Data Processing Addendum
Effective date: 1 January 2026
Last reviewed: 27 June 2026
Applies to: any agency or client ("Controller") that instructs phaneosAI ("Processor") to process personal data on its behalf.
1. Definitions
Terms used in this DPA have the meanings given in the GDPR where applicable:
- Controller: the entity that determines the purposes and means of processing personal data.
- Processor: phaneosAI, which processes personal data on behalf of the Controller.
- Data Subject: the identified or identifiable natural person whose personal data is processed.
- Personal Data: any information relating to a Data Subject.
- Subprocessor: a third party engaged by phaneosAI to assist in processing personal data.
- SCCs: the European Commission Standard Contractual Clauses (Decision 2021/914), Module Two (Controller to Processor).
2. Roles and scope
When phaneosAI processes personal data on behalf of a Controller under a services agreement, phaneosAI acts as a Processor and the Controller acts as the Controller.
When phaneosAI processes personal data for its own purposes, such as website analytics or partner registration, phaneosAI acts as a Controller and the Privacy Policy applies.
3. Processing instructions
phaneosAI will process personal data only:
- on documented instructions from the Controller, including as set out in the applicable statement of work or agreement;
- as required by applicable law, in which case phaneosAI will inform the Controller before processing, unless prohibited by law.
Processing includes collection, storage, analysis, transformation, deletion, and any other operation performed to deliver the agreed services.
4. Data categories and data subjects
The Controller determines the exact data categories. Typical personal data processed in phaneosAI projects may include:
- Contact data (name, email, phone, job title).
- Professional or client-project data.
- Usage data or feedback.
- Any special-category data only if explicitly authorized and necessary.
Data subjects may include the Controller's employees, customers, prospects, or end-users.
5. Subprocessors
phaneosAI engages the following subprocessors for core infrastructure and communication services:
| Subprocessor | Service | Location | Safeguards |
|---|---|---|---|
| Vercel | Website and application hosting | United States | SCCs; encryption in transit and at rest |
| Resend | Transactional email delivery | United States | SCCs; limited retention |
| OpenAI | AI model inference | United States | Business API terms; ZDR where available; SCCs |
| Anthropic | AI model inference | United States | Business API terms; ZDR where available; SCCs |
We may update this list. The Controller may object to a new subprocessor by written notice within 30 days. If the Controller reasonably objects, we will work with the Controller to find an acceptable alternative or allow termination of affected services.
6. Security measures
phaneosAI implements appropriate technical and organizational measures, including:
- encryption in transit (TLS 1.2+) and at rest;
- access control and MFA;
- regular vulnerability management;
- logging and monitoring;
- personnel training and confidentiality obligations;
- secure development practices.
Full details are in our Security Policy.
7. Confidentiality
Personnel authorized to process personal data are bound by confidentiality obligations and process data only as necessary.
8. Data subject rights
phaneosAI will assist the Controller, to the extent technically feasible, in responding to requests from data subjects exercising their rights under GDPR or other applicable law.
9. Breach notification
phaneosAI will notify the Controller without undue delay and, where feasible, within 48 hours of becoming aware of a personal data breach affecting personal data processed under this DPA. The notice will include known details about the breach and steps taken or proposed.
10. Return and deletion
Upon termination or expiry of the services, phaneosAI will, at the Controller's choice, return or delete the personal data processed under this DPA, except where retention is required by applicable law.
11. International transfers
When personal data is transferred from the European Economic Area, United Kingdom, or Switzerland to Vietnam, the United States, or other third countries, phaneosAI relies on:
- the SCCs (Module Two: Controller to Processor) approved by the European Commission;
- additional technical safeguards such as encryption and access controls;
- any supplementary measures required by the Controller's jurisdiction.
For UK transfers, the UK Addendum to the EU SCCs applies where relevant. For Swiss transfers, the Swiss SCCs or equivalent apply.
12. Audit and cooperation
phaneosAI will provide the Controller with information reasonably necessary to demonstrate compliance with this DPA and allow for audits, including inspections, conducted by the Controller or an auditor mandated by the Controller, subject to reasonable confidentiality and cost arrangements.
13. Termination
This DPA forms part of the broader services agreement and terminates together with it. Provisions on confidentiality, data return/deletion, and liability survive termination.
14. Governing law
This DPA is governed by the law of the Controller's jurisdiction where required by mandatory law, otherwise by the law of Vietnam, with the SCCs taking precedence where applicable.
This Data Processing Addendum is provided for compliance and contracting purposes. It does not constitute legal advice. Controllers should consult their own counsel to ensure that the DPA meets jurisdiction-specific requirements.