AI92 is live - our global soft launch is on: the full platform is open worldwide for the first 30 days.
LEGAL

Data Processing Addendum

Last updated: 13 August 2026

AI92 is operated by MASADA GATEWAY LTD, the registered business name of Portail Masada Ltée (Québec enterprise number 1177060754).
Registered office: 18C-3107 av. des Hôtels, Québec (Québec) G1W4W5, Canada
Lagos office: Plot 274 Ajose Adeogun Street, Victoria Island, Lagos 101241, Nigeria — Koloxo West Africa Ltd (RC 1876604), an affiliated company under common control.

Definitions

Applies to: All Customers

For purposes of this Data Processing Addendum, capitalised terms not defined herein have the meanings given in the AI92 Terms of Service. Capitalised data-protection terms have the meanings given in the Applicable Data Protection Laws as defined in this Section.

Applicable Data Protection Laws. "Applicable Data Protection Laws" means all data-protection, privacy, and similar laws applicable to the processing of Personal Data under this DPA, as they may be amended or superseded from time to time, including without limitation:

Europe. The European Union General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the United Kingdom General Data Protection Regulation read together with the Data Protection Act 2018, Switzerland's Federal Act on Data Protection ("FADP"), Norway's Personal Data Act, Iceland's Act 90/2018, Liechtenstein's Data Protection Act, and the implementing data-protection laws of every European Economic Area member state.

North America. In the United States: the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, the Utah Consumer Privacy Act, the Texas Data Privacy and Security Act, the Oregon Consumer Privacy Act, and analogous state-level privacy laws as they enter into force. In Canada: the Personal Information Protection and Electronic Documents Act ("PIPEDA"), Quebec's Law 25, Alberta's Personal Information Protection Act, British Columbia's Personal Information Protection Act, and the Privacy Act.

Latin America and the Caribbean. Brasil's General Data Protection Law ("LGPD", Law 13.709), Mexico's Federal Law on the Protection of Personal Data Held by Private Parties ("LFPDPPP"), Argentina's Personal Data Protection Law 25.326, Colombia's Statutory Law 1581 of 2012, Chile's Law 19.628, Peru's Law 29733, Uruguay's Law 18.331, Ecuador's Organic Law on Personal Data Protection, Costa Rica's Law 8968, the Dominican Republic's Law 172-13, Panama's Law 81 of 2019, Paraguay's Law 6534/2020, and the analogous statutes of every other country in the region.

Africa. South Africa's Protection of Personal Information Act ("POPIA"), Nigeria's Nigeria Data Protection Act 2023 ("NDPA") and the Nigeria Data Protection Regulation 2019, Kenya's Data Protection Act 2019, Egypt's Personal Data Protection Law (Law 151 of 2020), Ghana's Data Protection Act 2012, Morocco's Law 09-08, Tunisia's Organic Law 2004-63, Mauritius's Data Protection Act 2017, Senegal's Law 2008-12, Côte d'Ivoire's Law 2013-450, Rwanda's Law 058/2021, Uganda's Data Protection and Privacy Act 2019, Tanzania's Personal Data Protection Act 2022, Zimbabwe's Cyber and Data Protection Act 5 of 2021, Algeria's Law 18-07, Madagascar's Law 2014-038, the African Union Convention on Cyber Security and Personal Data Protection ("Malabo Convention"), the ECOWAS Supplementary Act on Personal Data Protection, and the analogous statutes of every other African nation.

Asia–Pacific. Australia's Privacy Act 1988, New Zealand's Privacy Act 2020, Japan's Act on the Protection of Personal Information ("APPI"), South Korea's Personal Information Protection Act ("PIPA"), Singapore's Personal Data Protection Act 2012 ("PDPA"), Thailand's Personal Data Protection Act B.E. 2562 (2019), Vietnam's Personal Data Protection Decree 13/2023, the Philippines' Data Privacy Act of 2012, Indonesia's Personal Data Protection Law 27/2022, Malaysia's Personal Data Protection Act 2010, India's Digital Personal Data Protection Act 2023 ("DPDPA"), China's Personal Information Protection Law ("PIPL"), Taiwan's Personal Data Protection Act, Hong Kong's Personal Data (Privacy) Ordinance, Macau's Personal Data Protection Act, and the analogous statutes of every other Asia–Pacific jurisdiction.

