Data Processing Agreement (DPA)

Effective Date: April 15, 2026  |  Last Updated: April 15, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service or Master Service Agreement ("Agreement") between:

Data Processor: Smalt AI PLT ("Processor", "we", "us")
Data Controller: The customer entity that has agreed to the Terms of Service ("Controller", "you")

This DPA sets out the terms under which the Processor processes personal data on behalf of the Controller in connection with the Smalt AI platform (the "Service").

1. Definitions

2. Scope and Purpose of Processing

DetailDescription
Subject Matter Provision of the Smalt AI platform, including AI-powered financial modelling, document generation, research, and productivity services.
Duration For the term of the Agreement, plus any post-termination data retention period.
Nature and Purpose Processing Customer inputs through AI models to generate outputs; storing conversation history; managing user accounts; providing customer support.
Types of Personal Data Name, email address, IP address, company information, job title, usage data, and any personal data included in content submitted to the Service by the Controller.
Categories of Data Subjects Controller's employees, contractors, and authorised users of the Service.

3. Controller Obligations

The Controller shall:

  1. Ensure it has a lawful basis for providing Personal Data to the Processor.
  2. Provide clear instructions to the Processor regarding the processing of Personal Data.
  3. Ensure that data subjects have been informed about the processing in accordance with Data Protection Laws.
  4. Be responsible for the accuracy, quality, and legality of Personal Data provided to the Processor.

4. Processor Obligations

The Processor shall:

  1. Process Personal Data only on documented instructions from the Controller, unless required by law.
  2. Ensure that persons authorised to process Personal Data have committed themselves to confidentiality.
  3. Implement appropriate technical and organisational security measures (see Section 6).
  4. Not engage another processor (sub-processor) without prior specific or general written authorisation of the Controller (see Section 7).
  5. Assist the Controller in responding to data subject rights requests.
  6. Assist the Controller in ensuring compliance with obligations related to security, breach notification, data protection impact assessments, and prior consultation.
  7. At the Controller's choice, delete or return all Personal Data after the end of the provision of services, and delete existing copies unless retention is required by law.
  8. Make available to the Controller all information necessary to demonstrate compliance with this DPA.
  9. Not use Personal Data for any purpose other than providing the Service, including not using Personal Data to train AI models.

5. Data Subject Rights

The Processor shall:

6. Security Measures

The Processor shall implement and maintain appropriate technical and organisational measures, including:

Technical Measures

Organisational Measures

7. Sub-processors

7.1 Authorised Sub-processors

The Controller provides general written authorisation for the Processor to engage the sub-processors listed below. An up-to-date list is maintained on our website.

Sub-processorPurposeLocation
Amazon Web Services (AWS)Cloud infrastructure and hostingUnited States / EU
AnthropicAI model provider (Claude)United States
Google (Gemini)AI model providerUnited States
StripePayment processingUnited States
Amazon SESTransactional email deliveryUnited States
ResendEmail deliveryUnited States

7.2 Changes to Sub-processors

8. Data Breach Notification

  1. The Processor shall notify the Controller without undue delay (and in any event within 48 hours) after becoming aware of a Data Breach affecting the Controller's Personal Data.
  2. The notification shall include:
  3. The Processor shall cooperate with the Controller and take reasonable steps to assist in the investigation, mitigation, and remediation of the Data Breach.

9. International Data Transfers

10. Audits

11. Data Retention and Deletion

12. Liability

Each party's liability under this DPA is subject to the limitations of liability set out in the Agreement.

13. Term and Termination

This DPA shall remain in effect for as long as the Processor processes Personal Data on behalf of the Controller. It shall automatically terminate when the Agreement terminates and all Personal Data has been deleted or returned.

14. Contact

Smalt AI PLT - Data Protection
Email: support@smaltai.com

By using the Service, the Controller acknowledges and agrees to this Data Processing Agreement.