Data Processing Addendum
How Autonomir processes personal data on behalf of enterprise customers when providing the Services.
Effective August 30, 2026 · Last updated August 30, 2026
Overview
This Data Processing Addendum (the “DPA”) describes how Autonomir Inc. (“Autonomir”) processes personal data contained in Customer Data when providing the Services. It supplements the Autonomir Enterprise Terms & Conditions and any applicable Order, and — where applicable data-protection law requires it — forms part of the Agreement.
This page is a summary of the framework. The specific, binding data-processing terms applicable to a customer are those referenced by or attached to that customer’s Agreement, which govern in the event of any conflict with this summary.
Roles of the parties
For personal data within Customer Data, the Customer acts as the controller (or “business”) and Autonomir acts as the processor (or “service provider”). Autonomir processes that personal data only to provide, secure, support, maintain and improve the Services and to perform its obligations under the Agreement, and otherwise on the Customer’s documented instructions — which include the Agreement.
Autonomir does not sell Customer Data and does not process it for its own independent commercial purposes outside the Agreement.
Confidentiality and security
Autonomir maintains administrative, technical, physical and organizational safeguards designed to protect personal data, as described in the Enterprise Terms & Conditions and Autonomir’s security practices. Autonomir requires personnel authorized to process personal data to be bound by appropriate confidentiality obligations.
Sub-processing
Autonomir engages sub-processors to help deliver, secure and support the Services. The categories of sub-processors Autonomir uses are described on the Subprocessors page. Autonomir remains responsible for its sub-processors’ performance, imposes data-protection and confidentiality obligations appropriate to their role, and provides enterprise customers with a mechanism to receive notice of changes.
International transfers
Where personal data is transferred across borders, Autonomir relies on the appropriate safeguards required by applicable law — such as the Standard Contractual Clauses — where and to the extent they apply.
Assistance and personal-data breaches
Taking into account the nature of the processing, Autonomir provides reasonable assistance to the Customer in responding to requests from data subjects and from supervisory authorities.
Autonomir will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer personal data processed by Autonomir, and will provide information reasonably available to it to help the Customer meet its own notification obligations.
Return and deletion
On expiration or termination, Autonomir makes Customer Data available for export for a limited period and then deletes it in accordance with the Enterprise Terms & Conditions, subject to legal retention obligations. Aggregated or de-identified information that does not identify the Customer or an individual is not subject to return or deletion.
Questions about this document can be sent to legal@autonomir.com. Where this document applies to an active subscription, the version referenced by or attached to your Order governs in the event of any conflict.
