Back to Trust Center
Effective: 2026-07-23

Data Processing Agreement (DPA) — ISMS Copilot

Overview

This Data Processing Agreement ("DPA") forms part of the terms of service between you (the "Customer" or "Data Controller") and ISMS Copilot (the "Processor" or "Data Processor") for the use of the ISMS Copilot AI compliance platform. This DPA complies with Article 28 of the General Data Protection Regulation (GDPR) and governs the processing of personal data on behalf of the Customer.

Effective Date: 2026-07-23. For the revision history of this document, see Appendix B (Change Log).

This DPA automatically applies to all ISMS Copilot customers processing personal data through the platform. No separate signature is required — your use of the service constitutes acceptance.

Who This Is For

This Data Processing Agreement is for:

  • Organizations using ISMS Copilot to process personal data
  • Compliance consultants handling client data through the platform
  • Data Protection Officers conducting vendor assessments
  • Legal and procurement teams evaluating data processing arrangements
  • Auditors reviewing GDPR Article 28 compliance

Definitions

  • "Customer" or "Data Controller": The organization or individual subscribing to ISMS Copilot services and determining the purposes and means of processing personal data.
  • "Processor" or "Data Processor": ISMS Copilot, processing personal data on behalf of the Customer.
  • "Customer Personal Data": Any personal data processed by ISMS Copilot on behalf of the Customer, including conversation content, uploaded documents, and associated metadata.
  • "Sub-processor": Any third-party processor engaged by ISMS Copilot to process Customer Personal Data.
  • "Data Subject": The identified or identifiable natural person to whom Customer Personal Data relates.
  • "Processing": Any operation performed on personal data, including collection, storage, use, disclosure, or deletion.
  • "Personal Data Breach": A breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data.
  • "Default AI Routing Path": AI processing for a request when Advanced Data Protection Mode is not enabled, served within the non-ADP routing envelope described in §3.1 (Anthropic and the OpenRouter allowlist, with Mistral as circuit-breaker failover). It does not refer to any single provider that is the current default within that envelope.
  • "Advanced Data Protection Mode" (ADP): The account- or organization-level setting that routes all AI processing to Mistral AI (EU, Frankfurt) with zero retention, bypassing the OpenRouter routing path and the Default AI Routing Path.

1. Scope and Applicability

1.1 Application of DPA

This DPA applies to all processing of Customer Personal Data by ISMS Copilot in the course of providing the platform services described in the Terms of Service.

1.2 Subject Matter of Processing

ISMS Copilot processes Customer Personal Data to provide AI-powered compliance assistance, including:

  • Processing user queries and generating AI responses
  • Storing conversation history and context
  • Analyzing uploaded compliance documents
  • Maintaining workspace configurations and custom instructions
  • Automated content moderation of chat messages (see §2.8 for retention)
  • Classifying whether an eligible authenticated request requires current external information and, where permitted by Customer settings and policy, retrieving request-scoped web evidence or the exact public URL supplied by the user
  • For paid Customers whose organization owner has installed the heygrc Slack bot: receiving messages addressed to the bot from the Customer's Slack workspace, processing them through the same AI pipeline as web chat, and posting AI responses back to the workspace

1.3 Duration of Processing

Processing continues for the duration of the Customer's active subscription and according to the Customer's configured data retention period (1 day to 7 years, or "keep forever"). Upon termination, all Customer Personal Data is deleted within 30 days unless longer retention is required by law or by §2.8 (moderation retention exception).

1.4 Nature and Purpose of Processing

  • Nature: Automated processing using AI models, database storage, file processing, and content moderation
  • Purpose: Provide compliance guidance, document analysis, policy generation, and knowledge management as instructed by the Customer

1.5 Categories of Data Subjects

  • Customer's employees and authorized users
  • Customer's clients and end-users (when mentioned in uploaded documents or queries)
  • Individuals referenced in compliance documentation
  • Security incident subjects
  • Slack workspace users (heygrc bot only): members of the Customer's Slack workspace who interact with the heygrc bot. These users typically do not hold an ISMS Copilot account; their messages addressed to the bot are processed under the Customer's organization (Slack-originated traffic rolls up to the organization owner for billing and quota purposes, and inherits the organization's Advanced Data Protection setting). Customer remains responsible for informing its Slack workspace users that messages addressed to the bot are processed by ISMS Copilot.

1.6 Categories of Personal Data

  • User account information (email addresses, authentication credentials)
  • Conversation content and AI interactions
  • Uploaded document content (policies, procedures, audit reports)
  • Workspace configurations and custom instructions
  • Usage metadata and timestamps
  • Special category data (Article 9 GDPR) and personal data relating to criminal convictions and offences (Article 10 GDPR) may be incidentally present, but are excluded from instructed processing on the Default AI Routing Path; intended workloads require Advanced Data Protection Mode (§4.2)
  • Slack integration data (heygrc bot only, paid Customers who install): Slack workspace metadata (team ID, team name, bot user ID), the OAuth bot token issued by Slack, the installer's ISMS Copilot user ID (audit trail), Slack message content of messages addressed to the bot (DMs to heygrc or @heygrc channel mentions only — no other workspace messages are read), and Slack user identifiers (slack_user_id) of users who interact with the bot

Special category data (Article 9 GDPR) and criminal-offence data (Article 10 GDPR) are excluded from the instructed processing on the Default AI Routing Path (see §4.2). Customers with special-category or criminal-offence workloads must use Advanced Data Protection Mode (Mistral, EU). Customer is responsible for not submitting such data to the Default AI Routing Path and for any Article 9(2) condition or, for Article 10 data, the Article 6(1) basis and legal authorization with appropriate safeguards required by Article 10, applicable to its own processing.

2. Processor's Obligations (Article 28(3) GDPR)

2.1 Processing Instructions

ISMS Copilot shall process Customer Personal Data only on documented instructions from the Customer, including:

  • Instructions provided through the platform interface (queries, document uploads, workspace configurations)
  • The user's express request to search, the Customer's web-search policy, and the user's selected Beyond URL scope
  • Data retention settings configured by the Customer
  • Advanced Data Protection Mode selection (EU-only vs. default AI processing)
  • Deletion requests submitted through the platform or to privacy@ismscopilot.com

Independent-controller disclosures (safety and legal reporting). Notwithstanding the instruction-only rule above, where ISMS Copilot becomes aware through content moderation of a credible threat to a person's life or safety, a suspected serious crime, or specific high-severity illegal content that meets its reporting threshold (such as child sexual abuse material or terrorism), it may disclose limited personal data to law enforcement, judicial authorities, or emergency services on its own initiative, as required or permitted by law. For such disclosures ISMS Copilot acts as an independent controller, not as the Customer's processor. These disclosures are rare, decided by a person, minimised to what is necessary, and governed by an internal authority-reporting procedure. See also the moderation retention exception in §2.8.

Prohibited Processing. ISMS Copilot enforces the following prohibitions through layered contractual and account-level controls:

(a) No training of AI models on Customer Personal Data. Enforced via Anthropic's and Mistral's commercial API terms (which prohibit training on Customer Content), and via account-level "Free Training Disallowed" and "Paid Training Disallowed" flags at OpenRouter, applied to all eight allowlisted underlying providers (Inceptron, DeepInfra, Cerebras, Google Vertex, Together AI, Fireworks AI, Nebius, and xAI via the "xAI (ZDR)" endpoint), layered on xAI's published API no-training default for the Grok route.

(b) No publication of model outputs derived from Customer Personal Data. OpenRouter "Free Publication Disallowed" is set at the account level.

(c) Retention by AI sub-processors is minimized to the request lifetime where contractually possible. OpenRouter Zero Data Retention is mandatory at the account level - per OpenRouter's published policy, ZDR-mandatory accounts can only route to endpoints with a Zero Data Retention policy. Existing approved Mistral inference routes use the documented commercial zero-retention posture. That statement does not extend to Mistral's web-search feature. Mistral web search runs on Mistral's stateful Conversations/Agents endpoint, which Mistral excludes from its zero-retention posture, and uses Brave Search (Brave Software, Inc., United States) as its web-search sub-processor. A non-ADP authenticated search therefore sends a minimized latest-request query from Mistral (EU) to Brave (United States); that query hop is not EU-only and not zero-retention, and standard (non-zero) retention applies. For this reason authenticated web search is not available under Advanced Data Protection Mode: it fails closed. Under Anthropic's standard commercial API terms, inputs and outputs are ordinarily deleted within approximately 30 days, content flagged by its safety systems may be retained up to 2 years, and safety-classification scores up to 7 years; this data is not used for model training. Customers requiring confirmed EU processing and zero retention can enable Advanced Data Protection Mode to route permitted AI inference through Mistral's confirmed Frankfurt routes; authenticated web search then fails closed, while exact user-selected page/document fetch remains available through EU Fly.

