Data Processing Agreement
version 1.0 · effective date · 16 July 2026
1. Parties and scope
This Data Processing Agreement ("DPA") forms part of the Terms of Service between the customer organisation accepting those terms (the "Customer", acting as controller) and SAFE AI LABS PTY LTD, trading as NeverTrust.ai (the "Processor"). It applies whenever we process personal data on the Customer's behalf in the course of providing the Services.
This DPA is incorporated by reference for all customers. Enterprise customers who require a countersigned copy can request one at [email protected].
2. Nature and purpose of processing
We process personal data to provide network-layer AI security monitoring: device enrolment and management, security-event reporting and review, organisation and user administration, billing, and support. Categories of data subjects include the Customer's administrators, team members, and device users. Categories of personal data include names, work email addresses, device hostnames and usernames, IP addresses, and security-event metadata (which may include content snippets of up to 512 characters where the Customer has not disabled them).
3. Processor obligations
As Processor, we will:
- process personal data only on the Customer's documented instructions, including as configured through the portal, unless required otherwise by applicable law;
- ensure that persons authorised to process personal data are bound by confidentiality obligations;
- implement the technical and organisational measures described on our Security page, including encryption in transit and at rest, row-level tenant isolation, and least-privilege access;
- assist the Customer, taking into account the nature of processing, in responding to data-subject requests and in meeting its security, breach-notification, and impact-assessment obligations;
- notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's data;
- delete or return personal data at the end of the engagement, subject to the retention schedule in the Privacy Policy (organisation deletion enters a 30-day grace period, then permanent removal); and
- make available information reasonably necessary to demonstrate compliance with this DPA and, at the Customer's cost, allow for and contribute to audits conducted by the Customer or its mandated auditor, no more than once per year absent a demonstrated breach.
4. Subprocessors
The Customer provides general authorisation for the subprocessors listed below. We will give at least 30 days' notice of intended additions or replacements by updating this page and, for material changes, by email to organisation administrators. The Customer may object on reasonable data-protection grounds; if we cannot address the objection, the Customer may terminate the affected Services.
| Provider | Purpose | Location |
|---|---|---|
| Amazon Web Services, Inc. | Application hosting, database hosting, and object storage | United States (data processed in Asia Pacific, Sydney) |
| Supabase Inc. | Authentication and database tooling | United States |
| Cloudflare, Inc. | Edge network, DDoS protection, and TLS termination | United States |
| Stripe, Inc. | Payment processing, subscription billing, and invoicing | United States |
| Resend Inc. | Transactional and marketing email delivery | United States |
| Google LLC | Website analytics (Google Analytics 4) | United States |
Each subprocessor is bound by a written agreement imposing data-protection obligations no less protective than this DPA.
5. International transfers
Our infrastructure is hosted in the AWS Asia Pacific (Sydney) region. Some subprocessors are located in the United States. Where personal data originating from the EEA, the United Kingdom, or Switzerland is transferred to a country without an adequacy decision, the parties rely on the European Commission's Standard Contractual Clauses (Controller-to-Processor, Module 2), which are incorporated into this DPA by reference, together with the UK Addendum where applicable.
For Australian customers, we handle personal information in accordance with the Australian Privacy Principles under the Privacy Act 1988 (Cth).
6. Liability and order of precedence
Each party's liability under this DPA is subject to the limitations of liability in the Terms of Service. If there is a conflict between this DPA and the Terms of Service concerning the processing of personal data, this DPA prevails.
7. Changes to this DPA
We may update this DPA to reflect changes in law or in the Services. The version number and effective date at the top of this page identify the current version. Material changes are notified to organisation administrators by email at least 30 days before they take effect.