Middle East. The United Arab Emirates' Federal Decree-Law 45 of 2021 on Personal Data Protection and the Dubai International Financial Centre Data Protection Law, the Saudi Arabia Personal Data Protection Law, Israel's Privacy Protection Law 5741-1981 and its implementing regulations, Qatar's Personal Data Privacy Protection Law (Law 13/2016) and the QFC Data Protection Regulations, Bahrain's Personal Data Protection Law (Law 30/2018), Oman's Personal Data Protection Law (Royal Decree 6/2022), Jordan's Personal Data Protection Law of 2023, Turkey's Law on the Protection of Personal Data ("KVKK", Law 6698), and the analogous statutes of every other Middle Eastern jurisdiction.

Eurasia and other regions. The Russian Federation's Federal Law on Personal Data (No. 152-FZ), Kazakhstan's Law on Personal Data and Its Protection, Uzbekistan's Law on Personal Data, and the analogous statutes of every other jurisdiction in which AI92 or the Customer processes Personal Data.

Catch-all. Any other data-protection, privacy, telecommunications-confidentiality, sectoral or similar law of any jurisdiction applicable to AI92 or the Customer in connection with the processing of Customer Personal Data under this DPA. AI92 monitors regulatory developments globally and updates this list (and the practices that implement it) as new laws come into force.

Where these regimes use different terminology for analogous concepts, this DPA uses the GDPR terminology and treats the equivalents under other Applicable Data Protection Laws as compatible terms. Where a regime imposes mandatory additional requirements (such as registration with a supervisory authority, designation of a local representative, or specific contractual clauses), AI92 and the Customer agree to give effect to such requirements through the Standard Contractual Clauses, the UK Addendum, or a regime-specific rider as set out in the International Data Transfers Section.

Controller means the party that determines the purposes and means of processing personal data.

Processor means a party that processes personal data on behalf of the Controller.

Customer Personal Data means any personal data contained in Customer Input or generated in connection with Customer's use of the API Services.

Sub-processor means any processor engaged by AI92 to process Customer Personal Data on Customer's behalf, including AI92's hosting providers, payment processor, and downstream service providers.

Roles of the Parties

Applies to: All Customers

In the relationship governed by the Terms and this DPA, Customer is the Controller of Customer Personal Data and AI92 is a Processor. AI92 is operated by Masada Gateway Ltd. Integrations with Meta platforms (Facebook, Instagram and Threads) are provided through Koloxo West Africa Ltd, the registered developer of our Meta applications, which acts as a processor for those integrations on behalf of Masada Gateway Ltd.

AI92 may also process certain personal data as a separate Controller, including data necessary to operate AI92's business (customer-relationship data, billing data, authentication credentials, audit data). The terms governing such Controller processing are described in AI92's Privacy Policy at ai92.ai/privacy-policy.

Processor Instructions

Applies to: All Customers

AI92 shall process Customer Personal Data only on the documented instructions of Customer, as set forth in the Terms and this DPA, or as required by applicable law.

If AI92 is required by applicable law to process Customer Personal Data otherwise than as instructed by Customer, AI92 shall (where legally permitted) inform Customer of that requirement before processing.

Confidentiality

Applies to: All Customers

AI92 shall ensure that personnel authorised to process Customer Personal Data are subject to confidentiality obligations no less protective than those set forth in the Terms of Service.

Security of Processing

Applies to: All Customers

AI92 shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk presented by the processing of Customer Personal Data, including:

(a) pseudonymisation and encryption of personal data at rest and in transit;

(b) the ability to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems;

(c) the ability to restore the availability of and access to personal data in a timely manner in the event of a physical or technical incident;

(d) a process for regularly testing, assessing, and evaluating the effectiveness of these measures.

The current implementation of these measures is described in AI92's security documentation. AI92's SOC 2 audit reports are available to Customer on request under non-disclosure terms.

Sub-processors

Applies to: All Customers

Customer authorises AI92 to engage Sub-processors to process Customer Personal Data, subject to the following conditions:

(a) AI92 maintains a current list of Sub-processors at ai92.ai/sub-processors;

(b) AI92 shall give Customer at least thirty (30) days' notice of any addition or replacement of a Sub-processor;

(c) Customer may object to any new Sub-processor on reasonable grounds within fifteen (15) days of notice - if Customer's objection cannot be resolved, Customer may terminate the affected API Services and receive a pro-rata refund of any pre-paid fees;

(d) AI92 imposes data-protection obligations on each Sub-processor that are no less protective than those in this DPA.

