Last updated: 2 March 2026 · Effective immediately for all customers
This DPA is automatically incorporated into your Aditya Labs Terms of Service when you process personal data using our platform. For a countersigned copy, email legal@adityalabs.ai.
"Controller" means you, the customer, who determines the purposes and means of processing personal data via the Aditya Labs platform.
"Processor" means B Mohan, trading as Aditya Labs, which processes personal data on behalf of the Controller.
"Personal Data" means any information relating to an identified or identifiable natural person processed through the Services.
"Sub-processor" means any third party engaged by Aditya Labs to process Personal Data.
Aditya Labs processes Personal Data solely to provide the Services as described in the Terms of Service, including:
Aditya Labs shall:
Aditya Labs uses the following sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase (AWS) | Database, auth, storage | US (AWS) |
| OpenAI | AI response generation | US (with EU DPA) |
| Vercel | Application hosting & CDN | Global Edge |
| Stripe | Payment processing | US/EU |
| Resend | Transactional email | US |
All sub-processors maintain their own DPAs and comply with GDPR requirements. We will notify you of any changes to sub-processors with 30 days' notice.
Where Personal Data is transferred outside the UK/EEA, Aditya Labs ensures appropriate safeguards via Standard Contractual Clauses (SCCs) as approved by the European Commission and the UK ICO's International Data Transfer Agreement (IDTA).
Aditya Labs will notify the Controller without undue delay, and in any event within 72 hours of becoming aware of a Personal Data breach (GDPR Article 33). Notification includes: nature of breach, categories and approximate number of data subjects affected, likely consequences, and measures taken.
For DPA-related queries, data subject requests, or to request a countersigned copy:
Email: legal@adityalabs.ai
General: hello@adityalabs.ai
Website: adityalabs.ai