Data Processing Agreement (DPA)
Erayaha DPA Standard v2.1 · Effective Date: August 6, 2026
This Data Processing Agreement ("DPA") supplements the Erayaha Terms of Service or other written agreement ("Agreement") between Erayaha Inc ("Provider", "Processor", "we", or "us") and the Customer ("Customer", "Controller", or "you") governing Customer's use of the Erayaha Document Intelligence platform. This DPA reflects the parties' agreement regarding the processing of Personal Data in compliance with Applicable Data Protection Laws (including GDPR, UK GDPR, CCPA/CPRA, and the Indian DPDP Act).
1. Definitions & Interpretation
Capitalized terms used but not defined in this DPA have the meanings given in the Agreement.
- "Applicable Data Protection Laws" means all worldwide privacy and data protection laws applicable to the processing of Personal Data under the Agreement, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR, the California Consumer Privacy Act as amended by CPRA ("CCPA"), and the Indian Digital Personal Data Protection Act ("DPDP").
- "Customer Personal Data" means any Personal Data contained within Customer Inputs or processed by Erayaha on behalf of Customer in providing the Service.
- "Controller", "Processor", "Data Subject", "Personal Data", "Processing", and "Personal Data Breach" have the meanings given under the GDPR.
2. Roles & Scope of Processing
- Role of the Parties: Customer is the Controller (or a Processor acting on behalf of a third-party Controller), and Erayaha is the Processor of Customer Personal Data.
- Documented Instructions: Erayaha shall process Customer Personal Data only on documented instructions from Customer (including with respect to transfers), as set forth in the Agreement, this DPA, or through Customer's configuration of the Service, unless required to do so by applicable law.
- Purpose and Duration: The processing shall be conducted solely to provide, maintain, and support the Document Intelligence service for the duration of the Agreement.
- Zero-Retention Architecture: Customer acknowledges that under Erayaha's Connected-Storage model, raw document text is processed transiently in volatile RAM memory and purged immediately upon inference completion.
3. Confidentiality & Personnel
Erayaha ensures that all personnel authorized to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and have received adequate training regarding data protection compliance.
4. Security of Processing & Technical Measures (TOMs)
Erayaha implements and maintains appropriate technical and organizational measures ("TOMs") designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, as detailed in Schedule 3 of this DPA.
5. Subprocessors
- Authorized Subprocessors: Customer provides general authorization for Erayaha to engage the subprocessors listed in Schedule 2 to this DPA.
- Notice of Changes: Erayaha will provide at least thirty (30) days' prior written notice (via email or posted to security.erayaha.ai) before engaging any new or replacement subprocessor. Customer may object on reasonable data protection grounds within fourteen (14) days of notice.
- Subprocessor Obligations: Erayaha imposes data protection terms on each subprocessor that provide at least the same level of protection as those in this DPA, and remains liable for the acts and omissions of its subprocessors.
6. Data Subject Rights Assistance
Taking into account the nature of the processing, Erayaha assists Customer by implementing appropriate technical measures, insofar as possible, to fulfill Customer's obligation to respond to Data Subject requests (e.g., access, rectification, erasure, restriction, or portability). If Erayaha receives a request directly from a Data Subject, Erayaha will promptly forward the request to Customer without responding directly, unless legally required.
7. DPIA & Supervisory Authority Consultation
Taking into account the nature of processing and the information available to Erayaha, Erayaha shall provide reasonable assistance to Customer with any data protection impact assessments (DPIAs) and prior consultations with competent supervisory authorities (including under Articles 35 and 36 of the GDPR / UK GDPR) that Customer reasonably considers required of it under Applicable Data Protection Laws.
8. Audit Rights & Compliance Verification
Upon Customer's reasonable prior written request, Erayaha shall make available to Customer all information reasonably necessary to demonstrate compliance with the obligations laid down in this DPA and Article 28 of the GDPR / UK GDPR, and shall allow for and contribute to audits, including inspections, conducted by Customer or an independent certified auditor mandated by Customer (who is bound by professional confidentiality obligations and is not a competitor of Erayaha), subject to the following conditions:
- Customer shall provide at least thirty (30) business days' prior written notice of any requested audit;
- Audits shall be conducted during normal business hours without disrupting Erayaha's normal business operations, at Customer's sole cost and expense, and without compromising the security or confidentiality of other customers' data;
- Audits shall occur no more than once in any twelve (12) month period, unless mandated by a competent supervisory authority or following a confirmed Personal Data Breach impacting Customer Personal Data; and
- Satisfaction via Security Summaries & Trust Reports: Customer acknowledges and agrees that Erayaha may satisfy its audit obligations by providing Customer with a summary copy of its continuous compliance posture, third-party penetration testing executive summaries, SOC 2 Type II / ISO 27001 auditor reports, or continuous monitoring attestations via security.erayaha.ai (Sprinto Trust Center portal) in lieu of an on-site physical inspection. Sprinto provides continuous compliance posture verification without receiving or storing Customer Document Content or end-user PII.
