This Data Processing Agreement ("DPA") is entered into by and between serveyou.ai LLC ("Processor" or "serveyou.ai") and the Platform User ("Controller" or "you") who has agreed to the serveyou.ai Terms of Service. This DPA supplements and is incorporated into the serveyou.ai Terms of Service and Privacy Policy.
This DPA governs the processing of personal data by serveyou.ai LLC on behalf of the Controller in connection with the Controller's use of the serveyou.ai platform and services.
Last updated: April 2, 2026
In this DPA, the following terms have the meanings set forth below. Capitalized terms not defined herein shall have the meanings given to them in the Terms of Service.
Controller determines the purposes and means of processing Personal Data collected through its Deployed Applications, AI agents, and other digital products built on the Platform. Processor processes Personal Data solely on behalf of Controller and in accordance with Controller's documented instructions, the Terms of Service, and this DPA.
The subject matter, duration, nature, purpose, types of Personal Data, and categories of Data Subjects are described in Annex A to this DPA.
Controller shall:
Processor shall:
Processor implements and maintains commercially reasonable technical and organizational security measures designed to protect Personal Data against Security Incidents, including but not limited to: encryption of Personal Data in transit (TLS 1.2 or higher) and at rest; access controls and authentication mechanisms; periodic security assessments and dependency auditing; confidentiality obligations for all personnel authorized to process Personal Data; incident detection and response capabilities; and physical security measures for data center facilities (provided by cloud infrastructure providers).
Processor shall regularly test, assess, and evaluate the effectiveness of its security measures and make improvements as commercially reasonable.
Controller hereby provides general authorization for Processor to engage Sub-processors to process Personal Data on behalf of Controller. Processor's current Sub-processors are listed at the end of this DPA in Annex B.
Processor distinguishes between two categories of Sub-processors:
(a) Infrastructure Sub-processors: These are services that Processor integrates into the core Platform infrastructure and that process Personal Data as part of normal Platform operations (e.g., cloud hosting, payment processing, core telecommunications). Processor maintains a current list of Infrastructure Sub-processors in Annex B of this DPA. If Processor adds or replaces an Infrastructure Sub-processor, Processor shall update Annex B and provide reasonable advance notice to Controller via email or in-app notification. Controller may object to a new Infrastructure Sub-processor by notifying Processor in writing within fifteen (15) days of receiving notice. If Controller objects and Processor cannot reasonably accommodate the objection, either party may terminate the affected Services upon thirty (30) days' notice.
(b) User-Selected Services: The Platform offers a selection of AI models, third-party APIs, and integrations that Controller may choose to enable and use in building its Deployed Applications (e.g., selecting a specific AI model for code generation or connecting a third-party API). When Controller actively selects and enables such a service, Controller's act of selection constitutes Controller's authorization for Processor to engage that service as a Sub-processor for Controller's data. No separate advance notification or objection period is required for User-Selected Services, because Controller is independently choosing to route its data through that service. Processor will maintain an up-to-date list of available User-Selected Services within the Platform interface.
For all Sub-processors (both Infrastructure and User-Selected), Processor shall: (i) ensure that each Sub-processor is subject to data protection obligations under that Sub-processor's standard commercial terms that are consistent with the protections in this DPA; and (ii) remain liable to Controller for the performance of each Sub-processor's obligations to the extent set forth in this DPA and the Terms of Service.
Processor shall notify Controller without undue delay (and in any event within seventy-two (72) hours) after becoming aware of a confirmed Security Incident affecting Personal Data processed on behalf of Controller. Such notification shall include, to the extent reasonably available: the nature of the Security Incident; the categories and approximate number of Data Subjects affected; the likely consequences of the Security Incident; and the measures taken or proposed to address the Security Incident and mitigate its effects.
Processor shall cooperate with Controller in investigating and remediating any Security Incident and shall provide Controller with reasonable assistance in fulfilling its breach notification obligations under Applicable Data Protection Law.