(d) PRC-jurisdiction provider blocklist. Alibaba Cloud International, Baidu Qianfan, DeepSeek, Moonshot AI, Xiaomi, and Z.AI are all blocked at the OpenRouter account level. The control is jurisdiction-based and enforced through provider selection and the account-level blocklist: based on the reviewed published deployment documentation, none of the allowlisted providers was found to operate PRC or Hong Kong infrastructure, though OpenRouter does not pin the per-request inference region. This is a Schrems II–style supplementary measure aligned with EDPB Recommendations 01/2020.

If ISMS Copilot believes an instruction violates GDPR or other data protection laws, we will immediately inform the Customer and have the right to suspend processing until the instruction is confirmed or modified. If Customer confirms an instruction that ISMS Copilot reasonably believes violates applicable data protection law, ISMS Copilot may refuse to execute the instruction and, if the disagreement cannot be resolved, terminate the affected processing activities with 30 days notice.

2.2 Confidentiality of Processing

ISMS Copilot ensures that all persons authorized to process Customer Personal Data:

  • Are subject to confidentiality obligations (contractual or statutory)
  • Receive appropriate training on data protection
  • Access data only on a need-to-know basis
  • Follow documented data handling procedures

2.3 Technical and Organizational Measures (Article 32 GDPR)

ISMS Copilot implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

Access Control Measures:

  • Row-level security in database preventing cross-user data access
  • User authentication required for all protected resources
  • Workspace isolation preventing cross-contamination of client data
  • Multi-factor authentication (MFA) support
  • Automatic session timeout controls

Encryption Measures:

  • TLS 1.3 encryption for data in transit
  • Database encryption at rest
  • Password hashing using industry-standard algorithms (irreversible)
  • Encrypted file storage in Supabase

Data Minimization Measures:

  • Only essential data collected (email, messages, files)
  • No unnecessary demographic or contact information collected
  • Analytics configured with sendDefaultPii: false
  • Customer-controlled retention periods with automated deletion
  • Web-search queries are derived only from the latest user request, bounded to the selected provider's limits, and exclude files, memories, workspace context, account identifiers, and user/device identifiers; credentials and signed URLs fail closed
  • Mistral's generated search prose, raw discovery response, and request-scoped fetched page text are not persisted in conversation history, Beyond run records, detector telemetry, or application logs

Availability and Resilience:

  • Automated database backups
  • Disaster recovery procedures
  • 24/7 monitoring and alerting via Sentry
  • Real-time uptime monitoring via BetterStack with instant Slack alerting
  • Public status page for transparency (status.ismscopilot.com)
  • Progressive incident escalation via email and SMS
  • Multi-provider AI failover: Anthropic → Mistral via circuit breaker for any non-ADP traffic served by Anthropic; for the paid Fast/Think/Beyond routes now defaulting to xAI via the "xAI (ZDR)" endpoint, the pre-first-token failover order is xAI, then Anthropic (Opus for Think, Sonnet for Fast), then Mistral (EU) if Anthropic's circuit breaker is open; OpenRouter aggregator-level failover across the allowlisted providers for OpenRouter-served traffic (the Essential subset is Google Vertex and Cerebras; other non-ADP plans span the eight allowlisted providers)

Testing and Evaluation:

  • Regular security assessments
  • Continuous error monitoring and logging
  • Automated data deletion testing
  • Access control verification procedures

For detailed technical and organizational measures and the per-activity Article 30 processing inventory, refer to our Register of Processing Activities (RoPA).

2.4 Sub-processor Engagement

General Authorization. Customer provides general authorization for ISMS Copilot to engage sub-processors for the processing of Customer Personal Data, subject to the conditions in this section.

Active Sub-processors. The following sub-processors actively process Customer Personal Data:

Sub-processorRole / when invokedLocationDPA / Transfer mechanism
Supabase (PostgreSQL + Storage)Database and file storage (always)EU (Frankfurt)GDPR-compliant
AWSUnderlying infrastructure for SupabaseEU-Central-1 (Frankfurt)GDPR-compliant
Anthropic ClaudeAI processing for any non-ADP plan (ADP off), as one of the permitted non-ADP providers, and the circuit-breaker failover context. A non-ADP request may instead be served by the OpenRouter allowlist (see the OpenRouter row), for any chat mode. For paid plans (Plus and above) in the Fast and Think modes and the Beyond assistant, xAI (via the "xAI (ZDR)" endpoint) is the current default and Anthropic is the pre-first-token failover (Opus for Think, Sonnet for Fast); ISMS Copilot may serve any non-ADP paid request, in any mode, via any of the eight allowlisted providers or Anthropic and may move cohorts or modes between them over time (control-neutral under §2.4, publication-only)United StatesSCCs; no training under Anthropic's commercial API terms; retention under Anthropic's standard commercial API terms (ordinary ~30-day deletion; safety-flagged content up to 2 years; safety-classification scores up to 7 years; not training). Customers needing zero retention can enable Advanced Data Protection.
OpenRouter (routing aggregator)AI processing for free / null-plan users with ADP off (may route to any of the seven allowlisted glm-4.7 underlying providers below); for the Essential plan with ADP off (restricted to a closed two-provider subset: Google Vertex and Cerebras); and for paid plans (Plus, Standard, Pro, Business) with ADP off, where xAI via the "xAI (ZDR)" endpoint (the eighth allowlisted underlying provider below, serving the Grok models) is the current default destination for the chat Fast and Think modes and the Beyond assistant, with Anthropic retained as the automatic pre-first-token failover, and ISMS Copilot may serve any non-ADP paid request, in any chat mode, via any of the eight allowlisted underlying providers or Anthropic, and may move any cohort or mode between these destinations over time (such moves within the disclosed envelope are control-neutral under §2.4: no advance notice, publication-only)United StatesOpenRouter's role is account-level enforcement (mandatory ZDR, training-disallowed, allowlist, PRC-blocklist, see below); legal transfer mechanism for Customer Personal Data leaving the EU is anchored at the underlying-provider layer (per-provider rows below)
↳ Inceptron (Inceptron AB)OpenRouter underlying provider (allowlisted)Sweden (EU)SCCs (EU HQ, but OpenRouter does not pin inference region, so treated as a possible transfer); ZDR + no-training enforced via OpenRouter account config
↳ DeepInfraOpenRouter underlying provider (allowlisted)United StatesSCCs; ZDR + no-training enforced via OpenRouter account config
↳ CerebrasOpenRouter underlying provider (allowlisted)United StatesSCCs; ZDR + no-training enforced via OpenRouter account config
↳ Google VertexOpenRouter underlying provider (allowlisted)United StatesSCCs + EU-US Data Privacy Framework certification; ZDR + no-training enforced via OpenRouter account config
↳ Together AIOpenRouter underlying provider (allowlisted, added 2026-05-25)United States (default routing to North America inference data centers per Together docs; region pinning not exposed by OpenRouter)SCCs; ZDR + no-training enforced via OpenRouter account config; SOC 2 Type II; published DPA
↳ Fireworks AIOpenRouter underlying provider (allowlisted, added 2026-05-25)United States (multi-region fleet: US, EU Frankfurt + Iceland, APAC Tokyo only; no PRC or Hong Kong infrastructure identified in Fireworks' published deployment docs; region pinning not exposed by OpenRouter)SCCs; ZDR + no-training enforced via OpenRouter account config; SOC 2 Type II; published DPA
↳ NebiusOpenRouter underlying provider (allowlisted, added 2026-05-25)Netherlands HQ; primary inference in Finland (EU) with US secondary per Nebius docs (region pinning not exposed by OpenRouter)SCCs; ZDR + no-training enforced via OpenRouter account config; published DPA + sub-processor list
↳ xAI (X.AI LLC), "xAI (ZDR)" endpoint, serving the Grok modelsOpenRouter underlying provider (allowlisted). The default destination for paid plans (Plus and above), ADP off, for the chat Fast and Think modes and the Beyond assistant, replacing the prior Anthropic default; Anthropic is retained as the automatic pre-first-token failover context (Opus for Think, Sonnet for Fast). Not used for free / null-plan glm-4.7 routing or under Advanced Data ProtectionUnited States (OpenRouter-published provider footprint; OpenRouter does not pin the per-request inference region)SCCs at the underlying-provider layer via xAI's published DPA (EU SCCs, Modules 2/3, Irish-law), with OpenRouter Article 28(4) sub-processor flow-down; zero data retention as configured and verified 2026-07-19 (OpenRouter account-level ZDR via the "xAI (ZDR)" endpoint); no-training per the OpenRouter account-level training-disallowed setting layered on xAI's published API no-training default
Mistral AIAI processing for ADP users (any plan); circuit-breaker failover destination for paid Anthropic; content moderation for all users; conversation compaction; conversation summaries; search-intent classification; and provider-attested source-URL discovery for eligible ADP-off authenticated search. Mistral's generated search prose is discarded. Bounded exact-fetched evidence goes only to the answer provider already applicable to the conversation or Beyond run. Authenticated web search fails closed under ADPExisting Mistral inference, moderation, and summarization routes documented in Frankfurt (EU). For ADP-off authenticated search, Mistral's web-search discovery runs on Mistral's stateful Conversations/Agents endpoint, which is outside Mistral's zero-retention posture, and Mistral engages Brave Search (Brave Software, Inc., United States) as Mistral's own web-search sub-processor (see Mistral's published sub-processor list). That discovery path is therefore not EU-only and not zero-retentionExisting inference/moderation routes: EU residency, zero retention, no training under Mistral's commercial API terms. Mistral web search is excluded from that zero-retention posture; via Mistral's web-search chain the minimized query reaches Brave (US) under standard, non-zero retention per the applicable Mistral/Brave provider terms, so web-search discovery is disclosed as a US transfer via Mistral rather than an EU zero-retention route. ISMS Copilot does not separately engage Brave for this launch route: Brave is engaged by Mistral, as Mistral's sub-processor (see the sub-processor chain transparency note below).
StripePayment processingGlobal (EU DPA)GDPR-compliant; PCI DSS Level 1
ConvertAPIDocument format conversionEU endpointGDPR-compliant; ISO 27001:2022; signed DPA
PostHogProduct analyticsEU (Frankfurt)GDPR-compliant
SentryError monitoringGermanyGDPR-compliant
VercelFrontend hostingGlobal CDNGDPR-compliant
Fly.ioBackend API hosting, chat orchestration, and request-scoped exact fetching of user-submitted or Mistral-attested public URLsEU deploymentGDPR-compliant
SendGrid (Twilio)Transactional emailUnited StatesSCCs
Kit (ConvertKit)Onboarding emailUnited States

