This Data Processing Agreement ("DPA") forms part of our Terms of Service between you ("Customer") and the DiscoveredBy provider named in section 1 of the Terms ("we" or "us"). It applies automatically, with no signature needed. If you need a signed copy for your records, email hello@discoveredby.ai.
1. Scope and roles
This DPA applies when we process personal data on your behalf in providing the Service ("Customer Personal Data"). For Customer Personal Data, you are the controller (or a processor acting for your own client) and we are your processor (or subprocessor). Under India's Digital Personal Data Protection Act 2023, you are the data fiduciary and we are your data processor; under the CCPA, we are your service provider. Personal data we handle for our own purposes, such as your account and billing, is covered by our Privacy Policy instead.
"Data Protection Law" means every law that applies to the processing of Customer Personal Data under the Terms, including the GDPR, the UK GDPR, the DPDP Act and US state privacy laws.
2. Your instructions
We process Customer Personal Data only on your documented instructions. The Terms, this DPA, and how you configure and use the Service are your complete instructions. We will tell you if we believe an instruction breaks Data Protection Law, unless the law prevents us. You are responsible for having a lawful basis for the data you put into the Service, and for any notices and consents it needs.
3. Our people
Everyone at DiscoveredBy who can access Customer Personal Data is bound by confidentiality, and accesses it only to provide, support or secure the Service.
4. Security
We maintain the technical and organisational measures in Annex 2, and we may improve them over time as long as the overall level of protection does not go down.
5. Personal data breaches
If we become aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data, we will notify you without undue delay. We will tell you what we know about its nature, the data and people affected, its likely consequences and the steps we are taking, and keep you updated as we learn more. Notifying you is not an admission of fault.
6. Subprocessors
You authorise us to use the subprocessors listed on our subprocessors page. We impose data protection obligations on each subprocessor as Data Protection Law requires, and we remain responsible for their performance.
We will notify you at least 30 days before a new subprocessor starts processing Customer Personal Data, or as soon as we can where a change is urgent to keep the Service running or secure. You may object on reasonable data protection grounds within that period. If we cannot address your objection, you may cancel the affected Service before the change takes effect.
7. Helping you meet your obligations
Taking into account the nature of the processing, we will help you:
- respond to requests from people exercising their rights; if we receive one directly, we will pass it to you and not answer it ourselves;
- carry out data protection impact assessments and consult supervisory authorities, where the processing requires it; and
- meet your own security and breach notification obligations.
8. International transfers
Our main servers are in Helsinki, Finland (European Union). Customer Personal Data is also processed in India, the United Arab Emirates and the United States, and wherever our subprocessors are located.
Where Customer Personal Data protected by the GDPR is transferred to a country without an adequacy decision, the Standard Contractual Clauses adopted by the European Commission in Decision (EU) 2021/914 are incorporated into this DPA: Module 2 where you are a controller and Module 3 where you are a processor. For those Clauses: Clause 7 does not apply; under Clause 9 option 2 applies, with the notice period in section 6; the optional wording in Clause 11 does not apply; Clauses 17 and 18 are governed by the law and courts of Ireland; and Annexes I and II are Annexes 1 and 2 below. For data protected by the UK GDPR, the UK International Data Transfer Addendum applies, with these Clauses as its Approved EU SCCs.
9. California and other US state laws
We will not sell or share Customer Personal Data, retain, use or disclose it for any purpose other than providing the Service, or combine it with personal data we receive from anyone else, except as those laws permit. We certify that we understand and will comply with these restrictions.
10. Return and deletion
On paid plans you can export your prompts, answers, citations and metrics from the app at any time, and on any plan you can ask us for a copy of Customer Personal Data. When you ask us to, during the agreement or after it ends, we will delete Customer Personal Data within 30 days, unless the law requires us to keep it. Copies in our database backups are overwritten within 7 days after that.
11. Audits
We will make available the information you reasonably need to show compliance with this DPA. If that is not enough, you or an independent auditor bound by confidentiality may audit our compliance once in any 12 months, with at least 30 days' notice, at your cost, during business hours and without disrupting other customers. A supervisory authority may audit as the law allows.
12. General
This DPA lasts as long as we process Customer Personal Data for you. If it conflicts with the Terms, this DPA wins; if it conflicts with the Standard Contractual Clauses, the Clauses win. Each party's liability under this DPA is subject to the limits in the Terms, except where Data Protection Law or the Clauses do not allow it.
Annex 1: Description of the processing
- Data exporter: the Customer, as identified in its DiscoveredBy account or order form.
- Data importer: the provider named in section 1 of the Terms; by default MicroPyramid Informatics Private Limited, HIG499, Viswa Sai Dham, behind Anupama Hospital, 6th Phase KPHB, Hyderabad, Telangana 500072, India. Contact: hello@discoveredby.ai.
- People whose data is processed: the Customer's users and invited team members; people the Customer names in prompts, personas, facts or project details; and people whose requests appear in server logs the Customer sends for crawler analytics.
- Personal data processed: names, email addresses and roles of users and invitees; IP addresses and browser details in sign-in and activity records; any personal data the Customer puts in prompts, personas, facts or project details; and server log lines, which we read only to keep requests from known crawlers and do not store for anyone else.
- Sensitive data: none is intended. The Customer must not put special category data in the Service.
- Frequency: continuous, for as long as the Customer uses the Service.
- Nature and purpose: hosting and storage; sending prompts to AI engines and storing their answers; analysing answers, imported analytics and crawler logs; and producing reports, alerts, recommendations and drafts for the Customer.
- Duration: the term of the Terms, plus the deletion period in section 10.
- Subprocessors: as listed on our subprocessors page, for the purposes stated there.
- Competent supervisory authority: as determined by Clause 13 of the Standard Contractual Clauses, based on the Customer's establishment.
Annex 2: Technical and organisational measures
Access control
- Role-based access (owner, editor, viewer) is checked on every API request, and each customer can reach only its own projects.
- Access is refused unless it has been explicitly granted.
- When staff need to sign in to a customer account to resolve a support request, the sign-in link they create is recorded in an audit log.
- Important actions in a project are recorded in an activity log.
Authentication
- No passwords: users sign in with a single-use email link that expires after 15 minutes and works only in the browser that asked for it, or with Google.
- Sign-in attempts are rate-limited by email address and by IP address.
- Session cookies are http-only, secure and same-site; signing out ends every session for that user.
Encryption and secrets
- All traffic to the app, the API and this website is encrypted with TLS.
- Google refresh tokens and WordPress application passwords are encrypted before they are stored.
- Sign-in links, invitations, API keys and report share links are stored only as one-way hashes.
- Secrets, tokens and full personal data are kept out of application logs.
Application security
- Request bodies and parameters are validated against a schema or a strict parser; database queries use bound parameters.
- Internal errors are never returned to clients.
- Pages we fetch for site audits can reach only public internet addresses.
- Integrations with Google use read-only access.
Infrastructure and availability
- Servers are hosted by Hetzner in Helsinki, Finland (European Union), and services run with restricted system privileges.
- The database is backed up daily, and backups are kept for 7 days.
Vulnerability management
- Security reports are accepted as described on our security page.