Upon Controller's written request and at Controller's expense, Processor shall make available information reasonably necessary to demonstrate compliance with this DPA. Controller may conduct an audit of Processor's data processing activities, subject to the following conditions: (a) audits shall be conducted no more than once per twelve (12) month period, unless required by a regulatory authority or triggered by a confirmed Security Incident affecting Controller's Personal Data; (b) Controller shall provide at least thirty (30) days' prior written notice; (c) audits shall be conducted during normal business hours and shall not unreasonably disrupt Processor's operations; and (d) Controller shall treat all information obtained during the audit as confidential.
Where Processor has obtained relevant certifications (such as SOC 2 Type II) or has engaged an independent auditor to conduct assessments, Processor may satisfy audit requests by providing copies of such certifications or audit reports.
Personal Data is processed and stored in the United States. The Services are intended for use by United States residents only, as described in the Terms of Service and Privacy Policy.
International Data Processing by Controller's Deployed Applications: Controller acknowledges that its Deployed Applications may be accessed by End-Users located outside the United States, including in jurisdictions subject to the European Union General Data Protection Regulation (GDPR), the UK General Data Protection Regulation (UK GDPR), or other international data protection frameworks. Controller is strictly prohibited from knowingly collecting, processing, or storing personal data subject to the GDPR, UK GDPR, or similar international frameworks through the Platform unless Controller has: (a) independently assessed and ensured its own compliance with all applicable international data protection laws; (b) implemented appropriate safeguards for international data transfers (such as Standard Contractual Clauses) between Controller and its End-Users as required by applicable law; and (c) ensured that Controller's privacy notices and consent mechanisms are adequate for the jurisdictions in which its End-Users are located. serveyou.ai LLC provides infrastructure services within the United States and does not independently comply with GDPR, UK GDPR, or other international data protection frameworks. If Controller's use of the Platform requires processing of data subject to international data protection laws, Controller assumes all associated risks and compliance obligations and shall indemnify serveyou.ai LLC against any claims arising from Controller's failure to comply with such laws. Controller may, at its own initiative and expense, implement geo-blocking or similar access restrictions on its Deployed Applications to limit access to United States residents.
To the extent that Processor processes Personal Data subject to the CCPA on behalf of Controller:
This DPA shall remain in effect for the duration of the Terms of Service. Upon termination of the Terms of Service, Processor shall delete or return Personal Data in accordance with the termination provisions of the Terms of Service and Section 4 of this DPA. Obligations under this DPA that by their nature should survive termination shall survive.
The total aggregate liability of each party under this DPA shall be subject to the limitations of liability set forth in the Terms of Service.
Subject Matter: Processing of Personal Data in connection with Controller's use of the serveyou.ai platform to build, deploy, and operate applications, AI agents, and digital products.
Duration: For the term of the Terms of Service plus any post-termination retention period.
Nature and Purpose: Hosting, storage, retrieval, transmission, and processing of Personal Data as necessary to provide the Platform services, including AI inference, telecommunications, payment processing, and application hosting.
Types of Personal Data: Identifiers (name, email, phone number, IP address); commercial information (transaction data); internet activity (browsing, interaction data); geolocation data; and any other categories of Personal Data that Controller chooses to collect through its Deployed Applications.
Categories of Data Subjects: End-Users of Controller's Deployed Applications; Controller's employees and contractors; and any other individuals whose Personal Data Controller processes through the Platform.
Infrastructure Sub-processors (integrated into core Platform operations):
User-Selected Services (available for Controller selection within the Platform):
Additional User-Selected Services may be made available within the Platform interface from time to time. Controller's selection and enablement of any such service constitutes authorization as described in Section 6(b).
Controller may also connect Third-Party Integrations to the Platform, which act as independent data controllers or processors under their own terms. Third-Party Integrations connected by the Controller are not Sub-processors of serveyou.ai LLC.
For questions regarding this DPA, contact:
Customer Service
customerservice@serveyou.ai