Every reference to ZDR / zero retention in the OpenRouter rows above is the account-level Zero Data Retention described in §3.1: no persistent retention of request content beyond serving the request; a provider may hold content transiently in memory for the duration of processing, as is inherent to serving an inference request. SCCs |

Sub-processor chain transparency (external recipient via Mistral). For the launch authenticated web-search route (ADP off), ISMS Copilot does not separately engage Brave and does not list Brave as one of its own Article 28 sub-processors. Brave Software, Inc. (United States) is engaged by Mistral as Mistral's own web-search sub-processor; the minimized latest-request query reaches Brave only through Mistral's web-search chain. Mistral publishes its own sub-processor list, which identifies Brave as its web-search sub-processor, and customers can review it there. For transparency, we disclose this onward Mistral (EU) to Brave (US) query hop as an external recipient reached via Mistral: it is not EU-only and not zero-retention, and standard, non-zero retention applies per the applicable Mistral/Brave provider terms. This launch route is distinct from the future Brave-direct route (see "Notified external search recipient" below), in which ISMS Copilot would itself call the Brave Search API; that route remains dark and carries its own 30-day advance-notice treatment.

User-directed feature (launch disclosure basis). Authenticated web search is a user-directed feature, not a change to baseline AI processing. It fires only on the user's own search intent, as determined by a conservative intent classifier applied to the user's latest request; it is disabled entirely under Advanced Data Protection Mode (it fails closed); it is controllable at both the organization and personal level through the Allow web search settings; and when a search runs it is shown to the user through an in-product provenance indicator. On that basis, ISMS Copilot discloses the launch (Mistral-mediated) web-search route at launch, through the Trust Center, this DPA, and the in-app changelog once the feature is live, as a user-directed, customer-controllable feature, rather than treating it as a change to baseline AI processing that would require 30 days' advance sub-processor notice. This rationale narrows, but does not eliminate, the interpretive question of whether the onward Mistral-to-Brave query hop should be treated as a new sub-processor path; the 30-day advance-notice mechanism continues to apply to the separate future Brave-direct route.

OpenRouter account-level controls (enforced by Better ISMS as the OpenRouter account holder, applied to every request, applicable to all eight allowlisted underlying providers):

  • Zero Data Retention is mandatory at the account level: per OpenRouter's published policy, ZDR-mandatory accounts can only route to endpoints with a Zero Data Retention policy. Zero Data Retention here means no persistent retention of request content beyond serving the request; a provider may still hold content transiently in memory for the duration of processing, as is inherent to serving an inference request.
  • Free Training Disallowed and Paid Training Disallowed are both set.
  • Free Publication Disallowed is set; the model-publication channel is closed.
  • Closed eight-provider allowlist. The seven glm-4.7 hosts (Inceptron, DeepInfra, Cerebras, Google Vertex, Together AI, Fireworks AI, and Nebius) plus xAI via the "xAI (ZDR)" endpoint for the Grok models may serve our requests. (The seven glm-4.7 hosts were expanded from 4 to 7 on 2026-05-25; xAI was activated for paid Customer-Content on 2026-07-21; see the customer-facing change log for the notices.)
  • PRC-jurisdiction blocklist — Alibaba Cloud International, Baidu Qianfan, DeepSeek, Moonshot AI, Xiaomi, and Z.AI are all blocked. This is a Schrems II–style supplementary measure aligned with EDPB Recommendations 01/2020.

Configuration-integrity caveat. OpenRouter account-level controls are configured per the policies above. Better ISMS does not currently rely on an OpenRouter API or signed attestation for real-time integrity. Evidence of the configuration is two-fold: (a) this DPA is itself a contemporaneous record of the configured controls as of its effective date, and (b) Better ISMS will demonstrate the live OpenRouter account configuration via a guided dashboard walkthrough on customer request (typically a recorded screen-share session). Ad-hoc screenshots may be captured on specific customer request or when controls materially change.

Notified external search recipient (future Brave-direct route), pending activation. This is a separate route from Brave's role as Mistral's web-search sub-processor above. At launch, SEARCH_RETRIEVAL_PROVIDER defaults to Mistral for eligible non-ADP discovery (Mistral in turn queries Brave), and the direct-Brave adapter (in which ISMS Copilot would call the Brave Search API itself, rather than reaching Brave via Mistral) remains dark. No earlier than 2026-08-12, and only after at least 30 days' actual notice plus founder contractual acceptance, eligible authenticated requests with ADP off may send a bounded query derived only from the latest user request directly to Brave Software, Inc. through the Brave Search API (United States; AWS infrastructure). ISMS Copilot would not send files, memories, workspace context, account identifiers, or user/device identifiers. Brave's standard API privacy notice states that query logs may be retained for up to 90 days; the transfer mechanism is the Standard Contractual Clauses. Brave's published DPA expressly excludes "Search Query Data" from its processor scope. We therefore disclose Brave as a limited external recipient and do not represent this query processing as covered by Brave's Article 28 processor terms. The Customer's decision to leave web search enabled under its plan and organization policy, together with the user's latest request or one-shot search preference, would be treated as the documented instruction for this limited disclosure; the conservative classifier would only determine whether that instruction requires current external evidence. We apply the materially-adverse-change notice and objection process below to this future recipient even though Brave's contractual classification for Search Query Data is not that of an Article 28 processor.

Customer-Activated Integrations. The following sub-processors only become active for a Customer's data when that Customer's authorized administrator (e.g., an organization owner) explicitly enables an optional integration in-product. Because activation is contingent on the Customer's affirmative installation step — and because no Customer Personal Data flows to the sub-processor unless and until that step occurs — the 30-day advance-notification rule for Active sub-processors below does not apply. By installing a Customer-Activated Integration, the Customer simultaneously authorizes ISMS Copilot to engage the corresponding sub-processor for the Customer's data only.

IntegrationSub-processorActivated byLocationDPA / Transfer mechanism
heygrc Slack botSlack Technologies, Inc.Paid-organization owner installs from the Connectors page; OAuth callback rejects free / null-plan installs with a paid_plan_required error. Uninstall hard-deletes integration records.United StatesSCCs

When a new Customer-Activated Integration is offered for installation (or replaced), ISMS Copilot will document the integration in this section and announce its availability through normal product-update channels. The 30-day pre-notification rule applies to additions to the Active Sub-processors table above (which run automatically on Customer Personal Data without a per-Customer activation step), not to integrations that require explicit Customer-side activation.

Reserved Sub-processors (code paths exist but are not invoked from any user-facing flow). The following providers have integration code in the platform but are not currently used to serve any user request:

Sub-processorCode path purposeStatus
OpenAIDirect OpenAI API pathReserved — not invoked from any current user-facing flow
X.AI (Grok)Direct X.AI API pathReserved — not invoked from any current user-facing flow
Google GeminiDirect Gemini API pathReserved — not invoked from any current user-facing flow

Activation of any Reserved sub-processor for live processing of Customer Personal Data requires customer notice under the change-of-sub-processor procedure in this §2.4 before any Customer Personal Data is processed.

