Naitra Data Processing Addendum (DPA)
Effective date: September 7, 2026
This Data Processing Addendum ("DPA") forms part of the agreement between Naitra LLC ("Naitra") and Customer for the Naitra service. It applies where Naitra processes personal information contained in Customer data.
1. Roles
Customer is the controller (or the business, under the California Consumer Privacy Act) of personal information in Customer data. Naitra is the processor (or service provider). Naitra processes personal information only on Customer's documented instructions, which are: to provide, secure, and support the service as described in the agreement. Naitra will inform Customer if, in its opinion, an instruction violates applicable data protection law.
2. Scope of processing
Subject matter: operation of the Naitra audit execution platform. Duration: the term of the agreement plus the export and deletion periods below. Nature and purpose: hosting, processing, evaluating, and displaying Customer's audit content and account data to deliver the service. Categories of data: business contact and account data of Customer's users, and any personal information contained in audit evidence and related content Customer chooses to upload. Data subjects: Customer's personnel and any individuals whose information appears in Customer's audit content.
3. Service provider commitments (CCPA)
Naitra will not sell or share personal information, will not retain, use, or disclose it for any purpose other than performing the services or as permitted by law, will not combine it with information from other sources except to perform the services, and certifies that it understands and will comply with these restrictions.
4. Confidentiality
Persons Naitra authorizes to process personal information are bound by confidentiality obligations. Access is limited to what is needed to operate and support the service.
5. Security
Naitra implements technical and organizational measures appropriate to the risk, including: encryption of data in transit and at rest; evidence storage with immutability controls and SHA-256 integrity hashing; envelope encryption of credentials with AWS KMS, with dedicated per-customer keys available on request; role-based access control; multi-factor authentication available and enforceable at the organization level; tenant isolation enforced at the application layer on every database query; and tamper-evident audit logging of security-relevant actions. The current description of measures is maintained at naitra.ai/security and will not materially decrease in protection during the term.
6. Subprocessors
Customer authorizes the subprocessors listed at naitra.ai/subprocessors, currently: Anthropic, Amazon Web Services, Supabase, Vercel, and Railway. Naitra will update that page before adding or replacing a subprocessor and will give at least 15 days advance notice to all customers by email to account administrators, so Customer may object on reasonable data protection grounds. If Customer objects and the parties cannot agree an alternative, Customer may terminate the affected service without penalty for the remainder of the prepaid term. Naitra remains responsible for its subprocessors' performance. Naitra's AI subprocessor does not use Customer data to train models and retains it no more than 30 days.
7. Assistance
Taking into account the nature of the processing, Naitra will assist Customer in responding to requests from individuals exercising privacy rights, and in meeting Customer's security, breach notification, and assessment obligations, with information reasonably available to Naitra. Naitra will respond to a request for assistance within 10 business days. If Naitra receives a request directly from an individual concerning Customer data, it will direct the individual to Customer and will not respond substantively except as required by law.
8. Incident notification
Naitra will notify Customer without undue delay and in any event within 72 hours after becoming aware of a breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to personal information in Customer data. The notification will include the information reasonably available to Naitra at that time, and Naitra will supplement it as the investigation proceeds. A notification given within 72 hours is not required to be complete.
9. Return and deletion
During the term, Customer can export its data through the service. For 30 days after termination, Customer may export its data, after which Naitra will delete personal information in Customer data, except where retention is required by law and except that evidence under an active immutability retention period configured during the term will be deleted when that period lapses. Deletion of a customer using a dedicated encryption key may be effected by destruction of that key, rendering the data permanently unreadable.
10. Audits and information
On written request, no more than once annually absent a genuine incident, Naitra will make available information reasonably necessary to demonstrate compliance with this DPA, including summaries of security measures, its subprocessor list, and available third-party assessments as they are obtained. Where this is insufficient, the parties will agree on a reasonable, confidential review process.
11. Data location
Naitra processes and stores Customer data in the United States. Evidence files are held in Amazon Web Services US East (Ohio), us-east-2. Where Customer is established in the United Kingdom or the European Economic Area, or is otherwise subject to the UK GDPR or the EU GDPR, transfers of personal information to Naitra in the United States are made under section 12 below.
12. International transfers
Where the EU GDPR applies, the parties incorporate the Standard Contractual Clauses approved by the European Commission in Implementing Decision (EU) 2021/914, module two, controller to processor, with Customer as data exporter and Naitra as data importer. Where the UK GDPR applies, the parties incorporate the International Data Transfer Addendum issued by the Information Commissioner's Office to those clauses. The security measures in section 5 are the technical and organizational measures for the purposes of those clauses, the subprocessor authorization in section 6 is general written authorization, and the governing law and venue in the clauses are as required by them rather than as stated in section 13.
13. Precedence
If this DPA conflicts with the agreement, this DPA controls for data protection matters. Where Naitra and Customer have entered into a Business Associate Agreement, that agreement controls for protected health information. This DPA is governed by the same law and venue as the agreement.
Contact for data protection matters: support@naitra.ai
Naitra