Data Processing Agreement
Effective date: 21 September 2026
This Agreement applies where Enji AI LLC processes personal data on your behalf in connection with Enji Lite. It forms part of the Terms of Use and you accept it when you accept them. You do not need to sign anything or ask us for a copy.
If you have a separately negotiated agreement with us, that agreement governs where the two differ.
1. Who is who
You are the controller. You decide which tools you connect to Enji Lite, what it does with the data in them, and what happens to the results.
We are the processor. Enji AI LLC, taxpayer identification number 01907202310418, 11 microdistrict 14/4, Bishkek City, Kyrgyz Republic, 720049. We process customer content on your instructions to provide the Service.
Where you are yourself a processor acting for someone else, you are our controller for the purposes of this Agreement, and we are your sub-processor.
Dodo Payments is neither, for customer content. Dodo Payments, our reseller and merchant of record, sells the subscription to you and handles buyer payment and tax data as an independent controller under its own terms — not on our instructions. Where it processes account or billing details on our instructions (for example customer records for our accounts), that is described in Enji Lite’s Privacy Policy, section 8, and is not customer content. Payment data never reaches this Agreement, and customer content never reaches Dodo Payments — we do not send it usage or metering events, or anything from your connected tools or chat. See Enji Lite’s Terms of Use for how billing works.
In this Agreement, “customer content” means personal data contained in the tools you connect — Jira, Linear, GitHub, GitLab, Confluence, Slack,Telegram and Fireflies — and in the chat answers, reports, and dashboards it produces from them.
2. What we process, and why
The full description is in Annex 1. In short: we process customer content only to provide the Service to you — syncing the tools you connect, answering your questions, generating reports and dashboards, and, where you ask for it in Jira, taking the specific action you request.
We process on your documented instructions. Your instructions are the Terms of Use, this Agreement, the settings you choose in the product, and anything else you tell us in writing. We do not process customer content for our own purposes.
If the law forces a transfer or disclosure, we tell you first. Where EU or Member State law requires us to transfer or otherwise process customer content beyond your instructions, we will inform you of that requirement before processing — unless the law prohibits us from telling you, on important grounds of public interest. We are established in the Kyrgyz Republic, so a demand made on us is more likely to arise under Kyrgyz law than under EU law; we treat a requirement under Kyrgyz law, or the law of any other country we operate in, exactly the same way, following the government-access commitments in Annex 4 where we cannot tell you in advance.
We will tell you if an instruction looks unlawful. If we think something you ask us to do infringes data protection law, we will say so and may pause that processing until it is resolved. We are not your legal adviser and we do not check your instructions routinely — this covers the case where a problem is obvious to us.
We do not train models on your content. We do not train any model on customer content and we do not sell it. See Enji Lite’s Privacy Policy, section 3, for how OpenAI is used.
3. Confidentiality
Everyone we allow near customer content is bound by confidentiality obligations that survive the end of their engagement, and access is limited to those who need it for support, security, incident response and abuse prevention.
4. Security
We maintain the technical and organisational measures in Annex 2, as required by Article 32.
5. Sub-processors
You give general written authorisation for us to engage the sub-processors in Annex 3, and for changes to that list under this section.
We impose data protection obligations on each sub-processor that are no less protective than those in this Agreement, and we remain liable to you for what they do.
We will give you at least 30 days’ notice before adding or replacing a sub-processor for customer content, by email to your account contact. Updating Annex 3 is how the list stays current; it is not how you are told — an edit to this page alone would not give you thirty usable days. If you object on reasonable data protection grounds within 14 days, tell us and we will try to resolve it. If we cannot, you may terminate the affected part of the Service; any refund follows Enji Lite’s Terms of Use.
Two limits worth stating rather than burying. First, OpenAI keeps its own sub-processor list and changes it on its own schedule; we pass on what we are told, and we do not control its timing. Second, its deletion terms carve out retention for legal obligations, dispute resolution, and combating harmful use of its services. We cannot promise you deletion at OpenAI that is wider than OpenAI gives us, and section 8 says what that means.
6. Helping you with data subjects
If someone exercises a right — access, correction, deletion, restriction, portability, objection — and it concerns customer content we hold for you, we will help you answer.
If a request reaches us directly, we will not answer it ourselves. We will pass it to you promptly, unless the law requires otherwise, because you are the controller and it is your answer to give.
Most of what you need is in the product: you can disconnect a tool, delete a project, and export your chat history as markdown. Where the product does not reach, ask us at contact@enji.ai.
7. Breaches, assessments, and the regulator
We will tell you about a personal data breach without undue delay and within 48 hours of becoming aware of one, with what we know at the time: what happened, which data and roughly how many people are affected, the likely consequences, and what we are doing about it. We will keep you updated as we learn more. Notifying your supervisory authority is your decision and your obligation — we will give you what you need to make it in time.
