Last updated September 2, 2026
This addendum applies wherever Raiw AI processes personal data on behalf of a customer using raiw. It forms part of the Terms of Service and takes effect without signature when you accept them; if your procurement process needs it executed as a separate document, write to [email protected] and we will sign this text. On any question about personal data we process for you, this addendum prevails over the Terms.
1. Definitions and roles
"Customer personal data" means personal data contained in the documents you upload, in the questions you ask, and in the output generated from them. Controller, processor, personal data, processing and personal data breach have the meanings given in the GDPR. "Data protection law" means the EU GDPR, the UK GDPR and the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection, and the US state privacy laws that apply to us, each as amended.
You are the controller of customer personal data. Raiw AI is the processor of it. Where you are yourself a processor for another controller, we are a sub-processor, and this addendum applies as though references to a controller were to your own controller. For account data about your users we are an independent controller, and the Privacy Policy governs that.
2. Instructions and purpose limitation
We process customer personal data only on your documented instructions, which consist of this addendum, the Terms, and your use of the service's features. We will tell you if we believe an instruction breaches data protection law, and we may pause the affected processing until it is resolved. We will not process customer personal data for our own purposes, we will not sell or share it, and we will not use it to train models.
We process it only for the duration and the purposes in Annex I, and only in a manner that lets you comply with your own obligations. If we can no longer meet an obligation in this addendum, we will tell you promptly and you may suspend the affected processing or terminate.
3. Confidentiality
Personnel authorized to process customer personal data are bound by written confidentiality obligations that survive the end of their engagement, and are given access only where their work requires it. We do not disclose customer personal data to anyone else except as this addendum permits or the law compels.
4. Security
We implement the technical and organizational measures described in Annex II, appropriate to the risk, as Article 32 requires. Those measures may change as the service evolves, and we will not reduce their overall level of protection.
5. Sub-processors
You give general written authorization for us to engage sub-processors. The current list is Annex III, published and kept current at Subprocessors. We update that page before a new sub-processor begins processing, and you have 30 days from the update to object on reasonable data-protection grounds. To be told when it changes rather than having to watch it, write to [email protected] and we will add you to the notification list.
If we cannot resolve an objection, you may terminate the affected part of the service and receive a pro-rata refund of prepaid fees for it. We impose data-protection obligations on each sub-processor that are no less protective than those in this addendum, and we remain liable for their performance.
6. Assisting you
- Data subject requests. The service gives you direct access to, export of, and deletion of the data in your workspaces, which is how most requests are satisfied without involving us. Where that is not enough, we will assist you, taking into account the nature of the processing. If a request reaches us directly we will not respond to it substantively; we will tell you, and let you answer.
- Breach notification. We will notify you without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting customer personal data, with the information you need for your own Article 33 notification and updates as we learn more.
- Impact assessments. We will provide reasonable assistance with data protection impact assessments and prior consultations under Articles 35 and 36.
- Government and law enforcement requests. If we receive a legally binding request for customer personal data, we will notify you before disclosing anything unless we are legally prohibited from doing so, and we will challenge a request that appears unlawful or overbroad. We disclose only the minimum the request compels. We have received no order requiring us to give a government bulk or direct access to customer personal data.
7. Audit
We will make available the information reasonably necessary to demonstrate compliance with Article 28, and allow for audits by you or an auditor you mandate — no more than once a year unless a supervisory authority requires otherwise or there has been a breach — on 30 days' notice, during business hours, without unreasonable disruption, and subject to confidentiality. Where a written response to your questions answers them, that is the first step before an on-site audit.
8. International transfers
Where customer personal data is transferred out of the EEA, the UK or Switzerland to a country without an adequacy decision, the parties incorporate the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor), or Module Three (processor to processor) where you act as a processor, with the following selections:
- Clause 7 (docking) applies.
- Clause 9(a): Option 2, general written authorization, with the 30-day notice period in section 5.
- Clause 11: the optional independent dispute resolution body does not apply.
- Clause 17: the law of the EEA member state in which the data exporter is established, or Irish law where the exporter is not established in the EEA.
- Clause 18(b): the courts of that same member state, or the courts of Ireland.
- Annexes I, II and III to the Clauses are populated by the Annexes below.
United Kingdom. The UK International Data Transfer Addendum (version B1.0) applies to UK transfers, with the Clauses above as its Approved EU SCCs. In Table 4, neither party may end the Addendum as set out in section 19 of it.
Switzerland. For transfers subject to Swiss law, references in the Clauses to the GDPR are read as references to the Swiss Federal Act on Data Protection, the competent authority is the Federal Data Protection and Information Commissioner, and "member state" is read so that Swiss data subjects may bring proceedings in Switzerland.
9. US state privacy law
For personal information subject to the California Consumer Privacy Act we are a "service provider" and you are the "business". We process personal information only to provide the service under the Terms, and we will not: retain, use or disclose it for any purpose other than those business purposes; sell or share it; combine it with personal information from another source except as the regulations permit; or use it outside our direct business relationship with you. We will notify you if we determine we can no longer meet these obligations, and we grant you the right to take reasonable and appropriate steps to confirm that we are using personal information consistently with them, which section 7 is the mechanism for. Equivalent commitments apply where we act as a processor under the Virginia, Colorado, Connecticut, Texas, Utah or other state privacy statutes.
