Back to 81i

Data Processing Agreement

Last updated: July 13, 2026

This page is mainly for Business customers and the people who review vendors before signing off on them. It explains, precisely, how 81i handles data on your organization's behalf.

Scope

This Data Processing Agreement (DPA) applies when your organization uses 81i’s Business plan and forms part of the agreement between your organization (the “Business Customer”) and 81i. It describes how we process personal data submitted by your team through the platform.

Controller vs processor

For data your team members input into 81i — messages, files, and project content — your organization is the data controller and 81i acts as the data processor, processing that data only to provide the service and on your organization’s documented instructions. For account and billing data tied directly to your organization’s 81i subscription, 81i acts as an independent controller.

Data categories

Depending on how your team uses 81i, processed data may include:

  • Team member names, work email addresses, and roles within the workspace.
  • Message content, uploaded documents, and images submitted through the platform.
  • Usage metadata — timestamps, provider routing decisions, and token counts.
  • API keys your organization chooses to connect.

Sub-processors

We rely on a small set of sub-processors to operate 81i. Each is bound by a data processing agreement at least as protective as this one:

  • Supabase — database hosting and authentication infrastructure.
  • Stripe — payment processing and billing.
  • OpenAI, Anthropic, Google, Meta, Groq, Cohere — AI inference providers in our routing pool that process message content to generate responses.
  • Resend — transactional email delivery (receipts, account and security notifications).

We’ll notify Business customers by email before adding a new sub-processor that will handle their data.

Security measures

We protect data with:

  • 256-bit AES encryption in transit and at rest.
  • Role-based access control, with production data access limited and logged.
  • Approval-gated onboarding for new team members on Business workspaces.
  • Regular dependency and vulnerability scanning across our infrastructure.

International transfers

81i and its sub-processors may process data in countries outside your organization’s home jurisdiction, including the United States and India. Where required, we rely on standard contractual clauses or equivalent safeguards with our sub-processors to ensure data receives a consistent level of protection wherever it’s processed.

Retention and deletion

We retain Business workspace data for as long as the subscription is active. Upon termination, your organization’s admin can request full export or deletion of workspace data; absent a request, we delete it within 30 days of the subscription ending, except where retention is required by law.

Business customer rights

As a Business customer, your organization can:

  • Request a copy of this DPA countersigned for your records.
  • Request an export of all workspace data at any time.
  • Ask us to delete specific team members’ data upon their departure from your organization.
  • Request details of our current sub-processor list and security practices for your own vendor review.

Contact

For DPA requests, security questionnaires, or a countersigned copy, contact security@81i.com.