aitonomy← Back to legal

Data Processing Agreement

Effective 6 July 2026  ·  Version 1.0


This is the Data Processing Agreement (the “DPA”) for the Aitonomy platform, between Baby Elephant B.V., a private limited company having its registered office at Emmastraat 23, 2282 AM Rijswijk, The Netherlands, registered with the Dutch Chamber of Commerce under number 27299029, trading under the name Aitonomy and in this DPA referred to as “Aitonomy”, and the Customer.

This DPA forms an integral part of the SaaS Terms and Conditions for the Aitonomy platform (the “Terms”) and of the Agreement. Terms written with a capital that are not defined in this DPA have the meaning given in the Terms.

1. Definitions

1.1In this DPA the following terms have the following meaning, and terms written with a capital that are not defined here have the meaning given in the Terms:

1.1.1Controller: the party that determines the purposes and means of the processing of Personal Data.

1.1.2Processor: the party that processes Personal Data on behalf of the Controller.

1.1.3Data Subject: an identified or identifiable natural person to whom Personal Data relates.

1.1.4Personal Data Breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.

1.1.5Sub-processor: a third party engaged by Aitonomy to process Personal Data in connection with the Service.

1.1.6Supervisory Authority: the competent data protection supervisory authority, which in the Netherlands is the Autoriteit Persoonsgegevens.

2. Roles and scope

2.1The Service enables the Customer to govern, run and measure Agents across its operations. The Service does not require Personal Data to function. However, the Customer Data that the Customer connects to or makes available to the Service — such as documents, records, tickets, code and prompts drawn from the systems the Customer connects — together with the account data of the Customer’s Users, may contain Personal Data.

2.2To the extent Aitonomy processes Personal Data in connection with the Service, Aitonomy acts as Processor and the Customer as Controller within the meaning of the GDPR. The Customer determines the purposes and means of the processing.

2.3Where the Order Form specifies a hosted deployment, Aitonomy processes Personal Data on the Customer’s behalf within the Service. Where the Order Form specifies an in-client deployment, Customer Data remains within the Customer Environment, and Aitonomy’s processing is limited to what is reasonably necessary for configuration, Support and any Service Metrics export agreed in the Order Form.

2.4This DPA forms an integral part of the Agreement, and the liability arrangements in the Terms apply to it. In the event of a conflict between this DPA and the Terms in respect of the processing of Personal Data, this DPA prevails.

3. Processing of Personal Data

3.1Aitonomy processes Personal Data only to provide and support the Service and on the documented instructions of the Customer. The Agreement, the Order Form, and the Customer’s configuration and use of the Service constitute the Customer’s documented instructions. Aitonomy will inform the Customer if, in its opinion, an instruction infringes the GDPR or other data protection law, unless prohibited from doing so by law.

3.2The subject matter of the processing is the provision of the Service. The nature and purpose of the processing is the governance, execution, review and measurement of Agents and the related operation of the Service. The processing continues for the duration of the Agreement.

3.3The types of Personal Data processed are determined by the Customer and may include the names, business contact details and role of the Customer’s Users, and any Personal Data incidentally contained in Customer Data that the Customer chooses to make available to the Service.

3.4The categories of Data Subjects are determined by the Customer and may include the Customer’s Users and employees, and any individuals whose Personal Data is incidentally contained in Customer Data.

3.5The Service is not intended for the processing of special categories of personal data or of personal data relating to criminal convictions and offences. The Customer is responsible for not making such data available to the Service.

4. Confidentiality and security

4.1Aitonomy ensures that the persons authorised to process Personal Data under its responsibility are bound by an appropriate duty of confidentiality.

4.2Aitonomy implements and maintains the technical and organisational measures set out in Schedule 1 to protect Personal Data against loss and against unlawful processing, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of the processing, and the risks to Data Subjects.

4.3The Customer may request Aitonomy to implement additional security measures. Aitonomy may charge the reasonable costs of implementing measures requested by the Customer. Aitonomy does not guarantee that the security measures are effective in all circumstances.

5. Sub-processors

5.1The Customer grants Aitonomy general authorisation to engage Sub-processors for the processing of Personal Data. A current list of Sub-processors is available at joinaitonomy.ai/legal/sub-processors.

5.2Aitonomy imposes on each Sub-processor, by contract, data protection obligations that are in substance the same as those set out in this DPA. Aitonomy remains responsible to the Customer for the performance of each Sub-processor’s obligations.

5.3Aitonomy will inform the Customer of any intended addition or replacement of a Sub-processor through its website or otherwise in writing. The Customer may object on reasonable data protection grounds within five (5) Business Days of the notice, in which case the parties will discuss a solution in good faith, failing which the Customer may terminate the affected part of the Service.

5.4Where Aitonomy engages a third party provider of AI models to process Customer Data through the Service, Aitonomy engages that provider under terms that prohibit the use of Customer Data and Personal Data to train the provider’s models. Aitonomy does not use Personal Data to train AI models.

