DEMOEvery visitor gets their own sample workspace, deleted after 7 days. Do not enter real data. Get in touch
aiAiAI
ETContact

Version 1.0 · 27 Sep 2026

AiAiAi data processing agreement (DPA)

GDPR Article 28

The Estonian version prevails if the two differ.

1. Parties and conclusion

The agreement is concluded electronically when the person creating the workspace confirms they may represent the Customer and accepts this version. The version accepted, the time and the person are recorded in the workspace. On request we also sign the agreement digitally.

2. Subject matter, nature and purpose

Subject matter: providing the AiAiAi service to the Customer: keeping the Customer's AI tool list, settings, reviews and users, and generating views from them.

Nature: storing, displaying, changing, deleting and generating views, driven by what the Customer's users do.

Purpose: only to provide the service to the Customer. Kratikaitse does not use Customer data for any other purpose. It does not sell, profile or market with it, and does not use it to train AI models.

3. Duration

This agreement applies while the Customer's workspace exists, plus the deletion period in section 7.

4. Types of personal data and data subjects

Data subjects: the Customer's employees and contractors who use AiAiAi, and people the Customer names in the tool list, settings or reviews.

Data:

The Customer does not enter special categories of personal data (GDPR Art. 9) into AiAiAi. The tool list is about AI tools, not about people's health, beliefs or other special-category data.

The Customer is responsible for having a legal basis for the data it enters and for informing its employees about the processing. For example, employees must know that confirmations of reading the staff rules are recorded.

5. Kratikaitse's obligations (GDPR Art. 28(3)(a)–(h))

Obligation
a Processes personal data only on the Customer's documented instructions. The instructions are this agreement, the Customer's use of the service's functions, and written instructions from the workspace owner. Kratikaitse tells the Customer without delay if it believes an instruction infringes data-protection law.
b Everyone with access to the data is bound by confidentiality. At present only Mart Liivand has administrative access.
c Applies GDPR Art. 32 security measures, see Annex 2.
d Uses sub-processors only as listed in Annex 3. New or changed sub-processors are announced at least 30 days in advance. The Customer may object, and if the objection cannot be resolved, may terminate.
e Helps the Customer answer data subject requests. Most actions (correcting and deleting tool list data, removing members) the Customer does in the service itself. Kratikaitse answers other requests without undue delay.
f Helps the Customer meet GDPR Arts. 32–36. Kratikaitse notifies the Customer of a personal data breach without undue delay and at the latest within 48 hours of discovering it.
g At the end of the agreement returns or deletes the data, see section 7.
h Makes available the information needed to demonstrate compliance and allows audits, see section 8.

6. Security measures

Kratikaitse applies the measures in Annex 2. The annex states what is actually in place, and, separately, what is not done.

7. Deletion and return

8. Information and audits

Kratikaitse answers the Customer's reasonable questions about the processing. The Customer or its appointed auditor may audit with at least 30 days' notice, no more than once a year (more often after a breach), at the Customer's cost. Existing documentation is used first.

9. International transfers

The database is in the European Union. Requests may be processed in a sub-processor's data centre outside the European Economic Area. The safeguards for such transfers are listed in Annex 3.

10. Liability

The parties' liability is governed by the AiAiAi terms of service. This agreement is an integral part of the terms of service.

11. Changes and governing law

Workspace owners are told about significant changes to this agreement at least 30 days in advance. Estonian law applies. Disputes are settled in Harju County Court.


Annex 1. Description of processing

Service AiAiAi: AI tool list, staff rules, list of basic controls, quarterly review and customer summary
Data location database: Cloudflare D1, EU jurisdiction
Frequency continuous, driven by user activity
Retention for the life of the workspace, then per section 7

Annex 2. Technical and organisational measures

Data minimisation. The service asks about AI tools, not people. Only an email address is required for a user. No AI model currently processes any data in the service.

Workspace isolation. Every workspace data row carries a workspace identifier. Every query filters on it, and the identifier comes from the verified session (the logged-in state), never from the request. Membership is re-checked on every request. A test script checks that trying to reach another workspace's data returns "not found". Honest limit: isolation is enforced in application code, not by database row-level security.

Authentication. Passwordless one-time email link (256-bit random token). Only the token's SHA-256 hash (a one-way fingerprint) is stored. The link is valid for 15 minutes, works once, and is limited to five links per address per 15 minutes. The session identifier is a 256-bit random value, and only its hash is stored. The cookie is HttpOnly, Secure and SameSite=Lax, lasts 30 days, and the session is deleted on logout.

Access. Workspace roles are owner, admin, member and viewer. The last owner cannot be removed. Only Mart Liivand has platform administrative access.

Web security. HTTPS only (HSTS). Request origin is checked (CSRF). A strict content security policy allows only the service's own scripts, styles and fonts. X-Frame-Options: DENY, nosniff and a restricted referrer policy apply. There are no third-party scripts, analytics or trackers.

Change history. All changes are logged (who, what, when). Database triggers prevent log entries from being changed or deleted while the workspace exists.

Data location, encryption and recovery. The database is Cloudflare D1 in the EU jurisdiction: data is stored and database queries run in the EU. Application code may run in Cloudflare's nearest data centre. The database is encrypted at rest (AES-256-GCM, keys managed by Cloudflare). Connections are encrypted with TLS. Point-in-time recovery (Time Travel) covers the last 7 days.

Logs. The request log (time, URL, request headers; cookies and authorisation headers redacted) is kept for 3 days. Only Mart Liivand has access.

Development and change. Source code is in a private git repository. Changes go through code review. Free-text input is validated and length-limited. All database queries are parameterised.

What we do not do, said plainly:

Annex 3. Sub-processors

Sub-processor Role Location Safeguard
Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA hosting, compute (Workers), database (D1), logs, CDN, DDoS protection database in the EU; requests processed in the nearest data centre EU–U.S. Data Privacy Framework certification, and the EU Standard Contractual Clauses included in Cloudflare's data processing terms

Planned, not in use today. These will be added under section 5(d) with 30 days' notice: Amazon Web Services EMEA SARL (email delivery with SES and AI model requests with Bedrock, both in EU regions) and a payment service provider.


OÜ Kratikaitse · Management Board member Mart Liivand