Sub-processor Requirements. ISMS Copilot ensures all sub-processors:

  • Provide sufficient guarantees of GDPR compliance
  • Agree to data processing terms substantially equivalent to this DPA
  • Implement appropriate technical and organizational measures
  • Remain subject to ISMS Copilot's supervision and audit rights

Changes to Sub-processors.

ISMS Copilot will provide notice of intended changes to sub-processors or sub-processor categories through our Trust Center (https://trust.ismscopilot.com) and in-app changelog, and, where required by this DPA, by email — including through our regular customer product-update or changelog email. Such notice will identify the change, the relevant effective date, and the method for Customer to object.

For materially adverse changes to this DPA or to our sub-processor framework, ISMS Copilot will provide at least 30 days' advance notice by in-app announcement and email, unless a shorter period is required by law or necessary to address an urgent security, legal, or operational issue. A change is materially adverse where it materially changes the nature of processing, introduces a new category of Customer Personal Data processed, materially weakens retention, training, security, transfer, or residency controls, or introduces a materially different jurisdiction or transfer-risk posture.

For control-neutral sub-processor changes, ISMS Copilot may provide notice by publishing the change in the Trust Center and the customer-facing change log. A control-neutral change is one that does not materially weaken the applicable retention, training, publication, security, transfer, or jurisdiction controls and does not expand the categories of Customer Personal Data processed. Examples include: (a) adding a vetted provider to an existing closed allowlist where the same zero-retention, no-training, transfer-mechanism, and jurisdiction-blocking controls continue to apply; and (b) adding an already-disclosed routing path (the closed OpenRouter allowlist) as a permitted destination for an already-disclosed paid cohort, alongside the existing Anthropic path and for any chat mode, and substituting among already-allowlisted providers or moving a cohort or mode between the Anthropic path and the allowlist, under unchanged account-level controls (mandatory ZDR, training-disallowed, publication-disallowed, allowlist, PRC-blocklist) and the same underlying-provider transfer mechanism (SCCs at the underlying-provider layer), where every permitted destination is equal to or stronger than the path it supplements or replaces on retention, training, and jurisdiction, the categories of Customer Personal Data are unchanged, and the account-level EU-residency guarantee (Advanced Data Protection) remains available to suppress the OpenRouter path entirely; and (c) activating the paid Customer-Content scope of a vetted provider already present on the closed OpenRouter allowlist (for example xAI via the "xAI (ZDR)" endpoint, serving the Grok models) and making it a permitted or default destination for an already-disclosed cohort and chat mode, in place of or alongside an existing destination such as Anthropic, where that destination is equal to or stronger than the destination it supplements or replaces on retention (the "xAI (ZDR)" endpoint operates under mandatory OpenRouter account-level Zero Data Retention, stronger than Anthropic's standard-commercial-API retention), no-training, and jurisdiction (United States, non-PRC), under unchanged account-level controls (mandatory ZDR, training-disallowed, publication-disallowed, allowlist, PRC-blocklist) and the same underlying-provider transfer mechanism (SCCs at the underlying-provider layer via the provider's published DPA with OpenRouter's Article 28(4) flow-down), the categories of Customer Personal Data are unchanged, and the account-level EU-residency guarantee (Advanced Data Protection) remains available to suppress the OpenRouter path entirely.

Customer may object during the stated notice period or, for a control-neutral change published without an advance notice period, at any time, by contacting privacy@ismscopilot.com. If Customer objects on reasonable data-protection grounds, the parties will work in good faith to resolve the objection, which may include making an available product configuration, such as Advanced Data Protection Mode (which routes all AI processing to Mistral AI in Frankfurt regardless of plan and is available to every user), available for the affected processing path. Where Customer's contract grants formal sub-processor objection rights and the objection cannot be resolved, Customer may terminate the affected service without penalty.

2.5 Data Subject Rights Assistance

ISMS Copilot will assist the Customer in fulfilling data subject rights requests, including:

ISMS Copilot will respond to Customer requests for data subject rights assistance within the timeframes specified below. Customer remains responsible for meeting GDPR's one-month response deadline to data subjects (Article 12(3)).

Right of Access (Article 15):

  • Self-service access to all conversations and files through the platform
  • Self-service complete data export in JSON format via Settings → Data Protection (available to all plans)

Right to Rectification (Article 16):

  • Self-service updates to account settings
  • Email-assisted email address changes (privacy@ismscopilot.com, within 30 days)

Right to Erasure (Article 17):

  • Self-service account deletion via Settings → Data Protection (available to all plans)
  • Email-mediated path for deletion within flagged threads (see §2.8 — moderation retention exception)
  • Complete data deletion within 30 days, subject to §2.8

Right to Data Portability (Article 20):

  • Machine-readable JSON export including all Customer Personal Data, available self-service in Settings → Data Protection

Right to Restrict Processing (Article 18) and Right to Object (Article 21):

Customer is responsible for verifying data subject identity before requesting data access or export. ISMS Copilot provides the tools and processes, but Customer maintains primary responsibility for responding to data subject requests.

2.6 Data Breach Notification

In the event of a Personal Data Breach affecting Customer Personal Data, ISMS Copilot will:

Detection and Assessment:

  • Continuously monitor for security incidents via Sentry and automated alerting
  • Conduct security incident review within 24 hours of detection
  • Assess risk and potential impact on Customer Personal Data

Notification to Customer:

  • Notify Customer within 48 hours of confirming a Personal Data Breach affects Customer Personal Data
  • For suspected breaches under investigation, provide preliminary notification within 24 hours with updates as information becomes available
  • Provide description of the breach, including categories and approximate numbers of affected data subjects
  • Describe likely consequences of the breach
  • Outline measures taken or proposed to address the breach and mitigate its effects
  • Provide contact point for further information

Cooperation:

  • Cooperate with Customer's investigation and remediation efforts
  • Provide reasonable assistance for Customer's notification to supervisory authorities and data subjects
  • Document all breaches and remediation measures

Customer remains responsible for determining whether notification to supervisory authorities (within 72 hours per Article 33) and data subjects (Article 34) is required. ISMS Copilot provides information to support Customer's decision and obligations.

2.7 Data Protection Impact Assessment (DPIA) Support

ISMS Copilot will provide reasonable assistance when Customer conducts a Data Protection Impact Assessment or prior consultation with a supervisory authority, including:

  • Providing the Register of Processing Activities for reference
  • Describing technical and organizational measures implemented
  • Clarifying data flows and sub-processor arrangements
  • Answering specific questions about processing operations

2.8 Deletion and Return of Data

Upon termination of services or Customer request, ISMS Copilot will:

Standard Deletion (Default):

  • Delete all Customer Personal Data within 30 days of termination
  • Overwrite backup data within 90 days
  • Provide written confirmation of deletion upon request

Data Export Before Deletion:

  • Customer may export their data self-service via Settings → Data Protection at any time
  • Export provided in JSON format

Legal Retention Exceptions:

  • Anonymized billing records retained for 7 years (tax and accounting compliance)
  • Anonymized analytics data may be retained
  • Data required to be retained by applicable law will be isolated and protected until the legal retention period expires
  • Slack integration data (heygrc bot only): if the Customer disconnects the integration (uninstall via Slack's app management UI, or removing the integration from the ISMS Copilot Connectors page), all Slack-specific records are hard-deleted within seconds via the app_uninstalled event handler — the OAuth bot token, workspace metadata in slack_integrations, and Slack-thread-to-ISMS-thread mappings in slack_threads are removed via cascading delete. Conversation content stored in the main messages and threads tables is preserved (it belongs to the Customer's organization and follows the Customer-configured retention setting), but the link from a Slack thread back to a specific Slack workspace user is severed at uninstall.

Moderation Retention Exception (Article 17 limitation). When a chat message is flagged by our automated content moderation system, a moderation_events record is retained containing only metadata — message identifier, thread identifier, abuse categories, and timestamp. The full message content is not stored in the moderation record itself. In addition, the affected thread is locked from user-initiated deletion to prevent destruction of abuse evidence. This is a security measure required to prevent abuse evidence from being destroyed.

Customer Content within a flagged thread is still subject to deletion on a verified Article 17 erasure request submitted to privacy@ismscopilot.com; we evaluate each such request against the legitimate-interest balancing test (Article 17(3)(e) and recital 47) and respond within 30 days. The audit metadata (no content) is retained for up to 12 months from creation, after which it is automatically purged.

2.9 Audit Rights

Customer has the right to audit ISMS Copilot's compliance with this DPA, subject to reasonable limitations:

Documentation Review:

On-Site Audits:

  • Customer may conduct on-site audits with 60 days advance written notice
  • Maximum of one audit per year unless necessitated by a data breach
  • Audits must be conducted during business hours and not interfere with operations

Customer is responsible for audit costs unless the audit reveals non-compliance that: (a) constitutes a personal data breach, or (b) involves systematic failure to implement documented security measures, or (c) results in regulatory enforcement action. In such cases, ISMS Copilot will bear reasonable audit costs incurred after the non-compliance was identified.

