Data Handling Agreement

Plain Language Summary

This agreement governs how Eira OS handles your data during a Membership. Key points: your data stays on our sovereign, on-premise infrastructure in the United States. No data goes to any third-party cloud. We do not train AI models on your data. Data is purged within 30 days after the Membership ends. We use encryption, access controls, and physical security to protect your data. If something goes wrong, we notify you within 72 hours.

Effective Date: August 9, 2026

1. Parties and Incorporation

This Data Handling Agreement ("DHA" or "Agreement") is entered into between Eira OS ("Eira OS," "we," "us," "our") and the entity engaging Eira OS for commercial services ("Member," "you," "your"). This Agreement is incorporated by reference into and forms part of the Eira OS Terms of Service. In the event of a conflict between this Agreement and the Terms of Service, the Terms of Service control. This Agreement applies to Memberships only. Consumer products, when available, are governed by separate terms.

2. Definitions

3. Data We Collect

Eira OS collects and processes only the Member Data necessary to perform the Services defined in the applicable Membership. This may include:

Eira OS does not collect more data than is necessary for the Membership. If the Member provides data that Eira OS does not need, Eira OS will flag it and exclude it from processing. The Member is responsible for ensuring all Member Data provided to Eira OS is properly authorized for sharing under applicable law and any obligations to third parties.

4. How Data Is Processed

Member Data is processed for the sole purpose of performing the Services defined in the Membership. Processing activities include:

  1. Analysis: AI-assisted and expert analysis of Member Data to produce findings, gap analyses, and recommendations;
  2. Cross-Referencing: Mapping Member Data against compliance frameworks, security standards, and best practices;
  3. Knowledge Base Compilation: Organizing Member Data and findings into structured knowledge bases in requested formats;
  4. Deliverable Production: Generating reports, roadmaps, policies, and other Deliverables for the Member.

Member Data is not processed for any purpose other than performing the Services. Eira OS does not use Member Data for marketing, product development, model training, service improvement, or any purpose unrelated to the Membership. See Section 7 for the prohibition on model training.

5. Where Data Is Processed

Sovereign, On-Premise, United States Only

All processing of Member Data occurs on Eira OS's sovereign, on-premise infrastructure located within the United States. No Member Data leaves Eira OS's controlled infrastructure.

6. Security Measures

Eira OS implements and maintains reasonable and appropriate technical, physical, and organizational security measures to protect Member Data. These measures include:

Technical Security

Physical Security

Organizational Security

7. No Model Training

We Do Not Train AI Models on Your Data

Eira OS does not use Member Data or Derived Data to train, fine-tune, improve, evaluate, or benchmark any AI model. This prohibition is absolute and applies during and after the Membership.

Specifically:

8. No Sub-Processors

Eira OS does not use sub-processors for Member Data processing. All processing is performed by Eira OS personnel on Eira OS-controlled infrastructure. No third party processes, accesses, or stores Member Data.

If Eira OS ever needs to engage a sub-processor for a specific Membership, Eira OS will:

  1. Notify the Member in writing before engaging the sub-processor;
  2. Obtain the Member's written consent;
  3. Ensure the sub-processor is bound by data protection obligations no less protective than this Agreement;
  4. Remain fully liable for the sub-processor's handling of Member Data.

Until and unless such written notice and consent occurs, no sub-processor processes any Member Data. The current list of sub-processors is: none.

9. Data Retention and Purge

Member Data is retained only for the duration necessary to perform the Services in the Membership. After the Membership concludes:

  1. Default Timeline: All Member Data and Derived Data is purged no later than thirty (30) days after termination or completion of the Membership, unless a different timeline is specified in the Membership;
  2. Purge Method: Data is securely deleted using cryptographic erasure or multi-pass overwrite in accordance with NIST SP 800-88 guidelines. Simple file deletion is not sufficient;
  3. Verification: Upon request, Eira OS will provide written confirmation that Member Data has been purged;
  4. Legal Hold: If Eira OS is legally required to retain Member Data beyond the purge timeline (e.g., litigation hold, regulatory requirement), Eira OS will notify the Member and retain only the data required for the minimum period necessary;
  5. No Backup Retention: Eira OS does not maintain backup copies of Member Data beyond the purge timeline. Backups, if any exist during the Membership, are purged on the same schedule as primary data.

