ServeYou Logo

Data Processing Agreement

serveyou.ai LLC Data Processing Agreement

This Data Processing Agreement ("DPA") is entered into by and between serveyou.ai LLC ("Processor" or "serveyou.ai") and the Platform User ("Controller" or "you") who has agreed to the serveyou.ai Terms of Service. This DPA supplements and is incorporated into the serveyou.ai Terms of Service and Privacy Policy.

This DPA governs the processing of personal data by serveyou.ai LLC on behalf of the Controller in connection with the Controller's use of the serveyou.ai platform and services.

Last updated: April 2, 2026

1. Definitions

In this DPA, the following terms have the meanings set forth below. Capitalized terms not defined herein shall have the meanings given to them in the Terms of Service.

  • "Personal Data" means any information relating to an identified or identifiable natural person that is processed by Processor on behalf of Controller in connection with the Services.
  • "Processing" means any operation or set of operations performed on Personal Data, including collection, recording, organization, storage, adaptation, alteration, retrieval, consultation, use, disclosure, dissemination, erasure, or destruction.
  • "Data Subject" means the identified or identifiable natural person to whom Personal Data relates, including End-Users of Controller's Deployed Applications.
  • "Sub-processor" means any third party engaged by Processor to process Personal Data on behalf of Controller.
  • "Security Incident" means any accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored, or otherwise processed by Processor.
  • "Applicable Data Protection Law" means all laws and regulations applicable to the processing of Personal Data under this DPA, including the California Consumer Privacy Act (CCPA/CPRA), the Children's Online Privacy Protection Act (COPPA), and any applicable federal and state privacy laws.

2. Scope and Roles

Controller determines the purposes and means of processing Personal Data collected through its Deployed Applications, AI agents, and other digital products built on the Platform. Processor processes Personal Data solely on behalf of Controller and in accordance with Controller's documented instructions, the Terms of Service, and this DPA.

The subject matter, duration, nature, purpose, types of Personal Data, and categories of Data Subjects are described in Annex A to this DPA.

3. Controller Obligations

Controller shall:

  • Ensure that it has a lawful basis for collecting and processing Personal Data through its Deployed Applications, including obtaining all required consents from Data Subjects;
  • Provide all required privacy notices to Data Subjects;
  • Ensure that its instructions to Processor comply with Applicable Data Protection Law;
  • Respond to Data Subject requests (access, deletion, correction, portability) in a timely manner;
  • Conduct data protection impact assessments where required by Applicable Data Protection Law;
  • Notify Processor promptly of any Data Subject requests that require Processor's assistance;
  • Maintain its own records of processing activities as required by Applicable Data Protection Law; and
  • Represent and warrant that it will not use the Platform to knowingly collect personal information from children under 13 without verifiable parental consent as required by COPPA and applicable state laws.

4. Processor Obligations

Processor shall:

  • Process Personal Data only on documented instructions from Controller, unless required by law to do otherwise, in which case Processor shall inform Controller of such legal requirement before processing (unless prohibited by law);
  • Ensure that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
  • Implement and maintain commercially reasonable technical and organizational security measures appropriate to the risk, including encryption in transit and at rest, access controls, monitoring, and regular security testing;
  • Not engage a Sub-processor without Controller's prior authorization (see Section 6 below);
  • Assist Controller in responding to Data Subject requests, to the extent commercially reasonable and at Controller's expense;
  • Assist Controller in ensuring compliance with security, breach notification, and impact assessment obligations under Applicable Data Protection Law, taking into account the nature of processing and the information available to Processor;
  • At Controller's choice, delete or return all Personal Data to Controller after the end of the provision of Services, and delete existing copies unless applicable law requires retention. Controller's User Content and Personal Data may be exported through the Platform's self-service export features and such other mechanisms as Processor may make available; additional Personal Data held by Processor may be requested by contacting customerservice@serveyou.ai. Processor's Platform IP (as defined in the Terms of Service) is Processor's confidential information and is not subject to data return obligations. Security logs, access logs, and usage records that do not contain substantive Personal Data content may be retained for up to twelve (12) months following termination for security, fraud prevention, and legal compliance purposes; and
  • Make available to Controller information reasonably necessary to demonstrate compliance with this DPA.

