Data Processing Agreement between MAIA Decision OS ("Processor") and Customer ("Controller")
Spacious Enterprises, LLC dba MAIA Decision OS (Wyoming Filing ID 2025-001632644, formed March 12, 2025)
Version: 1.0 — March 2026
1. Scope and Roles
This DPA applies to all Processing of Personal Data by MAIA Decision OS on behalf of the Customer in connection with the Services. The Customer is the data controller. MAIA is the data processor acting on the Customer's behalf.
MAIA processes Personal Data only in accordance with the Customer's documented instructions as set forth in this DPA and the underlying Agreement.
2. Description of Processing
MAIA processes data across the following activities:
- Account authentication — Email, password hash, passkey public keys, session tokens
- Purchase management — Email, name, Stripe customer ID, Decision Rehearsal purchase and usage records
- Decision rehearsal execution — Decision description, uploaded documents, Connected Data Source content, Navigator responses during the 9-stage pipeline
- Artifact generation — Decision Brief, Visual Intelligence report, Written Report (derived from rehearsal inputs)
- Connected Data Source access — OAuth tokens, search queries, fetched document content
- Transactional email — Email address, Navigator name (via Resend)
3. Zero Data Retention Architecture
MAIA operates under a Zero Data Retention (ZDR) architecture for Decision Rehearsal Data:
- Decision Rehearsal Data is processed in-memory and is not written to persistent storage
- Session state is maintained in Cloudflare Durable Objects during the active session and deleted upon session completion or expiration
- Connected Data Source content is cached with a maximum 24-hour TTL, after which it is permanently deleted
- Rehearsal artifacts are stored temporarily in Cloudflare R2 and available for download during the session, then permanently deleted
- Decision Rehearsal Data is not used to train, improve, or develop AI models
Account data (email, name, credentials, purchase records) persists for the duration of the account and is deleted within 30 days of account closure.
4. Security Measures
- Encryption in Transit: TLS via Cloudflare's global network
- Encryption at Rest: Cloudflare infrastructure-level encryption for KV and R2
- Authentication: PBKDF2 (100,000 iterations, SHA-256) + optional WebAuthn/FIDO2 passkeys
- Serverless Architecture: Cloudflare Workers — no dedicated servers, VMs, or persistent compute
- Access Control: Secrets stored as encrypted Worker Secrets, CORS enforcement, least privilege
5. Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Anthropic, PBC | AI inference — pipeline processing via API. Not used for model training. | United States |
| Cloudflare, Inc. | Infrastructure — Workers, KV, R2, Durable Objects, Pages, DNS, TLS | Global |
| Stripe, Inc. | Payment processing — Decision Rehearsal and LinkedIn Intelligence Pack purchases. Card data never touches MAIA. | United States |
| Resend, Inc. | Transactional email — verification, password reset, notifications | United States |
6. AI Inference and Model Training
MAIA uses Anthropic's Claude API for AI inference during rehearsal sessions. MAIA does not use Decision Rehearsal Data to train, fine-tune, or improve AI models — whether MAIA's own or those of any Sub-processor. Anthropic's commercial API policy states that data submitted via the API is not used to train Anthropic's models.
MAIA is the decision rehearsal engine. Claude is the inference engine. MAIA controls the pipeline, agent orchestration, and output structure. MAIA does not provide recommendations or advice — it rehearses decisions and maps action paths. The Navigator retains full decision-making authority.
7. Data Subject Rights
MAIA assists the Customer in responding to Data Subject requests (access, rectification, erasure, portability, objection). Given the ZDR architecture, Decision Rehearsal Data is not retained beyond the active session and cache expiration — requests for erasure are typically rendered moot by automatic deletion.
8. Personal Data Breach Notification
MAIA will notify the Customer without undue delay, and within 72 hours, after becoming aware of a Personal Data Breach. Notification includes: nature of the breach, categories and approximate numbers affected, likely consequences, and measures taken or proposed.
9. Data Return and Deletion
- Decision Rehearsal Data: Automatically deleted upon session completion and cache expiration (within 24 hours)
- Account data: Deleted within 30 days of account closure or Agreement termination
- Written confirmation of deletion provided upon request
10. International Data Transfers
The Services are hosted on Cloudflare's global edge network. Where Personal Data from the EEA, UK, or Switzerland is transferred to countries without adequacy decisions, transfers are governed by Standard Contractual Clauses (Module Two: Controller to Processor).
11. CCPA Provisions
Where the CCPA applies, MAIA acts as a "Service Provider." MAIA does not sell or share Personal Data, does not retain or use it for any purpose other than performing the Services, and does not combine it with data from other sources except as permitted by the CCPA.
This DPA is provided as a draft pending legal review. Customers are encouraged to have this document reviewed by legal counsel before execution. For the full document including schedules (Sub-processors, Standard Contractual Clauses, Technical and Organizational Measures), contact [email protected].