What this agreement is
This Data Processing Agreement ("DPA") applies whenever 1slash processes personal data on your behalf as part of the service. It is part of your contract with us, whether that is a signed service agreement or the Terms of Service. Where documents conflict on data protection, this DPA wins.
Roles, subject matter, duration
You are the controller (Art. 4(7) GDPR). We, Kiarash N.A., trading as 1slash, Postfach 13 02 66, 20102 Hamburg, Germany, are the processor (Art. 4(8) GDPR).
We process personal data only to run your service: building and maintaining your brain, operating your helpers, proving their work, and supporting you. This DPA lasts as long as the service contract, plus the deletion period described below.
What we process
Nature of processing: storing, structuring, and retrieving your business data; transmitting it to AI model providers for generation; and logging helper actions for proof. Purpose: delivering the 1slash service as you configure it.
Categories of data and of data subjects are determined by you: whatever you put into your brain (business documents, instructions, and where you choose, customer or employee data), concerning whomever it concerns. You define the scope through what you connect and teach.
Special categories of personal data (Art. 9 GDPR) are processed only when you deliberately instruct us to. If you plan that, tell us first, so additional safeguards can be agreed.
Our obligations
We process personal data only on your documented instructions, which include the laws you teach and the leash settings you configure. If we believe an instruction infringes the GDPR, we inform you without undue delay (Art. 28(3) GDPR).
Everyone working on your service is bound to confidentiality in writing.
We maintain the technical and organizational measures listed in Annex 2 and keep them at least at that level for the life of this DPA (Art. 32 GDPR).
Sub-processors: you give general authorization for the providers listed in Annex 1. We inform you before adding or replacing a sub-processor, and you may object within 14 days of the notice. If we cannot accommodate a justified objection, you may terminate the affected helpers.
We assist you, taking into account the nature of our processing, with data subject requests (Art. 28(3)(e) GDPR) and with your duties under Art. 32 to 36 GDPR, including impact assessments and prior consultations.
We notify you of a personal data breach without undue delay after becoming aware of it, aiming for 48 hours, describing what happened, the likely scope and consequences, and the measures taken or proposed.
When the contract ends, we make your data available to you for export in a readable form, then delete or return all personal data within 30 days, unless statutory law requires us to retain specific records. Copies in provider backups rotate out on the provider's schedule.
We make available the information necessary to demonstrate compliance with this DPA and allow audits: written information first, and remote or on-site inspections with reasonable advance notice, normally once per year, and more frequently only after a concrete incident.
Your obligations
You are responsible for the lawfulness of the personal data you put into the service and of the instructions you give, including having a valid legal basis for the data you connect to your brain. You remain the controller; data subjects exercise their rights against you, and we assist as described above.
Liability
The liability rules of your contract with us (the Terms of Service or your signed service agreement) apply to this DPA.
Annex 1: Sub-processors
- Vercel Inc., USA: hosting and the Vercel AI Gateway, which routes model requests. Safeguards: EU-US Data Privacy Framework and/or Standard Contractual Clauses.
- Anthropic, USA: AI model provider, where selected for your helpers. Safeguards: DPF/SCCs.
- OpenAI, USA: AI model provider, where selected for your helpers. Safeguards: DPF/SCCs.
- Google LLC, USA: AI model provider, where selected for your helpers. Safeguards: DPF/SCCs.
- Stripe, Inc., USA: payment processing for card payments, billing data only. Safeguards: DPF/SCCs.
Which model providers process your data depends on the models configured for your helpers. The current per-client list is documented in your brain, and we notify you before any change, as described above.
Annex 2: Technical and organizational measures
- Encryption: in transit via TLS and at rest at the provider level.
- Access control: least privilege throughout. Helpers act with borrowed, revocable permissions; our AI never owns client credentials, and you can cancel access anytime.
- Logging and proof: every helper action is recorded and independently checked. Helpers must show done, not say done.
- Availability: humans on call around the clock, provider-level redundancy and backups.
- Incident response: a defined process with client notification under this DPA.
- Confidentiality: all staff and contractors bound in writing before touching client data.
- Deletion: client data exported and purged at contract end as described in this DPA.