We use cookies
We use cookies to ensure you get the best experience on our website. For more information on how we use cookies, please see our cookie policy.

Data Processing Agreement

Data Processing Agreement - 1ma.ai

Last Updated: March 5, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between ООО «1ма» ("1ma.ai", "Processor") and the entity or individual agreeing to the Terms of Service ("Client", "Controller").

This DPA applies to the extent that 1ma.ai processes personal data on behalf of the Client in the course of providing the services described in the Terms of Service.

1. Definitions

  • "Personal Data" means any information relating to an identified or identifiable natural person, as defined by applicable data protection laws (including GDPR Article 4(1)).
  • "Processing" means any operation performed on Personal Data, including collection, recording, storage, retrieval, use, disclosure, erasure, or destruction.
  • "Data Controller" or "Controller" means the Client, who determines the purposes and means of processing Personal Data.
  • "Data Processor" or "Processor" means 1ma.ai, who processes Personal Data on behalf of the Controller.
  • "Sub-Processor" means a third party engaged by the Processor to process Personal Data on behalf of the Controller.
  • "Data Subject" means the identified or identifiable natural person to whom Personal Data relates.
  • "Applicable Data Protection Law" means all applicable laws relating to data protection and privacy, including GDPR (EU) 2016/679, the Law of the Republic of Belarus "On Personal Data" (2021), and any other applicable regulations.

2. Scope and Roles

a. Roles:

The Client acts as the Data Controller. 1ma.ai acts as the Data Processor, processing Personal Data solely on the Controller's documented instructions and for the purpose of providing the agreed services.

b. Subject Matter and Duration:

This DPA applies to the processing of Personal Data as part of the 1ma.ai service for the duration of the Client's active subscription. Upon termination of the subscription, data processing ceases and data is handled as described in Section 10.

c. Categories of Data Subjects:

  • End-Users: individuals who send messages to the Client's Instagram Business Account
  • Client's employees and authorized users (managers) of the 1ma.ai platform

d. Types of Personal Data Processed:

  • Names, Instagram usernames, and profile information of End-Users
  • Message content (text, media attachments)
  • Message metadata (timestamps, message type, direction)
  • Instagram account identifiers and profile data
  • Product catalog data provided by the Client

e. Nature and Purpose of Processing:

  • Receiving, storing, and displaying Instagram messages and comments
  • Processing message content through AI technologies to generate automated responses
  • Performing text recognition on media content (images)
  • Storing and indexing product catalog data for AI-powered search
  • Providing conversation analytics and reporting
  • Sending responses via Instagram messaging API

3. Obligations of the Processor

1ma.ai shall:

a. Process Personal Data only on documented instructions from the Controller, unless required to do so by applicable law. If such a legal requirement exists, the Processor shall inform the Controller before processing (unless prohibited by law).

b. Ensure that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

c. Implement appropriate technical and organizational security measures as described in Section 6.

d. Engage Sub-Processors only in accordance with Section 5.

e. Assist the Controller, taking into account the nature of processing, in responding to requests from Data Subjects exercising their rights under applicable data protection laws.

f. Assist the Controller in ensuring compliance with obligations related to security of processing, notification of data breaches, data protection impact assessments, and prior consultation with supervisory authorities, taking into account the nature of processing and the information available to the Processor.

g. At the choice of the Controller, delete or return all Personal Data after the end of the provision of services, and delete existing copies unless applicable law requires storage.

h. Make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in this DPA and allow for and contribute to audits as described in Section 8.

i. Immediately inform the Controller if, in the Processor's opinion, an instruction infringes applicable data protection laws.

4. Obligations of the Controller

The Controller shall:

a. Ensure that the processing of Personal Data through the service has a valid legal basis under applicable data protection laws.

b. Inform End-Users (Data Subjects) about the processing of their personal data through the service, including the use of AI-powered automated messaging, in accordance with applicable transparency requirements.

c. Maintain an appropriate privacy policy that covers the processing of End-User data through the 1ma.ai service.

d. Ensure that instructions given to the Processor comply with applicable data protection laws.

e. Handle and respond to Data Subject requests, with the Processor's assistance as needed.

f. Notify the Processor promptly of any changes that may affect the Processor's ability to comply with applicable data protection laws.

