This DPA governs the processing of personal information that the Vendor uploads, transmits, or otherwise makes available to the Altar AI platform in connection with the Vendor's use of the Services. By using the Services to upload or process personal information about third parties (including Couples or the Vendor's customers), the Vendor agrees to be bound by this DPA.
1Definitions
“Customer Personal Data” means any personal information about Couples, the Vendor's customers, or other individuals that the Vendor uploads to or processes through the Services.
“Controller” means the Vendor, who determines the purposes and means of processing Customer Personal Data.
“Processor” means Altar AI, who processes Customer Personal Data on behalf of the Vendor.
“Sub-Processor” means any third-party service provider engaged by Altar AI to assist in processing Customer Personal Data.
“Privacy Laws” means all applicable privacy and data protection laws, including PIPEDA, Quebec Law 25, the CCPA/CPRA, and other applicable Canadian and U.S. laws.
“Personal Data Breach” means any unauthorized access, disclosure, alteration, loss, or destruction of Customer Personal Data.
2Roles and Responsibilities
2.1Vendor as Controller
The Vendor acknowledges and agrees that with respect to Customer Personal Data, the Vendor acts as the Controller. The Vendor is solely responsible for:
- The lawful basis for collecting and processing Customer Personal Data;
- Obtaining all necessary consents from data subjects;
- Providing privacy notices to data subjects;
- Responding to data subject rights requests;
- Compliance with all applicable Privacy Laws regarding Customer Personal Data;
- The accuracy and lawfulness of Customer Personal Data uploaded to the Services.
2.2Altar AI as Processor
Altar AI processes Customer Personal Data only:
- On the documented instructions of the Vendor, including those expressed through the Vendor's use of the Services;
- As reasonably necessary to provide, maintain, and improve the Services;
- To comply with applicable laws.
If Altar AI cannot comply with the Vendor's instructions for any reason, we will inform the Vendor without undue delay.
3Scope of Processing
Categories of data subjects:
- Couples and engaged individuals planning weddings;
- The Vendor's customers and prospective customers;
- Other individuals whose information the Vendor uploads.
Categories of Customer Personal Data:
- Contact information (names, email addresses, phone numbers);
- Wedding details (dates, locations, guest counts, budgets);
- Communications and messages;
- Files, photos, and documents;
- Any other information the Vendor chooses to upload.
Purpose of processing:
- Hosting Customer Personal Data on the platform;
- Enabling Vendor's CRM functionality (storing messages, quotes, customer records);
- Facilitating communication between the Vendor and Couples;
- Providing analytics and reporting tools to the Vendor;
- Backup, security, and platform maintenance.
4Security Measures
Altar AI implements and maintains appropriate technical and organizational measures to protect Customer Personal Data, including:
- Encryption of data in transit (TLS) and at rest;
- Access controls and authentication systems;
- Role-based access for Altar AI personnel;
- Regular security testing and vulnerability assessments;
- Logging and monitoring of access to Customer Personal Data;
- Secure development practices;
- Personnel confidentiality obligations;
- Incident response procedures.
Altar AI may update its security measures from time to time, provided that updated measures provide at least equivalent protection.
5Sub-Processors
5.1Authorization
The Vendor authorizes Altar AI to engage Sub-Processors to assist in providing the Services. Current Sub-Processors include:
- Vercel (hosting and deployment);
- Supabase / Firebase (database and authentication);
- Anthropic (AI processing via Claude API — contractually prohibited from training on Customer Personal Data);
- Stripe (payment processing);
- Other infrastructure, communication, analytics, and security service providers.
An updated list of Sub-Processors is available at privacy@altarai.co upon request.
5.2Sub-Processor Obligations
Altar AI imposes data protection obligations on Sub-Processors that are no less protective than those in this DPA. Altar AI remains liable for the acts and omissions of its Sub-Processors that breach this DPA.
5.3Notice of Changes
Altar AI will provide notice of new Sub-Processors with access to Customer Personal Data at least thirty (30) days before they begin processing. The Vendor may object on reasonable data protection grounds; if the parties cannot resolve the objection, the Vendor may terminate the Services.
6AI Processing of Customer Personal Data
6.1AI Sub-Processor
Altar AI uses Anthropic, accessed through Anthropic's commercial API, to provide AI features within the Services. When the Vendor uses AI features that involve Customer Personal Data, such data is transmitted to Anthropic in real time, processed, and returned to the Services.
6.2No Training Use
Anthropic is contractually prohibited under its Commercial Terms of Service from using Customer Personal Data (or any commercial API data) to train, fine-tune, or improve any AI model. Altar AI does not train any AI model on Customer Personal Data.