Results remain confidential and may not be shared except as required by law.

Third-Party Certifications:

  • ISMS Copilot will obtain and maintain relevant security certifications (ISO 27001 in progress)
  • Certification reports may be shared upon request subject to NDA
  • Customers may rely on third-party certifications in lieu of conducting their own audits

3. International Data Transfers

3.1 Data Transfer Mechanisms

ISMS Copilot processes Customer Personal Data in accordance with Chapter V of the GDPR. Transfer mechanisms apply per Active sub-processor. Two framing notes: (i) for the OpenRouter allowlist, the Standard Contractual Clauses operate at the underlying-provider layer through the OpenRouter aggregator (OpenRouter-intermediated); ISMS Copilot does not sign separate direct SCCs with each underlying host. (ii) Where a provider holds EU-US Data Privacy Framework certification, that is an Article 45 adequacy mechanism, distinct from the Article 46 Standard Contractual Clauses relied on elsewhere.

Primary Storage (Always EU).

  • Database storage occurs in Frankfurt, Germany (AWS EU-Central-1)
  • Conversation history, uploaded files, and account data remain in the EU
  • No adequacy decision required for primary storage

AI Processing — per routing path.

  • ADP enabled (any plan): permitted AI processing uses Mistral AI's confirmed Frankfurt routes with zero retention. Authenticated web search is not available under ADP and fails closed, because Mistral web search is not EU-only and not zero-retention (it runs on Mistral's stateful endpoint and uses Brave (US) as sub-processor). Exact user-selected page/document fetch remains available through EU Fly and subsequent AI processing remains on Mistral.
  • Authenticated web search at launch, ADP off: the minimized latest-request query is sent to Mistral AI for provider-attested source-URL discovery. Mistral's web-search discovery runs on Mistral's stateful Conversations/Agents endpoint, which is outside Mistral's zero-retention posture and uses Brave (United States) as its web-search sub-processor, so the query hop reaches Brave (US) under standard (non-zero) retention and is not an EU-only zero-retention route. Mistral's generated search prose is discarded. The EU Fly.io service exact-fetches those URLs, applies SSRF and content/size/time controls, and passes bounded labeled page extracts to the answer model already applicable to the conversation or Beyond run. No additional semantic grounding model receives the complete draft. A discovered public host may be outside the EU and receives ordinary outbound request metadata from the EU fetcher.
  • Future Brave-direct route (not before 2026-08-12, and not part of launch): this is a distinct route from Brave's role as Mistral's sub-processor above; here ISMS Copilot would call the Brave Search API itself. Only after the notice and founder-acceptance conditions in §2.4 are complete could a minimized latest-request query be transferred directly to Brave Software, Inc. in the United States under SCCs. Brave standard query logs may be retained up to 90 days, and its published DPA excludes Search Query Data from processor scope. Personal and organization-level Never search the web controls would prevent the transfer.
  • Non-ADP AI processing is a single routing envelope (any plan, ADP off). With ADP off, AI requests are served within one non-ADP envelope whose permitted destinations are Anthropic Claude and the OpenRouter allowlist (the eight vetted underlying providers listed below, including xAI; the Essential-plan subset is Google Vertex + Cerebras), with Mistral (EU) as the circuit-breaker failover. ISMS Copilot may serve any non-ADP request via Anthropic or via any allowlisted provider, and may move any plan or cohort between these destinations over time; we do not commit to a fixed per-plan or per-request provider assignment. The per-plan descriptions that follow are the current routing snapshot within this single envelope, not a contractual per-plan limitation. Anthropic-served traffic follows Anthropic's standard commercial API terms (ordinary ~30-day deletion; safety-flagged content up to 2 years; safety-classification scores up to 7 years; not training); OpenRouter-served traffic is zero-retention (no persistent retention beyond serving the request; transient in-memory caching only); ADP (Mistral, EU) is zero-retention. Change classification (§2.4): control-neutral, no advance sub-processor notice. No new sub-processor is introduced (Anthropic and every allowlisted provider are already disclosed non-ADP sub-processors); only the set of cohorts that may be routed to each already-disclosed destination is broadened. The account-level controls, allowlist, PRC-blocklist, transfer mechanisms, and the Advanced Data Protection (Mistral, EU, zero-retention) guarantee are all unchanged, and ADP remains the contractual EU-only, zero-retention option available to any customer at any time. (Assessment note: broadening the free-tier cohort into a destination whose retention exceeds its prior zero-retention default has a stricter reading under which it could be viewed as materially adverse; ISMS Copilot has assessed this change as control-neutral on the basis above.) For paid plans (Plus and above) in the Fast and Think modes and the Beyond assistant, the current default destination is xAI (Grok) via the "xAI (ZDR)" endpoint and Anthropic is the pre-first-token failover; in any chat mode ISMS Copilot may serve a non-ADP paid request via any of the eight allowlisted providers or Anthropic and may move any cohort or mode between these destinations over time, which remains control-neutral under §2.4 (no advance notice, publication-only).
  • Paid (Plus and above) + ADP off: For the Fast and Think modes and the Beyond assistant the current default is xAI (Grok) via the "xAI (ZDR)" endpoint (zero data retention; US; SCCs at the underlying-provider layer), with Anthropic as the pre-first-token failover. In any chat mode, ISMS Copilot may serve a non-ADP paid request via any of the eight allowlisted underlying providers or Anthropic, and may move any cohort or mode between these destinations over time (such moves within the disclosed envelope are control-neutral under §2.4: no advance notice, publication-only). Anthropic Claude (United States) or the OpenRouter allowlist (mostly United States; Inceptron is Sweden (EU) and Nebius is Netherlands (EU), but OpenRouter does not pin inference region, so the SCC safeguard still applies to all eight), as permitted routing destinations for any chat mode. ISMS Copilot may serve a paid request via Anthropic or via any allowlisted provider; Anthropic is also the circuit-breaker failover context. Transfer mechanism for Anthropic-served traffic: SCCs (Module Three, Processor-to-Processor); supplementary measures: encryption in transit; no training under Anthropic's commercial API terms; retention under Anthropic's standard commercial API terms (inputs and outputs ordinarily deleted within approximately 30 days; content flagged by its safety systems retained up to 2 years; safety-classification scores up to 7 years; never used for model training). Transfer mechanism for OpenRouter-served traffic: the underlying-provider DPA / SCC / DPF stack, with OpenRouter account-level controls (mandatory ZDR, training-disallowed, publication-disallowed, closed eight-provider allowlist, PRC-blocklist) as the enforcement layer; that traffic is zero-retention (no persistent retention beyond serving the request; transient in-memory caching only). Fallback within a single request: where a paid request is first attempted on an allowlisted OpenRouter provider and that provider does not begin responding within a short time-to-first-response timeout, ISMS Copilot aborts the attempt and re-serves the request via the failover path. That failover path is Anthropic (Opus for Think, Sonnet for Fast) or, where Anthropic's circuit breaker is open (Anthropic degraded or unavailable), Mistral in the EU (see the failover provisions). In that fallback case a single request transits two disclosed destinations in sequence: the OpenRouter attempt is zero-retention (no persistent retention of Customer Content there beyond serving the request), and the second leg follows its standard posture (Anthropic under SCCs with retention under its standard commercial API terms as described above, or Mistral in the EU with zero retention). No additional sub-processor is involved and no control is weakened; the deepest fallback (Mistral, EU, zero-retention) is the most protective destination. Customers needing zero retention on every path, or contractual EU-only residency, can enable Advanced Data Protection at any time to route all AI processing through Mistral (EU).
  • Essential + ADP off: OpenRouter aggregator (United States), restricted to a closed two-provider subset of the allowlist: Google Vertex (multi-region; SCCs and EU-US Data Privacy Framework certification) and Cerebras (United States; SCCs). The same OpenRouter account-level controls (mandatory ZDR, training-disallowed, publication-disallowed, PRC-blocklist) apply as the enforcement layer. Customers needing contractual EU-only data residency can enable Advanced Data Protection at any time to route through Mistral (EU).
  • Free / null-plan + ADP off: OpenRouter aggregator (United States) routing to one of seven allowlisted underlying providers:
    • DeepInfra, Cerebras (United States): SCCs. Inceptron (Inceptron AB, Sweden / EU): SCCs as well, because OpenRouter does not pin inference region.
    • Google Vertex (multi-region; EU residency available at the underlying provider): SCCs and EU-US Data Privacy Framework certification.
    • Together AI (default routing to North America data centers per Together docs; region pinning not exposed by OpenRouter aggregator): SCCs.
    • Fireworks AI (multi-region fleet covering US, EU Frankfurt + Iceland, and APAC Tokyo only; no PRC or Hong Kong infrastructure identified in Fireworks' published deployment docs; region pinning not exposed by OpenRouter aggregator): SCCs.
    • Nebius (Amsterdam HQ; primary inference in Finland (EU) with US secondary per Nebius docs; per-request region pinning not currently exposed by OpenRouter aggregator, so the EU-primary posture is the published default but not contractually guaranteed via OpenRouter): SCCs for any US-routed traffic.
  • The transfer mechanism for the free-tier path is the underlying-provider DPA/SCC/DPF stack. OpenRouter account-level controls (mandatory ZDR, training-disallowed, publication-disallowed, closed eight-provider allowlist, PRC-blocklist) act as the enforcement layer ensuring Customer Personal Data only ever lands at endpoints with these mechanisms in place. OpenRouter's aggregator API does not currently expose per-provider region pinning to its account holders; for the three providers added on 2026-05-25 (Together AI, Fireworks AI, Nebius), regional routing follows each provider's default deployment posture. Based on each provider's published deployment documentation reviewed on 2026-05-25, none of those defaults places Customer Personal Data in PRC or Hong Kong infrastructure. Non-PRC default posture is not equivalent to contractual EU-only data residency; customers requiring the latter should enable Advanced Data Protection Mode, which routes every request to Mistral AI in Frankfurt and bypasses the OpenRouter aggregator entirely.

