Aigen Studio

Customer Data Processing Agreement

Aigen Studio, a service of AI Generation Oy · Last updated: 27 September 2026

Version 2026-09-27. This agreement forms part of the Aigen Studio Terms of Service and applies whenever Aigen Studio processes personal data on a customer's behalf.

1. Parties and roles

The customer — the company or organization using Aigen Studio — is the controller of personal data in the material it puts into or connects to Aigen Studio. AI Generation Oy, business ID 3365357-7, VAT ID FI33653577, Selkämerenkatu 12 B 34, 00180 Helsinki, registered in Finland is the processor of that material. AI Generation Oy is separately controller for its own account, security, service-email and business-contact purposes, as described in the Privacy Policy. The person who accepts the Terms for the customer confirms they are authorized to accept this agreement too. The contact for everything in this agreement is contact@aigen.fi.

2. Subject matter, instructions and duration

Processing supports the Aigen Studio service: website and competitor analysis, SEO recommendations and changes, content and social-post drafting, approval and publishing to connected platforms, performance and Search Console / Analytics reporting, lead tracking, file handling, notification emails, and AI assistance the customer requests. Operations include collection, storage, organization, analysis, generation, transmission to platforms the customer connects, retrieval, return and deletion.

The processor acts only on the customer's documented instructions — this agreement, the Terms, and the actions and settings the customer's users choose in the service — unless EU or Member State law requires otherwise; in that case it informs the customer first unless the law forbids it. It tells the customer without delay if it believes an instruction breaks data-protection law. The agreement lasts as long as the Terms, plus return and deletion under section 8.

3. People and data

Data subjects: the customer's users and representatives; people who appear in the customer's website content, posts, files and chats; website visitors whose conversion events the customer's lead-tracking snippet records; contacts in lead records; and people appearing in data from Google, Meta, LinkedIn or X accounts the customer connects.

Data: names, work contact details and roles; chat messages and the conversation history sent with a request; uploaded and generated files; drafts, posts, comments and approvals; brand memory and preferences; lead events and lead contact details; aggregate platform statistics; and activity records. Special-category data is not needed for ordinary use and must not be submitted without separately agreed instructions and safeguards. The customer is responsible for its lawful basis, transparency toward the people concerned, consent for lead tracking on its own website, and its right to provide the data.

4. Confidentiality and security

Access is limited to authorized people bound by confidentiality. The processor keeps measures appropriate to the risk (GDPR Art. 32). Measures operated in the application include:

These measures are not an encryption-at-rest certification of every provider, a complete disaster-recovery demonstration, or a promise of provider-wide erasure. Security information the processor holds is available on request at contact@aigen.fi.

5. Sub-processors and changes

The customer gives general authorization for the sub-processors in the annex (section 10). The processor imposes the data-protection duties of Art. 28 on each sub-processor it engages and remains responsible for them. It gives at least 30 days' notice of an intended addition or replacement where practicable (on request at contact@aigen.fi); the customer may object on reasonable data-protection grounds before the change takes effect. The parties then look for an alternative; if the objection remains unresolved, the customer may stop using the affected feature or end the Terms and receive a refund of prepaid fees for the unused period. An urgent security replacement is notified promptly with the reason, and the same objection route applies.

Platforms the customer connects — Google (Search Console, Analytics), Meta (Facebook, Instagram), LinkedIn and X — are not sub-processors. They are independent controllers of their own services, and Aigen Studio exchanges data with them because the customer connected them and asked for the action.

6. International transfers

This agreement does not claim EU-only processing. Several sub-processors are based in, or process data in, the United States. Personal data is transferred outside the EEA only with a GDPR Chapter V safeguard — an adequacy decision such as the EU–US Data Privacy Framework for certified providers, or standard contractual clauses in the provider's data processing terms. This agreement does not itself create those clauses. Questions: contact@aigen.fi.

7. Assistance, incidents and data-subject requests

The processor helps the customer respond to data-subject requests and meet Art. 32–36 duties (security, breach handling, impact assessments, prior consultation), taking into account the processing and the information available. Requests that reach the processor about customer data are forwarded promptly; it answers a data subject directly only on instruction or where law requires.

After becoming aware of a personal-data breach affecting customer data, the processor notifies the customer without undue delay with the information then available — the nature of the breach, categories and approximate numbers of people and records, likely consequences, and measures taken — and updates it as facts arrive.

8. Return, deletion and backups

During the relationship the customer can export or delete its content in the service and can ask contact@aigen.fi for a copy. When the customer deletes a brand, company or account (in the service or by request), the data is removed from application access immediately and cleanup of stored files is queued and retried until complete. Data retrieved from LinkedIn and X is also deleted automatically under those platforms' rules, as described in the Privacy Policy.

Records the processor must keep by law (for example accounting records), minimal deletion records, and temporary backup copies may remain. Backups are kept by the hosting provider under its own schedule; this agreement does not state backup geography or final purge time. Deleted customer data is not returned to active use after a restore.

9. Accountability, audits and priority

The processor makes available the information reasonably needed to demonstrate compliance with Art. 28 and allows and contributes to audits, including inspections, by the customer or an independent auditor it mandates, with reasonable notice, confidentiality and scope. This agreement prevails over the Terms on personal-data processing. Mandatory law and data-subject rights are unaffected.

10. Annex — sub-processors

ProviderRole in Aigen StudioPublic terms
Replit, Inc. (USA)Application hosting, managed PostgreSQL database (operated with Neon), file storage, and the gateway for Google Gemini modelsDPA · sub-processors
Clerk, Inc. (USA)Sign-in, accounts, multi-factor authentication and sessionsDPA
Anthropic, PBC (USA)AI models for chat, analysis and content generationCommercial terms (incl. DPA)
OpenAI, L.L.C. (USA)AI models, including image generationDPA
Google LLC (USA)Gemini AI models (through Replit) and page-speed checks of public web addressesData processing terms
Resend, Inc. (USA)Delivery of invitation and notification emailsDPA

What each AI request sends: the messages in the request, the conversation history sent with it, relevant brand memory, parsed attachment content and the results of tools the request used. Under their API terms, these providers do not use data sent through their APIs to train their models by default, and Aigen Studio does not opt in to any such use.

11. Known limitations

So that nothing here is read as more than it is: this agreement does not claim EU-only processing, does not create standard contractual clauses for each provider, does not state backup geography or final purge times, and does not confirm that a data protection impact assessment has been completed for any particular customer's use. Contact contact@aigen.fi about any of these points.