9. Security Incident & Breach Notification
Upon becoming aware of a confirmed Personal Data Breach impacting Customer Personal Data, Erayaha will:
- Notify Customer in writing without undue delay and, where feasible, within seventy-two (72) hours of becoming aware of the breach, in accordance with GDPR and UK GDPR Article 33.
- Provide timely information regarding the nature of the incident, estimated categories and numbers of Data Subjects affected, and mitigation steps taken or proposed.
- Take reasonable and prompt remedial steps to contain and mitigate the effects of the incident.
- Data Subject Notifications: Customer acknowledges and agrees that, as Controller, Customer maintains sole responsibility for assessing whether notification to affected Data Subjects is required under GDPR Article 34 or equivalent data protection laws. Erayaha will provide reasonable cooperation and timely incident information to support Customer in meeting its statutory obligations.
10. Deletion or Return of Personal Data
Upon termination or expiration of the Agreement, Erayaha shall, at Customer's choice, securely delete or return all Customer Personal Data in its possession or control within thirty (30) days, unless applicable law requires continued retention.
11. International Data Transfers
Where transfers of Customer Personal Data from the EEA, UK, or Switzerland to countries without an adequacy decision occur, the parties agree to be bound by the EU Standard Contractual Clauses (2021/914) (Module 2: Controller-to-Processor, or Module 3: Processor-to-Processor) and the UK International Data Transfer Addendum, incorporated by reference in Schedule 4.
12. DPA Modifications & Subprocessor Updates
This DPA may only be modified by mutual written agreement of the parties, provided that Erayaha may update the list of Authorized Subprocessors in Schedule 2 in accordance with Section 5 by providing at least thirty (30) days' prior notice via email or publication on security.erayaha.ai, subject to Customer's right to object on reasonable data protection grounds within fourteen (14) days of notice.
Scope & Details of Processing (Annex I)
This Schedule 1 serves as Annex I to the Standard Contractual Clauses and satisfies the mandatory requirements of GDPR Article 28(3):
A. Subject Matter & Duration
The provision of AI-assisted document intelligence, contract analysis, redline generation, and Connected-Storage CLM analysis services under the Agreement. The duration equals the term of the Agreement plus thirty (30) days for secure data deletion.
B. Nature & Purpose of Processing
Transient optical and structural document parsing, ephemeral in-memory prompt inference, clause risk classification, citation verification, redline generation, role-based user authentication, and plan usage telemetry.
C. Categories of Data Subjects
Customer employees, contractors, authorized end users, contract counterparties, signatories, legal representatives, and individuals referenced in Customer Inputs submitted for analysis.
D. Categories of Personal Data Processed
- Identity & Contact: Name, work email address, phone number, corporate title, employer organization, signature blocks, and OAuth tenant identifiers.
- Contractual & Transactional: Agreement terms, clause excerpts, operational obligations, financial consideration amounts, effective dates, and negotiation annotations within analyzed contracts.
- Usage & Telemetry: Session timestamps, feature utilization, token volume, document category classifications, and API execution latency.
- Special Categories of Data: Erayaha does not intentionally process Special Categories of Personal Data (e.g., health, racial/ethnic origin, biometric data) and Customer covenants not to submit such data.
E. Processing Operations & Frequency
Continuous during active user sessions: transient memory processing, ephemeral inference execution, formatting, automated error detection, token counting, and immediate volatile RAM deletion following inference completion.
F. DPA Liability & Covered Claims
Claims arising under or in connection with this DPA ("DPA Covered Claims") shall be subject to the aggregate liability limitations, exclusions, and caps set forth in Section 10 (Limitation of Liability & Unlimited Claims) of the Terms of Service.
Authorized Subprocessors
| Subprocessor | Role / Processing Activity | Location / Region |
|---|---|---|
| Cloudflare, Inc. | Edge DNS, Static CDN, Edge Workers runtime, D1 session store | Global Edge / USA / EU |
| Amazon Web Services (AWS Bedrock) | Stateless LLM inference runtime (Zero data retention agreement) | USA / EU Regions |
| Google Cloud Platform (Firebase) | Authentication synchronization & user profile metadata store | USA / EU Multi-Region |
| Microsoft Corporation | Microsoft 365 OAuth SSO & Graph Connected-Storage API | Customer-Configured Tenant |
| Google LLC | Google Workspace OAuth & Docs Integration Runtime | Customer-Configured Tenant |
Technical & Organizational Security Measures (TOMs)
Erayaha enforces comprehensive technical and organizational safeguards across 8 core security pillars to protect Customer Personal Data:
1. Ephemeral In-Memory Processing & Pseudonymization
Customer document text is analyzed exclusively in volatile RAM buffers. Zero document content is written to persistent disk storage, and buffers are purged immediately upon response generation.
