Skip to content

Data Processing Addendum

Effective: January 1, 2026

Who this is for

This Addendum applies where a business customer ("Customer") uses Secure AI and, in doing so, puts personal data belonging to other people — its own clients, patients, applicants or staff — through the Services. It forms part of the Terms of Use between the Customer and Secure Artificial Intelligence, Inc. ("Secure AI").

Individual consumers do not need it. The Privacy Policy covers personal use in full.

Roles

The Customer is the controller of the personal data it submits and decides what goes in. Secure AI is the processor and acts on the Customer's documented instructions — which, in the ordinary course, are the instructions given by using the product.

Where Secure AI decides things for itself — account records, billing, keeping the service secure and working — it is a controller for that limited purpose, and the Privacy Policy governs it.

What is processed

  • Subject matter: provision of an AI assistant and the features around it.
  • Duration: for as long as the Customer's account is open, plus the deletion window below.
  • Nature and purpose: transmitting prompts to AI providers and returning answers; storing what the Customer chooses to save.
  • Types of data: whatever the Customer's people type or upload. Secure AI does not require any particular category.
  • Data subjects: the Customer's staff, and whoever is described in the material they submit.

Secure AI does not require special-category data and asks Customers not to submit it. Regulated health records in particular are out of scope: Secure AI is not a business associate under HIPAA and does not sign BAAs.

Redaction, and why it matters here

Before any message reaches a third-party AI provider, direct identifiers — names, email addresses, phone numbers, and the Customer's own account identifiers — are stripped from it. The provider receives the question without being told whose question it is.

This is a real reduction in exposure and is described plainly rather than sold: it removes the identifiers the system can recognise. It is not a guarantee of anonymisation. Free text can identify a person through context that no filter can see — a rare diagnosis, a named matter, a small town. The Customer remains the controller and is responsible for what it chooses to submit.

Security

  • Conversations are encrypted at rest with AES-256-GCM.
  • Decryption keys are released only to clients that can prove what they are: the mobile apps through Firebase App Check, the desktop app by signing a fresh challenge with a key held in the operating system's keychain. A web browser cannot do either and is therefore not given the key.
  • Access to production systems is limited to personnel who need it.
  • Personal data is segregated per account, and access is enforced by the identity in the request rather than by anything the client asserts.

Secure AI does not currently hold a SOC 2 report. Where a Customer needs one, Secure AI will say where it is with it rather than imply a certification it does not have.

Subprocessors

Secure AI uses the subprocessors listed at secureai.one/subprocessors, which names each one and what it does. The Customer authorises their use by accepting this Addendum.

Secure AI will give notice before adding or replacing a subprocessor, and remains responsible for their performance. A Customer that objects on reasonable data-protection grounds may raise it, and if it cannot be resolved, may terminate the affected Services.

International transfers

Personal data may be processed in the United States and in other countries where the subprocessors above operate. Where data is transferred out of the EEA, the United Kingdom or Switzerland, the transfer relies on the European Commission's Standard Contractual Clauses, together with the UK Addendum where the UK GDPR applies. Those clauses are incorporated here by reference.

Assisting the Customer

Where a data subject exercises a right — access, correction, erasure, portability, objection — and the Customer needs help answering, Secure AI will provide reasonable assistance, taking into account the nature of the processing and the information available to it.

Secure AI will also provide the information the Customer reasonably needs for a data protection impact assessment or a consultation with a supervisory authority.

Personal data breaches

Secure AI will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's data, and will include what it knows: what happened, which categories and roughly how many records are involved, the likely consequences, and what is being done about it. Where the full picture is not yet clear, Secure AI will report what it has rather than wait to be certain.

Confidentiality

Personnel with access to personal data are bound by confidentiality obligations, and access is granted only where the work requires it.

Deletion and return

A Customer may delete individual content at any time from within the product. On termination, Secure AI will delete the Customer's personal data within 30 days, except where it must be kept longer to comply with law — billing records being the usual example.

Backups age out on their own cycle and are not selectively edited; data in a backup is deleted when that backup expires.

Audits

Secure AI will make available the information reasonably necessary to demonstrate compliance with this Addendum, and will respond to a reasonable security questionnaire once in any twelve-month period. Where a Customer's regulator requires an on-site audit, the parties will agree its scope and timing in advance.

Order of precedence

Where this Addendum conflicts with the Terms of Use, this Addendum governs for matters of personal data processing. Everything else in the Terms continues to apply.

Signing it

Most Customers do not need a countersigned copy: accepting the Terms of Use accepts this Addendum with them. Where a compliance team needs a signed version on file, email company@secureai.one with the entity name and address, and we will return one.

© 2026 Secure Artificial Intelligence, Inc.