5. Security Measures

Processor implements and maintains commercially reasonable technical and organizational security measures designed to protect Personal Data against Security Incidents, including but not limited to: encryption of Personal Data in transit (TLS 1.2 or higher) and at rest; access controls and authentication mechanisms; periodic security assessments and dependency auditing; confidentiality obligations for all personnel authorized to process Personal Data; incident detection and response capabilities; and physical security measures for data center facilities (provided by cloud infrastructure providers).

Processor shall regularly test, assess, and evaluate the effectiveness of its security measures and make improvements as commercially reasonable.

6. Sub-processors

Controller hereby provides general authorization for Processor to engage Sub-processors to process Personal Data on behalf of Controller. Processor's current Sub-processors are listed at the end of this DPA in Annex B.

Processor distinguishes between two categories of Sub-processors:

(a) Infrastructure Sub-processors: These are services that Processor integrates into the core Platform infrastructure and that process Personal Data as part of normal Platform operations (e.g., cloud hosting, payment processing, core telecommunications). Processor maintains a current list of Infrastructure Sub-processors in Annex B of this DPA. If Processor adds or replaces an Infrastructure Sub-processor, Processor shall update Annex B and provide reasonable advance notice to Controller via email or in-app notification. Controller may object to a new Infrastructure Sub-processor by notifying Processor in writing within fifteen (15) days of receiving notice. If Controller objects and Processor cannot reasonably accommodate the objection, either party may terminate the affected Services upon thirty (30) days' notice.

(b) User-Selected Services: The Platform offers a selection of AI models, third-party APIs, and integrations that Controller may choose to enable and use in building its Deployed Applications (e.g., selecting a specific AI model for code generation or connecting a third-party API). When Controller actively selects and enables such a service, Controller's act of selection constitutes Controller's authorization for Processor to engage that service as a Sub-processor for Controller's data. No separate advance notification or objection period is required for User-Selected Services, because Controller is independently choosing to route its data through that service. Processor will maintain an up-to-date list of available User-Selected Services within the Platform interface.

For all Sub-processors (both Infrastructure and User-Selected), Processor shall: (i) ensure that each Sub-processor is subject to data protection obligations under that Sub-processor's standard commercial terms that are consistent with the protections in this DPA; and (ii) remain liable to Controller for the performance of each Sub-processor's obligations to the extent set forth in this DPA and the Terms of Service.

7. Security Incident Notification

Processor shall notify Controller without undue delay (and in any event within seventy-two (72) hours) after becoming aware of a confirmed Security Incident affecting Personal Data processed on behalf of Controller. Such notification shall include, to the extent reasonably available: the nature of the Security Incident; the categories and approximate number of Data Subjects affected; the likely consequences of the Security Incident; and the measures taken or proposed to address the Security Incident and mitigate its effects.

Processor shall cooperate with Controller in investigating and remediating any Security Incident and shall provide Controller with reasonable assistance in fulfilling its breach notification obligations under Applicable Data Protection Law.

8. Audits

Upon Controller's written request and at Controller's expense, Processor shall make available information reasonably necessary to demonstrate compliance with this DPA. Controller may conduct an audit of Processor's data processing activities, subject to the following conditions: (a) audits shall be conducted no more than once per twelve (12) month period, unless required by a regulatory authority or triggered by a confirmed Security Incident affecting Controller's Personal Data; (b) Controller shall provide at least thirty (30) days' prior written notice; (c) audits shall be conducted during normal business hours and shall not unreasonably disrupt Processor's operations; and (d) Controller shall treat all information obtained during the audit as confidential.

Where Processor has obtained relevant certifications (such as SOC 2 Type II) or has engaged an independent auditor to conduct assessments, Processor may satisfy audit requests by providing copies of such certifications or audit reports.

9. Data Transfers

Personal Data is processed and stored in the United States. The Services are intended for use by United States residents only, as described in the Terms of Service and Privacy Policy.

