Third Party Index

Snapshot 19858

Document
Subprocessor list
URL
https://autogenai.com/dpa/#subprocessors
Fetched
HTTP status
200
Content type
text/html; charset=UTF-8
Fetch mode
static
Size
161522 bytes
SHA-256 (raw)
0e7b923efcbecbc92c2139536c0fd0e7515ed9dc00590198f3f6e32aa08e3430
SHA-256 (normalized text)
64b35f95d273d339db2280cd716f9bda621d3332a76a8de6284f36725e9bb8be

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Customer Terms & Conditions
Applicable to Order Forms signed on or after 6 November 2025
AUTOGENAI DATA PROCESSING ADDENDUM
This Data Processing Addendum (“DPA”), and its schedules and annexes, forms part of the Agreement. Any terms used but not defined in this DPA will have the same meaning as set out in the Agreement.
For the purposes of the Agreement and the delivery of the Services, the Customer is the data controller and AutogenAI is the data processor. Each party shall, in connection with the exercise of its rights and the performance of its obligations under the Agreement, comply with the Applicable Data Protection Laws. The type of personal data processed by AutogenAI under this Agreement and the duration and purpose of such processing is set forth in Annex A. In respect of its access to and/or processing of any such personal data of Customer in the provision of the Services, AutogenAI shall: a. have in place appropriate technical and organisational measures to ensure an appropriate level of security for the processing of such personal data of Customer and to protect such personal data against unauthorised or unlawful processing or accidental loss, destruction or damage; b. preserve the integrity of such personal data of Customer and prevent the loss or corruption of such personal data;
c. only process such personal data in accordance with the Agreement and any other written instructions and directions of Customer and not for its own purpose and ensure that anyone in its organisation processing personal data of Customer is subject to the same duties of confidence as set out in this DPA;
d. notify Customer without undue delay if it becomes aware of any accidental, unauthorised or unlawful destruction, loss, alteration, or disclosure of, or access to Customer’s personal data (a “Security Incident”) and provide sufficient detail of the Security Incident for Customer to take action to remedy the Security Incident to the extent required by Applicable Data Protection Laws;
e. provide such reasonable assistance and information to Customer as it may reasonably require to allow the Customer to comply with its obligations under the Applicable Data Protection Laws;
f. upon termination of the Agreement at the direction of Customer either return such personal data to Customer or securely destroy such personal data and delete any copies, except where AutogenAI is required by applicable law to retain the personal data or copies of the personal data;
g. where required under Applicable Data Protection Laws, allow Customer and its auditors, at Customer’s own cost and expense and upon reasonable prior written notice, to conduct audits or inspections during the Term and for 12 months thereafter, in connection with the processing of any such personal data to ensure any personal data processing by AutogenAI is in accordance with Applicable Data Protection Laws;
h. maintain complete and accurate records to demonstrate its compliance with this DPA; and
i. not transmit any personal data of Customer or otherwise process it outside the European Economic Area, United Kingdom or Australia unless it has complied with its applicable obligations under Applicable Data Protection Laws including by ensuring adequate safeguards in relation to such transfer.
Customer authorises AutogenAI to engage other processors (referred to in this section as sub-processors) when processing Personal Data. Processor’s existing sub-processors are listed in Annex A. In relation to the processing of Customer’s personal data under the Agreement, AutogenAI has entered or (as the case may be) will enter with such third party sub-processors into a written agreement incorporating terms which are the same as or substantially similar to those set out in this DPA. As between Customer and AutogenAI, AutogenAI shall remain fully liable for all acts or omissions of any third party sub-processor appointed by AutogenAI pursuant to the Agreement and this DPA.
Processor may appoint new sub-processors provided that they notify Controller in writing 14 days before the new sub-processor is granted access to Personal Data.
Nothing in the Agreement shall relieve AutogenAI of its own direct responsibilities and liabilities under Applicable Data Protection Laws.
For the purposes of this DPA the terms “data controller”, “data processor”, “personal data”, “process” and “processing” shall have the meaning set out in the Applicable Data Protection Laws and “subprocessor” means any third party appointed by or on behalf of AutogenAI to process Customer’s personal data in connection with this Agreement. For the purpose of this DPA, AutogenAI is considered a “processor” and the Customer is a “controller”, and references to personal data include references to “personal information” under Applicable Data Protection Law.
Annex A
PARTICULARS OF PROCESSING
Scope
AutogenAI will process the types of personal data listed below in order to provide its services to Customer.
Nature & Purpose of processing
In relation to Authorised users, to allow the following activities:
access to the Services
use of the Services
access and use of the Support Services
training and development services
user administration
usage reporting
provision of internet based searching
For any other purposes, AutogenAI must anonymise the data.
Duration of the processing
For the duration of the Agreement.
Types of personal data
For Authorised Users the following personal data is processed:
Login details
System usage details
Employer details
Job title
And any other personal data that Authorised Users input into the system
Categories of data subject
Authorised Users of the Customer
Subprocessors
Name	Location of Processing	Description of Processing
AWS	UK	Hosting & Infrastructure, LLM provider (for UK & EU Customers only)
AWS	US	Hosting & Infrastructure, LLM provider (for US Customers only)
AWS	Australia	Hosting & Infrastructure, LLM provider (for Australian Customers only)
AWS	Canada	Hosting & Infrastructure, LLM provider (for Canadian Customers only)
Docebo	Italy	Learning Management Services
OpenAI	US	LLM provider
OpenAI	EU	LLM Provider
Microsoft Azure	UK	Hosting and LLM provider ((for UK & EU Customers only)
Microsoft Azure	US	Hosting & Infrastructure, LLM provider (for US Customers only)
Microsoft Azure	Australia	Hosting & Infrastructure, LLM provider (for Australian Customers only)
Microsoft Azure	Canada	Hosting & Infrastructure, LLM provider (for Canadian Customers only)
AutogenAI	US*	Subprocessor for UK & Australia customers
AutogenAI	UK*	Subprocessor for US & Australia customers
AutogenAI	Australia*	Subprocessor for UK & US
Mistral	Sweden, EU	LLM Provider (for non-region-exclusive customers only)
Google	UK	LLM Provider (for UK & EU Customers Only)
Google	US	LLM Provider (for US Customers Only)
Google	Australia	LLM Provider (for Australian Customers Only)
Exa Labs, Inc.	US	Internet-based searching & retrieval (Zero Data Retention; transient in-memory processing)
* = Data Access and Regional Restrictions:
Regional Data Boundaries: Where clients have agreed terms specifying that their data must not leave a particular region (e.g., the UK), we ensure that such data remains stored and processed exclusively within the designated region.
Access Restrictions: In such cases, only authorized staff located within the corresponding regional company (e.g., UK-based staff for UK data) will have access to the data. Staff from our AU and US companies will not access this data, ensuring compliance with regional data handling agreements.
** = Changes to Data Processors and Third-Party Providers
We will notify affected customers in advance if we appoint new sub-processors or make significant changes to existing ones, as required under our data processing agreement.
For other third-party providers that do not qualify as sub-processors but are involved in processing or storing client non personal data, we will notify affected customers if there are material changes, additions, or removals that may impact the service.
Customers with specific provisions in their agreements—such as single-tenancy environments, single-country data storage requirements, or other customised arrangements—will receive tailored notifications regarding changes that may uniquely impact their service.