profusia ai
Draft for attorney review — not yet in force.

Part of the legal pack — see also: Terms of Service · Privacy Policy · Acceptable Use Policy · Refund Policy. The in-force privacy page this product operates under today is /privacy, unaffected by this draft.

Profusia AI — Data Processing Addendum

Effective date: [DATE]

This Data Processing Addendum ("DPA") forms part of the Profusia AI Terms of Service (the "Agreement") between Evadaroo & Company, LLC, a Pennsylvania limited liability company trading as Profusia AI ("Profusia", "Processor"), and the customer identified in the Agreement ("Customer", "Controller"). It applies where Profusia processes Personal Data on Customer's behalf. Where this DPA conflicts with the Agreement on data protection, this DPA governs.


1. Definitions

Terms not defined here have the meaning given in the GDPR. "Data Protection Laws" means the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018 ("UK GDPR"), the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended by the CPRA ("CCPA"), and other applicable US state privacy laws, each as applicable. "Customer Personal Data" means Personal Data contained in Customer Content and processed by Profusia under the Agreement. "SCCs" means the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914. "UK Addendum" means the UK Information Commissioner's International Data Transfer Addendum to the SCCs, version B1.0.

2. Roles and scope

2.1 Customer is the Controller (or processor acting for a third-party controller) and Profusia is the Processor (or sub-processor) of Customer Personal Data. Under the CCPA, Profusia is a Service Provider.

2.2 Profusia is a Controller for the limited set of data it processes for its own account: the account and billing relationship with Customer, security and abuse prevention, and its own audit and delivery records. That processing is described in the Privacy Policy and is outside this DPA.

2.3 Details of processing are in Annex I. Security measures are in Annex II. Sub-processors are in Annex III.

3. Profusia's obligations

Profusia will:

3.1 Process only on documented instructions. Profusia processes Customer Personal Data only to provide, secure, and support the Service in accordance with the Agreement, this DPA, and Customer's use of the product, or as required by law — in which case, unless the law forbids it, Profusia will tell Customer first.

3.2 Never sell or share it. Profusia will not sell Customer Personal Data, will not share it for cross-context behavioral advertising, and will not retain, use, or disclose it for any purpose other than performing the Service, including not combining it with data from other sources except as permitted by the CCPA. Profusia certifies it understands and will comply with these restrictions.

3.3 Never train models on it. Profusia will not use Customer Personal Data or Customer Content to train, fine-tune, or improve any machine-learning model. AI providers process content only as set out in Section 8 and Annex III.

3.4 Bind its people to confidentiality, and limit access to those who need it to perform the Service.

3.5 Implement the measures in Annex II, appropriate to the risk, taking account of the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing.

3.6 Assist Customer with data subject requests (Section 6), with security, breach notification, and, taking account of the nature of processing and the information available to Profusia, with data protection impact assessments and prior consultations.

3.7 Notify Customer of a Personal Data Breach without undue delay and in any event within 72 hours of becoming aware, with the nature of the breach, the categories and approximate number of data subjects and records affected so far as known, the likely consequences, the measures taken or proposed, and a contact point. Profusia will provide updates as facts emerge and will not delay an initial notice to complete an investigation.

3.8 Delete or return Customer Personal Data on termination, per Section 9.

3.9 Make available the information needed to demonstrate compliance, and submit to audits, per Section 10.

3.10 Tell Customer if an instruction infringes Data Protection Laws, in Profusia's opinion.

4. Customer's obligations

Customer will: (a) have a lawful basis for the Personal Data it puts into the Service and for Profusia's processing of it; (b) provide required notices and obtain required consents from data subjects; (c) issue instructions that comply with Data Protection Laws; (d) configure sharing, roles, audience groups, and portals so that Personal Data reaches only intended recipients — every outward link the Service mints is a bearer link, and Customer is responsible for who holds one; and (e) not put special-category data, protected health information subject to HIPAA, payment card data subject to PCI DSS, children's data, or government-classified data into the Service, which is not designed or certified for it.

5. Sub-processors

5.1 General authorization. Customer authorizes Profusia to engage the sub-processors listed in Annex III, and to engage others on the terms below.