6.3Anthropic Retention
Anthropic retains commercial API logs for a short period (currently 7 days) for security and abuse prevention purposes only, after which the data is deleted. The Vendor acknowledges and accepts this retention period.
6.4Vendor Acknowledgment of AI Processing
By using AI features within the Services that process Customer Personal Data, the Vendor:
- Acknowledges that Customer Personal Data will be transmitted to and processed by Anthropic as a Sub-Processor;
- Warrants that the Vendor has obtained any consents from data subjects required for AI processing under applicable Privacy Laws;
- Agrees that AI processing is integral to the Services and is consented to by the Vendor's use of such features.
6.5No Decisions With Legal Effect
AI features within the Services do not make decisions that produce legal effects or similarly significant effects on data subjects. AI features generate suggestions, recommendations, and content that the Vendor (or the data subject) may choose to act upon. Final decisions remain with the human user.
7Data Subject Requests
Altar AI will provide reasonable assistance to the Vendor in responding to data subject rights requests, including requests for access, correction, deletion, portability, and objection.
If Altar AI receives a data subject request directly relating to Customer Personal Data, we will:
- Forward the request to the Vendor without undue delay;
- Not respond to the request directly except as instructed by the Vendor or required by law.
8Personal Data Breach Notification
If Altar AI becomes aware of a Personal Data Breach affecting Customer Personal Data, we will:
- Notify the Vendor without undue delay, and in any event within seventy-two (72) hours of discovery;
- Provide information about the nature of the breach, categories and approximate number of affected individuals, likely consequences, and remediation steps;
- Cooperate with the Vendor's response, including notifications to data subjects and regulators where required;
- Take reasonable steps to mitigate the breach.
The Vendor is responsible for any required notifications to data subjects or regulators arising from a breach affecting Customer Personal Data, except where Altar AI is independently required to notify.
9International Transfers
Customer Personal Data may be transferred to and processed in countries outside the Vendor's home jurisdiction, including the United States, where Altar AI's Sub-Processors operate. Altar AI ensures that appropriate safeguards are in place for such transfers, including contractual safeguards with Sub-Processors and compliance with applicable Privacy Laws.
10Audit Rights
Upon reasonable written request (no more than once per twelve (12) months, except in connection with a Personal Data Breach), the Vendor may request information reasonably necessary to verify Altar AI's compliance with this DPA. Altar AI will respond by providing documentation, summaries of security audits, or third-party certifications. On-site audits will not be conducted unless required by law and will be at the Vendor's expense.
11Return or Deletion of Customer Personal Data
Upon termination of the Vendor's Account or upon written request:
- Altar AI will return Customer Personal Data to the Vendor in a commonly used, machine-readable format, or
- Altar AI will securely delete Customer Personal Data within ninety (90) days, subject to backup retention periods and legal obligations.
Altar AI may retain Customer Personal Data only to the extent required by law, in which case it remains subject to the security and confidentiality obligations of this DPA.
12Confidentiality
Altar AI ensures that personnel authorized to process Customer Personal Data are bound by appropriate confidentiality obligations and have received privacy and security training.
13Vendor Warranties and Indemnification
The Vendor warrants and represents that:
- It has all necessary rights and consents to upload Customer Personal Data to the Services;
- Customer Personal Data was lawfully collected;
- Its instructions to Altar AI comply with applicable Privacy Laws;
- It has provided appropriate privacy notices to data subjects.
The Vendor will indemnify and hold Altar AI harmless from any claims, fines, penalties, or damages arising from the Vendor's breach of these warranties or violation of Privacy Laws with respect to Customer Personal Data.
14Liability
The liability provisions in the Terms & Conditions apply to this DPA. To the extent permitted by Privacy Laws, neither party's liability under this DPA exceeds the limits set out in the Terms & Conditions.
15Term and Termination
This DPA remains in effect for as long as Altar AI processes Customer Personal Data on behalf of the Vendor. Provisions that by their nature should survive termination (including return/deletion, confidentiality, indemnification, and liability) survive.
16Changes to This DPA
Altar AI may update this DPA from time to time to reflect changes in law or business practices. Material changes will be communicated to Vendors at least thirty (30) days before taking effect. Continued use of the Services after the effective date constitutes acceptance.
17Governing Law and Dispute Resolution
This DPA is governed by the laws of Ontario, Canada. Disputes are resolved in accordance with the dispute resolution provisions of the Terms & Conditions.
18Order of Precedence
In the event of a conflict between this DPA and the Terms & Conditions or Privacy Policy, this DPA controls with respect to data protection matters relating to Customer Personal Data.
19Contact
Privacy and data protection inquiries:
By using the Services to process Customer Personal Data, the Vendor agrees to this DPA.