AirMemo
AirMemo
Sheet 01
Rev A
Governed push
Scale 1:1

AirMemo — Data Processing Addendum (DPA)

Version 1.0 — pilot draft · 2026-09-15 · BOILERPLATE, NOT LEGAL ADVICE. Standard B2B data-processing addendum. It has not been reviewed by counsel; have it reviewed before any customer signs (especially if any customer is subject to GDPR/CCPA). Placeholders in [BRACKETS] must be filled in.

1. Applicability. This DPA applies whenever AirMemo ("Processor" or "Provider") processes Personal Data on behalf of Customer ("Controller") in the course of the Service, and supplements the AirMemo Terms of Service ("Terms"). Capitalized terms not defined here have the meanings in the Terms.

2. Roles and Scope. Customer is the Controller of Customer Data (including Personal Data contained in memos, audit records, receipts, and device/agent metadata); AirMemo is a Processor processing that data solely to provide the Service. AirMemo processes data only on documented instructions from Customer (which include these Terms, the DPA, and the product documentation), unless required otherwise by applicable law (in which case AirMemo will inform Customer, unless law forbids it).

3. Data Processing Details.

  • Categories of data processed: memo content and metadata (author, scope, priority, expiry); device/agent identifiers and platform type; delivery receipts (proof hashes, timestamps, injection points); audit events (actor, action, target, timestamp); account/billing data (email, org name, billing identifiers via Stripe); optional opt-in telemetry (OTel — off by default).
  • Categories of data subjects: Customer's employees and contractors whose devices/agents are enrolled.
  • Purposes: providing the Service — queueing, scoping, delivery of memos into agent session context, receipt generation, audit, quota enforcement, billing, and support.
  • Retention: per §6 of this DPA.
  • Sub-processors: [hosting: Railway/Neon, S3 object storage; payment processing: Stripe — see §7; list to be completed by the company].

4. Controller Obligations. Customer will ensure it has lawful grounds for processing and that its instructions (including memo content pushed through the Service and scope/audience choices) comply with applicable law. Customer is responsible for authorizing "who-may-push" under its role model and for revoking devices promptly when personnel or hardware change hands. Where the DPA requires Customer choice, Customer must make the election.

5. Provider Obligations. AirMemo will: (a) process Personal Data only on documented instructions, as above; (b) ensure persons authorized to process are bound by confidentiality; (c) implement appropriate technical and organizational measures — including the controls in the security whitepaper (signed/HMAC'd transport, read-only hook, secret scanning, mandatory expiry + revocation, per-author/scope rate limits, append-only audit, fail-open delivery, adapter exit-code discipline); (d) not "sell" or share Personal Data, and not use it for advertising or profiling; (e) assist Customer with its obligations concerning data-subject rights and security, taking into account the nature of processing (deletion/rectification requests are implemented through memo revocation and offboarding/erasure flows); (f) maintain records of processing as required by law.

6. Retention, Deletion, and Erasure (the AirMemo contract — matches architecture-scaffold §6).

  1. Live retention: memos are active for 90 days, then archived (delivered messages move to PGMQ archive tables); receipts and audit events are append-only and exported on the §14 monthly cadence; the live database never scans history. PGMQ archive tables are pruned only after export — the export copy is the durable copy. Exports are written as JSONL manifests by the retention tooling (retention export-audit / export-org; infra/cloud/railway.ts documents the destination as existing S3/R2-compatible object storage — write-once bucket policy is a B5 item, not yet enforced).
  2. Offboarding / erasure (export-before-delete): within the offboarding flow, Customer may export its audit trail, receipts, and memo content at no charge during [the first 30 days after termination]. After export (or if Customer declines export), AirMemo will: revoke all devices; export audit/receipts to the Customer's own bucket [enterprise tier — otherwise delete]; and hard-delete org rows and queues within 30 days.
  3. Append-only receipts/audit: receipts and audit events are insert-only by design (no UPDATE/DELETE). During the retention window they are retained as the governance record; on erasure they are included in the export and then deleted per the offboarding flow. AirMemo will not retain copies beyond the erasure window except where law requires or the Customer elects extended export retention.
  4. Telemetry: spans/telemetry capture is opt-in per OTel convention and off by default; receipts (hash proofs) are the metric of record and are never derived from telemetry.

7. Sub-processors. Customer authorizes the sub-processors listed in §3 and updates notified by AirMemo. AirMemo will impose data-protection terms on sub-processors equivalent to this DPA and remain liable for their acts. Current list: [list all infra/payment sub-processors with names and jurisdictions — company to complete].

8. Transfers. Where Personal Data is transferred across borders, the parties will implement appropriate safeguards (e.g., EU SCCs / UK IDTA where applicable — [counsel to confirm applicability and attach the module]). Until such safeguards are in place, AirMemo will not transfer Personal Data to a third country without lawful basis.

9. Security Incident Notification. AirMemo will notify Customer without undue delay after becoming aware of a security incident affecting Customer Personal Data, providing available details and a reasonable timeline for updates; will take steps to mitigate; and will cooperate with Customer's investigation. Notification is not an admission of liability. [The company should define a concrete SLA, e.g., notification within 72 hours, per incident class.]

10. Audits and Compliance Evidence. During the pilot, AirMemo's append-only audit trail, receipts, and status page are the compliance evidence, made available to Customer on request. Customer may exercise audit rights through documented requests; on-site audits are [not offered during pilot / offered for the enterprise tier]. [SOC 2 report will be made available when the audit is obtained (deal-funded — see whitepaper §4); not currently available.]

11. Data Subject Rights. AirMemo will reasonably assist Customer in fulfilling data-subject requests (access, correction, erasure, restriction) using the Service's tooling (revocation, offboarding/erasure, export). If AirMemo receives a request directly, it will advise the requester to contact Customer and may inform Customer.

12. Liability. The liability section of the Terms applies to this DPA, including the cap. Each party's aggregate liability under the Terms and DPA together will not exceed the cap in the Terms §13.

13. Term. This DPA applies as of the Effective Date of the Terms and continues until all Personal Data is deleted or returned per §6, whichever is later. The obligations in §§5(e)–(f), 6, 9 survive termination.

14. Conflicts. In case of conflict between the Terms and this DPA, the DPA governs with respect to data processing. Customer Data is processed only under this DPA.