Controlled-pilot contract draft · 2 August 2026

Data processing terms

This summary supports pilot review. A signed order form or data-processing agreement must identify the parties and any negotiated requirements.

Roles and instructions

For client-submitted service data, the client determines the authorised purpose and AT Infotech processes the data only to provide, secure and support AT AI under documented instructions. AT Infotech informs the client if an instruction appears unlawful and does not sell client data.

Processing details

Confidentiality and security

Access is limited to authorised personnel and services. Measures include tenant isolation, role checks, privileged MFA, encrypted transport, protected secrets, audit logs, backup controls, vulnerability remediation and incident response. Security is reviewed proportionate to risk.

Sub-processors and transfers

The production register must name hosting, identity, email and any enabled AI provider. AT Infotech remains responsible for contractual controls over subprocessors and will communicate material changes. Cross-border processing, if any, is documented and restricted where applicable.

Requests, incidents and assistance

AT Infotech will reasonably assist the client with verified access, correction, deletion, grievance, security and regulatory requests. Suspected breaches are contained, investigated, documented and communicated without undue delay under the signed agreement and applicable law.

Return, export and deletion

A tenant administrator may request a bounded portable export. Permanent tenant deletion requires a recent completed export, exact tenant confirmation, Platform Admin MFA and absence of a legal hold. Non-identifying completion evidence may remain for accountability.

Audit and precedence

Relevant control evidence can be supplied subject to security and confidentiality limits. Signed client terms prevail over this summary. Contact: sureshkardam@gmail.com.