5.2 Notice of change. Profusia will give Customer at least 30 days' notice before a new or replacement sub-processor begins processing Customer Personal Data, by updating /privacy and notifying workspace owners by email or in-product notice.

5.3 Objection. Customer may object on reasonable data protection grounds within those 30 days. The parties will discuss in good faith. If Profusia cannot offer a reasonable alternative, Customer may terminate the affected part of the Service without penalty and receive a pro-rata refund of prepaid, unused fees.

5.4 Flow-down and liability. Profusia will impose data protection obligations on each sub-processor no less protective than this DPA, and remains liable to Customer for each sub-processor's performance.

6. Data subject rights

6.1 Profusia will, taking account of the nature of the processing, assist Customer by appropriate technical and organizational measures in responding to data subject requests.

6.2 Most requests need no ticket. Access and portability are served by the console's export; rectification is editing the record; erasure of a person and of a whole workspace are product acts an admin or owner can perform. Where a request cannot be served by a product act, Profusia will assist at Customer's reasonable request.

6.3 If a data subject contacts Profusia directly about Customer Personal Data, Profusia will not respond substantively; it will refer them to Customer and tell Customer promptly.

7. International transfers

7.1 Profusia is established in the United States. Where Customer Personal Data protected by the GDPR is transferred to Profusia, the SCCs are incorporated into this DPA by reference and apply as follows:

  • Module Two (Controller to Processor) where Customer is a controller; Module Three (Processor to Processor) where Customer is itself a processor.
  • Clause 7 (docking) applies. Clause 9: Option 2 (general written authorization), with the notice period in Section 5.2. Clause 11: the optional independent dispute-resolution body is not used. Clause 17: governed by the law of Ireland. Clause 18(b): courts of Ireland.
  • Annex I.A/I.B are populated by Annex I of this DPA; Annex II by Annex II of this DPA; Annex III (sub-processors) by Annex III of this DPA.

7.2 United Kingdom. For transfers subject to the UK GDPR, the UK Addendum is incorporated: Table 1 is populated by the parties' details in the Agreement; Tables 2 and 3 by Section 7.1 and the Annexes; Table 4: neither party may end the Addendum as set out in Section 19.

7.3 Switzerland. For transfers subject to the Swiss FADP, the SCCs apply with "Switzerland" read for the EU where necessary, the Swiss Federal Data Protection and Information Commissioner as supervisory authority, and "personal data" extended to data of legal entities while Swiss law so provides.

7.4 Conflict. Where the SCCs or the UK Addendum conflict with this DPA, the SCCs or the UK Addendum govern.

7.5 Government access. Profusia will, to the extent legally permitted, notify Customer of any binding request from a public authority for Customer Personal Data, challenge requests it believes unlawful or overbroad, and disclose only the minimum required. Profusia has received no national-security order requiring it to provide access to Customer Personal Data as of the effective date of this DPA.

8. AI processing

8.1 In-app AI is off unless the deployment has a provider configured, and off entirely on the Free plan. Where Customer uses an AI feature, the relevant document, plan, or card text — and an audio clip where a question is spoken — is transmitted to the answering provider for that request only.

8.2 Profusia stores no conversation and no transcript, and the models are given no tools, so a model cannot act on the workspace.

8.3 Providers whose free tiers reserve the right to train on inputs are structurally excluded from Customer Content on any deployment serving more than the single workspace that accepted that trade. The exclusion is implemented in code and fails closed.

8.4 Each AI provider is a sub-processor listed in Annex III and processes content under its own API terms. Where a provider offers zero-data-retention terms, Profusia prefers them. Profusia does not warrant a provider's retention posture beyond what that provider publishes.

8.5 Outputs may be inaccurate. Profusia makes no representation that AI output is accurate, complete, or fit for Customer's purpose, and Customer is responsible for review before reliance. Profusia does not use AI to make decisions producing legal or similarly significant effects on data subjects.

9. Deletion and return

9.1 Customer may export Customer Personal Data at any time using the product's own export, on every plan, without charge.

9.2 On termination, the workspace becomes unreachable immediately and remains recoverable and exportable for 30 days. After that window a daily job permanently erases its database rows and stored files. Customer may request immediate erasure inside the window.

