Loading…
Loading…
DRAFT FOR PRODUCT PREVIEW — not legal advice and not a binding agreement. Pending counsel, operating-entity designation, and partner review. Mandatory consumer and data-protection rights are not waived.
This Data Protection summary describes how the marketplace approaches personal data governance, security, and data-subject requests. It complements the Privacy Notice and is aimed at customers’ security/privacy reviewers.
Internal assurance drafts (RoPA, DPIA, breach-72h runbook, DPA/BAA templates, PCI Stripe SAQ narrative, SOC 2 evidence index) support sales and audits but are not signed contracts or certifications until countersigned or attested by an auditor.
Typical pattern: Customer is controller of end-user chat and knowledge content; MyInstantAI / platform operator acts as processor for that content. For marketplace account data we may act as controller — TBD counsel per entity.
Sub-processors include hosting, database, optional Redis, LLM providers, Stripe, and OAuth vendors you enable. A schedule will attach to the DPA.
Marketplace chat across Studio, website, App, Ask AI, and embed — transcripts, session and correlation ids.
OAuth connector tokens — sealed at rest; not included in DSAR export packages.
Knowledge sources — uploads, paste, and limited same-site crawl text.
Audit & traceability — append-oriented events for security and support.
Leads & custom requests — prospect contact fields when submitted.
Workspace RBAC — membership and roles for access control.
Lawful bases are mapped per activity in the RoPA draft and must be confirmed by counsel before production marketing claims.
Product controls encouraging minimisation: confirm-before-write on side effects, guardrails against collecting PAN/OTP/passwords in chat, PII redaction hooks on live paths, and body-size limits on APIs.
Access / portability: authorised workspace owner/admin may obtain a JSON export via the DSAR export API (excludes OAuth secrets and raw provider tokens).
Erasure: managed workspace erasure endpoint for admins creates audit tombstones; residual copies in backups/subprocessors follow their deletion cycles once production backup policy is live (TBD).
Rectification / restriction / objection: process via support until self-serve tooling exists; timelines TBD (GDPR 30 days / POPIA as applicable).
Identity verification: we may require proof of authority over the workspace before fulfilling requests.
Access: workspace RBAC; OIDC path for production; staging mock rails only under dual acknowledgment flags.
Encryption: TLS in transit; OAuth token encryption at rest; Postgres as durable store when DATABASE_URL is set (required in production).
Network egress: SSRF protections and DNS pinning for guarded fetches; Shopify/Zendesk host allowlists.
Integrity: webhook HMAC (timestamp + body); timing-safe compares for secrets; append-oriented audit inserts.
Application: zod validation, content-length caps, CSP (unsafe-eval removed; unsafe-inline residual documented), optional Redis rate limits that fail closed when Redis is configured but unavailable.
Supply chain: CI typecheck/tests/catalogue integrity/static-eval gates; secret scanning; critical dependency audit.
Draft 72-hour breach runbook exists for internal use. Customer notification commitments and supervisory authority filings will be defined in the DPA and local law (e.g. POPIA, GDPR Art. 33/34).
Report suspected incidents via SECURITY.md / support channels immediately.
Staging hosting and LLM regions may involve transfers outside the customer’s country. EU residency, Azure Private Link, and Key Vault-backed KMS are tracked as partner/Azure dependencies — not claimed as complete on staging alone.
Transfer tools (SCCs, TIAs): TBD counsel per customer.
HIPAA: not offered without an executed BAA and PHI architecture decision. Do not upload PHI for production use under this draft.
PCI: card data must not be entered in chat; Stripe Checkout / Payment Links handle cards. SAQ narrative is draft evidence only.
Children’s data and special-category data: not targeted; customer must not configure agents to solicit them without legal review.
Configure agents and knowledge lawfully; obtain end-user notices where you are controller; manage OAuth scopes; review audit logs; execute DPA before scaling regulated workloads; and keep admin accounts secured.
Data protection / DSAR: partner or MyInstantAI support with workspace id. DPO / Information Officer formal contacts: TBD.