Application and roles
These terms apply when incorporated into a written agreement between Auxerta, LLC (the “Provider”) and the customer identified in that agreement (the “Customer”). “Customer Data” means data, instructions, and project records supplied by or on behalf of the Customer for the engagement. The executed agreement or statement of work is the “Order.”
The parties’ respective controller, processor, or equivalent roles shall be recorded for each processing activity. Any data processing addendum required by applicable law shall be executed before the relevant processing begins and shall prevail over these terms in respect of its subject matter.
Business contact and administrative information handled for Auxerta’s own purposes is covered by the Auxerta privacy policy. A customer dataset processed on instructions remains subject to the engagement’s documented purpose and restrictions.
Processing specification
Before transferring data, the parties shall document the subject matter, purpose, duration, data categories, affected individuals, permitted operations, and Customer instructions. The specification must address access, processing locations, approved tools and providers, and the requirements for return or deletion.
Purpose limitation and instructions
The Provider shall process Customer Data solely for the agreed purposes and in accordance with documented lawful instructions, except where otherwise required by applicable law. Use for unrelated model training, independent research, publication, or onward licensing requires separate written authorization. No such authorization arises from a general reference to AI or publication of a privacy notice.
Human review and automated processing
Where included in scope, authorized reviewers may inspect data, model outputs, and labels to perform annotation or evaluation. The agreement must identify the permitted review and AI-assisted processing. Access to sensitive material and transmission to external model providers require prior agreement on purpose, access, and applicable safeguards.
Confidentiality, security, and providers
The Provider shall comply with the confidentiality, security, subprocessor, and transfer provisions of the Order and any applicable data processing addendum. Access shall be limited to authorized persons subject to appropriate confidentiality obligations. Subprocessor appointments and changes remain subject to the authorization procedure required by the addendum and applicable law. General authorization to perform services does not permit an undisclosed processing purpose.
Security incidents, assistance, and audit
The Provider shall notify the Customer of security incidents and assist with individual-rights requests, regulatory obligations, and assurance procedures to the extent required by the applicable addendum and law. Notification periods, designated contacts, audit rights, and related procedures are governed by those requirements. No security certification is represented by these terms.
Retention, return, and deletion
Retention and disposal provisions shall distinguish source data, working copies, review records, deliverables, and backups. The Provider shall return or delete Customer Data in accordance with the Order, the applicable addendum, and legal retention obligations. Information retained under a lawful exception remains subject to the applicable confidentiality and purpose restrictions. Termination confers no additional right to use Customer Data.
Data instructions and inquiries
Agree on the processing terms and a transfer channel before sending a dataset. Direct service inquiries to partner@auxerta.com and privacy requests to contact@auxerta.com. Customer instructions and formal notices must also follow the executed agreement.