Email Communications (US-Based).

  • Email addresses transferred to SendGrid and Kit (United States)
  • Protected by Standard Contractual Clauses approved by the European Commission
  • Customers can minimize transfers by unsubscribing from non-essential emails

Slack Integration (US-Based, paid Customers who install heygrc only).

  • Workspace metadata, OAuth bot token, message events addressed to the bot, and AI response posts transferred to/from Slack Technologies, Inc. (United States)
  • Protected by Standard Contractual Clauses
  • Customer controls activation: the integration only exists if a paid-organization owner installs the bot, and can be removed at any time by uninstalling from Slack or via the Connectors page in the ISMS Copilot app (uninstall hard-deletes all Slack-side records held by ISMS Copilot per §2.8)

3.2 Standard Contractual Clauses (SCCs)

For transfers to the United States, ISMS Copilot relies on Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914):

  • Customer to ISMS Copilot: Module Two (Controller to Processor) applies where Customer acts as data controller
  • ISMS Copilot to US sub-processors: Module Three (Processor to Processor) applies
  • Governing law for SCCs: French law (Clause 17, Option 1)
  • Competent supervisory authority: CNIL, France (Clause 13)

Copies of executed SCCs with sub-processors are available on request via privacy@ismscopilot.com.

3.3 Supplementary Measures

ISMS Copilot implements supplementary measures to protect data transferred outside the EU. These measures are layered and apply per routing path:

For all transfers outside the EU:

  • End-to-end encryption (TLS 1.3) for all data in transit
  • Customer ability to control transfer destination via Advanced Data Protection Mode (Mistral / Frankfurt)
  • Continuous monitoring of legal developments regarding international transfers
  • For authenticated web search, latest-turn-only query construction; strict length and word bounds; no files, memories, workspace context, account identifiers, or user/device identifiers; credential and signed-URL rejection; personal/organization hard-off controls; Mistral-prose discard; and EU exact-fetch of only provider-attested URLs

For paid-tier transfers served by Anthropic:

  • No training on Customer Content under Anthropic's commercial API terms
  • retention under Anthropic's standard commercial API terms (inputs and outputs ordinarily deleted within approximately 30 days; content flagged by its safety systems retained up to 2 years; safety-classification scores up to 7 years; never used for model training); customers needing zero retention can enable Advanced Data Protection at any time to route through Mistral (EU, no retention)

For OpenRouter transfers (free-tier, Essential, and paid plans Plus and above):

  • OpenRouter account-level controls applied to every request: mandatory Zero Data Retention (no persistent retention beyond serving the request; transient in-memory caching only); Free Training Disallowed + Paid Training Disallowed; Free Publication Disallowed
  • Closed eight-provider allowlist (the seven glm-4.7 hosts, Inceptron, DeepInfra, Cerebras, Google Vertex, Together AI, Fireworks AI, Nebius, plus xAI via the "xAI (ZDR)" endpoint for the Grok models; the seven glm-4.7 hosts were expanded from 4 to 7 on 2026-05-25, and xAI was activated for paid Customer-Content on 2026-07-21). For Essential plan routing the closed two-provider subset is further restricted to Google Vertex and Cerebras. For paid plans (Plus and above) in the Fast and Think modes and the Beyond assistant, xAI via the "xAI (ZDR)" endpoint is the default and Anthropic is the pre-first-token failover; the glm-4.7 hosts otherwise serve the free / null-plan path.
  • PRC-jurisdiction blocklist (Alibaba Cloud Int., Baidu Qianfan, DeepSeek, Moonshot AI, Xiaomi, Z.AI all blocked) — a Schrems II–style jurisdiction-based supplementary measure aligned with EDPB Recommendations 01/2020
  • Each underlying provider independently confirms zero retention or no-training-on-customer-data in their published policies
  • Contractual chain to the underlying providers: ISMS Copilot has an executed Data Processing Agreement with OpenRouter (accepted via the OpenRouter Terms as a paid commercial customer), which incorporates the EU Standard Contractual Clauses for the ISMS Copilot to OpenRouter transfer, and under which OpenRouter is contractually required to bind each underlying model provider, by written agreement, to data-protection obligations no less protective than its own (GDPR Article 28(4) sub-processor flow-down) and remains liable for those providers' acts and omissions. This flow-down is what anchors the per-provider transfer mechanisms above; customers do not contract with the underlying providers individually.
  • Advanced Data Protection remains the account-level EU-residency guarantee: enabling it at the organization level routes permitted AI processing to Mistral's confirmed EU routes, suppresses OpenRouter for every user, and disables authenticated web search entirely (it fails closed, because Mistral web search is not EU-only and not zero-retention). Exact user-selected page/document fetch remains available under ADP through EU Fly.

3.4 Transfer Impact Assessment

ISMS Copilot has conducted a Transfer Impact Assessment (TIA) for US-based sub-processors and determined that:

  • Standard Contractual Clauses provide appropriate safeguards under GDPR Chapter V
  • Supplementary technical and contractual measures (encryption, no-training, zero retention, OpenRouter account-level controls including the PRC blocklist) enhance protection
  • Customers have the option to avoid US AI processing transfers entirely by enabling Advanced Data Protection Mode (EU-only permitted AI processing with zero retention; authenticated web search is unavailable and fails closed, because Mistral web search is not EU-only and not zero-retention)
  • Email transfers to US providers (SendGrid, Kit) remain regardless of Advanced Data Protection Mode but are protected by SCCs and encryption

The complete Transfer Impact Assessment, including risk assessment methodology and US surveillance law analysis, is available on request via privacy@ismscopilot.com.

Organizations with strict EU data residency requirements should enable Advanced Data Protection Mode to eliminate AI processing transfers and simplify Transfer Impact Assessment obligations.

4. Customer Obligations as Data Controller

4.1 Lawfulness of Processing Instructions

Customer warrants that:

  • All processing instructions comply with GDPR and applicable data protection laws
  • Customer has a lawful basis for processing all personal data uploaded to the platform
  • Customer has informed data subjects about the processing and their rights
  • Customer maintains appropriate records of processing activities (Article 30 GDPR)

4.2 Special Category and Criminal-Offence Data (excluded from the Default AI Routing Path)

ISMS Copilot does not authorize the processing of special category data or personal data relating to criminal convictions and offences through the Default AI Routing Path. OpenRouter's data processing terms state that OpenRouter is not required to process Sensitive Data unless expressly agreed and that no such processing is intended. ISMS Copilot has not entered into such an agreement with OpenRouter for OpenRouter-routed traffic. Accordingly:

(a) Customer, as controller, instructs ISMS Copilot not to submit special category or criminal-offence data to the Default AI Routing Path, and shall not do so; (b) any such data that Customer nonetheless includes in a prompt, message, or upload is submitted at Customer's sole responsibility, on the basis of an Article 9(2) condition (or, for Article 10 data, an Article 6(1) basis and either official-authority control or authorization under Union or Member State law providing appropriate safeguards, as required by Article 10) that Customer has established and can evidence, and subject to Customer's obligations under §4.1 and §5; (c) for any processing intended to involve special category or criminal-offence data, Customer shall enable Advanced Data Protection Mode, which routes all AI processing to Mistral AI (EU, Frankfurt) with zero retention and does not use the OpenRouter routing path; and (d) ISMS Copilot gives no representation that special-category or criminal-offence content is detected, filtered, or blocked before it reaches a sub-processor, and does not warrant the suitability of the Default AI Routing Path for such data.

Where such data is nonetheless present on the Default AI Routing Path, the sub-processors' baseline Article 28 obligations (confidentiality, Article 32 security, the Article 28(4) sub-processor flow-down, deletion, and the applicable Standard Contractual Clauses safeguards) continue to apply to it as personal data. The exclusion in this section concerns the absence of any enhanced warranty for the special-category subset, not a withdrawal of those baseline protections.