Initial Sub-processors include AI92's hosting providers (Amazon Web Services, Microsoft Azure, Google Cloud Platform - for the regions and services documented at ai92.ai/sub-processors), the payment processor (Stripe, Inc.), and the documentation host (Mintlify, Inc.). The list at ai92.ai/sub-processors is the authoritative current record.

International Data Transfers

Applies to: All Customers

AI92's processing of Customer Personal Data may involve transfer of that data outside the country in which the Customer or the data subjects reside. To the extent any such transfer is restricted by Applicable Data Protection Laws, AI92 implements the cross-border transfer mechanism required by, or recognised under, the law of the originating jurisdiction. The mechanisms in this Section apply on a per-jurisdiction basis and AI92 may rely on more than one mechanism for a given transfer.

Europe and the United Kingdom. For transfers governed by the GDPR or the UK GDPR, the parties adopt the European Commission's Standard Contractual Clauses (Implementing Decision 2021/914/EU, Module 2 - Controller-to-Processor) incorporated by reference and completed as follows: (i) the time periods in Clauses 9 and 14 of the SCCs are completed in accordance with the GDPR's applicable thresholds; (ii) the docking clause does not apply to additional parties without the Customer's consent; (iii) Annex I (List of Parties) is completed with the Customer's identifying information from registration and AI92 as data importer; (iv) Annex II (Technical and Organisational Measures) refers to AI92's security documentation; and (v) Annex III (Sub-processors) refers to the list of Sub-processors maintained by AI92. For transfers under the UK GDPR, the parties additionally adopt the UK Information Commissioner's International Data Transfer Addendum to the SCCs. Where AI92 holds a current certification under the EU–US Data Privacy Framework, the Swiss–US Data Privacy Framework, or the UK Extension to the EU–US Data Privacy Framework, the parties may also rely on that certification for transfers to AI92's United States infrastructure.

Switzerland. For transfers governed by the Swiss FADP, the parties adopt the SCCs as recognised by the Swiss Federal Data Protection and Information Commissioner ("FDPIC"), with the adjustments published by the FDPIC for the Swiss legal context.

Latin America. For transfers governed by Brasil's LGPD, the parties give effect to the cross-border transfer regime under Articles 33 to 36 LGPD, including reliance (as applicable) on standard contractual clauses adopted by the Brasilian Autoridade Nacional de Proteção de Dados ("ANPD") under Resolution 19/2024, and any specific authorisation issued by ANPD where required. For transfers governed by Mexico's LFPDPPP, AI92 provides the Customer with the disclosures required by Article 36 LFPDPPP and the implementing Regulation, and Customer obtains the consents required from data subjects. For transfers governed by Argentina's Law 25.326, Colombia's Law 1581, Chile's Law 19.628, Peru's Law 29733, or other LATAM regimes, AI92 implements the standard contractual clauses or other mechanism recognised by the supervisory authority of the relevant jurisdiction.

Africa. For transfers governed by South Africa's POPIA, AI92 ensures compliance with Section 72 POPIA and obtains data subject consent or relies on an applicable lawful basis. For transfers governed by Nigeria's NDPA, Kenya's Data Protection Act, or other African regimes, AI92 ensures compliance with the cross-border transfer requirements imposed by the relevant supervisory authority (including the Nigeria Data Protection Commission, the Office of the Data Protection Commissioner of Kenya, the South African Information Regulator, and other equivalent regulators), and implements the standard contractual clauses, certification, or other mechanism recognised by that authority. AI92 will, where required, register or designate a local representative and respond to local-regulator inquiries within the applicable time limits.

Asia–Pacific. For transfers governed by China's PIPL, the parties adopt the Standard Contract for the Outbound Cross-Border Transfer of Personal Information issued by the Cyberspace Administration of China, complete a security assessment with the CAC where the transfer thresholds are exceeded, or rely on a certification recognised under the PIPL, as applicable. For transfers governed by India's DPDPA, AI92 limits transfers to jurisdictions permitted by the notifications issued under Section 16 DPDPA and complies with any specific conditions imposed by the rules. For transfers governed by Australia's Privacy Act, AI92 takes reasonable steps under Australian Privacy Principle 8 to ensure the overseas recipient handles the personal information consistently with the APPs. For transfers governed by Japan's APPI, South Korea's PIPA, Singapore's PDPA, Thailand's PDPA, Vietnam's PDPD, the Philippines' DPA, Indonesia's PDP Law, Malaysia's PDPA, Taiwan's PDPA, Hong Kong's PDPO, or other Asia–Pacific regimes, AI92 implements the standard contractual clauses, certification, government-to-government adequacy mechanism, or other transfer mechanism recognised by the supervisory authority of the relevant jurisdiction.