9.3 Profusia will retain Customer Personal Data after that only where law requires, and will continue to protect it for as long as it does.

9.4 Backups and the operational records listed in Annex I expire on their own stated cycles.

10. Audit

10.1 Profusia will make available to Customer the information reasonably necessary to demonstrate compliance with this DPA, including the current descriptions in Annexes II and III, the public trust and privacy pages, and the forwardable security packet.

10.2 Where that is not sufficient for a Customer subject to Data Protection Laws, Customer may, once in any 12-month period, on 30 days' written notice, conduct an audit — remote and document-based by default — at Customer's expense, during business hours, without unreasonable disruption, and subject to confidentiality. A regulator's audit right is not limited by this Section.

10.3 Profusia holds no SOC 2 report, ISO 27001 certificate, HIPAA attestation, or third-party penetration test, and none is in progress. This is stated plainly rather than implied otherwise; a customer whose procurement requires one should raise it before contracting.

11. Liability

Each party's liability under this DPA is subject to the limitations and exclusions in the Agreement, except where Data Protection Laws do not permit that limitation. Nothing in this DPA limits a data subject's rights under the SCCs.

12. Term

This DPA takes effect on the effective date above and continues until Profusia has ceased all processing of Customer Personal Data.


Annex I — Details of processing

A. List of parties

  • Data exporter / Controller: the Customer named in the Agreement. Contact: the workspace owner's email on file. Role: controller (or processor for a third-party controller).
  • Data importer / Processor: Evadaroo & Company, LLC, d/b/a Profusia AI, [REGISTERED OFFICE ADDRESS], Pennsylvania, USA. Contact: legal@evadaroo.com. Role: processor. Activities: providing the Profusia AI document hosting, publishing, planning, and optional AI features described in the Agreement.

B. Description of transfer

ItemDetail
Categories of data subjectsCustomer's personnel (workspace members and their roles), Customer's clients and recipients who open shared links or portals, and any individuals described within documents, plans, comments, or datasets that Customer chooses to put into the Service.
Categories of personal dataAccount data (email, optional name, hashed password, role, membership); content data (whatever appears in documents, versions, plans, cards, comments, datasets, and their metadata); usage data (audit events attributing actions to a user, AI call ledger, per-document per-day view counts with no visitor identifier); portal visitor data (a self-reported display name and a hashed session).
Special categoriesNone permitted. Customer must not place special-category data, PHI, payment card data, children's data, or classified data in the Service.
FrequencyContinuous, for the duration of the Agreement.
Nature and purposeHosting, storage, version retention, indexing for search, delivery to recipients Customer designates, work tracking, audit, optional AI answering, optional notification email, and optional one-way sync into Customer's own Google Drive.
RetentionAs in the Privacy Policy: content until deleted and purged; audit log 400 days; AI call ledger 90 days; portal sessions 90 days; a deleted workspace erased 30 days after deletion.
Sub-processor transfersAs in Annex III; same subject matter, nature, and duration.

C. Competent supervisory authority. Determined under SCC Clause 13 by the Member State of the exporter's establishment or its EU representative; where the exporter is not established in the EU, the authority of the Member State where the data subjects are located.


Annex II — Technical and organizational security measures

These describe measures actually implemented. Nothing here is aspirational.

Tenant isolation. Every database query runs through a single workspace-scoping choke point, so an unscoped cross-tenant query cannot be written rather than being a bug to watch for. Each workspace is additionally served from its own subdomain, so the browser's own origin rules enforce separation independently of application code and independently of whether a share token is valid. Every new workspace-scoped table must pass a cross-tenant proof before it ships — an automated suite authenticates two independent workspaces and shows that one, handed the other's real identifiers, is correctly refused.

Access control. Owner / admin / member / viewer roles govern what a person may do. A document or a whole space can be narrowed to a named group. Removing a membership ends that person's live sessions immediately. Whether a person may hand a document to an outsider is a separate right from whether they may write it. An access key is rotatable from the operator console, and connected assistants are separately disconnectable, because they are different credentials.

Credential handling. Share links, site links, embed tokens, plan links, portal tokens, sign-in sessions, OAuth tokens, and per-workspace access keys are high-entropy and stored only as SHA-256 hashes. A database read alone never yields a usable secret. A password on a share link is stored as a PBKDF2-SHA256 derivation at the runtime's maximum iteration count, and the unlock door is rate-limited per IP and per link before any verification work, so it is not a token oracle.