Customer remains responsible for (i) classifying its inputs, (ii) ensuring it does not submit excluded data to the Default AI Routing Path, (iii) any Article 9(2) condition or, for Article 10 data, the Article 6(1) basis and official-authority control or legal authorization with appropriate safeguards required by Article 10, applicable to Customer's own processing, and (iv) conducting a Data Protection Impact Assessment (Article 35) where required.

4.3 Data Subject Rights Management

Customer is responsible for:

  • Receiving and responding to data subject rights requests
  • Verifying data subject identity before requesting data from ISMS Copilot
  • Determining whether to notify supervisory authorities and data subjects in case of breaches
  • Ensuring data subjects are informed about ISMS Copilot's role as processor

4.4 Data Retention Configuration

Customer must:

  • Configure appropriate data retention periods matching their data protection policies
  • Review retention settings periodically to ensure compliance
  • Request deletion when data is no longer necessary for the original purpose

4.5 Workspace Isolation

Customer should:

  • Create separate workspaces for different clients or data categories
  • Avoid mixing personal data from different data subjects in single workspaces
  • Delete workspaces when projects are completed and data is no longer needed

5. Liability and Indemnification

5.1 Allocation of Liability

Under Article 82 GDPR:

  • Customer and ISMS Copilot are each liable for damages caused by their own GDPR violations
  • ISMS Copilot is exempt from liability if it proves it was not responsible for the event giving rise to the damage
  • ISMS Copilot is not liable for damages resulting from Customer's unlawful processing instructions

5.2 Indemnification

Customer will indemnify ISMS Copilot against any claims, fines, or damages arising from:

  • Customer's violation of GDPR or other data protection laws
  • Customer's unlawful processing instructions
  • Customer's failure to obtain necessary consents or legal basis for processing
  • Customer's submission of special category or criminal-offence data to the Default AI Routing Path contrary to §4.2 (Customer must use Advanced Data Protection Mode for such workloads)

Nothing in this §5.2 limits data-subject rights or requires Customer to indemnify ISMS Copilot to the extent a claim, fine, or damage is attributable to ISMS Copilot's breach of this DPA or its obligations under applicable data protection law, including Article 28(4) or Article 82 GDPR.

6. Term and Termination

6.1 Term

This DPA takes effect on the date Customer first uses ISMS Copilot services and continues for as long as ISMS Copilot processes Customer Personal Data.

6.2 Termination

This DPA terminates automatically upon:

  • Termination of the Terms of Service
  • Completion of all processing activities and deletion of Customer Personal Data

6.3 Effect of Termination

Upon termination:

  • ISMS Copilot will delete or return all Customer Personal Data as described in §2.8 (subject to the moderation retention exception)
  • Obligations regarding confidentiality, data security, and legal retention survive termination
  • Customer's right to audit survives for 12 months after termination

7. Amendments and Updates

7.1 DPA Updates

ISMS Copilot may update this DPA to reflect:

  • Changes in data protection laws or regulatory guidance
  • Changes to processing operations or sub-processors
  • Improvements to security measures or data protection practices

7.2 Notification of Changes

  • Materially adverse changes to this DPA (changes that materially weaken Customer's data-protection rights, reduce retention or training protections, introduce a materially different jurisdiction or transfer-risk posture, or otherwise impose materially new obligations on Customer) will be notified at least 30 days in advance by in-app announcement and email, including through ISMS Copilot's regular customer product-update or changelog email.
  • Non-materially-adverse changes to this DPA (clarifications, additions to existing closed sub-processor allowlists that do not weaken the applicable controls, alignment with regulatory guidance, etc.) will be notified through the Trust Center, the in-app changelog, and the customer-facing change log at https://trust.ismscopilot.com/changelog.
  • The updated DPA will be posted at https://trust.ismscopilot.com/dpa with a new "Effective Date" and "Last Updated" date.
  • Continued use of services after the effective date constitutes acceptance of the updated DPA.
  • Customer may object during the stated notice period by contacting privacy@ismscopilot.com (see §7.3).

7.3 Objection Rights

  • Customer may object to material changes within 30 days of notification
  • The simplest in-product alternative is to enable Advanced Data Protection Mode, which keeps all AI processing in the EU at Mistral regardless of plan
  • For customers under contracts with formal sub-processor objection rights, formal objection may be sent to privacy@ismscopilot.com; if the objection cannot be resolved, Customer may terminate the service without penalty

8. Governing Law and Jurisdiction

8.1 Governing Law

This DPA is governed by:

  • The General Data Protection Regulation (EU) 2016/679
  • French data protection law (Data Protection Act 78-17 of 6 January 1978)
  • The laws of France for contractual interpretation

8.2 Jurisdiction

Any disputes arising from this DPA will be subject to the jurisdiction of French courts, with the supervisory authority being the Commission Nationale de l'Informatique et des Libertés (CNIL).

9. Contact Information

9.1 Data Protection Contacts

For DPA-related questions or requests:

  • Email privacy@ismscopilot.com from your registered account email address
  • Include "DPA Request" or "Data Processing Agreement" in the subject line

9.2 Data Protection Officer

ISMS Copilot has not designated a Data Protection Officer as we do not meet the mandatory designation criteria under GDPR Article 37. For data protection inquiries related to this DPA, contact privacy@ismscopilot.com.

9.3 Supervisory Authority

Commission Nationale de l'Informatique et des Libertés (CNIL)

  • Website: https://www.cnil.fr/en
  • Address: 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France
  • Phone: +33 1 53 73 22 22

Appendix A: Processing Details Summary

Subject Matter. Provision of AI-powered compliance assistance platform including conversation processing, document analysis, knowledge management, automated content moderation, and policy-controlled authenticated web research.

Duration. For the term of the Customer's active subscription plus retention period configured by Customer (1 day to 7 years), followed by 30-day deletion window. Moderation metadata retained up to 12 months per §2.8.

Nature and Purpose.

  • Nature: Automated AI processing, database storage, file conversion and analysis, content moderation, search-intent classification, and transient web-evidence retrieval
  • Purpose: Enable compliance professionals to receive AI guidance, analyze documents, generate policies, manage compliance knowledge, and ground current/company-specific claims in retrieved sources

Categories of Data Subjects.

  • Customer employees and authorized platform users
  • Customer clients (when referenced in documents or queries)
  • Individuals mentioned in compliance documentation
  • Security incident subjects
  • Slack workspace users interacting with the heygrc bot (paid Customers who install only) — see §1.5

Categories of Personal Data.

  • Contact information (email addresses)
  • Authentication credentials (hashed passwords)
  • Conversation content and AI interactions
  • Uploaded compliance documents
  • Usage metadata and timestamps
  • Special category data (Article 9) and criminal-offence data (Article 10): excluded from the Default AI Routing Path (§4.2); may be incidentally present in unstructured customer inputs at the Customer's responsibility
  • Moderation metadata (message ID, thread ID, abuse categories, timestamp — no message content) for flagged messages only
  • Slack integration data (paid Customers who install heygrc only) — see §1.6
  • For web search: limited recent conversation text used by the intent classifier; an ADP-off minimized latest-request query; transient public search results or exact-URL page text; bounded excerpts and source titles/URLs supplied to the already applicable answer/Beyond model; generated answer and source links retained under the conversation setting

Sensitive data (SCC Annex I.B safeguards). Special category data (Article 9) and personal data relating to criminal convictions and offences (Article 10) may be incidentally present in unstructured customer inputs at the Customer's responsibility. Such data is excluded from instructed processing on the Default AI Routing Path under §4.2, and intended workloads require Advanced Data Protection Mode. Applied restrictions and safeguards include strict purpose limitation to providing the services; no training; no publication of model outputs derived from Customer Personal Data; TLS in transit and encryption at rest; mandatory Zero Data Retention, the closed provider allowlist, and the PRC-jurisdiction blocklist for OpenRouter-routed traffic; the Anthropic and authenticated web-search retention and transfer controls disclosed in §§2.1(c) and 3.1; and Advanced Data Protection Mode as an EU-only, zero-retention alternative for AI processing.

Appendix B: Sub-processor Change Log

This appendix tracks all sub-processor additions, removals, and changes since the DPA effective date. For materially-adverse changes, customers are notified at least 30 days before the change takes effect; control-neutral changes and user-directed or customer-activated features are notified through the mechanisms in §2.4 (Trust Center and in-app changelog) and do not all require 30 days' advance notice.