2. End-to-End Cryptographic Protection
All network transit is encrypted with TLS 1.3. Persistent metadata, authentication secrets, and session stores are encrypted at rest using industry-standard AES-256 cipher suites.
3. Least Privilege, RBAC & MFA
Access to production environments enforces strict least-privilege role-based access controls (RBAC), hardware-backed Multi-Factor Authentication (MFA), and automated credential rotation.
4. System Resilience & Disaster Recovery
Stateless Cloudflare edge worker runtime with automated multi-region failover, DDoS mitigation, and robust business continuity procedures ensuring continuous operational availability.
5. Vulnerability Management & Trust Center
Automated CI/CD security scanning, software composition analysis (SCA), annual third-party penetration testing, and continuous compliance monitoring via Sprinto at security.erayaha.ai.
6. Physical & Data Center Security
All hosting infrastructure resides in SOC 2 Type II and ISO 27001 certified Tier-IV facilities operated by Cloudflare and AWS with 24/7 biometric and environmental controls.
7. Tamper-Evident Security Logging
Immutable audit logging across administrative access, automated threat alerts, and strict architectural isolation between operational telemetry and customer document data.
8. Data Minimization & Automated Deletion
Strict data minimization policies prohibiting persistent retention of document text, accompanied by automated 30-day deletion routines for terminated account records.
Cross-Border Data Transfer Terms
For transfers of Customer Personal Data subject to GDPR or UK GDPR to countries outside the EEA/UK not recognized as providing an adequate level of data protection:
- EU Standard Contractual Clauses (EU SCCs): The parties incorporate the Standard Contractual Clauses approved by European Commission Implementing Decision (EU) 2021/914:
- Module 2 (Controller-to-Processor) applies where Customer is a Controller and Erayaha is a Processor.
- Module 3 (Processor-to-Processor) applies where Customer is a Processor acting on behalf of a third-party Controller.
- Clause 7 (Docking Clause): The optional docking clause applies.
- Clause 9 (Subprocessors): Option 2 (General written authorization) applies with a thirty (30) day prior written notice period.
- Clause 11 (Redress): The optional independent dispute resolution mechanism is not selected.
- Clause 13 (Competent Supervisory Authority): The Data Protection Commission of Ireland (Irish DPC) shall act as competent supervisory authority (or the supervisory authority of the EU Member State in which Customer is established).
- Annexes: Schedule 1 serves as Annex I, and Schedule 3 serves as Annex II.
- UK International Data Transfer Addendum: For transfers subject to the UK GDPR, the UK Information Commissioner's Office (ICO) International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (Version B1.0) is incorporated:
- Tables 1 to 3 are completed with corresponding information from the Agreement, Schedule 1 (Annex I), and Schedule 3 (Annex II).
- In Table 4, both the Exporter and the Importer may terminate the Addendum in accordance with its Section 19.
- Swiss Transfers: For transfers subject to the Swiss Federal Act on Data Protection (FADP), references to the GDPR are interpreted to refer to the FADP, and the competent authority is the Swiss Federal Data Protection and Information Commissioner (FDPIC).
California Consumer Privacy Act (CCPA/CPRA) Terms
Erayaha acts as a "Service Provider" with respect to Customer Personal Data under the CCPA. Erayaha certifies that it does not "sell" or "share" Customer Personal Data, and does not retain, use, or disclose Customer Personal Data outside the direct business relationship or for any purpose other than performing the services specified in the Agreement.
India Digital Personal Data Protection Act (DPDP Act 2023) Terms
Notwithstanding any general designation in the Preamble, for processing activities subject to the India Digital Personal Data Protection Act, 2023 ("DPDP Act"), Erayaha acts as a "Data Fiduciary" solely with respect to user account registration PII and authentication records, and as a "Data Processor" with respect to Customer Document Content analyzed on Customer's behalf under documented instructions. Data Principals may exercise statutory rights via privacy@erayaha.ai, with right to escalate to the Data Protection Board of India.
Enterprise Procurement & Custom Execution
If your procurement or legal compliance team requires a countersigned standalone PDF or DOCX copy of this DPA with custom exhibits, please contact our Data Protection Office:
Erayaha Inc · Legal & Data Compliance
2261 Market Street, San Francisco, CA 94114, USA
DPA Inquiries: privacy@erayaha.ai
Legal Contracts: legal@erayaha.ai
Live Trust Center: security.erayaha.ai ↗