Middle East. For transfers governed by the UAE PDPL, the Dubai International Financial Centre Data Protection Law, the Saudi Arabia PDPL, Israel's Privacy Protection Law, Qatar's PDPPL, Bahrain's PDPL, Oman's PDPL, Jordan's PDPL, Turkey's KVKK, or other Middle Eastern regimes, AI92 implements the standard contractual clauses, adequacy decision, or other mechanism recognised by the supervisory authority of the relevant jurisdiction, and registers or designates a local representative where required.

Eurasia and other regions. For transfers governed by the Russian Federation's Federal Law 152-FZ, AI92 complies with the localisation requirements of Article 18(5) and obtains data subject consent in writing where required. For transfers governed by Kazakhstan's Law on Personal Data, Uzbekistan's Law on Personal Data, or any other Applicable Data Protection Law, AI92 implements the cross-border transfer mechanism required by, or recognised under, the law of the originating jurisdiction.

General. Where the Applicable Data Protection Laws of a Customer's jurisdiction require a specific transfer mechanism, contractual clauses, or regulatory filing that is not expressly listed above, AI92 will, on the Customer's reasonable request and at the Customer's cost (if any), execute or implement the additional documentation reasonably required to give effect to that mechanism. AI92 monitors regulatory developments globally and updates the transfer mechanisms above as new requirements come into force.

Data Subject Rights

Applies to: All Customers

AI92 shall, to the extent legally permitted, promptly notify Customer if AI92 receives a request from a data subject for access, rectification, erasure, restriction of processing, portability, or objection (a Data Subject Request). AI92 shall not respond to such a Data Subject Request except on the instructions of Customer, unless required by applicable law.

AI92 shall provide Customer with such information and reasonable assistance as Customer may require to enable Customer to respond to a Data Subject Request, including by providing or facilitating provision of data export.

Personal Data Breach Notification

Applies to: All Customers

AI92 shall notify Customer without undue delay, and in any event within seventy-two (72) hours of becoming aware, of any personal data breach affecting Customer Personal Data.

The notification shall include, to the extent then known: (a) a description of the nature of the breach, including the categories of personal data and approximate number of data subjects affected; (b) the likely consequences; (c) the measures taken or proposed to address the breach; and (d) the name and contact details of the data protection officer or other point of contact for further information.

Data Protection Impact Assessments

Applies to: All Customers

On request, AI92 shall provide reasonable assistance to Customer with any data protection impact assessment or prior consultation with supervisory authorities that Customer is required to carry out under GDPR Article 35 or analogous provisions of LATAM data-protection law.

Return and Deletion of Customer Personal Data

Applies to: All Customers

On termination of the Terms, AI92 shall, at Customer's option, return or delete Customer Personal Data, subject to retention as required by applicable law and as permitted by this DPA.

AI92 may retain Customer Personal Data only as required by applicable law (including tax-record obligations), or as permitted by this DPA, for the audit-log retention period set forth in the Privacy Policy, or for the credit-ledger retention period set forth in the Privacy Policy.

Audit Rights

Applies to: All Customers

Customer (or an independent third-party auditor reasonably acceptable to AI92, bound by confidentiality obligations) may audit AI92's compliance with this DPA no more than once per twelve-month period, on at least thirty (30) days' prior written notice, during AI92's normal business hours, and at Customer's expense.

In lieu of an on-site audit, AI92 may provide Customer with its then-current SOC 2 audit reports, penetration-testing reports, and other relevant third-party attestations. Customer shall accept these as satisfying its audit rights unless they do not address Customer's reasonable concerns.

Governing Law and Conflict

Applies to: All Customers

This DPA is governed by the same law as the Terms of Service, except where mandatory data-protection law requires a different governing law.

In case of conflict between the Terms and this DPA, this DPA controls with respect to the processing of personal data.

If you are an Enterprise customer with a Master Services Agreement (MSA), the DPA terms may be modified by your MSA. In case of conflict, the MSA controls.

Contact

Applies to: All Customers

If you have any questions about this Data Processing Addendum, please contact us: