Firebird Solutions Limited · NZBN 9463794 · Auckland, New Zealand
Draft — pending final legal review. The effective date is set when this document is finalised. Feedback: [email protected].
Version: 1.0 Effective date: draft — effective date set on publication
DRAFT — NOT LEGAL ADVICE. A DPA is a contract you will be held to by regulators and by customers' procurement teams. Have this one reviewed before offering it. Do not offer a DPA until the subprocessor list is complete and the deletion mechanism in section 10 matches what the platform actually does.
This Data Processing Addendum ("DPA") forms part of the Atamaia Terms of Service between Firebird Solutions Limited ("Atamaia", "Processor") and the customer agreeing to those Terms ("Customer", "Controller").
It applies where Atamaia processes Personal Data on the Customer's behalf and that processing is subject to Data Protection Law.
How to accept: this DPA applies automatically to any customer processing Personal Data subject to Data Protection Law in the Hosted Service, on any plan including the free plan. GDPR Art. 28 requires a written processor contract regardless of whether the customer pays. If you require a signed copy, email [email protected].
"Data Protection Law" — the New Zealand Privacy Act 2020; the EU General Data Protection Regulation 2016/679 ("GDPR"); the UK GDPR and Data Protection Act 2018; the Australian Privacy Act 1988; the California Consumer Privacy Act as amended; and any other applicable privacy law.
"Personal Data" — personal information or personal data within Customer Content, as defined under Data Protection Law.
"Data Subject", "Processing", "Controller", "Processor", "Supervisory Authority" — as defined in the GDPR, and their equivalents under other Data Protection Law.
"Security Incident" — a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data processed by Atamaia.
"Standard Contractual Clauses" / "SCCs" — the clauses annexed to European Commission Implementing Decision (EU) 2021/914.
2.1 For Personal Data within Customer Content, the Customer is the Controller and Atamaia is the Processor.
2.2 For account, billing and request telemetry data described in the Privacy Policy as controller data, Atamaia is a Controller in its own right, and this DPA does not apply to that processing.
2.2A Agent execution traces are an exception and are treated as Customer Content, not as controller telemetry, because they can contain the substance of Personal Data — tool call arguments and model requests and responses. Atamaia processes them as Processor under this DPA, and they are subject to sections 3, 7, 9 and 10 in full. ⚠️ This has an engineering consequence: agent traces are currently append-only and permanent. Section 10's deletion obligation cannot be met for them without a purge path. See open decisions #1.
2.3 Where the Customer is itself a processor for a third-party controller, the Customer warrants it has authority to instruct Atamaia as set out in this DPA, and Atamaia is a subprocessor.
3.1 Atamaia will process Personal Data only:
3.2 Atamaia will not:
3.3 Atamaia will inform the Customer if, in its opinion, an instruction infringes Data Protection Law.
| Subject matter | Provision of the hosted Atamaia AI identity, memory and context management service |
| Duration | For the term of the Terms, plus the retention period in section 10 |
| Nature and purpose | Storage, retrieval, indexing, embedding for search, graph relationship construction, transmission, backup, and — where the Customer enables agent features — execution of Customer-configured agent workflows |
| Types of Personal Data | Determined by the Customer. May include names, contact details, identifiers, and any personal information the Customer or its AI identities place into memories, facts, documents, tasks, messages or identity configurations |
| Special categories | Determined by the Customer. The Customer must establish the Art. 9 condition and comply with section 5.4 |
| Categories of Data Subject | Determined by the Customer. Typically the Customer's personnel, and any individuals referred to in Customer Content |
| Frequency | Continuous, on the Customer's instruction |
5.1 The Customer warrants that it has a lawful basis for the Personal Data it places into the Hosted Service, and has given all notices and obtained all consents required.
5.2 The Customer is responsible for the accuracy and lawfulness of Personal Data it provides, and for its own compliance with Data Protection Law.
5.3 The Customer is responsible for configuring access controls — roles, organisational units and group membership — appropriately, and for the actions of users it admits to its tenant.
5.4 The Customer must not place into the Hosted Service any data listed in section 3 of the Acceptable Use Policy — in particular HIPAA-regulated protected health information, cardholder data, or government identity credentials. Atamaia's security measures are not designed or certified for those regimes.
