Naitra Naitra
Data Processing Addendum

Naitra Data Processing Addendum (DPA)

Effective date: July 6, 2026

This Data Processing Addendum ("DPA") forms part of the agreement between Naitra LLC ("Naitra") and Customer for the Naitra service. It applies where Naitra processes personal information contained in Customer data.

1. Roles

Customer is the controller (or the business, under the California Consumer Privacy Act) of personal information in Customer data. Naitra is the processor (or service provider). Naitra processes personal information only on Customer's documented instructions, which are: to provide, secure, and support the service as described in the agreement. Naitra will inform Customer if, in its opinion, an instruction violates applicable data protection law.

2. Scope of processing

Subject matter: operation of the Naitra audit execution platform. Duration: the term of the agreement plus the export and deletion periods below. Nature and purpose: hosting, processing, evaluating, and displaying Customer's audit content and account data to deliver the service. Categories of data: business contact and account data of Customer's users, and any personal information contained in audit evidence and related content Customer chooses to upload. Data subjects: Customer's personnel and any individuals whose information appears in Customer's audit content.

3. Service provider commitments (CCPA)

Naitra will not sell or share personal information, will not retain, use, or disclose it for any purpose other than performing the services or as permitted by law, will not combine it with information from other sources except to perform the services, and certifies that it understands and will comply with these restrictions.

4. Confidentiality

Persons Naitra authorizes to process personal information are bound by confidentiality obligations. Access is limited to what is needed to operate and support the service.

5. Security

Naitra implements technical and organizational measures appropriate to the risk, including: encryption of data in transit and at rest; evidence storage with immutability controls and SHA-256 integrity hashing; envelope encryption of credentials with AWS KMS, with dedicated per-customer keys available on request; role-based access control; multi-factor authentication available and enforceable at the organization level; tenant isolation enforced at the application layer on every database query; and tamper-evident audit logging of security-relevant actions. The current description of measures is maintained at naitra.ai/security and will not materially decrease in protection during the term.

6. Subprocessors

Customer authorizes the subprocessors listed at naitra.ai/subprocessors, currently: Anthropic, Amazon Web Services, Supabase, Vercel, Railway, and Stripe. Naitra will update that page before adding or replacing a subprocessor and, for customers who subscribe to notice, will provide at least 15 days advance notice so Customer may object on reasonable data protection grounds. Naitra remains responsible for its subprocessors' performance. Naitra's AI subprocessor does not use Customer data to train models and retains it no more than 30 days.

7. Assistance

Taking into account the nature of the processing, Naitra will assist Customer in responding to requests from individuals exercising privacy rights, and in meeting Customer's security, breach notification, and assessment obligations, with information reasonably available to Naitra. If Naitra receives a request directly from an individual concerning Customer data, it will direct the individual to Customer and will not respond substantively except as required by law.

8. Incident notification

Naitra will notify Customer without undue delay after becoming aware of a breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to personal information in Customer data, and will provide information reasonably available to help Customer meet its own notification obligations, supplementing as investigation proceeds.

9. Return and deletion

During the term, Customer can export its data through the service. For 30 days after termination, Customer may export its data, after which Naitra will delete personal information in Customer data, except where retention is required by law and except that evidence under an active immutability retention period configured during the term will be deleted when that period lapses. Deletion of a customer using a dedicated encryption key may be effected by destruction of that key, rendering the data permanently unreadable.

10. Audits and information

On written request, no more than once annually absent a genuine incident, Naitra will make available information reasonably necessary to demonstrate compliance with this DPA, including summaries of security measures, its subprocessor list, and available third-party assessments as they are obtained. Where this is insufficient, the parties will agree on a reasonable, confidential review process.

11. Data location

Naitra processes and stores Customer data in the United States.

12. Precedence

If this DPA conflicts with the agreement, this DPA controls for data protection matters. This DPA is governed by the same law and venue as the agreement.

Contact for data protection matters: support@naitra.ai