Data Processing Addendum (DPA)
Standard terms governing AmeritAI's (Norshin LLC) obligations as a data processor, for business customers.
Last updated: August 2, 2026
This DPA forms part of the Terms of Service and sets the data-protection terms that apply to business customers. To request a countersigned copy, contact privacy@ameritai.com.
1. Roles of the Parties
For personal data of your end-users processed through the Service, you (the business customer) are the data controller and Norshin LLC is the data processor, acting only on your documented instructions. For your own account data, Norshin LLC is the controller as described in the Privacy Policy.
2. Subject Matter, Duration, and Purpose
We process personal data for the duration of your subscription, solely to provide the Service: automating and assisting conversations across web chat, Meta channels (Messenger, Instagram, WhatsApp), Telegram, SMS, and voice, and related features you enable.
3. Data Subjects and Categories of Data
Data subjects: your customers and prospects who interact with your assistant. Categories: identifiers (name, email, phone, platform-scoped IDs), message content, and technical/usage data. You must not use the Service to collect special-category or highly sensitive data.
4. Processor Obligations
We will: (a) process personal data only on your instructions; (b) ensure personnel are bound by confidentiality; (c) implement appropriate technical and organizational security measures; (d) assist you with data-subject requests and with security, breach-notification, and impact-assessment obligations; and (e) delete or return personal data at the end of the engagement, subject to legal retention.
5. Subprocessors
You authorize us to engage the subprocessors listed at ameritai.com/subprocessors. We impose data-protection obligations on them and remain responsible for their performance. We will provide a mechanism to notify you of changes.
6. International Transfers
Where personal data is transferred across borders, we rely on appropriate safeguards such as the EU Standard Contractual Clauses (SCCs).
7. Audits
On reasonable request, we will make available information necessary to demonstrate compliance with this DPA, and allow for audits consistent with confidentiality and security.
Execution and Requests
For a signed DPA, the subprocessor list, or security documentation, contact privacy@ameritai.com. See also our Subprocessors and Security pages.