International Data Processing by Controller's Deployed Applications: Controller acknowledges that its Deployed Applications may be accessed by End-Users located outside the United States, including in jurisdictions subject to the European Union General Data Protection Regulation (GDPR), the UK General Data Protection Regulation (UK GDPR), or other international data protection frameworks. Controller is strictly prohibited from knowingly collecting, processing, or storing personal data subject to the GDPR, UK GDPR, or similar international frameworks through the Platform unless Controller has: (a) independently assessed and ensured its own compliance with all applicable international data protection laws; (b) implemented appropriate safeguards for international data transfers (such as Standard Contractual Clauses) between Controller and its End-Users as required by applicable law; and (c) ensured that Controller's privacy notices and consent mechanisms are adequate for the jurisdictions in which its End-Users are located. serveyou.ai LLC provides infrastructure services within the United States and does not independently comply with GDPR, UK GDPR, or other international data protection frameworks. If Controller's use of the Platform requires processing of data subject to international data protection laws, Controller assumes all associated risks and compliance obligations and shall indemnify serveyou.ai LLC against any claims arising from Controller's failure to comply with such laws. Controller may, at its own initiative and expense, implement geo-blocking or similar access restrictions on its Deployed Applications to limit access to United States residents.

10. CCPA-Specific Terms

To the extent that Processor processes Personal Data subject to the CCPA on behalf of Controller:

  • Processor is a "service provider" as defined in the CCPA and processes Personal Data on behalf of Controller for the "business purposes" described in the Terms of Service and this DPA;
  • Processor shall not sell or share Personal Data, as those terms are defined by the CCPA;
  • Processor shall not retain, use, or disclose Personal Data for any purpose other than providing the Services as specified in the Terms of Service and this DPA, or as otherwise permitted by the CCPA;
  • Processor shall not combine Personal Data received from Controller with personal information received from other sources or collected from Processor's own interactions with Data Subjects, except as permitted by the CCPA; and
  • Processor certifies that it understands and will comply with the restrictions set forth in this Section.

11. Term and Termination

This DPA shall remain in effect for the duration of the Terms of Service. Upon termination of the Terms of Service, Processor shall delete or return Personal Data in accordance with the termination provisions of the Terms of Service and Section 4 of this DPA. Obligations under this DPA that by their nature should survive termination shall survive.

12. Limitation of Liability

The total aggregate liability of each party under this DPA shall be subject to the limitations of liability set forth in the Terms of Service.

Annex A: Details of Processing

Subject Matter: Processing of Personal Data in connection with Controller's use of the serveyou.ai platform to build, deploy, and operate applications, AI agents, and digital products.

Duration: For the term of the Terms of Service plus any post-termination retention period.

Nature and Purpose: Hosting, storage, retrieval, transmission, and processing of Personal Data as necessary to provide the Platform services, including AI inference, telecommunications, payment processing, and application hosting.

Types of Personal Data: Identifiers (name, email, phone number, IP address); commercial information (transaction data); internet activity (browsing, interaction data); geolocation data; and any other categories of Personal Data that Controller chooses to collect through its Deployed Applications.

Categories of Data Subjects: End-Users of Controller's Deployed Applications; Controller's employees and contractors; and any other individuals whose Personal Data Controller processes through the Platform.

Annex B: Sub-processors

Infrastructure Sub-processors (integrated into core Platform operations):

  • Stripe — Payment processing; United States
  • Twilio — Telecommunications (SMS, voice); United States

User-Selected Services (available for Controller selection within the Platform):

  • xAI — AI model inference; United States
  • Anthropic — AI model inference; United States
  • Google (Gemini) — AI model inference; United States

Additional User-Selected Services may be made available within the Platform interface from time to time. Controller's selection and enablement of any such service constitutes authorization as described in Section 6(b).

Controller may also connect Third-Party Integrations to the Platform, which act as independent data controllers or processors under their own terms. Third-Party Integrations connected by the Controller are not Sub-processors of serveyou.ai LLC.

Contact

For questions regarding this DPA, contact:

Customer Service
customerservice@serveyou.ai