5. Sub-Processors

a. General Authorization:

The Controller provides general written authorization for the Processor to engage Sub-Processors for the purpose of delivering the services. The current list of Sub-Processors is maintained at the Sub-Processors List page.

b. Notification of Changes:

The Processor shall notify the Controller of any intended changes to the list of Sub-Processors (additions or replacements) at least 30 days in advance, providing the Controller the opportunity to object to such changes.

c. Right to Object:

If the Controller objects to a new Sub-Processor on reasonable data protection grounds within 15 days of receiving notice, the parties shall discuss the objection in good faith. If no resolution can be reached, the Controller may terminate the affected services without penalty.

d. Sub-Processor Agreements:

The Processor shall impose data protection obligations on each Sub-Processor that are no less protective than those set out in this DPA. The Processor remains fully liable to the Controller for the performance of each Sub-Processor's obligations.

6. Security Measures

The Processor shall implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of Personal Data at rest and in transit (AES-256, TLS/HTTPS)
  • Row-level security policies ensuring data isolation between clients
  • Access controls and role-based permissions
  • Secure authentication mechanisms
  • Regular security assessments and monitoring
  • Incident response procedures
  • Secure deletion procedures for data no longer needed

7. Data Breach Notification

a. The Processor shall notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting the Controller's data.

b. The notification shall include:

  • A description of the nature of the breach, including categories and approximate number of Data Subjects and records affected
  • The name and contact details of the Processor's point of contact
  • A description of the likely consequences of the breach
  • A description of the measures taken or proposed to address the breach and mitigate its effects

c. The Processor shall cooperate with the Controller and take reasonable steps to assist in the investigation, mitigation, and remediation of the breach.

8. Audits

a. The Processor shall make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA.

b. The Controller may conduct an audit of the Processor's compliance with this DPA, subject to the following conditions:

  • The Controller shall provide at least 30 days prior written notice
  • Audits shall be conducted during normal business hours
  • Audits shall not unreasonably interfere with the Processor's operations
  • The Controller shall bear the costs of the audit
  • Audits shall be limited to once per calendar year, unless a data breach has occurred or a supervisory authority requires an additional audit
  • The Controller shall treat all information obtained during the audit as confidential

c. The Processor may satisfy audit requests by providing relevant compliance certifications, audit reports, or other documentation that reasonably demonstrates compliance.

9. International Data Transfers

a. Personal Data may be transferred to and processed in jurisdictions outside the Controller's country, including countries where the Processor's Sub-Processors operate.

b. For transfers of Personal Data from the EU/EEA/UK to countries not recognized as providing adequate data protection, the Processor shall ensure that appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Binding data processing agreements with Sub-Processors
  • Supplementary technical and organizational measures as needed

c. The Processor shall comply with the requirements of the Law of the Republic of Belarus "On Personal Data" regarding cross-border data transfers where applicable.

10. Data Deletion and Return

a. Upon termination of the Client's subscription, the Processor shall:

  • Cease processing Personal Data within 24 hours of termination
  • Delete all Personal Data within 30 days of termination
  • Provide confirmation of deletion upon the Controller's request

b. The Controller may request export of their data prior to termination by contacting hello@1ma.ai.

c. The Processor may retain Personal Data to the extent required by applicable law, provided that such data is processed only for the purpose of compliance with legal obligations and is subject to appropriate confidentiality and security measures.

11. Liability

a. Each party's liability under this DPA is subject to the limitations set out in the Terms of Service.

b. The Controller is responsible for ensuring the lawfulness of processing instructions and for compliance with data protection obligations that apply to the Controller.

c. The Processor is responsible for processing Personal Data in accordance with the Controller's documented instructions and this DPA, and for ensuring that Sub-Processors comply with equivalent obligations.

12. Term and Termination

This DPA shall remain in effect for the duration of the Client's use of 1ma.ai services. It shall automatically terminate when the Client's subscription ends or is terminated. Obligations relating to confidentiality, data deletion, and liability shall survive termination.

13. Contact

For any questions or requests related to this DPA, contact us at:

ООО «1ма» 📧 hello@1ma.ai