Roles and instructions
Where AdaMind processes Customer Personal Data on behalf of a business customer, the customer is controller/business and AdaMind is processor/service provider, except for processing AdaMind independently determines under the Privacy Notice. Processing includes hosting, databases, AI-assisted operations, collaboration, support, security, and customer instructions.
Customers are responsible for lawful collection, notices, consent, instructions, data minimization, rights requests, and the content they submit.
Current security and infrastructure facts
Hosting, databases, and infrastructure are provided through OVHcloud in Virginia, USA. Server access is restricted to authorized AdaMind development and maintenance. IIS request logging is disabled, although limited application and integration error logs may be generated. AdaMind will notify affected customers after a confirmed breach where required by law.
AdaMind does not provide an AdaMind-controlled encrypted secrets vault or guaranteed managed customer-project backups. Customers control credentials and independent backups. AdaMind infrastructure backups exclude customer project folders and customer project databases.
Current providers
| Provider | Purpose |
|---|---|
| OVHcloud | Infrastructure, hosting and databases in Virginia, USA |
| OpenAI | AI prompts and selected project context |
| Zoho Mail | Transactional email |
| Google Analytics | Commercial website analytics |
| GoDaddy | Domain registration and DNS |
| GitHub | Customer-authorized repository integration and backups |
| Stripe | Payment processing when activated |
| WhatsApp / Meta | Optional customer support communications |
Customers generally authorize these providers as needed for requested features. Provider terms and data locations may apply.
Return, retention, and deletion
After paid access expires, the intended account status is read-only for 30 days. Planned notices occur at expiration, seven days before deletion, and one day before deletion. The automated workflow remains in implementation. Customers must export data and maintain independent backups.
Billing and tax records may be retained for legal periods, limited sanitized application logs for up to 90 days where generated, and incident or legal records as necessary.
Status of this online DPA
This page is a baseline disclosure, not a fully executed enterprise DPA. Customers requiring GDPR Article 28 terms, standard contractual clauses, audit schedules, technical-measures annexes, or negotiated commitments should contact admin@adamind.dev before submitting regulated personal data.
AdaMind