Data Processing Addendum
Last updated: 20 August 2026 · Version 1.0
This Data Processing Addendum (“DPA”) is for organizations in the United Kingdom, the European Economic Area / Switzerland, and the United States that use IAM-Token for a business purpose. It forms part of the Terms of Service when you create a workspace, buy a Business plan, or otherwise use the Service for an organization.
Personal / consumer accounts are covered by the Privacy Policy only. This DPA does not apply to HIPAA-regulated PHI unless we sign a separate BAA with you.
1. Parties and roles
- Customer is the organization that holds the account. Customer is the controller (UK/EU GDPR) of Customer Data, and the “business” under US state privacy laws.
- IAM-Token (“I amToken”, “Processor”) processes Customer Data only to provide the Service. We are the processor (UK/EU GDPR) and a “service provider” / “contractor” under the CCPA/CPRA and similar US state laws.
- Model providers that fulfill a request process it under their own terms. Customer instructs us to transmit the request to the provider selected by routing.
2. Customer Data
“Customer Data” means content Customer submits through the Service, files, workspace member details, and any personal data of Customer's end users in that content. It does not include Account Data we control ourselves (your billing email, hashed password, our usage metadata and invoices), which the Privacy Policy covers.
Details of processing:
- Subject matter: AI routing, workspaces, and billing.
- Duration: the Term, plus the deletion periods in the Privacy Policy.
- Nature: transmit to model providers, bill, secure, and support.
- Purpose: Customer's instructions as configured in the product (including Settings).
- Types of data: as listed in Privacy Policy section 3. Customer decides whether submitted content contains special-category or sensitive data.
- Data subjects: Customer's staff, end users, and anyone whose data Customer includes in a request.
3. Instructions
Customer instructs Processor to process Customer Data to provide the Service, including routing to model providers and subprocessors on the Subprocessors list. Additional written instructions must be sent to privacy@iam-token.com. We will tell you if an instruction appears unlawful.
Processor will not use Customer Data to train its own foundation models, will not sell Customer Data, and will not use Customer Data to build profiles for third-party advertising.
4. Confidentiality and security
Personnel who handle Customer Data are under confidentiality duties. Security measures currently include: TLS in transit on deployed environments; encryption at rest for BYOK keys and TOTP secrets; hashed passwords and session tokens; optional MFA; access limited to operators who need it. We will maintain measures appropriate to the risk. Report incidents to privacy@iam-token.com.
5. Subprocessors
Customer authorizes the vendors on the Subprocessors page, including Stripe, the transactional email provider, infrastructure host, and model providers Customer uses (or that auto-routing selects). We will impose data-protection terms no less protective than this DPA on our own processors. Model providers remain independent as to their inference stack.
Notice of new subprocessors: 30 days on that page and by email to the account owner, with a right to object as stated there.
6. International transfers (UK, EEA, Switzerland)
Customer Data may be processed in the United States and other countries where Processor or a subprocessor operates. For restricted transfers the following are incorporated as of the date Customer accepts this DPA, without a wet signature:
- EEA: EU Commission Standard Contractual Clauses (Decision (EU) 2021/914), Module 2 (controller → processor). Customer is data exporter; IAM-Token is data importer. Clause 17/18: Ireland law and courts unless Customer is established in another EU Member State, in which case that Member State's law and courts apply.
- United Kingdom: the UK International Data Transfer Addendum to the EU SCCs issued by the ICO (version B1.0, in force 21 March 2022, as updated), with Table 4 completed so that either party may end the Addendum as the ICO template allows. Mandatory UK clauses prevail for UK transfers.
- Switzerland: the SCCs with the adaptations required by the FDPIC (including Swiss data subjects and the Swiss Federal Act on Data Protection).
SCC annexes: the descriptions in sections 1–2 of this DPA and the Subprocessors list are Annex I and III; security measures in section 4 are Annex II. Adequacy decisions apply where they exist (including, when in force, UK–US or EU–US Data Privacy Framework participants among subprocessors).
7. Assistance, DSARs, DPIAs
Taking into account the nature of processing, we will help Customer respond to data-subject requests, and with DPIAs and consultations with the ICO, a lead EU supervisory authority, or a US state attorney general, by providing the product tools (member removal, Settings) and information we can reasonably give. End-user requests about Customer Data should go to Customer first. If we receive one directly, we will forward it to Customer's account email unless legally prohibited.
8. Personal-data breaches
We will notify Customer without undue delay and, where feasible, within 72 hours of becoming aware of a personal-data breach affecting Customer Data, with the facts we then know (nature, likely consequences, measures taken). Customer remains responsible for notifying the ICO, EU authorities, or US residents when the law puts that duty on the controller / business.
9. Return and deletion
During the Term, Customer can request export or deletion by asking privacy@iam-token.com (there is no in-app bulk export yet). After the Term we delete or anonymize Customer Data as described in the Privacy Policy (including the 30-day restore window on personal-style accounts and support-gated closure for workspaces). Invoice, tax, and security records we must keep are not Customer Data for this clause.
10. Audits
Once per 12 months, on 30 days' notice, Customer may request information reasonably needed to verify this DPA (security overview, this page, subprocessors). An independent auditor under confidentiality may inspect, at Customer's cost, if that information is not enough and there is a reasonable suspicion of material non-compliance. We may refuse an audit that threatens other customers' security; we will then offer an alternative that still lets Customer meet UK GDPR Article 28 / EU GDPR Article 28.
11. United States (CCPA/CPRA and similar state laws)
Processor is Customer's service provider. We will not: sell or share Customer Data; retain, use, or disclose it outside the business purpose of providing the Service (including not for our own commercial purposes, except as permitted for service providers); or combine it with personal information from other sources except as permitted to provide the Service (for example abuse detection). We certify that we understand these restrictions. If we can no longer meet them we will tell Customer. Customer may take reasonable steps to stop unauthorized use, including instructing us to delete Customer Data we still hold.
We will not use sensitive personal information to infer characteristics. We honor a GPC signal on our own properties as an opt-out of sale/share; we do not sell or share in that sense today.
12. UK extra terms
- UK GDPR and the Data Protection Act 2018 apply to UK Customer Data.
- Complaints may be made to the Information Commissioner's Office: ico.org.uk.
- If UK law requires a UK representative, Customer may request our current appointment at privacy@iam-token.com.
13. Liability and order of documents
Liability under this DPA is subject to the limitations in the Terms, except that nothing in this DPA limits liability that cannot be limited under UK or EU data-protection law as between a controller and a processor toward data subjects. If this DPA conflicts with the Terms on data protection, this DPA controls.
14. Changes
We may update this DPA for law or product changes. Material reductions of Customer's protection will be notified by email at least 30 days in advance. Continued use after that date is acceptance, or Customer may stop using the Service before it takes effect.
15. Contact
Privacy / DPA: privacy@iam-token.com
Support: support@iam-token.com
This DPA is a click-wrap template for UK, EU, and US business customers. Have counsel review it. A signed paper copy is available on request if your procurement team requires one.