GoMask.ai Data Processing Agreement (DPA)
Effective Date: 20th August 2025
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Autonify Limited (trading as GoMask.ai) ("GoMask", "we", "our", "us") and the customer ("Controller", "you"). It governs GoMask's processing of personal data on your behalf when you use the GoMask.ai SaaS platform ("Service").
1. Scope & Roles
- • GoMask acts as the Processor of personal data uploaded or provided through the Service.
- • The Customer acts as the Controller.
- • This DPA applies solely to the GoMask.ai SaaS platform. Consulting and professional services provided by Autonify Limited are outside its scope.
2. Nature & Purpose of Processing
Processing is carried out to deliver all services necessary to provide, support, secure, and maintain the GoMask.ai platform, including but not limited to:
- • Data masking, synthesis, and related test data management features.
- • Account creation, billing, and customer support.
- • Security monitoring and compliance assurance.
3. Types of Personal Data Processed
Account Data: name, email, phone, job title, company, payment details.
Customer-Uploaded Datasets: which may include personal data if customers upload production data.
Usage & Operational Data: logs, analytics, and support interactions.
4. Data Retention & Deletion
- • Customer-uploaded datasets: deleted immediately after processing, or within 30 days of account closure.
- • Account and billing records: retained for 6 years to comply with UK legal requirements.
- • Operational logs and analytics: retained for up to 12 months.
Upon request, GoMask will delete or return customer data in accordance with these timeframes.
5. Sub-Processors
- • GoMask is authorised to engage sub-processors necessary for providing the Service.
- • A current list of sub-processors (e.g. AWS, Azure, Stripe, HubSpot, Railway.com, GitHub, Docsify) is maintained by GoMask and available upon request.
- • Customers grant general authorisation for the use of sub-processors. GoMask is not required to provide advance notice for new sub-processors.
6. Security Measures
GoMask will implement industry-standard technical and organisational measures, including:
- • Encryption of data at rest and in transit.
- • Role-based access controls.
- • Full audit logging.
- • Regular penetration testing and vulnerability assessments.
7. Data Breach Notification
In the event of a personal data breach, GoMask will notify the Customer without undue delay and, in any event, within 72 hours of becoming aware of the breach.
8. Audit Rights
Customers are not entitled to conduct direct audits of GoMask systems. Instead, GoMask will provide security certifications, reports, or summaries (e.g. SOC 2, ISO 27001, penetration test results) upon request.
9. International Data Transfers
- • Data may be transferred outside the UK/EEA where necessary to provide the Service (e.g. use of Stripe or HubSpot).
- • Such transfers will be safeguarded by the use of Standard Contractual Clauses (SCCs) and other lawful mechanisms.
10. Governing Law
This DPA is governed by the laws of England and Wales. Disputes will be subject to the exclusive jurisdiction of the courts of England and Wales.
11. Contact
For privacy and data protection matters, please contact:
Email: [email protected]
Company: Autonify Limited (trading as GoMask.ai)
Jurisdiction: England, United Kingdom