Data Processing Agreement - 1ma.ai
Last Updated: March 5, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between ООО «1ма» ("1ma.ai", "Processor") and the entity or individual agreeing to the Terms of Service ("Client", "Controller").
This DPA applies to the extent that 1ma.ai processes personal data on behalf of the Client in the course of providing the services described in the Terms of Service.
1. Definitions
2. Scope and Roles
a. Roles:
The Client acts as the Data Controller. 1ma.ai acts as the Data Processor, processing Personal Data solely on the Controller's documented instructions and for the purpose of providing the agreed services.
b. Subject Matter and Duration:
This DPA applies to the processing of Personal Data as part of the 1ma.ai service for the duration of the Client's active subscription. Upon termination of the subscription, data processing ceases and data is handled as described in Section 10.
c. Categories of Data Subjects:
d. Types of Personal Data Processed:
e. Nature and Purpose of Processing:
3. Obligations of the Processor
1ma.ai shall:
a. Process Personal Data only on documented instructions from the Controller, unless required to do so by applicable law. If such a legal requirement exists, the Processor shall inform the Controller before processing (unless prohibited by law).
b. Ensure that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
c. Implement appropriate technical and organizational security measures as described in Section 6.
d. Engage Sub-Processors only in accordance with Section 5.
e. Assist the Controller, taking into account the nature of processing, in responding to requests from Data Subjects exercising their rights under applicable data protection laws.
f. Assist the Controller in ensuring compliance with obligations related to security of processing, notification of data breaches, data protection impact assessments, and prior consultation with supervisory authorities, taking into account the nature of processing and the information available to the Processor.
g. At the choice of the Controller, delete or return all Personal Data after the end of the provision of services, and delete existing copies unless applicable law requires storage.
h. Make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in this DPA and allow for and contribute to audits as described in Section 8.
i. Immediately inform the Controller if, in the Processor's opinion, an instruction infringes applicable data protection laws.
4. Obligations of the Controller
The Controller shall:
a. Ensure that the processing of Personal Data through the service has a valid legal basis under applicable data protection laws.
b. Inform End-Users (Data Subjects) about the processing of their personal data through the service, including the use of AI-powered automated messaging, in accordance with applicable transparency requirements.
c. Maintain an appropriate privacy policy that covers the processing of End-User data through the 1ma.ai service.
d. Ensure that instructions given to the Processor comply with applicable data protection laws.
e. Handle and respond to Data Subject requests, with the Processor's assistance as needed.
f. Notify the Processor promptly of any changes that may affect the Processor's ability to comply with applicable data protection laws.
5. Sub-Processors
a. General Authorization:
The Controller provides general written authorization for the Processor to engage Sub-Processors for the purpose of delivering the services. The current list of Sub-Processors is maintained at the Sub-Processors List page.
b. Notification of Changes:
The Processor shall notify the Controller of any intended changes to the list of Sub-Processors (additions or replacements) at least 30 days in advance, providing the Controller the opportunity to object to such changes.
c. Right to Object:
If the Controller objects to a new Sub-Processor on reasonable data protection grounds within 15 days of receiving notice, the parties shall discuss the objection in good faith. If no resolution can be reached, the Controller may terminate the affected services without penalty.
d. Sub-Processor Agreements:
The Processor shall impose data protection obligations on each Sub-Processor that are no less protective than those set out in this DPA. The Processor remains fully liable to the Controller for the performance of each Sub-Processor's obligations.
6. Security Measures
The Processor shall implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
7. Data Breach Notification
a. The Processor shall notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting the Controller's data.
b. The notification shall include:
c. The Processor shall cooperate with the Controller and take reasonable steps to assist in the investigation, mitigation, and remediation of the breach.
8. Audits
a. The Processor shall make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA.
b. The Controller may conduct an audit of the Processor's compliance with this DPA, subject to the following conditions:
c. The Processor may satisfy audit requests by providing relevant compliance certifications, audit reports, or other documentation that reasonably demonstrates compliance.
9. International Data Transfers
a. Personal Data may be transferred to and processed in jurisdictions outside the Controller's country, including countries where the Processor's Sub-Processors operate.
b. For transfers of Personal Data from the EU/EEA/UK to countries not recognized as providing adequate data protection, the Processor shall ensure that appropriate safeguards are in place, including:
c. The Processor shall comply with the requirements of the Law of the Republic of Belarus "On Personal Data" regarding cross-border data transfers where applicable.
10. Data Deletion and Return
a. Upon termination of the Client's subscription, the Processor shall:
b. The Controller may request export of their data prior to termination by contacting hello@1ma.ai.
c. The Processor may retain Personal Data to the extent required by applicable law, provided that such data is processed only for the purpose of compliance with legal obligations and is subject to appropriate confidentiality and security measures.
11. Liability
a. Each party's liability under this DPA is subject to the limitations set out in the Terms of Service.
b. The Controller is responsible for ensuring the lawfulness of processing instructions and for compliance with data protection obligations that apply to the Controller.
c. The Processor is responsible for processing Personal Data in accordance with the Controller's documented instructions and this DPA, and for ensuring that Sub-Processors comply with equivalent obligations.
12. Term and Termination
This DPA shall remain in effect for the duration of the Client's use of 1ma.ai services. It shall automatically terminate when the Client's subscription ends or is terminated. Obligations relating to confidentiality, data deletion, and liability shall survive termination.
13. Contact
For any questions or requests related to this DPA, contact us at:
ООО «1ма» 📧 hello@1ma.ai