Data Processing Agreement

Version 1.0 (pre-launch) · Effective date: [date] · Contact: sales@datumos.ai

This Data Processing Agreement (the "DPA") is entered into between the customer identified in the Order Form (the "Customer", the controller) and [COMPANY LEGAL NAME], [REGISTERED ADDRESS], [REGISTRATION NUMBER] (the "Provider", the processor). It forms part of the Terms of Service and governs the processing of personal data that the Provider carries out on the Customer's behalf in the course of providing DatumOS (the "Service"). It is drafted to meet Article 28 of Regulation (EU) 2016/679 (the "GDPR"). Capitalised terms not defined here have the meaning given in the Terms of Service.

1. Subject matter and duration

1.1. The subject matter of the processing is the operation of the Customer's dedicated DatumOS Instance, including the AI agents that read, analyse and act on data within it under the Customer's configuration.

1.2. The processing lasts for the term of the agreement and the export window that follows it, until the Provider has destroyed the Instance in accordance with section 10.

2. Nature and purpose of the processing

The Provider hosts, stores, transmits, indexes, displays and analyses Customer Data, and executes the Customer's configured agents, routines and Flows, for the purpose of providing the Service as described in the Terms and the documentation. This includes: receiving messages from Connected Systems the Customer has connected; storing cases, sessions and attachments; sending prompts and receiving outputs from the Model Provider selected by the Customer; running commands inside isolated execution environments; and answering in the channel where the agent was asked. The Provider does not process Customer Data for its own purposes, except for operational telemetry that is not tied to identified individuals.

3. Categories of data subjects and personal data

3.1. Data subjects: the Customer's employees, contractors and administrators; the Customer's own customers, users, suppliers and business contacts appearing in cases, conversations, tickets, e-mails, code repositories, CRM records and documents; other persons mentioned in content the Customer connects to the Instance.

3.2. Categories of data: identification and contact data (names, e-mail addresses, user identifiers in connected systems); professional data (roles, teams, group memberships); communication content (messages, tickets, e-mails, comments, attachments); technical data (log entries, identifiers, IP addresses, system configuration); business data relating to individuals (CRM records, orders, support history); and any other personal data the Customer chooses to include. The Service is not designed for special categories of data under Article 9 GDPR or for data relating to criminal convictions; the Customer must not connect systems containing such data without a prior written agreement with the Provider on additional measures.

4. Customer's instructions and responsibilities

4.1. The Provider processes personal data only on the Customer's documented instructions, including with regard to transfers to third countries, unless required to do so by Union or Member State law, in which case the Provider informs the Customer before processing unless the law prohibits it. The Terms, this DPA, the Order Form and the configuration the Customer applies in the Instance (Spaces, integrations, access policies, autonomy levels, model provider restrictions, knowledge bases) constitute the Customer's instructions. Further instructions may be given in writing.

4.2. The Provider informs the Customer without delay if, in its opinion, an instruction infringes the GDPR or other data protection law.

4.3. The Customer is responsible for the lawfulness of the personal data it processes through the Service, for informing data subjects, for the decisions about which systems to connect, which Model Providers to use and which autonomy level to grant the agent, and for the instructions its users give to the agent.

5. Confidentiality

The Provider ensures that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation, and that they process it only on instructions and to the extent necessary for their role. Access to production systems is limited to named personnel and logged.

6. Security of processing

6.1. Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing as well as the risk to the rights and freedoms of natural persons, the Provider implements the technical and organisational measures set out in Annex 1 and keeps them under review.

6.2. The Provider may update the measures provided the overall level of security is not reduced.

7. Sub-processors

7.1. The Customer gives general authorisation for the Provider to engage the sub-processors listed in Annex 2. The Provider imposes on each sub-processor, by written contract, data protection obligations equivalent to those in this DPA, and remains fully liable to the Customer for the sub-processor's performance.

7.2. The Provider notifies the Customer of any intended addition or replacement of a sub-processor at least 30 days in advance by e-mail to the Organisation administrators. The Customer may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, the Customer may terminate the affected part of the Service with a pro-rata refund of prepaid fees.

7.3. Model Providers (currently Anthropic and OpenAI) and Connected Systems that the Customer selects, licenses and connects under its own account are engaged by the Customer directly and are not sub-processors of the Provider. Where the Order Form provides for model access issued through the Provider, the relevant Model Provider is listed in Annex 2 as a sub-processor.