We will also give you reasonable help with data protection impact assessments and prior consultation under Articles 35 and 36, taking into account what we know about how the Service works.
We will also tell you about security incidents that are not personal data breaches — for example a compromised connected-tool credential or reports reachable by someone who should not reach them — even where no law requires it, on the same timeline as above.
8. Deletion
On your instruction, or when your workspace closes, we delete customer content — your projects, the AI assistant’s chat history, connected-tool sync data, and messenger channel and message records — subject to the exceptions below. You can export your chat history as markdown at any time while your workspace is open, and we recommend doing that before you ask for deletion — this is the extent of what we can give back to you; we do not offer a full return of everything synced from your connected tools.
Backups are retained for 7 days on the same infrastructure the Service runs on, then age out on their ordinary cycle.
Disconnecting a tool is not the same as deletion. It stops future syncing immediately but does not delete data already synced, with two exceptions: disconnecting Confluence deletes its indexed knowledge-base content immediately, because that content is stored as search vectors rather than raw synced records and disconnecting Fireflies deletes its synced transcripts immediately. Data from every other integration is intended to be removed when your workspace closes.
Messenger history follows its own window regardless of deletion requests. Slack and Telegram messages are retained only for the window your plan allows and are permanently removed by an automated process once they age past it — see Enji Lite’s Privacy Policy, section 10, for the current windows.
Three things survive deletion, for a limited time or for good, and you should know which.
- Task context already sent to an OpenAI. It is held under that OpenAI’s own terms and deletion schedule. We cannot recall it, and neither can it always delete it immediately — see section 5. If this matters to you, scope what you connect and what you ask the assistant about accordingly.
- A record that a deletion happened, carrying the date and an internal reference. It holds no name, no email, and nothing from your connected tools or reports. Because we keep nothing that identifies you afterwards, we cannot later confirm to you, or to a regulator, that your particular workspace was deleted — only that a deletion occurred on a given date. If you need evidence of erasure for your own records, ask us for written confirmation before you delete, and we will give it while the workspace still exists.
- Traces of AI requests, kept so we can help you with questions about answers. They are deleted automatically within 30 days.
9. Audits and information
Ask and we will answer. We will give you the information you reasonably need to show that we are meeting this Agreement, including this page, the security measures in Annex 2, our current sub-processor list, and answers to a security questionnaire.
Audits. You may audit our compliance, or appoint an independent auditor to do it, no more than once a year unless a supervisory authority requires more or we have had a breach affecting you. Give us 30 days’ notice, agree the scope with us first, keep what you learn confidential, and do not disrupt the Service or other customers. We will make a person available who can answer properly. If your questions can be answered with documents, we will offer that first — not to avoid the audit, but because it is usually faster for both of us.
You bear your own costs. If an audit needs substantial engineering time beyond answering questions, we may charge for it at a reasonable rate, agreed before it starts.
10. International transfers
Your data is stored in Europe. Profile photos, project logos, feedback attachments, and AI-generated chart images are stored on AWS infrastructure in Ireland (eu-west-1). The rest of Enji Lite’s production compute and databases run on Google Cloud in europe-west3 (Frankfurt) — see Annex 2. Emails are sent through Amazon SES in Ireland (eu-west-1), and traces of AI requests are stored on Hetzner in Nuremberg, Germany.
Three things reach outside the EU/EEA and UK, and all three are restricted transfers.
Our team includes people in the Kyrgyz Republic, which has no UK or EU adequacy decision. When someone there accesses customer content — for support, security, incident response or abuse prevention — that is a transfer even where the data itself is stored within the EU/EEA or UK. It is made under the safeguards in Annex 4.
OpenAI is are in the United States. Selected task context goes to it under its data processing terms; see Annex 3.
Cloudflare, as CDN and security edge, carries customer content in transit only — TLS is terminated at whichever of its locations serves the request, which is not always inside Europe, and nothing is stored there afterwards. See Annex 3.
You can ask us for a copy of the transfer safeguards we rely on.
11. Liability, changes, and everything else
Liability under this Agreement is subject to the limits in Enji Lite’s Terms of Use, with three exceptions that override them.
The Standard Contractual Clauses come first. Where Annex 4 applies, Clause 12 of the Clauses governs liability to data subjects, and nothing in the Terms of Use or this Agreement reduces it. A data subject’s rights against us under the Clauses are not capped by our liability terms.
Statutory liability is not capped either. Article 82 of the GDPR gives data subjects a right to compensation, and it is not ours to limit by contract — including how liability is apportioned between us and you as controller.
And the cap does not reach your own regulator. Fines or enforcement directed at us are ours.
