Data Processing Addendum
The terms on which DashAPI processes personal data on a customer's behalf.
Effective: August 1, 2026 | Last updated: August 1, 2026
support@dashapi.ai1. Application and acceptance
This Data Processing Addendum (DPA) forms part of theDashAPI Terms of Service or other written agreement (the Agreement) between DashAPI, Inc. (DashAPI,we) and the customer (Customer, you).
It applies where we process Personal Data on your behalf and Data Protection Laws apply to that processing. By using the Service you accept this DPA; no signature is required. If your procurement process requires a countersigned copy, email support@dashapi.ai.
It applies to the DashAPI platform and to LinkMe where LinkMe is used under an organisation account.
2. Definitions
- Data Protection Laws — all laws on privacy and the processing of personal data that apply to a party, including the EU GDPR, the UK GDPR and Data Protection Act 2018, the Swiss FADP, and US state privacy laws.
- Customer Personal Data — personal data contained in Your Data that we process on your behalf under the Agreement.
- Data Subject, controller, processor, processing, personal data breach — as defined in the GDPR, or the closest equivalent under the applicable law.
- SCCs — the Standard Contractual Clauses annexed to European Commission Implementing Decision (EU) 2021/914.
- UK Addendum — the UK Information Commissioner's International Data Transfer Addendum to the SCCs, version B1.0.
- Sub-processor — a third party engaged by us to process Customer Personal Data.
Terms defined in the Agreement have the same meaning here.
3. Roles of the parties
For Customer Personal Data, you are the controller (or a processor acting for another controller) and we are the processor (or sub-processor). Each party will comply with its own obligations under Data Protection Laws.
We act as a controller in our own right for a limited set of data described in ourPrivacy Policy — account and billing contact details, support correspondence, security and audit logs, and aggregated, de-identified usage analytics. That processing is governed by the Privacy Policy, not this DPA.
4. Processing on documented instructions
We will process Customer Personal Data only on your documented instructions, which comprise the Agreement, this DPA, your configuration and use of the Service, and any further written instruction you give that we accept. We will not sell Customer Personal Data, share it for cross-context behavioural advertising, retain or use it outside our direct business relationship with you, or combine it with data from other sources except as permitted by Data Protection Laws.
We will tell you if, in our opinion, an instruction infringes Data Protection Laws, and may suspend performance of that instruction until it is resolved. If we are legally required to process Customer Personal Data other than on your instructions, we will tell you before doing so unless the law prohibits that notice.
We will not use Customer Personal Data to train AI models, and our AI sub-processors are contractually prohibited from doing so.
5. Customer obligations
You warrant and undertake that:
- you have a lawful basis for the processing you instruct, and have provided all required notices and obtained all required consents from Data Subjects;
- your instructions comply with Data Protection Laws;
- you will not submit special-category data, government identifiers, payment card data or children's data to the Service unless a separate written agreement with us expressly permits it; and
- you are responsible for the accuracy and quality of Customer Personal Data and for configuring access and retention appropriately in your organisation.
6. Confidentiality of personnel
We ensure that personnel authorised to process Customer Personal Data are subject to binding confidentiality obligations, are granted access on a least-privilege, need-to-know basis, and receive appropriate data protection and security guidance.
7. Security measures
We implement and maintain appropriate technical and organisational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, taking account of the state of the art, implementation cost, and the nature, scope, context and purposes of processing. Those measures are described in Annex 2 and in ourSecurity Overview. We may update them provided the level of protection is not reduced.
8. Sub-processors
You give us general authorisation to engage Sub-processors. Our current Sub-processors are listed atdashapi.ai/legal/subprocessors. We impose data protection obligations on each Sub-processor that are no less protective than those in this DPA, and we remain fully liable to you for their performance.
We will give at least 30 days' notice before adding or replacing a Sub-processor that processes Customer Personal Data, through that page and by email to customers who have subscribed to notices. You may object on reasonable, documented data protection grounds within 30 days, and the process and remedies in clause 6 of the Sub-processors page apply.
9. Assistance with data subject requests
The Service gives you the ability to access, correct, export and delete Customer Personal Data yourself. Taking that into account, we will provide reasonable assistance to help you respond to a Data Subject exercising rights under Data Protection Laws.
If a Data Subject contacts us directly about Customer Personal Data, we will not respond substantively other than to direct them to you, and will forward the request to you without undue delay unless we are legally prohibited from doing so.
10. Assistance with DPIAs and consultations
Taking into account the nature of processing and the information available to us, we will provide reasonable assistance with your data protection impact assessments and any prior consultation with a supervisory authority that relates to your use of the Service.
11. Personal data breach
We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice will describe, to the extent known: the nature of the breach and the categories and approximate number of Data Subjects and records affected; the likely consequences; the measures taken or proposed; and a contact point for further information. Where the full picture is not yet available we will provide information in phases.
We will take reasonable steps to contain and remediate the breach, and will assist you in meeting your own notification obligations. Our notification is not an acknowledgement of fault or liability.
12. Return and deletion
On termination or expiry of the Agreement, you may export Customer Personal Data through the Service for 30 days. After that period we will delete Customer Personal Data from live systems, with backup copies being deleted as our backup rotation passes, unless retention is required by law. On written request we will confirm deletion.
We may retain aggregated, de-identified data that no longer identifies any individual, and records required for our legal, tax or audit obligations.