10. Data Return and Destruction

Upon termination or completion of the Membership, the Member may request return of its Member Data. Eira OS will:

  1. Return all Member Data to the Member in a mutually agreed format (e.g., encrypted archive, secure transfer);
  2. Provide Deliverables and Derived Data as specified in the Membership;
  3. Purge all Member Data, Derived Data, and any copies from Eira OS infrastructure within thirty (30) days of the return or termination date;
  4. Provide written certification of destruction upon request;
  5. Not retain any copy of Member Data except as required by law and with notice to the Member.

The Member is responsible for maintaining its own backups of Member Data. Eira OS is not responsible for data loss after the purge timeline has elapsed.

11. Breach Notification

In the event of a suspected or confirmed data security incident involving Member Data, Eira OS will:

  1. Notify the Member: Within seventy-two (72) hours of confirming that a security breach has occurred that is reasonably likely to have compromised Member Data. Notification will be made by phone and confirmed in writing;
  2. Provide Details: To the extent known at the time of notification, Eira OS will provide: the nature of the breach, the categories of Member Data affected, the likely consequences, and the measures taken or proposed to address the breach;
  3. Investigate: Eira OS will conduct a prompt investigation to determine the scope and impact of the breach;
  4. Remediate: Eira OS will take reasonable steps to contain the breach, secure affected systems, and prevent recurrence;
  5. Document: Eira OS will maintain a record of the breach, the investigation, and the remediation measures;
  6. Cooperate: Eira OS will cooperate with the Member and any regulatory authorities as required by law.

Eira OS is not required to notify the Member of a breach that does not involve Member Data or that has no reasonable likelihood of affecting Member Data.

12. Data Subject Rights

If Member Data contains Personal Data, the Member is responsible for handling data subject requests. Eira OS will assist the Member in fulfilling data subject requests where feasible, including:

Eira OS does not interact directly with the Member's data subjects. The Member remains the data controller and is responsible for all data subject communications. Eira OS acts as a data processor on behalf of the Member.

13. Cross-Border Data Transfer Prohibition

No Member Data Leaves the United States

Eira OS does not transfer, transmit, or make accessible Member Data to any system, person, or entity located outside the United States. This prohibition is absolute and applies to all forms of transfer, including remote access, cloud processing, and data replication.

This provision does not apply to data that has been anonymized or de-identified such that it can no longer be associated with the Member or any individual, and that is used solely for aggregate, non-identifiable statistical purposes. However, Eira OS does not currently engage in such anonymization during or after Memberships.

14. Audit Rights

The Member may audit Eira OS's compliance with this Data Handling Agreement upon thirty (30) days written notice. Audits may include:

Audits will be conducted during business hours, at the Member's expense, and will not unreasonably interfere with Eira OS operations. The Member may audit no more than once per twelve (12) month period unless a documented security incident has occurred. Audit results are confidential and subject to the confidentiality provisions of the Terms of Service.

15. Liability for Data Incidents

Eira OS's liability for any data security incident involving Member Data is governed by the limitation of liability provisions in the Terms of Service, Section 11. The Member acknowledges that:

16. Changes to This Agreement

Eira OS may update this Data Handling Agreement from time to time. The effective date at the top of this page indicates when the current version was posted. Changes apply to new Memberships entered into after the effective date. Memberships already in progress are governed by the Agreement in effect at the time the Membership was initiated, unless the Membership expressly provides otherwise.

17. Execution

This Data Handling Agreement may be executed electronically or in writing. Execution may be by: (a) signing an Membership that references this Agreement, (b) written acknowledgment of this Agreement, or (c) making payment for Services, which constitutes acceptance of this Agreement as part of the Terms of Service.

Eira OS

By: _________________________________
Name: Avondale.AI
Title: Founder & CTO
Date: _______________________________

Member

By: _________________________________
Name: _______________________________
Title: ______________________________
Date: _______________________________

Relationship to Terms of Service: This Data Handling Agreement is incorporated by reference into the Eira OS Terms of Service. In the event of a conflict between this Agreement and the Terms of Service, the Terms of Service control. This Agreement does not create any warranty or right not expressly stated in the Terms of Service or the applicable Membership.