Within those limits the cap applies as written. Nothing in this section is an attempt to contract out of the Clauses.
We may update this Agreement as the Service, the law, or our sub-processors change. If a change materially reduces your protection we will give you at least 30 days’ notice and you may terminate; any refund follows Enji Lite’s Terms of Use. Otherwise the updated version takes effect when posted with a new effective date.
This Agreement is governed by the law of England and Wales, as Enji Lite’s Terms of Use are — except that Annex 4 governs itself where the Standard Contractual Clauses say so.
Annex 1 — Details of the processing
Subject matter. Provision of Enji Lite: an AI assistant that connects to the project-management, source-control, knowledge-base and messaging tools you authorize, answers questions about your projects, and generates reports and dashboards.
Duration. For as long as Enji Lite’s Terms of Use are in force, plus the time needed to complete deletion under section 8.
Nature of the processing. Connecting to and syncing the tools you authorize (Jira, Linear, GitHub, GitLab, Confluence, Slack, Telegram, Fireflies); reading connected content to answer questions; sending selected task context to OpenAI; generating chat answers, reports, dashboards and — in Jira only, actions you explicitly request and confirm; delivering scheduled reports and answers into connected Slack and Telegram channels; storing and displaying results; emailing notifications that include customer content, such as results of scheduled tasks; keeping traces of AI requests for up to 30 days to help you with questions about answers; support and security operations.
Purpose. Providing Enji Lite to you. Nothing else.
Categories of data subjects
- Your personnel who use the Service
- Contributors, authors and participants in the connected tools — issue reporters and commenters in Jira and Linear, commit authors and reviewers in GitHub and GitLab, page authors in Confluence, participants in connected Slack channels and Telegram chats and meeting organisers and participants in connected Fireflies transcripts, who may include people outside your organisation.
- People whose personal data appears in connected content — issues, comments, commits, messages, pages, or logs
- People identified in chat answers, reports and dashboards produced from the above
Categories of personal data
- Identifiers in connected-tool metadata — names and email addresses of issue/commit/message participants, Slack participant email addresses specifically, Fireflies meeting organiser and participant names and email addresses.
- Any personal data present in synced issues, comments, commits, pages, messages, or meeting transcripts — what each speaker said, summaries, meeting links.
- The same, as reproduced in chat answers, generated reports, dashboards and charts
Special category data. Not sought, not requested, and not knowingly processed. It could appear inside the tools you connect, which is why you should scope access to what you need Enji Lite to answer questions about.
Frequency. Continuous for the duration of the Terms of Use.
Annex 2 — Security measures
- Encryption in transit and at rest.
- Credentials and secrets stored encrypted, with restricted access.
- Access control. Least-privilege, need-to-know. Human access to customer content is limited to support, security, incident response and abuse prevention.
- Tool credentials. OAuth-connected tools (Jira, GitHub, GitLab, Linear, Confluence) act under the connecting user’s own OAuth grant or personal access token; Fireflies connects with an API key the user creates, stored encrypted rather than a long-lived secret we mint ourselves. Slack and Telegram connect through our own bot credentials, stored encrypted.
- Infrastructure. Profile photos, project logos, feedback attachments and generated chart images are stored on AWS in eu-west-1 (Ireland); emails are sent through Amazon SES in eu-west-1 (Ireland); traces of AI requests are stored on Hetzner in Nuremberg, Germany. The rest of Enji Lite’s production infrastructure runs on Google Cloud in europe-west3 (Frankfurt).
- Separation. Customer content is segregated by account and workspace.
- Resilience. Backups are retained for 7 days on the same infrastructure the Service runs on, then age out on their ordinary cycle.
- Database isolation and least-privilege access for services.
- Monitoring of availability, metrics and logs, with a public status page.
- Vulnerability checks, automated, on every change and weekly.
- Recovery. Documented recovery and rollback procedures.
- Retention limits. Messenger history kept only for the plan’s window; traces of AI requests deleted after 30 days.
Annex 3 - Sub-processors
Amazon Web Services (S3) - object storage - profile photos, logos, attachments, generated charts - Ireland (eu-west-1).
Amazon Web Services (SES) - email notifications, including results of scheduled tasks - Ireland (eu-west-1).
Google Cloud - hosting, compute, databases, backups - europe-west3 (Frankfurt).
OpenAI - AI processing of selected task context; embeddings - United States.
Hetzner - hosting of our self-hosted tracing tool for AI requests - Germany (Nuremberg).
Cloudflare - CDN and security edge, TLS termination - United States company, global edge network.
