the GDPR is in place, such as an adequacy decision or the European Commission’s standard contractual clauses.

6.3 Where Aitonomy uses third party AI models to process Customer Data, including frontier models, it provides these through infrastructure located within the European Economic Area, so that the processing takes place within the European Economic Area. Where such a provider is subject to the law of a country outside the European Economic Area, Aitonomy puts in place appropriate safeguards, such as the European Commission’s standard contractual clauses.

7. Assistance, data subject requests and Personal Data Breaches

7.1 Taking into account the nature of the processing and the information available to it, Aitonomy provides reasonable assistance to the Customer in meeting its obligations to respond to requests from Data Subjects, to implement appropriate security measures, to notify and handle Personal Data Breaches, and to carry out data protection impact assessments and any prior consultation with a Supervisory Authority. Aitonomy may charge its reasonable costs for such assistance.

7.2 If Aitonomy receives a request from a Data Subject relating to Personal Data processed under this DPA, it will, where legally permitted, forward the request to the Customer without undue delay and will not respond to the request itself except on the Customer’s instruction.

7.3 Aitonomy notifies the Customer without undue delay after becoming aware of a Personal Data Breach affecting the Customer’s Personal Data, and provides the information reasonably available to it to enable the Customer to meet its obligations under the GDPR.

7.4 The Customer remains responsible for notifying the relevant Supervisory Authority and, where required, the affected Data Subjects.

8. Audit

8.1 Aitonomy makes available to the Customer the information reasonably necessary to demonstrate compliance with this DPA, including documentation of the technical and organisational measures set out in Schedule 1 and, where Aitonomy holds one, a certificate, an audit report or a third party report.

8.2 If the Customer has substantiated grounds to believe that Personal Data is not being processed in accordance with this DPA, the Customer may, at most once per calendar year and on at least two weeks prior notice, have an audit carried out at its own cost by an independent auditor bound by confidentiality, in order to verify Aitonomy’s compliance. The audit will be conducted so as to cause the least possible disruption to Aitonomy’s operations.

8.3 The parties will discuss the findings of an audit, and Aitonomy will implement reasonable improvement measures, taking into account the risks, the state of the art, and the costs of implementation.

9. Return and deletion

9.1 On termination of the Agreement, Aitonomy returns or, at the Customer’s choice, deletes the Personal Data it processes on the Customer’s behalf, within a reasonable period and in such a way that it can no longer be used, unless storage is required by law. For in-client deployments, Personal Data remains within the Customer Environment.

9.2 Personal Data contained in routine backups is deleted in accordance with Aitonomy’s backup cycle, and remains subject to the confidentiality and security obligations of this DPA until deleted.

10. General

10.1 This DPA is governed by the laws of the Netherlands. Any dispute arising from or in connection with it is submitted exclusively to the competent court of The Hague (Rechtbank Den Haag), the Netherlands.

10.2 If any provision of this DPA is invalid or unenforceable, the remaining provisions remain in force, and the invalid provision is replaced by a valid provision that reflects the original intention as closely as possible.

Schedule 1: Technical and Organisational Measures

Aitonomy implements the following technical and organisational measures. Where the Agreement includes the platform, they apply to the hosted platform; for in-client deployments the Customer controls the environment in which it runs, and they apply to Aitonomy’s access and tooling. Where the Agreement concerns services, they apply to Aitonomy’s access to and handling of Customer Materials and Deliverables.

Hosting and data residency. The platform is hosted on cloud infrastructure located within the European Economic Area, and Customer Materials and Deliverables are stored within the European Economic Area.

Access control. Access to Personal Data is restricted to authorised personnel on a least privilege, role-based basis, requires individual authentication and multi-factor authentication, and is reviewed and revoked when no longer needed.

Encryption. Personal Data is encrypted in transit using current transport encryption and is encrypted at rest. Where the deployment supports it, Customer Data is encrypted using keys managed by the Customer.

Separation. Customer instances are logically separated so that one customer cannot access another customer’s data.

Logging and monitoring. Access to and processing of Personal Data is logged, and systems are monitored for security events.

Secure development. Changes to the platform follow secure development practices, including code review and dependency and vulnerability scanning.

Backup and recovery. Data is backed up, and the ability to restore the availability of and access to Personal Data after an incident is maintained and tested.

Vulnerability management. Systems are patched, and the security of the platform is tested periodically, including through vulnerability assessment and penetration testing.

Incident response. Aitonomy maintains a process to detect, respond to and report security incidents and Personal Data Breaches.

Personnel. Personnel with access to Personal Data are bound by confidentiality and receive appropriate security awareness training.

Sub-processor management. Sub-processors are engaged under contractual data protection obligations and are reviewed.


Baby Elephant B.V., trading as Aitonomy · Emmastraat 23, 2282 AM Rijswijk, The Netherlands · KvK 27299029

Version 1.1 · 3 September 2026

Baby Elephant B.V., trading as Aitonomy  ·  Emmastraat 23, 2282 AM Rijswijk, The Netherlands  ·  KvK 27299029 Version 1.1  ·  [DATE]