Data Processing & GDPR Compliance
Last Updated: August 5, 2026
PegAIsus is committed to responsible data processing and protecting personal information. This page explains how our AI Employee solutions are designed to support GDPR-aligned operations for our business customers.
GDPR at a Glance
We process data only as necessary to provide our services, use appropriate security safeguards, support data-subject rights, and act as a Data Processor when processing personal data on behalf of our customers.
What this page covers
GDPR Commitment • Controller & Processor • Data Processing Agreement • Information Security • Storage & Retention • Transfers • Customer Responsibilities • Data Subject Rights • Breaches • Sub-processors • Contact
1. Our GDPR Commitment
PegAIsus is committed to processing personal data lawfully, fairly, and transparently. Our services are designed with privacy and security in mind, following principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, confidentiality, and accountability.
2. Data Controller & Data Processor
PegAIsus may act as either a Data Controller or a Data Processor depending on the circumstances. We are generally the Data Controller for contact forms, demo requests, marketing communications, website analytics, business enquiries, and account administration. For customer implementations, PegAIsus generally acts as the Data Processor and customers remain the Data Controllers.
3. Data Processing Agreement (DPA)
Where required by applicable law, PegAIsus can enter into a Data Processing Agreement with customers. Our DPA may address processing instructions, confidentiality, security measures, international transfers, sub-processors, audit rights, data deletion, and the return of customer data.
4. Information Security
Protecting customer information is fundamental to our services. Safeguards may include secure cloud infrastructure, encryption in transit where supported, encryption at rest where appropriate, access controls, authentication procedures, least-privilege access, activity logging, updates, monitoring, and internal access restrictions.
5. Data Storage & Retention
Personal data is retained only for as long as necessary to deliver services, meet contractual obligations, resolve disputes, maintain security, and comply with legal obligations. Retention periods vary according to the data processed and customer instructions.
6. International Data Transfers
Personal data may be processed outside a customer’s country of residence depending on the selected services. Where required, PegAIsus implements appropriate safeguards, including Standard Contractual Clauses, adequacy decisions, or other legally recognised transfer mechanisms.
7. Customer Responsibilities
Customers remain responsible for determining a lawful basis for processing, providing privacy notices, obtaining required consent, configuring AI Employees appropriately, reviewing AI-generated responses where needed, and responding to requests from data subjects. PegAIsus supports customers but cannot fulfil the obligations of the Data Controller.
8. Data Subject Rights
Individuals may have rights to access data, correct inaccuracies, request deletion, restrict or object to processing, receive data in a portable format, withdraw consent, or lodge a complaint with a supervisory authority. Where PegAIsus is a Data Processor, requests should generally be directed to the relevant customer.
9. Personal Data Breaches
PegAIsus maintains procedures for identifying, investigating, and responding to security incidents. Where required by law or contract, affected customers are notified without undue delay following confirmation of a personal data breach affecting their information.
10. Sub-processors
PegAIsus may use carefully selected third-party providers for services such as cloud hosting, email, calendar and CRM integrations, analytics, communications, and infrastructure. Sub-processors are expected to maintain appropriate security and confidentiality standards.
11. Contact Us
Questions about data processing practices or GDPR compliance may be submitted through the PegAIsus Contact page at www.pegaisus.co/contact.
Questions about data processing?
For data processing or privacy questions, please contact PegAIsus through our Contact page.
© 2026 PegAIsus. All rights reserved.
Serving businesses worldwide