Atamaia will ensure that personnel authorised to process Personal Data are bound by confidentiality obligations and are granted access only where necessary for their role. {{TRAINING — a data protection training warranty is standard and expected under GDPR Art. 28(3)(b), but only include it if it is true and documentable. For a one- or two-person operation, "personnel are bound by written confidentiality obligations and are briefed on their data protection responsibilities" is honest and sufficient.}}
7.1 Atamaia implements appropriate technical and organisational measures under GDPR Art. 32, described in Annex A and in Privacy Policy section 7. These include, at rest, AES-256-GCM encryption with per-tenant key derivation of integration credentials and provider API keys (connector connection strings, model-provider credentials, OAuth client secrets and PKCE verifiers), and full-volume at-rest encryption of the database storage; TLS 1.2+ in transit; tenant isolation enforced at the data layer; role-based access control; and audit logging of consequential actions. Content of memories, facts, documents, tasks, messages and agent traces is stored on volume-encrypted storage of hardware we operate in New Zealand and is NOT additionally field-encrypted as at the effective date; field-level encryption of content is on the roadmap (taking into account its interaction with full-text search). We state this precisely rather than warrant more than is true.
**Personnel are bound by written confidentiality obligations and receive security training before access is granted; for a two-person operation, the training is documented internally and refreshes annually.
7.2 Atamaia may update these measures provided the level of protection is not reduced.
7.3 Security Incidents. Atamaia will notify the Customer without undue delay of becoming aware of a Security Incident affecting the Customer's Personal Data.
⚠️ A fixed 48-hour clock was drafted here and removed. GDPR requires only "without undue delay" of a processor; committing to a hard deadline is a self-imposed obligation with no benefit, and it presupposes monitoring, alerting and an on-call path that we use no third-party error-monitoring or performance-monitoring service being blank suggests may not exist yet. Reinstate a hard number once incident detection is real — enterprise customers do ask for one, and 72 hours is the defensible answer.
The notification will describe the nature of the incident, the categories and approximate volume of data affected so far as known, the likely consequences, the measures taken or proposed, and a contact point. Atamaia will provide reasonable cooperation to help the Customer meet its own notification obligations.
7.4 Notification is not an admission of fault or liability.
8.1 The Customer gives general authorisation for Atamaia to engage the subprocessors listed at /subprocessors.
8.2 Atamaia will give at least 30 days' notice before engaging a new subprocessor that will process Customer Content, whether or not that content contains Personal Data.
8.3 The Customer may object within that period on reasonable data protection grounds. The parties will discuss in good faith. If the objection cannot be resolved, the Customer may terminate the affected part of the Hosted Service and receive a pro-rata refund of prepaid fees.
8.4 Atamaia will impose on each subprocessor obligations no less protective than those in this DPA, and remains liable to the Customer for each subprocessor's performance as if it were Atamaia's own, subject to section 13.1.
8.5 External Providers. Where the Customer configures a third-party AI model, embedding or inference provider using its own credentials, that provider is engaged by the Customer, not by Atamaia. It is not an Atamaia subprocessor, Atamaia gives no warranty in respect of it, and the Customer is responsible for its lawful basis, transfer mechanism and contractual terms with that provider.
9.1 The Hosted Service gives the Customer direct ability to access, correct, export and delete Personal Data through the API and dashboard. The Customer should use these first.
9.2 Where the Customer cannot fulfil a request through the service, Atamaia will provide reasonable assistance, taking into account the nature of the processing.
9.3 If Atamaia receives a request directly from a Data Subject relating to the Customer's Personal Data, it will not respond substantively and will forward the request to the Customer without undue delay.
9.4 Atamaia will provide reasonable assistance with data protection impact assessments and prior consultations under GDPR Arts. 35–36, taking into account the information available to it.
9.5 Atamaia may charge a reasonable fee for assistance that is excessive or repetitive, after telling the Customer in advance.
10.1 At the end of the provision of services, the Customer may elect that Atamaia either delete or return all Personal Data, as GDPR Art. 28(3)(g) requires. The Customer may also export Personal Data itself at any time through the API or dashboard; self-service export does not displace the election in this clause.