10. Deletion and return
You may export your data through the service at any time, including after termination and before deletion runs. We delete customer personal data within 30 days of account closure, along with the copies held by our sub-processors, except where law requires us to retain it — in which case we continue to protect it and process it only for that purpose. The exceptions are listed in section 9 of the Privacy Policy. We will confirm deletion in writing on request.
11. Liability, changes and term
Each party's liability under this addendum is subject to the limitations and exclusions in the Terms of Service, except where data protection law does not permit that. This addendum lasts as long as we process customer personal data for you, and the obligations that protect that data survive its termination. We may update it to reflect a change in law, in the Clauses, or in the service; where an update materially affects your rights we will give notice as we would for a change to the Terms, and every document currently in force is listed in the legal register.
Annex I: description of processing
A. Parties
| Data exporter | The customer, acting as controller (or as processor for its own controller). Name, address and contact are those on the customer's account. Activities relevant to the transfer: uploading documents to raiw and asking questions of them. |
|---|---|
| Data importer | Raiw AI, 2800 E. Enterprise Ave, Ste 333, Appleton, WI 54913, United States, acting as processor. Contact for data protection: [email protected]. Activities relevant to the transfer: providing document storage, text extraction, indexing, retrieval and question answering as described in the Terms. |
B. Description of the transfer
| Categories of data subject | Determined by the customer. Typically the customer's personnel, clients, counterparties, and any individual named in an uploaded document or in a question asked of it. |
|---|---|
| Categories of personal data | Determined by the customer. Any personal data contained in uploaded documents, in the text and vectors derived from them, and in questions and answers, plus the account data of the customer's users. |
| Sensitive data | Not permitted without our prior written agreement, and the service is not configured for it. See section 6 of the Terms. Where a customer nevertheless uploads it, it is subject to the same measures as all other content and to the access restrictions in Annex II. |
| Frequency of the transfer | Continuous, for the duration of the customer's subscription. |
| Nature and purpose of the processing | Storage; text extraction including optical character recognition; segmentation into passages; generation of vector embeddings; similarity retrieval; and generation of answers — in order to provide document search and question answering to the customer. |
| Retention period | For the term of the agreement, plus the deletion period in section 10. Sub-processors retain data only for as long as needed to perform their function, and no longer than their own published terms allow. |
| Transfers to sub-processors | As set out in Annex III, for the purposes and durations stated there. |
C. Competent supervisory authority
The supervisory authority of the EEA member state in which the data exporter is established. Where the exporter is not established in the EEA but has designated a representative under Article 27, the authority of the member state where that representative is established. Where neither applies, the authority of the member state in which the data subjects are located. For UK transfers, the Information Commissioner's Office; for Swiss transfers, the Federal Data Protection and Information Commissioner.
Annex II: technical and organizational measures
These are the measures actually in place, not a wish list. Each one below is implemented in the software or in how it is operated, and section 4 is our commitment not to weaken them.
Implemented in the service
- Encryption in transit. All traffic to the service is over TLS, terminated at our edge, with HTTP requests redirected to HTTPS and HSTS set.
- Encryption of stored secrets. Third-party provider credentials are encrypted at rest with an authenticated cipher, keyed from a secret held in the environment rather than in the database or the source tree. Passwords and API tokens are stored only as hashes, so a stolen database copy yields no working credential.
- Tenant isolation. Every document, passage and vector carries its owning organization, and every read is scoped to it. Cross-tenant access is prevented by the query layer rather than by convention, and tested.
- Access control. Role-based permissions per organization and per workspace, at four levels of authority, with membership changes recorded.
- Least privilege for files. Uploaded files and export archives are served through short-lived signed URLs, never public links, and ownership is re-checked on every request rather than trusted from the URL.
- Logging and audit. Sign-ins, document access, policy acceptance, deletions and membership changes are recorded with actor, time, address and user agent, and retained independently of the acting account so an investigation into a past period is still possible.
- Data minimization in model calls. Only the passages relevant to a query are transmitted to a model provider, never whole corpora.
- Zero-retention enforcement. An organization or workspace can be restricted to model providers offering zero data retention. The restriction is enforced both when a model is selected and at the moment it is called, and a model whose status cannot be confirmed is refused rather than assumed compliant.
- Deletion that reaches storage. Deleting an account removes stored objects from the file store before the database rows that name them, so nothing is left orphaned in a bucket.
- Resilience of processing. Batch work is durable and re-runnable, so a failure mid-run does not leave partial or duplicated state.
- Secure development. Dependencies are pinned, and every change runs an automated suite before release that includes the tenant-isolation and data-rights tests and the framework's own deployment security checks under production settings.
Operational
- Personnel. Access to production systems and to customer personal data is limited to named personnel who need it for their work, each under a written confidentiality obligation. Access is removed when it is no longer needed.
- Credential handling. Production secrets live in the deployment environment, not in the repository, and are rotatable independently of one another so that rotating one does not force the disclosure or re-entry of the rest.
- Incident response. Reports reach [email protected], published at
/.well-known/security.txt. On a confirmed incident we contain it, assess whether personal data was affected, and notify affected customers under section 6. - Sub-processor diligence. Each sub-processor in Annex III is engaged under terms that include data-protection obligations no less protective than these, and is listed publicly before it begins processing.
Annex III: sub-processors
The list of authorized sub-processors, with the purpose, the data each receives and its location, is published and kept current at Subprocessors. That page is incorporated into this addendum as Annex III, and section 5 governs how it changes.