Data Processing Practices
Version 1.0 — in effect from 15 July 2026
These Practices form part of each Applied AI Labs statement of work that incorporates them. The version that applies to an engagement is the one in effect on that statement of work's Effective Date, whatever this page says later. We keep prior versions and will provide the one that applies to you on request.
This page sets out how Applied AI Labs Corp. ("AAL", "we") handles personal data a client makes available to us when we deliver our services. It covers who is responsible for what, what we do and don't do with your data, where our people are, and what happens if something goes wrong. It is written to meet the requirements that apply to a processor under European data protection law (GDPR Article 28 and related regulations) and to a service provider under United States state privacy law (California Consumer Privacy Act and related regulations).
1. When this applies
This applies where we process personal data on your behalf in delivering an engagement. Most of our diagnostic work runs on anonymized or aggregated data — volumes, cycle times, costs — in which case there is no personal data of yours to process and none of this is engaged.
It does not cover personal data we handle for our own purposes, such as when someone contacts us commercially. That is our Privacy Policy.
2. Who we are and where our people are
AAL is a Delaware corporation. Our engineering team is in Budapest, Hungary, and our commercial team is in the United States and the United Kingdom. People outside the United States may access your data in delivering the work. We will tell you before we start accessing your personal data from a country not listed here.
3. What we do with your data
You are the controller of your personal data and we are the processor. Under United States state privacy law we act as a service provider or processor, as that law uses those terms.
We will use your data only to deliver the engagement described in your statement of work, and only on your instructions — which are the statement of work and any change order. We will not use it to train, fine-tune or improve any model. We will not use it to build benchmarks or for any other purpose of our own. We will not sell or share it. We will not combine it with data from other sources. If a law forces us to process it some other way, we will tell you first unless that law forbids it.
We will ask for as little personal data as the work needs, and will work from pseudonymized, aggregated or redacted data wherever that does not get in the way of the result. We will tell you if an instruction looks like it breaches data protection law, and may pause that part of the work until it is sorted out.
4. How we protect it
We will apply technical and organizational measures appropriate to the risk (GDPR Article 32 and related regulations). In practice that means: access is limited to the AAL people working on your engagement and is removed when their involvement ends; everyone with access is under a written confidentiality obligation; your data stays in our own systems; and we never put client data into consumer-grade AI tools.
We will give you a fuller description of our current measures on request, and we are happy to complete your security questionnaire.
5. Who else touches it
We use third-party services to do our work — things like hosting, collaboration tools and AI providers. We will tell you which ones may handle your data on request, and we will tell you before we bring in a new one that will. If you object on reasonable data protection grounds within ten business days and we cannot resolve it, either of us can end the engagement.
We hold each of them to obligations no less protective than these Practices, and we stay responsible to you for what they do.
6. Where your data goes
If we need to move your personal data out of the European Economic Area to a country without an adequacy decision (GDPR Chapter V and related regulations), we will put the European Commission's standard contractual clauses in place, at no charge to you. Where an adequacy decision covers the transfer — including if you are certified under the EU–US Data Privacy Framework — we rely on that instead for as long as it stands.
7. If something goes wrong
If we become aware of a breach of security affecting your data, we will tell you without undue delay and in any event within 72 hours. We will tell you what we know — what happened, roughly how much and whose data is involved, what it likely means, and what we are doing about it — and follow up as we learn more. We will help contain it, and help you with any notification you have to make to a regulator or to affected people.
Routine noise that doesn't compromise anything — port scans, failed log-ins, denial-of-service attempts — isn't a breach and doesn't trigger a notice.
8. Helping you meet your obligations
You stay responsible, as controller, for responding to people exercising their data protection rights, for any data protection impact assessment (GDPR Article 35 and related regulations), and for notifying regulators and individuals. We will give you reasonable help with each of those, taking into account what we know and the nature of the work. If someone contacts us directly about your data, we will not answer substantively — we will send them to you.
9. Records and checking up on us
We will keep records of the processing we do for you (GDPR Article 30 and related regulations) and give you the information you reasonably need to satisfy yourself that we are doing what this page says.
You can audit us, or appoint an independent auditor who isn't a competitor of ours, once a year on thirty days' notice, during business hours, at your cost — and more often if a regulator requires it or if there has been a breach affecting your data. Where an existing report or a completed questionnaire answers the question, we may offer that instead.
10. When the engagement ends
On request, we will return or delete your personal data from our active systems, whichever you prefer, unless a law requires us to keep it. Anything in routine backups goes when that backup cycle turns over, and stays protected under these Practices until it does.
11. Changes to this page
We may update these Practices, but we will not make a change that materially reduces the protection your data gets.
Every version has a number and a date it takes effect. Your statement of work incorporates the version in effect on its Effective Date — a later change here does not affect an engagement already running. We keep prior versions and will send you the one that applies to you on request.
12. Contact
For a copy of a specific version, a completed security questionnaire, the standard contractual clauses, or anything else on this page:
