1. Parties and scope
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between the customer using Anasa for business purposes (“Customer”) and the Anasa provider identified in the Legal Notice (“Anasa”). It applies where Anasa processes personal data contained in Cloud captures, encrypted vault metadata, managed-AI requests, or support material on Customer's behalf.
Customer is the controller and Anasa is the processor for that customer data. Each party may be an independent controller for account, billing, fraud-prevention, security, and legal-compliance data it processes for its own purposes.
2. Processing details
- Subject matter: providing Anasa Cloud, managed AI, support, security, and related account operations.
- Duration: the service term plus the limited retention and deletion periods described in the Privacy Policy and this DPA.
- Nature and purpose: storage, transmission, synchronization, inference requested by an authorized user, troubleshooting, protection, deletion, and return.
- Data subjects: Customer users and people whose personal data Customer places in submitted content.
- Data types: account identifiers, device and usage metadata, capture text and attachments, encrypted vault objects and metadata, managed-AI prompts and selected note context, and support communications.
- Special categories: not intentionally required by Anasa. Customer must not submit them unless it has a lawful basis and appropriate safeguards.
3. Customer instructions
Anasa will process customer personal data only on documented instructions in the Terms, this DPA, product settings, and support requests, unless Union or Member State law requires otherwise. Anasa will inform Customer of a legally required instruction unless prohibited.
Customer is responsible for lawfulness, notices, permissions, user access, and the accuracy of its instructions.
4. Confidentiality and security
People authorized to process customer data are bound by confidentiality. Anasa maintains technical and organizational measures appropriate to the service, including access controls, TLS, provider credential protection, ownership checks, deletion workflows, and client-side encryption for optional vault sync. Current details and assurance limits are on the Security page.
5. Subprocessors
Customer gives general authorization for the providers on the Subprocessor list. Anasa will provide advance notice of material additions or replacements to subscribers. Customer may object on reasonable data-protection grounds; the parties will try to resolve the concern, and if they cannot, Customer may stop the affected hosted feature.
6. Data-subject requests and compliance assistance
Taking account of the nature of processing, Anasa will provide reasonable assistance for access, correction, deletion, restriction, portability, objection, security assessments, breach notifications, and regulator consultations. Customer remains responsible for responding to requests as controller.
7. Incidents
Anasa will notify Customer without undue delay after becoming aware of a personal-data breach affecting customer data and will provide available information needed for Customer's obligations. Notification is not an admission of fault.
8. Return and deletion
Local notes remain in Customer's folder. Customer can drain capture queues, sync encrypted vault data to an authorized device, export account data, reset vault sync, and delete the account. At the end of service Anasa deletes or returns processor-held customer data as described in Data portability and exit, unless law requires retention.
9. International transfers
Where processing moves personal data outside the EEA without an adequacy decision, the parties rely on applicable safeguards such as the European Commission's Standard Contractual Clauses, including relevant modules and supplementary measures.
10. Information and audits
Anasa will make available information reasonably necessary to demonstrate compliance and allow proportionate audits by Customer or an agreed independent auditor. Audits must protect other customers, confidential information, and service security, and normally use existing documentation before on-site access.
11. Order of precedence
For data-protection matters, this DPA controls over conflicting general Terms. The liability and governing-law provisions of the Terms apply unless data-protection law requires otherwise.
12. Acceptance and contact
An authorized business customer accepts this DPA by accepting the Terms and enabling an in-scope hosted feature. For a countersigned copy or data-protection question, email hey@anasa.md.