Data Processing Agreement
Last updated: July 29, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between RAUM AI ("Processor") and the customer ("Controller") and applies whenever RAUM AI processes personal data on the Controller's behalf. A countersigned copy is available on request from hello@raum.am.
1. Roles
The Controller determines the purposes and means of processing. RAUM AI acts solely as Processor and processes personal data only on documented instructions from the Controller, which include the configuration the Controller sets in the product (connected Zendesk account, selected AI provider, enrichment and automation settings).
2. Subject matter and duration
The subject matter is the provision of AI-assisted customer support tooling integrated with the Controller's Zendesk account. Processing lasts for the term of the subscription, plus the retention window in section 7.
3. Categories of data and data subjects
Data subjects: the Controller's support agents and administrators, and the end customers who raise support tickets with the Controller.
Categories of personal data: ticket subjects and bodies and any personal data the end customer includes in them; requester identifiers; agent account details (name, email, role); and operational logs. RAUM AI does not require, and asks the Controller not to submit, special-category data.
4. Subprocessors
The Controller provides general written authorisation for RAUM AI to engage the subprocessors listed at raum.am/subprocessors. That page is updated before a new subprocessor handling personal data is engaged, and the Controller may object on reasonable data-protection grounds. Each subprocessor is bound by obligations no less protective than those in this DPA.
Where the Controller uses the bring-your-own-key model, the AI provider the Controller selects is engaged under the Controller's own agreement with that provider and is not a RAUM AI subprocessor. See Subprocessors for detail.
5. Security measures
RAUM AI maintains technical and organisational measures appropriate to the risk, including:
- Encryption in transit (TLS) for all connections, and encryption at rest for the database and object storage.
- Application-level AES-256-GCM encryption of stored third-party credentials, held separately from the application database in a managed secret store.
- Strict per-organisation data isolation: every stored record and cache entry is scoped to an immutable organisation identifier.
- Automatic redaction of personal data (emails, phone numbers, payment identifiers, tokens) from operational logs.
- Least-privilege access to production systems, with credentials held in a managed key vault rather than in source code or configuration.
- Automated database backups with point-in-time recovery and geographically redundant backup storage.
- Read-only defaults: automated ticket actions that modify a ticket are disabled by default and require explicit per-connection approval.
6. International transfers
RAUM AI's infrastructure is hosted in the United States. Where personal data is transferred from the EEA, the United Kingdom or Switzerland, the transfer is made under the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum where applicable. Those clauses are incorporated into this DPA by reference.
7. Retention and deletion
The Controller may delete data at any time from within the product. On termination, the organisation is deactivated immediately — third-party credentials are revoked and all automated processing stops — and the associated data is permanently deleted after a 14-day recovery window, by an automated retention job. Operational logs are retained for up to 30 days.
The Controller may request deletion sooner, or a copy of its data before deletion, by writing to hello@raum.am. Backup copies age out on the backup retention schedule.
8. Data subject rights
RAUM AI will assist the Controller, taking into account the nature of the processing, in responding to requests to exercise data subject rights. Where a request reaches RAUM AI directly, we will not respond on the Controller's behalf and will refer the request to the Controller without undue delay.
9. Personal data breach
RAUM AI will notify the Controller without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting the Controller's data, providing the information reasonably available to support the Controller's own notification obligations.
10. Audit
RAUM AI will make available the information reasonably necessary to demonstrate compliance with this DPA and will contribute to audits conducted by the Controller or an auditor it mandates, on reasonable notice and no more than once per year except where required by a supervisory authority.
11. Contact
Data protection enquiries: hello@raum.am.