Data Processing Addendum (DPA)
Contractual personal data processing terms for SATIA LLC business customers (B2B).
Last updated: September 8, 2026This Data Processing Addendum ('DPA') supplements the Terms of Service of SATIA LLC (8 The Green, Suite B, Dover, Delaware, United States, 19901; hereinafter 'Satia' or the 'Processor') and governs the processing of third-party personal data executed by Satia on behalf of the business customer (hereinafter, the 'Customer' or the 'Controller'). This agreement complies with the Delaware Personal Data Privacy Act (DPDPA - 6 Del. C. § 12D-101 et seq.), the General Data Protection Regulation (GDPR), and equivalent data protection statutes.
1. Scope & Applicability
This DPA applies exclusively when and to the extent that SATIA LLC processes Customer Personal Data in connection with the provision of the Satia AI Operating System (Dynamic ERP V3, Satia Docs, voice and messaging agents, automations, and browser agents).
This document becomes legally binding upon the Customer's acceptance of the Terms of Service or upon the Customer uploading or transmitting end-user personal data through Satia APIs, dynamic tables, or channels.
2. Legal Qualifications of Parties
With respect to Customer Personal Data processed under this agreement:
- Customer as Data Controller: Customer independently determines the lawful bases, purposes, and means of processing personal data regarding its end-users, prospective leads, and contacts interacting with Satia.
- SATIA LLC as Data Processor: Satia acts strictly as a Data Processor (or Service Provider under US privacy laws), processing such data solely on behalf of Customer and in accordance with its documented instructions.
3. Documented Instructions & Duties
Satia contractually covenants to:
- Process Customer Personal Data only on documented instructions from Customer as set out in the Terms of Service, agent configurations, and this DPA, unless required by mandatory applicable law.
- Ensure that all personnel authorized to access customer data are bound by strict contractual confidentiality commitments or professional secrecy obligations.
- No Commercial Data Exploitation: Satia will not monetize, sell, or rent customer personal data or utilize it for independent marketing purposes outside the provision of the Service.
4. Technical & Organizational Measures (TOMs)
Satia maintains enterprise-grade technical and organizational safeguards designed to protect personal data against accidental or unlawful destruction, loss, alteration, or unauthorized disclosure:
- Cryptographic Multitenancy & Mandatory RLS: Every tenant operates under mandatory PostgreSQL Row Level Security (RLS) policies that isolate database records and prevent cross-tenant exposure without verified session token signatures.
- Advanced Encryption: TLS 1.3 encryption in transit and AES-256 encryption at rest for databases and knowledge base object storage buckets (Satia Docs).
- Principle of Least Privilege: Role-based access controls (RBAC) and mandatory multi-factor authentication (MFA) for administrative and engineering access to cloud environments.
- Resilience & Backups: Automated daily backups and business continuity procedures ensuring prompt recovery and service availability.
5. Authorized Subprocessors
Customer provides general authorization for Satia to engage the following sub-processors for technical service delivery:
| Subprocessor | Processing Scope | Location |
|---|---|---|
| Supabase Inc. / AWS | Cloud hosting, PostgreSQL database with RLS, auth, and secure storage at rest. | United States |
| Google LLC (Gemini API) | Model inference, computer vision, and Satia Docs captioning under enterprise zero-training terms. | United States |
| OpenAI LLC (OpenAI API) | Language model reasoning and vector embeddings under enterprise zero-training terms. | United States |
| Meta Platforms Inc. | Commercial messaging integration (WhatsApp Cloud API and Instagram Graph API). | United States |
| Telephony Carriers | Voice synthesis, SIP carrier routing, and voice agent call processing. | United States |
Subprocessor Guarantees: Satia executes binding data processing agreements with each subprocessor imposing data protection terms no less protective than those in this DPA.
Notice of Changes: Satia will update this subprocessor roster with at least ten (10) days' prior notice, enabling Customer to object on reasonable data protection grounds.
6. Security Incident Notification
In the event of a confirmed Personal Data Breach impacting Customer Personal Data:
- Notification Window: Satia will notify Customer without undue delay and, where feasible, within seventy-two (72) hours of becoming aware of the confirmed breach.
- Incident Details: Notification shall detail the nature of the breach, affected records, immediate remedial actions taken, and primary security contacts.
- Regulatory Assistance: Satia will reasonably cooperate with Customer to fulfill regulatory breach notification obligations to authorities (including the Delaware Attorney General or European supervisory bodies).
7. Data Subject Rights Assistance (DSAR)
Taking into account the nature of the processing, Satia provides reasonable technical and operational assistance to allow Customer to fulfill Data Subject requests (access, correction, deletion, portability, and opt-out under DPDPA):
- Self-Service Features: Satia provides direct UI controls within the Dynamic ERP and Satia Docs to inspect, export, edit, or purge end-user records and transcripts.
- Direct Inquiries: If a Data Subject submits a request directly to Satia, Satia will instruct the individual to direct their request to Customer as the responsible Controller.
8. Data Deletion & Return
Upon contract termination or upon Customer's written request:
Satia shall, at Customer's election, securely delete or return all Customer Personal Data stored within the platform, including ERP rows, RAG vectorized vectors, transcripts, and channel tokens, within thirty (30) days, unless applicable federal or state law requires prolonged retention.
Schedule A: Technical Processing Specifications
Categories of Data Subjects:
Customer end-users, sales prospects, business leads, messaging contacts (WhatsApp/WebChat), and telephony callers.
Types of Personal Data:
Contact information (name, phone, email), messaging transcripts, audio recordings, custom ERP properties defined by Customer.
Processing Purpose & Nature:
RAG contextual grounding of autonomous agents, automation workflows, automated telephony handling, and secure multitenant database persistence.
Processing Duration:
For the duration of Customer's active subscription until requested deletion.
Require a countersigned enterprise DPA?
For enterprise tenants requiring custom execution or specific Standard Contractual Clauses (SCCs), reach out to our legal compliance team.