DATA PROCESSING ADDENDUM (DPA)
Last Updated: September 4, 2026
This Data Processing Addendum (“DPA”) supplements the AIdeaBlocks Terms of Service (the “Agreement”) entered into by and between AIdeaBlocks (“Data Processor” or “AIdeaBlocks”) and the entity agreeing to the Terms of Service (“Data Controller” or “Customer”).
This DPA governs the processing of Personal Data in connection with Customer’s access to and use of the AIdeaBlocks Platform, including subscriptions provisioned via Google Cloud Marketplace.
1. DEFINITIONS
- “Applicable Data Protection Law” means all laws and regulations applicable to the processing of Personal Data under the Agreement, including, without limitation, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA/CPRA”), the European Union General Data Protection Regulation (“EU GDPR”), and the UK General Data Protection Regulation (“UK GDPR”).
- “Customer Data” means any primary enterprise data, text, files, or content uploaded, connected, or processed through the Services by or on behalf of Customer.
- “Metadata” means platform telemetry, configuration settings, audit logs, user credentials, and administrative parameters maintained strictly to operate, secure, and monitor the Services.
- “Personal Data” means any information processed by AIdeaBlocks on behalf of Customer that identifies or relates to an identified or identifiable natural person, or as defined under Applicable Data Protection Law.
- “Security Incident” means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Metadata or Personal Data processed by AIdeaBlocks.
2. ROLES & PROCESSING SCOPE
2.1 Roles of the Parties
The parties acknowledge and agree that with respect to the processing of Personal Data:
- Customer is the Data Controller (or “Business” under CCPA).
- AIdeaBlocks is the Data Processor (or “Service Provider” under CCPA).
2.2 Scope and Purpose of Processing
AIdeaBlocks shall process Personal Data solely for the limited and specified business purposes of providing, securing, and supporting the Services in accordance with Customer’s documented instructions, the Agreement, this DPA, and Google Cloud Marketplace entitlement agreements.
2.3 CCPA/CPRA Specific Commitments
AIdeaBlocks certifies that it understands and will comply with all obligations under the CCPA/CPRA. AIdeaBlocks shall not:
- “Sell” or “share” (as defined under CCPA) Customer Personal Data;
- Retain, use, or disclose Customer Personal Data for any purpose other than the specific business purposes specified in the Agreement;
- Retain, use, or disclose Customer Personal Data outside of the direct business relationship between Customer and AIdeaBlocks;
- Combine Customer Personal Data with personal data received from or on behalf of another third party, except as expressly permitted under CCPA.
3. ARCHITECTURAL BOUNDARIES & NO MODEL TRAINING
3.1 Zero Primary Data Storage
AIdeaBlocks enforces a zero-storage architecture for Customer Data. Customer Data processed through the Platform passes through transient memory solely for real-time processing and execution and is never saved, cached, or permanently stored on AIdeaBlocks infrastructure.
3.2 Tenant Isolation for Metadata
Any Personal Data contained within platform Metadata (e.g., user email addresses, account IDs, and audit logs) is segregated and stored strictly within isolated storage buckets dedicated exclusively to Customer’s tenant account.
3.3 Strict AI Model Training Prohibition
AIdeaBlocks shall never use Customer Data, Metadata, queries, prompts, or generated outputs to train, retrain, fine-tune, or validate any public, foundational, proprietary, or multi-tenant artificial intelligence or machine learning models.
4. TECHNICAL AND ORGANIZATIONAL SECURITY MEASURES
4.1 Security Standards
AIdeaBlocks shall implement and maintain appropriate technical, physical, and organizational security measures designed to protect Personal Data against Security Incidents. These measures include, but are not limited to:
- Encryption: Encryption of Metadata in transit using TLS 1.3 (or higher) and at rest using AES-256 bit encryption.
- Access Controls: Enforcing strict Role-Based Access Control (RBAC), multi-factor authentication (MFA), and the principle of least privilege for AIdeaBlocks personnel.
- Isolation: Logical tenant separation ensuring Customer Metadata cannot be accessed by other tenants or unauthorized entities.
4.2 Personnel Confidentiality
AIdeaBlocks ensures that all employees and contractors authorized to process Personal Data are subject to strict contractual confidentiality obligations and regular data privacy training.
5. SUB-PROCESSORS
5.1 Authorized Sub-processors
Customer grants general authorization to AIdeaBlocks to engage third-party sub-processors (such as cloud infrastructure providers, including Google Cloud Platform) to assist in rendering the Services.
5.2 Sub-processor Obligations
AIdeaBlocks shall:
- Impose data protection terms on any sub-processor that offer at least the same level of protection as those set forth in this DPA;
- Remain fully liable to Customer for the performance of each sub-processor’s obligations.
6. SECURITY INCIDENT NOTIFICATION & SUPPORT
6.1 Incident Notification
In the event of a confirmed Security Incident affecting Customer Personal Data or Metadata, AIdeaBlocks shall notify Customer without undue delay (and in no event later than 48 hours after becoming aware of the incident) via email to support@aideablocks.com or Customer’s primary administrative account email.
6.2 Assistance
AIdeaBlocks shall provide reasonable assistance and information to Customer to enable Customer to fulfill its obligations regarding incident response, data protection impact assessments (DPIAs), and notifications to regulatory authorities or affected individuals under Applicable Data Protection Law.
7. DATA SUBJECT RIGHTS
AIdeaBlocks shall, to the extent legally permitted, promptly notify Customer if it receives a request directly from a Data Subject (such as a request to access, correct, or delete Personal Data). AIdeaBlocks shall not respond to such requests directly except on Customer’s documented instructions or as required by Applicable Data Protection Law. AIdeaBlocks will provide reasonable technical support to assist Customer in fulfilling Data Subject requests.
8. DATA RETURN & DELETION
Upon termination or expiration of the Agreement or customer subscription:
- Primary Customer Data remains solely on Customer’s own managed systems.
- AIdeaBlocks shall automatically and permanently delete all associated Customer Metadata and any cached Personal Data from its isolated tenant buckets within thirty (30) calendar days following termination, unless retention is strictly required by applicable legal obligations.
9. INTERNATIONAL DATA TRANSFERS
To the extent that processing involves the transfer of Personal Data originating from the European Economic Area (EEA), the United Kingdom, or Switzerland to countries outside those regions, the parties agree that such transfers shall be governed by the standard contractual clauses (SCCs) approved by the European Commission or equivalent UK transfer mechanisms, which are hereby incorporated by reference.
10. CONTACT & GOVERNING LAW
This DPA is governed by the choice of law and jurisdiction specified in the Agreement (State of California), without giving effect to conflict of law principles.
Data Processor Contact:
AIdeaBlocks
Attn: Privacy & Security Team
Email: support@aideablocks.com
