Data processing addendum

Last updated 15 September 2026. This is our GDPR Article 28 data processing addendum in plain language: what Ahel Technologies OÜ does with the personal data your workspace puts through ahel, and what you can hold us to. It applies to every workspace; a signed copy on your company’s name is one email away.

Who this is between

This addendum is between you, the customer who owns an ahel workspace (the controller), and Ahel Technologies OÜ, registered in Estonia under code 17078164 (the processor). It is part of the terms of service and applies whenever personal data of your customers, teammates, or users passes through ahel on your behalf. If this addendum and the terms disagree, this addendum wins for data protection.

What we process, and why

Subject matter: the configuration, credentials, prompts, tool calls, and results that your workspace stores in ahel or sends through your gateway. Duration: as long as your workspace exists, plus the deletion window below. Nature and purpose: serving your gateway to the AI clients you connect, running the tasks and automations you ask for, recording the activity your workspace needs for its own audit, and billing. Categories of data: contact details of teammates and of anyone named in the work you run, account identifiers, and whatever content you put into a prompt or a connected app. Data subjects: your teammates and the people your work concerns. We process nothing for a purpose of our own beyond running and securing the service.

Your instructions

We process personal data only on your documented instructions. Using the product is the instruction: what you install, connect, schedule, and send through the gateway. We will not process it for anything else unless a law of the European Union or of Estonia requires it, in which case we tell you first unless that law forbids it. If we think an instruction breaks data protection law, we tell you and may hold it until it is resolved.

Confidentiality

Everyone at ahel who can reach customer data is bound by a written duty of confidentiality. Access to production systems is limited to the people who operate them. Credentials you store are encrypted at rest with a key held separately from the database and are never shown back, to you or to us.

Security

We keep technical and organisational measures appropriate to the risk: encryption in transit and at rest, per-workspace isolation enforced in every query, a gateway policy that decides what a connected client may execute, an activity record of every credential use, digest-verified backups, and the measures described on the security page, which is the live statement of what is and is not in place. We help you meet your own Article 32 to 36 obligations, including impact assessments and prior consultation, with the information we hold.

Subprocessors

You authorise the subprocessors on our subprocessor register, last updated 15 September 2026. Each one is bound by written terms at least as protective as this addendum, and we remain responsible for their work. Before a new one handles customer data we update the register and email owners who hold a signed copy of this addendum at least 30 days ahead; you may object within that window, and if we cannot offer an alternative you may end the affected service without penalty. The model providers you connect on your own key are your own processors under their own terms; we forward your requests to them and nothing more.

Helping with people's rights

If someone asks us to exercise a right over data you control (access, correction, deletion, restriction, portability, objection), we pass the request to you without undue delay and do not answer it ourselves. Owners and admins can correct and delete workspace data from the product; for a copy of the data, or anything the product cannot do yet, write to privacy@ahel.ai and we help within the 30 days the privacy policy promises.

If something goes wrong

If we become aware of a personal data breach affecting your data, we notify the workspace owner without undue delay, and in any case within 72 hours of becoming aware, with what we know at that point: what happened, which data and roughly how many people, the likely consequences, and what we have done about it. We keep you informed as we learn more and keep a record of the incident.

Where the data goes

Application data is hosted in the European Union (Germany). Some subprocessors on the register are in, or route through, the United States; those transfers rest on the European Commission’s standard contractual clauses or an adequacy decision. The providers you connect on your own key send data wherever that provider runs, under your own agreement with them.

When it ends

Delete your account, or ask us to delete your workspace, and we delete its data. Backups holding a copy are kept for disaster recovery only and are never restored to bring individual data back. Before deleting, ask us for a copy at privacy@ahel.ai. We keep only what a law of the European Union or of Estonia requires us to keep, such as invoices.

Audits

We make available the information needed to show we meet Article 28. Once a year, or after a breach, you may ask written questions or, with 30 days notice and at a time that does not disrupt the service, have an independent auditor bound by confidentiality inspect the parts of our operation that process your data. The security page and the register are the starting point.

Liability

Each party is liable for its own breaches of this addendum and of the GDPR as the law allocates them. The liability limits in the terms of service apply to this addendum too, except where the law does not allow them to.

Request a signed copy

Send your company name, registry number, and the email address of the workspace owner. We return this addendum as a PDF signed by Ahel Technologies OÜ, dated, with the subprocessor register as it stands that day, for you to countersign.

Request a signed copy

Questions about this addendum go to privacy@ahel.ai. The privacy policy covers your own personal data as an ahel user.