OpenAI and Cloudflare above have signed data processing agreements with us, incorporating the EU Standard Contractual Clauses and the UK Addendum — for OpenAI, on the processor-to-processor module; for Cloudflare, its own data processing addendum, accepted on our account. AWS and Hetzner process data within the EU under their data processing terms.
Sign-in is through Google only. Google acts under its own terms as an independent identity provider for that login. Voice input in chat uses the browser’s built-in speech recognition; in some browsers, such as Chrome, speech is sent to the browser vendor under its own terms, and we receive only the resulting text. The browser vendor is not our sub-processor.
Tools you connect yourself. GitHub, GitLab, Atlassian (Jira, Confluence), Linear and Fireflies are not listed as sub-processors here. Enji Lite reads these under the connecting user’s own OAuth grant, personal access token or API key, rather than under a separate arrangement between us and that provider. Because access is scoped to your own tenant or instance with that provider, where that data is processed depends on your own account and data-residency settings, not on anything we control. Slack and Telegram are not listed either: our bot works only in the channels and chats you add it to, and messages there are handled by Slack and Telegram under your own arrangements with them.
Other providers involved in running the Service: Dodo Payments (reseller and merchant of record — independent controller of buyer payment and tax data; receives no customer content).
Annex 4 - Transfer safeguards
The instruments
EEA personal data — the EU Standard Contractual Clauses, Commission Implementing Decision (EU) 2021/914 of 4 June 2021, using Module Two where you are a controller and Module Three where you are yourself a processor. They are incorporated by reference and deemed executed by both of us when you accept the Terms of Use.
UK personal data — the same Clauses as amended by the UK Addendum (the International Data Transfer Addendum issued under s119A(1) Data Protection Act 2018), or the UK IDTA where that is more appropriate.
Swiss personal data — the same Clauses, read with “GDPR” meaning the Swiss FADP, the Swiss Federal Data Protection and Information Commissioner as supervisory authority, and “Member State” including Switzerland.
Elections under the Clauses
Clause 7 - docking. Does not apply.
Clause 9(a) - sub-processors. Option 2, general written authorisation. The notice period is 30 days, as set out in section 5 of this Agreement.
Clause 11(a) - independent dispute resolution. The optional independent dispute-resolution body does not apply.
Clause 13 - supervisory authority. The authority of the Member State in which you are established. If you are not established in the EEA, the authority of the Member State in which your Article 27 representative is designated under Article 27 GDPR. If neither applies, the Irish Data Protection Commission.
Clause 17 - governing law. Option 1. The law of Ireland, which allows third-party beneficiary rights.
Clause 18(b) - forum. The courts of Ireland.
Annex I.A — the parties
Data exporter: you — the customer identified by the workspace that accepted these Terms of Use, with the contact details held on that account. Your role is controller, or processor where you are acting for someone else. Activities: using Enji Lite to connect project-management, source-control, knowledge-base and messaging tools.
Data importer: Enji AI Limited Liability Company, 11 microdistrict, 14/4, Bishkek City, Kyrgyz Republic, 720049 · contact@enji.ai. Role: processor. Activities: as described in Annex 1.
Contact point for data subject complaints and enquiries under the Clauses: contact@enji.ai. You may also write to either Article 27 representative:
European Union — Prighter EU Rep GmbH, Schellinggasse 3/10, 1010 Vienna, Austria, FN 639035 h · support@prighter.com · Trust Center: app.prighter.com/portal/16660917026.
United Kingdom — Mad Devs Group Ltd, 27 Old Gloucester Street, London WC1N 3AX, company 11793394 · privacy@maddevs.io, a company related to ours by common ownership
Government and law-enforcement access — Clauses 14 and 15
We rely on the Clauses rather than on any adequacy decision for these transfers, so how we — and OpenAI — behave when an authority comes asking is the substance of the transfer assessment rather than a footnote to it.
What we commit to, and these are Clause 15 obligations rather than goodwill:
- We tell you. If we receive a legally binding request from a public authority for customer content, we notify you promptly, and if we are prohibited from doing so we ask for a waiver of that prohibition and record that we asked.
- We challenge. Where there are reasonable grounds, we challenge the request — including interim measures to suspend disclosure — and we do not hand anything over while a challenge is live unless compelled.
- We give the minimum. If we must disclose, we provide only what the request actually compels, after checking it is lawful on its face.
- We keep a record of the requests we receive and what we did, and we will share it with you on request to the extent the law allows.
What we cannot promise. We cannot guarantee that a foreign authority will never compel disclosure, and no contract can.
Transfer risk assessment
These transfers are supported by an assessment of the risks of transferring to the Kyrgyz Republic and the United States, covering the legal regime in each, the practical likelihood of authority access to data of this kind, and the measures in Annex 2. You can ask us for it.
Where the Clauses conflict with this Agreement, the Clauses prevail.