10.2 On termination of the agreement or on account close, we will delete or return all Personal Data — including the content of the customer's AI identities — by an irreversible cascade purge, within 30 days of the effective termination date (immediately for paid accounts electing immediate purge), preceded by an offer of full export. Backups roll off their 30-day retention cycle. A deletion receipt is provided. In-life deletions remain recoverable by design (Privacy Policy 8.2). This clause takes effect only when the account-close purge mechanism ships; the DPA is not offered to customers before then.
10.3 Atamaia may retain Personal Data where required by law, for the period required, and will continue to protect it under this DPA for as long as it is retained.
10.4 Personal Data in backups is deleted on the backup rotation cycle described in Privacy Policy section 8.
11.1 Atamaia will make available information reasonably necessary to demonstrate compliance with this DPA.
11.2 Where the Customer reasonably requires an audit, Atamaia will first provide any relevant third-party audit reports or certifications it holds. none available at publication; internal audit records exist and are available on reasonable request under the DPA
11.3 If those are insufficient, the Customer may conduct an audit no more than once in any 12-month period, on at least 30 days' written notice, during business hours, subject to confidentiality, without unreasonably disrupting operations, and at the Customer's cost — unless the audit reveals material non-compliance, in which case Atamaia bears the reasonable cost.
11.4 Audits must not access other customers' data or compromise tenant isolation.
12.1 Where Atamaia transfers Personal Data out of the EEA or UK, the parties agree that the Standard Contractual Clauses are incorporated into this DPA and apply, with:
12.2 For UK transfers, the International Data Transfer Addendum (version B1.0) applies to the SCCs, with Tables 1–4 completed from this DPA and the importer's ending of the Addendum permitted under Section 19.
12.3 For transfers out of New Zealand, Atamaia complies with IPP 12 of the Privacy Act 2020 by ensuring recipients are subject to comparable safeguards through contract.
12.4 If a transfer mechanism is invalidated, the parties will negotiate an alternative in good faith.
13.1 Each party's liability under this DPA is subject to the limitations and exclusions in section 18 of the Terms, except where Data Protection Law does not permit that limitation.
⚠️ This needs a commercial decision before the DPA is offered. Terms §18 caps aggregate liability at the greater of three months' fees or NZ$100. For a NZ$30/month customer that is NZ$100 for a data breach affecting everything they have ever stored. No enterprise procurement team will accept it, and SCC Clause 12 does not permit it as against data subjects in any event, so §13.3 partially defeats it already. The usual answer is a super-cap for data protection breaches — e.g. 12 months' fees, or a fixed floor of NZ$25,000–50,000 — negotiated per enterprise deal. See open decisions #6.
13.2 In the event of conflict, this DPA prevails over the Terms in respect of the processing of Personal Data, and section 1 of the Terms is to be read accordingly. For all other matters the Terms prevail.
13.3 Where the SCCs apply and conflict with this DPA, the SCCs prevail.
13.4 Governing law. This DPA is governed by the laws of New Zealand and the courts of New Zealand have non-exclusive jurisdiction, except that Clauses 17 and 18 of the SCCs govern where the SCCs apply. {{Align with Terms §22 once the contracting entity is settled — open decisions #4.}}
This DPA takes effect when the Customer accepts the Terms and continues until Atamaia ceases all processing of Personal Data on the Customer's behalf.
| Measure | Implementation |
|---|---|
| Encryption at rest | AES-256-GCM with per-tenant key derivation for memory content ⚠️ confirm scope |
| Encryption in transit | TLS for all connections |
| Tenant isolation | Enforced at the data layer as a global filter, not per-query |
| Access control | Role-based access control; organisational unit tree; group membership on resources; separately gated administrative permissions |
| Authentication | Password hashing; JWT sessions; individually revocable scoped API keys |
| Audit logging | Consequential actions attributed to user and API key; append-only |
| Personnel | Confidentiality obligations; access on a need-to-know basis |
| Backups | Encrypted; rotation per Privacy Policy section 8 |
| Incident response | Triage and notification per section 7.3. internal alerting on application errors; no third-party monitoring |
| Subprocessor management | Written contracts; documented register; 30 days' notice of change |
| Business continuity | daily encrypted database backups with 30-day retention on our own hardware; a verified restore test runs weekly |
| Certifications | none — we host on our own hardware and hold no certifications; we will state this plainly rather than imply otherwise |