EffectiveChangeNotice issued
2026-07-23 (control-neutral; strengthening; no advance notice)DeepInfra removed from the z-ai/glm-5.2 provider set; in-request Zero Data Retention added. DeepInfra (a previously-allowlisted OpenRouter underlying provider) is removed from the closed only list for z-ai/glm-5.2 across chat, the API, and heyGRC review, leaving Together AI, Fireworks AI, and Inceptron; DeepInfra carried ~0% of glm-5.2 traffic and was dropped for lacking a publicly-verifiable SCC-bearing DPA. In the same change, request-level data_collection:"deny" + zdr:true were added to the glm-5.2 provider pins (the shared chat glm-5.2 route, which the partner premium tier also uses; the API glm-5.2 pin; and the heyGRC review glm-5.2 pin), so zero-retention and no-training are enforced in-request and no longer rest on the OpenRouter account-level toggle alone. DeepInfra remains on the account allowlist for other models.Control-neutral / strengthening under §2.4: the recipient set is narrowed (a provider removed) and retention controls are strengthened, so the 30-day advance-notice rule for materially-adverse changes does not apply. Communicated via in-app changelog and the Trust Center on the effective date.
2026-07-21 (control-neutral; no advance notice; published effective 2026-07-21)xAI (X.AI LLC), via the OpenRouter "xAI (ZDR)" endpoint (Grok models) - already present on the OpenRouter account allowlist and already serving the logged-out demo - now activated for paid Customer-Content and made the default OpenRouter underlying-provider destination for paid plans (Plus and above), ADP off, for the chat Fast and Think modes and the Beyond assistant, replacing the prior Anthropic default; Anthropic retained as the pre-first-token failover. Classified control-neutral under §2.4(c): zero data retention (as configured and verified 2026-07-19, stronger than the Anthropic path it replaces), no-training, US (non-PRC) jurisdiction, and the SCC transfer mechanism all continue to apply under unchanged OpenRouter account-level controls; the Advanced Data Protection (Mistral, EU, zero-retention) guarantee remains available to suppress the OpenRouter path entirely.Published in the Trust Center and customer-facing change log, effective 2026-07-21 (control-neutral, publication-only per §2.4). Customers may object at any time or enable Advanced Data Protection.
On publication (target launch day)Authenticated web-search Mistral bridge. Mistral performs intent classification for eligible users and provider-attested source-URL discovery when ADP is off. Its generated search prose is discarded. The EU Fly.io service exact-fetches attested or user-submitted public pages, and bounded evidence goes to the already applicable answer/Beyond model. No additional semantic grounding model receives the draft. Authenticated web search fails closed under ADP; exact ADP page/document fetch remains available. The direct-Brave route (ISMS Copilot calling the Brave API itself) is not constructed or called. Raw discovery and page evidence is not persisted by ISMS Copilot.Trust Center and in-app disclosure update. Mistral and Fly are already-disclosed recipients. Mistral's web search runs on Mistral's stateful Conversations/Agents endpoint (outside Mistral's zero-retention posture) and uses Brave (US) as its web-search sub-processor, so the non-ADP query hop reaches Brave (US) under standard retention and is not EU-only or zero-retention; see the internal launch decision record. This entry is effective only when the feature is published and live.
2026-08-12 (earliest; materially adverse; pending, not the launch default)Potential future Brave-direct external recipient (distinct from Brave's launch role as Mistral's web-search sub-processor). A future non-ADP route in which ISMS Copilot would call the Brave Search API itself may send only a bounded latest-request query to Brave Search in the United States; no files, memories, workspace context, account identifiers, or user/device identifiers would be sent. Brave standard query logs may be retained up to 90 days; SCCs apply; Brave's DPA excludes Search Query Data from processor scope, so Brave is disclosed as a limited external recipient rather than represented as an Article 28 processor.Notice package drafted 2026-07-13. 2026-08-12 is available only if notice is actually issued on 2026-07-13; otherwise activation moves to at least 30 days after actual notice. Founder acceptance is also required. Brave remains dark meanwhile.
2025-11Initial sub-processor list established (Anthropic, Mistral AI, Supabase, Stripe, ConvertAPI, PostHog, Sentry, Vercel, Fly.io, SendGrid, Kit)Initial publication
2026-04-16heygrc Slack integration made available to paid organizations as a Customer-Activated Integration (see §2.4 — Customer-Activated Integrations). Slack Technologies, Inc. only becomes a sub-processor for a Customer's data when that Customer's organization owner explicitly installs the bot from the Connectors page; uninstall hard-deletes all integration records. Activation gated on paid plan; free / null-plan organizations cannot install. Transfer mechanism: SCCs.Documented in this DPA revision (2026-04-27); the integration's availability for installation went live 2026-04-16. The 30-day advance-notification rule does not apply to Customer-Activated Integrations because no Customer's data flows to Slack unless and until that Customer's organization owner takes an explicit installation step.
2026-05-27OpenRouter added as routing aggregator for free-tier and null-plan users with ADP off. Routes initially to four allowlisted underlying providers: Inceptron, DeepInfra, Cerebras, Google Vertex. Account-level controls enforced: mandatory Zero Data Retention, Free/Paid Training Disallowed, Free Publication Disallowed, closed 4-provider allowlist, PRC-jurisdiction blocklist (Alibaba Cloud Int., Baidu Qianfan, DeepSeek, Moonshot AI, Xiaomi, Z.AI). Free-tier users previously served by reserved direct-API paths are now served via OpenRouter. ADP path (Mistral) and paid path (Anthropic) unchanged.2026-04-27 (30-day customer email under prior §2.4 wording)
2026-05-28Essential plan ($12/mo) routing. The new Essential plan, with ADP off, routes through OpenRouter restricted to a closed two-provider subset of the existing allowlist: Google Vertex and Cerebras. No new sub-processor is introduced: OpenRouter, Google Vertex, and Cerebras are already on the list above (added 2026-05-27), with the same account-level controls (mandatory ZDR, training-disallowed, publication-disallowed, PRC-blocklist) and transfer mechanisms (SCCs; EU-US DPF for Google Vertex). ADP-on (any plan, including Essential) continues to route to Mistral (EU). This is a routing-scope extension to a new paid plan using already-disclosed sub-processors.No new sub-processor is added, so the 30-day advance-notice rule for sub-processor additions does not apply. Communicated via in-app changelog and the Trust Center on 2026-05-28.
2026-06-23OpenRouter underlying-provider allowlist expanded from 4 to 7. Three additions: Together AI, Fireworks AI, Nebius. First control-neutral sub-processor change under the new §2.4 wording (also effective 2026-06-23). Account-level controls unchanged. Each addition evaluated against the same privacy-and-jurisdiction bar as the original four (zero-retention posture, no training on customer data, published DPA, non-PRC jurisdiction, public deployment-region disclosure). Novita AI evaluated under the same review and not added (public-disclosure opacity on infrastructure location prevents evidencing the §3.1.4 PRC-jurisdiction control).2026-05-26 (in-app changelog + Trust Center publication). Bundled labeled entry in the May 2026 monthly product-changelog email shipping in the first days of June. A more detailed internal change record is available on request.
2026-06-13 (issued; never published)Amendment B (superseded by Amendment C before publication). Amendment B would have expanded OpenRouter scope to paid-plan overflow routing after the 4-hour token cap, gated by an explicit per-session end-user election, restricted to the Google Vertex / Cerebras subset. It was issued on 2026-06-13 but never published or made operative, and is superseded in full by Amendment C below. Recorded here for historical completeness only.Not published. Superseded by Amendment C before any customer notice took effect.
2026-06-23 (control-neutral)OpenRouter allowlist added as a permitted paid routing destination alongside Anthropic, for any chat mode. For paid plans (Plus, Standard, Pro, Business) with ADP off, the closed 7-provider OpenRouter allowlist becomes a permitted AI-routing destination alongside Anthropic, for any chat mode (fast, think, or agentic/Beyond), mirroring the free / null-plan path. ISMS Copilot may serve a paid request via Anthropic or via any allowlisted provider, and may move any paid cohort or mode between them over time without a further sub-processor change. Anthropic is not removed: it remains a disclosed paid provider and the circuit-breaker failover context, no longer the sole paid path. No new sub-processor is introduced (OpenRouter and all seven underlying providers are already disclosed). Account-level controls (mandatory ZDR, training-disallowed, publication-disallowed, allowlist, PRC-blocklist) and the underlying-provider transfer mechanism are unchanged. Retention for any traffic served by Anthropic follows Anthropic's standard commercial API terms (ordinary ~30-day deletion; safety-flagged content up to 2 years; safety-classification scores up to 7 years; not training); traffic served by an allowlisted OpenRouter provider is zero-retention. ADP remains the account-level EU-residency guarantee.Control-neutral change under §2.4; communicated via in-app changelog and the Trust Center on the effective date. The 30-day advance-notice rule for materially-adverse changes does not apply because no new sub-processor is introduced, the same account-level controls and underlying-provider transfer mechanism apply unchanged, every allowlisted provider is equal-or-stronger than Anthropic on retention / training / jurisdiction, and ADP remains available to keep all processing in the EU.

All future sub-processor changes will be documented here with effective date, sub-processor name and location, nature of change (addition, removal, replacement), processing purpose, and customer notification date.