NARA

/dpa · last updated 29 April 2026

Data processing
addendum.

Our standard DPA. If you need a counter-signed version with your company name on it, email [email protected] and we'll send a PDF.

Roles

You (the customer) are the Controller of personal data you process through NARA.

NARA is the Processor — we handle that data only on your documented instructions, which include the configuration choices you make in the admin dashboard.

Each model provider (OpenAI, Anthropic, Google, etc.) is a Sub-processor; PostHog, the payment gateways, and ServerOptima are also Sub-processors. The full list is on the security page and is updated as it changes.

Subject matter + duration

We process the personal data described in the privacy policy for the duration of your subscription, plus a 30-day grace window for data deletion.

Categories of data subjectsyour end users, your team members, contacts you submit to NARA.
Categories of dataidentifiers (email, IDs), authentication artefacts (hashed passwords, tokens), usage records (prompts, generations, credits), device + network metadata (IPs, UAs).

Confidentiality + security

Everyone with access to your data is under a binding NDA and trained on data protection.

Technical + organisational measures are described in the security overview. We map them to ISO 27001 controls; SOC 2 Type II is in flight.

We notify you of a confirmed personal data breach within 72 hours of discovery, with the details required under GDPR Art. 33 to the extent we have them.

International transfers

Data is processed in our primary region (us-east-1) and any additional regions you've enabled. EU-origin data is transferred under Standard Contractual Clauses (Module 2 / Module 3 as appropriate).

If you require a region-locked deployment we offer it on the Business plan (see /services).

Sub-processors

We give you 14 days' notice before adding or replacing a sub-processor. You can object — and if we can't accommodate, you can terminate the affected portion of the service with a prorated refund.

Current sub-processors: Convex, ServerOptima, Cloudflare, PostHog, the payment gateways you've enabled, and the model providers you've enabled.

Assistance

We assist you with data-subject requests (access, rectification, portability, erasure) within 30 days.

We provide records of processing on request for your Art. 30 register.

On termination we delete or return all customer personal data within 30 days, unless retention is required by law.

Audits

You can review our latest pen-test summary and SOC 2 evidence pack on request, under NDA.

On the Business plan, an annual on-site audit is included; otherwise audits are by mutual agreement.

Questions · [email protected]