13. Audits and information rights
We will make available the information reasonably necessary to demonstrate compliance with this DPA, including our security documentation and, when available, third-party attestations. Where that is insufficient to satisfy an audit obligation under Data Protection Laws, you may audit us, or appoint an independent auditor who is not our competitor, on the following basis: no more than once every 12 months unless required by a supervisory authority or following a personal data breach; on at least 30 days' written notice; during business hours; subject to confidentiality; without access to other customers' data or to our multi-tenant infrastructure in a way that would compromise it; and at your cost.
14. International transfers
We may transfer and process Customer Personal Data in the United States and other countries where we or our Sub-processors operate.
- EEA transfers. Where we transfer Customer Personal Data out of the EEA to a country without an adequacy decision, the SCCs are incorporated into this DPA by reference, using Module Two (controller to processor) or Module Three (processor to processor) as applicable. You are the data exporter, we are the data importer. Clause 7 (docking) applies; the optional clause 9(a) option 2 (general written authorisation, 30 days) applies; clause 11 does not include the optional independent dispute resolution body; clause 17 selects the law of Ireland; clause 18(b) selects the courts of Ireland. Annexes I and II of the SCCs are populated by Annex 1 and Annex 2 of this DPA, and Annex III by our Sub-processors page.
- UK transfers. The UK Addendum is incorporated and amends the SCCs for transfers subject to the UK GDPR. Tables 1 to 3 are populated by the corresponding details in this DPA, and in Table 4 neither party may end the Addendum as set out in section 19.
- Swiss transfers. The SCCs apply with references to the GDPR read as references to the Swiss FADP, the competent authority being the Swiss Federal Data Protection and Information Commissioner, and the term "member state" not being read to exclude Data Subjects in Switzerland from enforcing their rights in their place of habitual residence.
Where a transfer mechanism is invalidated, we will work with you in good faith to implement a valid alternative. We will notify you if we become subject to a legally binding request from a public authority for Customer Personal Data, unless prohibited, and will challenge requests that are unlawful or overbroad.
15. US state privacy laws
Where US state privacy laws apply, we act as your service provider or processor as those terms are defined in the California Consumer Privacy Act and comparable laws. We certify that we:
- do not sell or share Customer Personal Data;
- do not retain, use or disclose it except to perform the services under the Agreement, or as otherwise permitted by those laws;
- do not retain, use or disclose it outside our direct business relationship with you;
- do not combine it with personal information received from other sources, except as those laws permit;
- will notify you if we determine we can no longer meet these obligations; and
- grant you the right to take reasonable steps to stop and remediate unauthorised use.
16. Liability and precedence
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement. Where the SCCs apply, nothing in the Agreement limits a Data Subject's rights under them.
In the event of a conflict, the order of precedence is: the SCCs and UK Addendum, then this DPA, then the Agreement — in each case only to the extent of the conflict and only for the subject matter concerned.
Annex 1 — Details of processing
| Item | Detail |
|---|---|
| Exporter | The Customer, acting as controller (or processor) of Customer Personal Data submitted to the Service. |
| Importer | DashAPI, Inc., providing a cloud data intelligence and workflow platform, acting as processor. Contact: support@dashapi.ai. |
| Subject matter | Provision of the DashAPI platform: ingestion, normalisation, enrichment, storage, AI analysis and retrieval of Customer data. |
| Duration | The term of the Agreement, plus the export and deletion periods in clause 12. |
| Nature and purpose | Hosting, storage, organisation, structuring, retrieval, analysis, generation of summaries and insights, transmission of notifications and messages the Customer sends, and deletion — all on the Customer's instructions. |
| Categories of Data Subject | The Customer's personnel and authorised users; the Customer's customers, prospects, contacts and meeting participants; recipients of communications or booking pages the Customer sends. |
| Categories of Personal Data | Identification and contact details; professional details such as employer, role and seniority; account and authentication data; communication content and metadata; calendar and meeting data; notes, records, tasks and documents the Customer creates; usage and interaction records; enrichment records retrieved from third-party providers. |
| Special categories | Not requested and not permitted without a separate written agreement. Any that a Customer submits regardless is processed under the same measures. |
| Frequency | Continuous, for the duration of the Agreement. |
| Sub-processors | As listed at dashapi.ai/legal/subprocessors, for the purposes and durations stated there. |
| Competent supervisory authority | Determined under clause 13 of the SCCs by reference to the exporter's establishment or its EU representative. |
Annex 2 — Security measures
The technical and organisational measures we apply are described in ourSecurity Overview, which is incorporated here and covers:
- pseudonymisation and encryption — TLS in transit, encryption at rest for databases, object storage and backups, and hashed credentials and tokens;
- ensuring confidentiality, integrity, availability and resilience — tenant scoping enforced server side, role-based access control, audit logging, monitoring and alerting, idempotent background processing;
- restoring availability and access after an incident — encrypted backups on a regular schedule with documented and exercised restore procedures;
- regular testing and evaluation — peer review, automated test suites including authorisation tests, static security analysis, dependency vulnerability scanning and prioritised patching;
- personnel measures — least-privilege access, written confidentiality obligations, logged support access, and prompt revocation on role change;
- sub-processor management — assessment before engagement, written data protection agreements, and periodic review;
- incident response — documented detection, containment, notification and post-incident review process.
Contact
Data protection enquiries, DPA countersignature requests and audit requests:support@dashapi.ai.
Other legal documents
- Terms of ServiceThe contract for using the DashAPI platform.
- Privacy PolicyWhat we collect, why, and the rights you have.
- Acceptable Use PolicyWhat you may and may not do with the platform.
- Sub-processorsThird parties that process data on our behalf.
- Security OverviewHow we protect data, and how to report a flaw.
- Cookie PolicyCookies and similar technologies on our sites.
- Website Terms of UseRules for browsing dashapi.ai itself.