Skip to content
Legal

Data Processing Agreement

version 1.0 · effective date · 16 July 2026

1. Parties and scope

This Data Processing Agreement ("DPA") forms part of the Terms of Service between the customer organisation accepting those terms (the "Customer", acting as controller) and SAFE AI LABS PTY LTD, trading as NeverTrust.ai (the "Processor"). It applies whenever we process personal data on the Customer's behalf in the course of providing the Services.

This DPA is incorporated by reference for all customers. Enterprise customers who require a countersigned copy can request one at [email protected].

2. Nature and purpose of processing

We process personal data to provide network-layer AI security monitoring: device enrolment and management, security-event reporting and review, organisation and user administration, billing, and support. Categories of data subjects include the Customer's administrators, team members, and device users. Categories of personal data include names, work email addresses, device hostnames and usernames, IP addresses, and security-event metadata (which may include content snippets of up to 512 characters where the Customer has not disabled them).

3. Processor obligations

As Processor, we will:

  • process personal data only on the Customer's documented instructions, including as configured through the portal, unless required otherwise by applicable law;
  • ensure that persons authorised to process personal data are bound by confidentiality obligations;
  • implement the technical and organisational measures described on our Security page, including encryption in transit and at rest, row-level tenant isolation, and least-privilege access;
  • assist the Customer, taking into account the nature of processing, in responding to data-subject requests and in meeting its security, breach-notification, and impact-assessment obligations;
  • notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's data;
  • delete or return personal data at the end of the engagement, subject to the retention schedule in the Privacy Policy (organisation deletion enters a 30-day grace period, then permanent removal); and
  • make available information reasonably necessary to demonstrate compliance with this DPA and, at the Customer's cost, allow for and contribute to audits conducted by the Customer or its mandated auditor, no more than once per year absent a demonstrated breach.

4. Subprocessors

The Customer provides general authorisation for the subprocessors listed below. We will give at least 30 days' notice of intended additions or replacements by updating this page and, for material changes, by email to organisation administrators. The Customer may object on reasonable data-protection grounds; if we cannot address the objection, the Customer may terminate the affected Services.

ProviderPurposeLocation
Amazon Web Services, Inc.Application hosting, database hosting, and object storageUnited States (data processed in Asia Pacific, Sydney)
Supabase Inc.Authentication and database toolingUnited States
Cloudflare, Inc.Edge network, DDoS protection, and TLS terminationUnited States
Stripe, Inc.Payment processing, subscription billing, and invoicingUnited States
Resend Inc.Transactional and marketing email deliveryUnited States
Google LLCWebsite analytics (Google Analytics 4)United States

Each subprocessor is bound by a written agreement imposing data-protection obligations no less protective than this DPA.

5. International transfers

Our infrastructure is hosted in the AWS Asia Pacific (Sydney) region. Some subprocessors are located in the United States. Where personal data originating from the EEA, the United Kingdom, or Switzerland is transferred to a country without an adequacy decision, the parties rely on the European Commission's Standard Contractual Clauses (Controller-to-Processor, Module 2), which are incorporated into this DPA by reference, together with the UK Addendum where applicable.

For Australian customers, we handle personal information in accordance with the Australian Privacy Principles under the Privacy Act 1988 (Cth).

6. Liability and order of precedence

Each party's liability under this DPA is subject to the limitations of liability in the Terms of Service. If there is a conflict between this DPA and the Terms of Service concerning the processing of personal data, this DPA prevails.

7. Changes to this DPA

We may update this DPA to reflect changes in law or in the Services. The version number and effective date at the top of this page identify the current version. Material changes are notified to organisation administrators by email at least 30 days before they take effect.