Encryption. TLS in transit on every route, with HSTS. Files in Cloudflare R2 and metadata in Cloudflare D1, encrypted at rest by the platform. The one third-party credential the Service can hold — the optional Google drive.file authorization — is AES-GCM encrypted at rest under a wrapping key held outside the database, never returned by any interface, and erased with the workspace.

Content isolation. Customer content is never executed server-side. Delivered pages are static files under a strict Content Security Policy permitting at most a page's own dataset as a network destination. Comment highlighting reads a delivered document from the surrounding page rather than injecting into it.

Logging and audit. Publishing, sharing, revoking, permission changes, sign-ins, and other privileged mutations are written to an append-only audit trail, retained 400 days, exportable as CSV by an administrator. AI calls are metered against the model that actually answered.

Abuse resistance. Rate limits on anonymous and credential-guessable surfaces; per-workspace daily and monthly AI spend ceilings that hard-stop before a call; an emergency lock that refuses share links and portals.

Availability and recoverability. Nightly backups with verification; the erasure sweep is chained behind a verified backup, so nothing is permanently erased on a night that did not verify. An operator readiness page computes — never asserts — the state of every sweep, the last verified backup, and the nights held. Whether a dump restores is proven on every QA run rather than assumed.

Deletion. Deletion is soft by default; every read filters deleted rows, including anonymous delivery lookups, so a share link stops resolving the moment content is trashed. Permanent erasure is a separate, explicitly confirmed act, scheduled with a grace window that a restore cancels.

Organizational measures. Access to production is limited to the company's principal. Change management runs through an automated test suite, a typecheck gate, and a deploy-verify record. A published vulnerability disclosure contact is maintained per RFC 9116.

Stated limitations. Isolation is logical, not physical. There is no dedicated security officer and no formal third-party audit or penetration test. There is no regional-pinning guarantee. These are recorded here rather than omitted.


Annex III — Sub-processors

Infrastructure and operations

Sub-processorPurposeDataLocation
Cloudflare, Inc.Hosting, object storage, database, deliveryAll Customer Personal Data stored in the ServiceUS company; global network
ResendNotification email, where switched onRecipient email address, notification title and body, linkUS
ClerkIdentity: sign-up, verification, invitation email, password reset — where switched onEmail address, sign-in metadataUS

AI model providers — engaged only where AI features are configured and used, for the content of the request being answered:

Sub-processorNotes
Google LLC (Gemini, via Google AI Studio)Also the provider for spoken questions
Anthropic, PBCPaid tier; does not train on submissions
OpenAI, L.L.C.Paid tier
Groq, Inc.Free tier — excluded from Customer Content under Section 8.3
Cerebras SystemsFree tier — excluded from Customer Content under Section 8.3
OpenRouterFree tier — excluded from Customer Content under Section 8.3
Mistral AIFree tier — excluded from Customer Content under Section 8.3
Cloudflare Workers AISmall-model fallback

All are US or EU/US-operating providers. Which are enabled is a deployment decision; none are enabled by default.

Not a sub-processor: a Google Drive account Customer connects is Customer's own destination, not ours. Profusia writes into it and has no read path. An assistant Customer connects over MCP is Customer's own vendor relationship.

Not a sub-processor — Paddle. Paddle (Paddle.com Market Limited and its affiliates) is our reseller and Merchant of Record for paid plans. It processes billing contact, payment and tax details as an independent controller under its own privacy notice (paddle.com/legal/privacy), for the purchase itself. It receives no Customer Personal Data from the Service, so it is not a sub-processor under this DPA. Payment details go to Paddle, never to us.

Not a sub-processor — Uiia. The help assistant on /help is Uiia (uiia.app), a separate product of the same company. It receives only the question a visitor types there and nothing from Customer's workspace, so it processes no Customer Personal Data.

Current list. Maintained at https://profusia.ai/privacy. Changes follow Section 5.2.


Evadaroo & Company, LLC · [REGISTERED OFFICE ADDRESS] · Pennsylvania, USA · legal@evadaroo.com