8. Assistance to the Customer

8.1. Taking into account the nature of the processing, the Provider assists the Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling the Customer's obligation to respond to data subject requests. The Service provides search, export and deletion functions for this purpose; requests received directly by the Provider are forwarded to the Customer without undue delay.

8.2. The Provider assists the Customer in ensuring compliance with Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments and prior consultation), taking into account the nature of the processing and the information available to the Provider. Assistance beyond the Service's built-in functions and the documentation may be charged at the Provider's professional services rates.

9. Personal data breaches

9.1. The Provider notifies the Customer without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer Data. The notification is sent to the Organisation administrators and to the contact in the Order Form and describes, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a point of contact. Information may be provided in phases.

9.2. The Provider cooperates with the Customer and takes reasonable steps to contain and remediate the breach. The Provider does not notify supervisory authorities or data subjects on the Customer's behalf unless instructed or required by law.

10. Deletion and return of data

10.1. The Customer may export Customer Data at any time through the panel or the API. After the end of the agreement the Instance is suspended and the Customer has an export window of 30 days.

10.2. After the export window the Provider destroys the Instance, including its database, object storage and encryption key, within a further 30 days, and deletes remaining copies, except for backups which expire under the Provider's backup schedule of no more than 35 days and data the Provider must retain under Union or Member State law. On request the Provider confirms destruction in writing.

11. Audits

11.1. The Provider makes available to the Customer all information necessary to demonstrate compliance with Article 28 GDPR, including the measures in Annex 1, summaries of relevant third-party attestations for its hosting provider, and answers to reasonable written security questionnaires.

11.2. Where this is insufficient, the Customer or an independent auditor bound by confidentiality and mandated by the Customer may audit the Provider's processing once per 12 months, or additionally after a personal data breach or at the request of a supervisory authority, on at least 30 days' written notice, during business hours, without unreasonable disruption, and at the Customer's cost. Audits do not extend to other customers' Instances or to the hosting provider's data centres, for which the Provider relies on that provider's audit reports.

12. International transfers

12.1. The Provider processes Customer Data in the European Union, in the AWS region agreed in the Order Form (by default eu-central-1, Frankfurt). Enterprise customers may select another AWS region; where that region is outside the EU/EEA, the Customer instructs the transfer by that choice.

12.2. Where the Provider or a sub-processor transfers personal data to a third country without an adequacy decision, the Provider ensures appropriate safeguards under Chapter V GDPR, in particular the Standard Contractual Clauses adopted by the European Commission (Decision 2021/914) with supplementary measures where needed, and provides a copy on request. Transfers by the Customer to Model Providers and Connected Systems under the Customer's own accounts are the Customer's responsibility.

13. Liability and precedence

The liability provisions of the Terms of Service apply to this DPA. In case of conflict between this DPA and the Terms with respect to the processing of personal data, this DPA prevails. Mandatory provisions of the GDPR prevail over this DPA.

Annex 1: Technical and organisational measures

Annex 2: Authorised sub-processors

Sub-processorServiceLocation of processingApplies
Amazon Web Services EMEA SARLCloud hosting: compute, database, object storage, key management, networking, managed agent sandboxesEU (eu-central-1, Frankfurt) by default; other AWS regions only where the Customer selects themAlways
Microsoft Ireland Operations Ltd.Azure Bot Service relaying messages between Microsoft Teams and the InstanceEU; per Microsoft's data residency for the Customer's tenantWhere the Customer connects the Teams channel
Anthropic, PBCLarge language models (Claude)United States (EU-US Data Privacy Framework or SCCs)Only where model access is issued through the Provider; otherwise engaged by the Customer directly
OpenAI, L.L.C. / OpenAI Ireland Ltd.Large language and embedding modelsUnited States / EU (EU-US Data Privacy Framework or SCCs)Only where model access is issued through the Provider; otherwise engaged by the Customer directly
[PAYMENT PROCESSOR, e.g. Stripe Payments Europe, Ltd.]Card payments and invoicingEU / United StatesWhere the Customer pays by card; billing contact data only

The current version of this list is published at https://datumos.ai/dpa.html#subprocessors. Changes are notified as described in section 7.