6. International transfers

6.1Aitonomy processes Personal Data within the European Economic Area.

6.2Aitonomy will not transfer Personal Data to a country outside the European Economic Area unless a valid transfer mechanism under the GDPR is in place, such as an adequacy decision or the European Commission’s standard contractual clauses.

6.3Where Aitonomy uses third party AI models to process Customer Data, including frontier models, it provides these through infrastructure located within the European Economic Area, so that the processing takes place within the European Economic Area. Where such a provider is subject to the law of a country outside the European Economic Area, Aitonomy puts in place appropriate safeguards, such as the European Commission’s standard contractual clauses.

7. Assistance, data subject requests and Personal Data Breaches

7.1Taking into account the nature of the processing and the information available to it, Aitonomy provides reasonable assistance to the Customer in meeting its obligations to respond to requests from Data Subjects, to implement appropriate security measures, to notify and handle Personal Data Breaches, and to carry out data protection impact assessments and any prior consultation with a Supervisory Authority. Aitonomy may charge its reasonable costs for such assistance.

7.2If Aitonomy receives a request from a Data Subject relating to Personal Data processed under this DPA, it will, where legally permitted, forward the request to the Customer without undue delay and will not respond to the request itself except on the Customer’s instruction.

7.3Aitonomy notifies the Customer without undue delay after becoming aware of a Personal Data Breach affecting the Customer’s Personal Data, and provides the information reasonably available to it to enable the Customer to meet its obligations under the GDPR.

7.4The Customer remains responsible for notifying the relevant Supervisory Authority and, where required, the affected Data Subjects.

8. Audit

8.1Aitonomy makes available to the Customer the information reasonably necessary to demonstrate compliance with this DPA, for example by means of a certificate, an audit report, or a third party report.

8.2If the Customer has substantiated grounds to believe that Personal Data is not being processed in accordance with this DPA, the Customer may, at most once per calendar year and on at least two weeks prior notice, have an audit carried out at its own cost by an independent auditor bound by confidentiality, in order to verify Aitonomy’s compliance. The audit will be conducted so as to cause the least possible disruption to Aitonomy’s operations.

8.3The parties will discuss the findings of an audit, and Aitonomy will implement reasonable improvement measures, taking into account the risks, the state of the art, and the costs of implementation.

9. Return and deletion

9.1On termination of the Service, Aitonomy returns or, at the Customer’s choice, deletes the Personal Data it processes on the Customer’s behalf, within a reasonable period and in such a way that it can no longer be used, unless storage is required by law. For in-client deployments, Personal Data remains within the Customer Environment.

9.2Personal Data contained in routine backups is deleted in accordance with Aitonomy’s backup cycle, and remains subject to the confidentiality and security obligations of this DPA until deleted.

10. General

10.1This DPA is governed by the laws of the Netherlands. Any dispute arising from or in connection with it is submitted exclusively to the competent court of The Hague (Rechtbank Den Haag), the Netherlands.

10.2If any provision of this DPA is invalid or unenforceable, the remaining provisions remain in force, and the invalid provision is replaced by a valid provision that reflects the original intention as closely as possible.

Schedule 1: Technical and Organisational Measures

Aitonomy implements the following technical and organisational measures. These measures apply to the hosted Service. For in-client deployments the Customer controls the environment in which the Service runs, and these measures apply to Aitonomy’s access and tooling.

Hosting and data residency. The Service is hosted on cloud infrastructure located within the European Economic Area.

Access control. Access to Personal Data is restricted to authorised personnel on a least privilege, role-based basis, requires individual authentication and multi-factor authentication, and is reviewed and revoked when no longer needed.

Encryption. Personal Data is encrypted in transit using current transport encryption and is encrypted at rest. Where the deployment supports it, Customer Data is encrypted using keys managed by the Customer.

Separation. Customer instances are logically separated so that one customer cannot access another customer’s data.

Logging and monitoring. Access to and processing of Personal Data is logged, and systems are monitored for security events.

Secure development. Changes to the Service follow secure development practices, including code review and dependency and vulnerability scanning.

Backup and recovery. Data is backed up, and the ability to restore the availability of and access to Personal Data after an incident is maintained and tested.

Vulnerability management. Systems are patched, and the security of the Service is tested periodically, including through vulnerability assessment and penetration testing.

Incident response. Aitonomy maintains a process to detect, respond to and report security incidents and Personal Data Breaches.

Personnel. Personnel with access to Personal Data are bound by confidentiality and receive appropriate security awareness training.

Sub-processor management. Sub-processors are engaged under contractual data protection obligations and are reviewed.

Baby Elephant B.V., trading as Aitonomy  ·  Emmastraat 23, 2282 AM Rijswijk, The Netherlands  ·  KvK 27299029 Version 1.0  ·  6 July 2026