Effective · July 27, 2026
Data processing addendum
Scope and parties
This Data Processing Addendum (“DPA”) applies where a business customer (“Customer”, “Controller”) uses AdjiCera Professional or AdjiCera Call in a way that has us process personal data on the Customer’s behalf. It supplements and forms part of our Terms of Service between the Customer and Adjibar LLC (“AdjiCera”, “Processor”, “we”). If this DPA and the Terms conflict on the subject of data processing, this DPA governs.
Architecture note. AdjiCera is on-device by default. Recordings, transcripts, and study or meeting material are generated and stored on the end user’s machine and are never transmitted to us. As a result, for those categories we are neither a controller nor a processor — that data never enters our systems. This DPA covers the limited personal data we do process on our servers, described in our Privacy Policy.
Roles: controller and processor
For the account, subscription, device, and AdjiCera Call registration data processed through the service, the Customer is the Controller and Adjibar LLC is the Processor, acting only on the Customer’s documented instructions — which the Terms, this DPA, and the Customer’s configuration of the product constitute. We will tell the Customer if, in our view, an instruction breaches applicable data-protection law.
For our own operational purposes — billing, fraud prevention, tax and accounting records, and securing our infrastructure — we act as an independent Controller, as described in our Privacy Policy. We do not sell personal data, do not share it for cross-context behavioural advertising, and do not use it to train AI models.
Categories of data and data subjects
Data subjects are the Customer’s authorised users (for example, employees who hold an account or register an AdjiCera Call username).
Categories of personal data we process on our servers — the full detail is in Section 3 of the Privacy Policy:
- Account information — email address, display name, account type, subscription status.
- Device and licence records — anonymous device and installation identifiers, platform, activation timestamps.
- AdjiCera Call registration — username, display name, registration and last-seen timestamps, shortened user-agent.
- Payment ledger — transaction type, amount, currency, timestamp, and the processor’s customer reference (card details never reach us).
- Prime AI usage ledger — feature used, token counts, and calculated cost (the content of Prime requests is not stored).
- Security and diagnostic data — transient IP addresses for rate-limiting, and anonymous connection diagnostics.
We do not process, on our servers, the contents of recordings, transcripts, calls, chat, or voice profiles. Call signaling and chat are end-to-end encrypted and are not readable by us.
Sub-processors
We engage sub-processors to process personal data on our behalf. Each is bound by contract to data-protection obligations no less protective than those in this DPA, and we remain responsible for their performance. We disclose information only to sub-processors in the following categories, as described in Section 7 of the Privacy Policy:
- Cloud hosting and storage — runs the website, APIs, and the stored account records, in United States data centres.
- Payment processing — handles checkout, cards, subscriptions, and invoices; receives payment details directly, not through us.
- Connectivity infrastructure — relays already-encrypted AdjiCera Call media when a direct connection is not possible.
- AI processing — a third-party provider that generates responses for optional Prime features, receiving only the text the user chooses to send.
We will give the Customer notice of any intended addition or replacement of a sub-processor with a reasonable opportunity to object on legitimate data-protection grounds. To receive the current list of named sub-processors, or to subscribe to change notifications, email info@adjicera.com.
Security measures
We maintain technical and organisational measures appropriate to the risk, described on our Security page. In summary: traffic to our servers is encrypted in transit with TLS; AdjiCera Call signaling and chat are additionally end-to-end encrypted; session tokens are random and expire; stored records are held behind authenticated interfaces with access limited to what is needed to run the service; and the most sensitive material never reaches us because it stays on the user’s device. No system is perfectly secure, and these measures are a description of practice, not a warranty.
Confidentiality and personnel
We limit access to personal data to personnel who need it to provide the service, and those personnel are bound by confidentiality obligations. We process personal data only for the purposes set out in this DPA and the Privacy Policy, and not for any incompatible purpose.
Assisting the Controller and data-subject rights
Taking into account the nature of the processing, we will provide reasonable assistance to help the Customer respond to requests from data subjects to access, correct, delete, or restrict their personal data, and to meet the Customer’s own security, breach-notification, and impact-assessment obligations.
If we receive a request directly from one of the Customer’s data subjects, we will, unless legally required to act, refer the request to the Customer. Individuals may also exercise their own rights over data we hold as described in Section 10 of the Privacy Policy.
Personal-data breaches
If we become aware of a personal-data breach affecting data we process for the Customer, we will notify the Customer without undue delay, provide the information reasonably available to us about the nature and likely consequences of the breach and the measures taken, and cooperate to remediate it.
Deletion and return of data
On termination of the service, or on the Customer’s written request, we will delete or return the personal data we process on the Customer’s behalf, and delete existing copies, except to the extent we are required by law to retain it — for example, payment and transaction records kept up to seven years for tax and accounting purposes, as stated in Section 8 of the Privacy Policy. Data held only on end-user devices is deleted by the user; we have no means to reach it.
Retention and international transfers
We retain personal data only as long as needed for the purposes set out in the Privacy Policy, then delete or anonymise it on the schedule described there. Our servers and sub-processors are located in the United States, and AdjiCera is currently offered to residents of the United States; we do not currently market to the European Union, EEA, or United Kingdom. Where cross-border transfer safeguards become applicable, the parties will put an appropriate transfer mechanism in place.
Contact and changes
For DPA requests — including a signed copy, the current sub-processor list, or a data-processing question — email info@adjicera.com. For privacy requests, support@adjicera.com. We may update this DPA; the current version always lives at this URL, and material changes are handled as described in the Privacy Policy.
Adjibar LLC
1200 Western Ave, Seattle, WA 98101, USA