Skip to main content

Data Processing Agreement

Last Updated: August 27, 2026
Applies To: Customers who need a formal Data Processing Agreement for their own GDPR, CCPA, or similar compliance obligations

1. Purpose and Scope

This Data Processing Agreement ("DPA") forms part of the agreement between you ("Customer," the data controller) and Namos Labs, operator of Imori ("Processor," "we," "us"), and applies whenever we process personal data on your behalf through your use of Imori. It supplements, and does not replace, our Terms of Service and Privacy Policy.

If your organization requires a countersigned DPA (e.g. a standalone document referencing Article 28 GDPR) for procurement or compliance purposes, use the form below or email team@namoslabs.com and we'll send one over.

2. Roles of the Parties

For personal data that end users submit into Imori under your organization's account (e.g. team member content, workspace member details), you act as the data controller and we act as the data processor, processing personal data only on your documented instructions as set out in this DPA and our Terms of Service.

3. Details of Processing

  • Subject matter: Provision of the Imori AI writing platform
  • Duration: For as long as we provide the service to you, plus any post-termination retention described in Section 8
  • Nature and purpose: Storing, processing, and generating written content; account authentication; billing; product analytics (where enabled); customer support
  • Categories of data subjects: Your team members, workspace collaborators, and end users who interact with Imori under your account
  • Categories of personal data: Name, email address, account credentials (via Clerk), authored content (drafts, artifacts, style guides), usage/device data, and — if the voice agent is used — microphone audio

4. Our Obligations as Processor

  • Process personal data only on your documented instructions, unless required to do otherwise by law
  • Ensure personnel with access to personal data are bound by confidentiality obligations
  • Implement appropriate technical and organizational security measures (see Section 6)
  • Assist you in responding to data subject requests (access, rectification, erasure, portability) that reach us relating to your account
  • Notify you without undue delay after becoming aware of a personal data breach affecting your data
  • Delete or return personal data at the end of the engagement, as described in Section 8
  • Make available information reasonably necessary to demonstrate compliance with this DPA

5. Subprocessors

You authorize us to engage the following subprocessors to provide the Imori service. Each is bound by a data processing agreement providing an equivalent level of data protection.

  • Clerk — authentication and account management
  • Convex — application database and hosting
  • Stripe — payment processing
  • Resend — transactional email delivery
  • Sentry — error monitoring and performance tracing
  • OpenRouter, OpenAI, and/or Anthropic — AI text generation
  • ElevenLabs — voice agent transcription and speech synthesis
  • Netlify — web hosting and content delivery
  • Google Analytics, PostHog, and/or Plausible — product analytics, only where enabled and consented to

We'll notify you of any new subprocessor by updating this page. If you object to a new subprocessor on reasonable data protection grounds, contact us at team@namoslabs.com within 30 days.

6. Security Measures

  • Encryption of personal data in transit and at rest
  • Access to production data scoped to authenticated identity, not shared credentials
  • Continuous error and anomaly monitoring
  • Rate limiting and abuse detection on public endpoints
  • Regular dependency and vulnerability patching

7. International Transfers

Where personal data is transferred outside the European Economic Area, United Kingdom, or Switzerland, we rely on Standard Contractual Clauses or an equivalent recognized transfer mechanism with our subprocessors.

8. Deletion and Return of Data

Upon termination of your account, we will delete your personal data within 30 days, except where retention is required by law (e.g. billing/tax records) or covered by anonymized backups that are not restored to production. You may also request deletion or export of your data at any time before termination.

9. Audit Rights

On reasonable written request, no more than once per year, we'll provide information reasonably necessary to demonstrate compliance with this DPA, such as summaries of our security practices. On-site audits may be arranged by mutual agreement.

10. Contact

Email: team@namoslabs.com

Operated by: Namos Labs

Response Time: Within 72 hours for DPA and compliance requests

This DPA reflects how Imori actually processes data today. If your organization needs a countersigned or customized version, reach out and we'll work with you directly.