Version 1.0 · Effective Date: July 14, 2026

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between ENGINIFYAI, of ENGINIFYAI.COM (“EnginifyAI,” “Processor”) and the customer agreeing to those Terms (“Customer,” “Controller”). It applies to the extent EnginifyAI processes Personal Data on Customer’s behalf in connection with the EnginifyAI service (the “Service”). By using the Service, Customer accepts this DPA. Customers requiring a signed copy may request one at dpo@enginifyai.com.

1. Definitions

Terms such as “Personal Data,” “Processing,” “Controller,” “Processor,” “Data Subject,” and “Supervisory Authority” have the meanings given in the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”). “Data Protection Laws” means all laws applicable to the processing of Personal Data under this DPA, including the GDPR, the UK GDPR, and the California Consumer Privacy Act (“CCPA”).

2. Roles and Scope

2.1 As between the parties, Customer is the Controller and EnginifyAI is the Processor of the Personal Data described in Annex A.

2.2 EnginifyAI will process Personal Data only on Customer’s documented instructions, including as set out in the Terms of Service, this DPA, and Customer’s use of the Service, unless required to do otherwise by applicable law.

3. Processor Obligations

EnginifyAI shall:

3.1 Confidentiality: Ensure that personnel authorized to process Personal Data are bound by confidentiality obligations.

3.2 Security: Implement and maintain the technical and organizational measures described in Annex B, appropriate to the risk.

3.3 Data Subject Requests: Taking into account the nature of the processing, assist Customer by appropriate measures, insofar as possible, in responding to Data Subject requests to exercise their rights under Data Protection Laws.

3.4 Assistance: Assist Customer in ensuring compliance with its obligations regarding security, breach notification, data protection impact assessments, and prior consultation, taking into account the information available to EnginifyAI.

3.5 Personal Data Breach: Notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer’s Personal Data, and provide information reasonably available to assist Customer in meeting its notification obligations.

3.6 Deletion or Return: Upon termination of the Service, delete or return Customer’s Personal Data in accordance with the deletion provisions of the Privacy Policy, except where retention is required by applicable law or governed by the Global Library license described in the Terms of Service.

3.7 Audits: Make available to Customer information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to audits, including by making available relevant third-party certifications and reports of its subprocessors (such as SOC 2 Type 2 reports) in lieu of on-site audits where appropriate.

4. Subprocessors

4.1 Customer provides general authorization for EnginifyAI to engage the subprocessors listed in Annex A.

4.2 EnginifyAI imposes data protection obligations on each subprocessor that are no less protective than those in this DPA, and remains liable for its subprocessors’ performance.

4.3 EnginifyAI will provide notice of the addition or replacement of a subprocessor (via its published subprocessor list or on request), giving Customer the opportunity to object on reasonable data protection grounds.

5. International Transfers

Where EnginifyAI transfers Personal Data outside the EEA, the UK, or Switzerland, such transfers are made under an appropriate safeguard recognized by Data Protection Laws, including the EU Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), which are incorporated into this DPA by reference.

6. CCPA

To the extent the CCPA applies, EnginifyAI acts as a “service provider.” EnginifyAI shall not sell Personal Data, nor retain, use, or disclose it for any purpose other than performing the Service or as permitted by the CCPA.

7. Liability and Term

7.1 Each party’s liability under this DPA is subject to the limitations of liability set out in the Terms of Service.

7.2 This DPA takes effect when Customer accepts the Terms of Service and continues until EnginifyAI has ceased all processing of Customer’s Personal Data.

7.3 This DPA is governed by the same governing law and jurisdiction as the Terms of Service, except where Data Protection Laws require otherwise.

Annex A – Details of Processing

Subject matter: Provision of the EnginifyAI AI prompt building and content generation platform.

Duration: For the term of the Customer’s use of the Service.

Nature and purpose: Storage, hosting, processing, and transmission of Personal Data to enable the Service, including transmitting user prompts to selected AI providers to generate outputs.

Types of Personal Data: Account and profile data (name, email, username), billing data, usage and technical data (IP address, device/browser information), and any Personal Data contained within prompts or content that Customer chooses to submit.

Categories of Data Subjects: Customer’s authorized users and any individuals whose Personal Data is included in prompts submitted to the Service.

Subprocessors:

SubprocessorPurposeLocation
SupabaseDatabase, authentication, storage of account data and saved promptsUnited States
VercelApplication hosting and deliveryUnited States
AnthropicAI model processingUnited States
OpenAIAI model processingUnited States
xAIAI model processingUnited States
Google (Gemini)AI model processingUnited States
StripeBilling and payment processingUnited States
InMotion HostingMarketing website hosting (contact forms) and email services (cPanel/Roundcube)United States
Google AnalyticsMarketing website analyticsUnited States

Annex B – Technical and Organizational Measures

  • Encryption: Data encrypted in transit (TLS) and at rest (AES-256); API keys encrypted at the application level.
  • Access control: Role-based access; production data access restricted to authorized personnel on a need-to-know basis; multi-factor authentication on administrative accounts.
  • Infrastructure: Hosted on SOC 2 Type 2 and ISO 27001 certified infrastructure (Supabase, Vercel).
  • Data segregation: Logical separation of customer data; row-level security controls.
  • Backups: Encrypted backups within the primary data region.
  • Deletion: Automated deletion of private data from EnginifyAI systems on account deletion, as described in the Privacy Policy.
  • Monitoring: Continuous security monitoring, logging, and vulnerability testing.

DPA Version: 1.0, Last Updated: July 14, 2026