Data Processing Agreement
This is an unreviewed engineering stub. The wording is not legal advice and is not binding. Every [BRACKETED]item needs counsel's input — 6 placeholders on this page. It is not enforced against customers until reviewed and this banner is removed.
⚠️ DRAFT — PENDING LEGAL REVIEW
Standard boilerplate, not reviewed by counsel and not legal advice. The security measures (Schedule 1) are a reasonable starting list that Engineering + counsel must confirm. Items marked
[CONFIRM: …]need your decision.
Effective date: 2026-06-01 · Version: 2026.06.01-draft
This Data Processing Agreement ("DPA") forms part of the
Terms of Service and applies where
[CONFIRM: legal entity — "Agent Dojo, Inc."] ("Agent Dojo," "Processor")
processes personal data on behalf of the Customer ("Controller") in providing
the Service. Capitalized terms not defined here have the meaning in the Terms;
"personal data," "processing," "controller," "processor," and "data subject" have
the meaning in the GDPR.
1. Roles and scope
The Customer is the controller (or a processor acting for its own customers) and Agent Dojo is the processor. Subject matter: provision of the Service. Duration: the term of the Terms. Nature/purpose: hosting, processing, and analysis of Customer Data to deliver voice mock-call training and scoring. Data subjects: the Customer's Users and trainees. Categories: account and contact data, usage data, and voice recordings/transcripts the Customer submits.
2. Processing instructions
Agent Dojo will process personal data only on the Customer's documented instructions (including the Terms and Customer's use of the Service), unless required by law, in which case it will notify the Customer where legally permitted. Agent Dojo will inform the Customer if, in its opinion, an instruction infringes data-protection law.
3. Confidentiality
Agent Dojo ensures that personnel authorized to process personal data are bound by appropriate confidentiality obligations.
4. Security measures
Agent Dojo implements and maintains the technical and organizational measures in Schedule 1, appropriate to the risk.
5. Subprocessors
The Customer provides general authorization for Agent Dojo to engage the
subprocessors listed at /legal/subprocessors (Schedule
2). Agent Dojo will impose data-protection terms on each subprocessor no less
protective than this DPA and remains responsible for their performance. Agent
Dojo will give notice of any intended addition or replacement of a subprocessor;
the Customer may object on reasonable data-protection grounds within 30 days,
and the parties will work in good faith to resolve the objection.
[CONFIRM: objection window + notice mechanism — 30 days is common]
6. Data subject requests
Taking into account the nature of the processing, Agent Dojo will assist the Customer by appropriate technical and organizational measures, insofar as possible, to respond to data-subject requests, and will promptly forward any request it receives directly to the Customer rather than responding itself (except to confirm receipt).
7. Assistance
Agent Dojo will provide reasonable assistance to the Customer with data-protection impact assessments, prior consultations, and security obligations, taking into account the information available to it.
8. Audit rights
Agent Dojo will make available information reasonably necessary to demonstrate
compliance with this DPA and allow for and contribute to audits, including
inspections, conducted by the Customer or an auditor it mandates — no more than
once per 12 months (unless required by a supervisory authority), on at least
30 days' notice, during business hours, subject to confidentiality, and not
unreasonably interfering with operations. Agent Dojo may satisfy audit requests by
providing then-current third-party reports/certifications where available.
[CONFIRM: audit frequency/scope/cost — once-yearly + report-first is common]
9. International transfers
Where Agent Dojo transfers personal data out of the EEA, Switzerland, or the UK to a country without an adequacy decision, the transfer is governed by the European Commission's Standard Contractual Clauses (Module 2 or 3 as applicable), incorporated by reference, and the UK International Data Transfer Addendum for UK transfers, together with any supplementary measures.
10. Personal data breach
Agent Dojo will notify the Customer without undue delay and in any event within 72 hours after becoming aware of a personal data breach affecting Customer personal data, with the information then available, and will provide updates and reasonable cooperation as the investigation proceeds.
11. Return and deletion
On expiry or termination, Agent Dojo will, at the Customer's choice, return or delete Customer personal data within 30 days, and delete existing copies, except to the extent retention is required by law (in which case this DPA continues to apply to the retained data). Backups are purged on the 35-day backup cycle.
12. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms.
Schedule 1 — Technical and organizational security measures
[CONFIRM: Engineering + counsel to verify each item against current systems.]
- Encryption — TLS 1.2+ in transit; encryption at rest for databases, object storage, and backups.
- Access control — role-based access, least privilege, unique accounts, and multi-factor authentication for administrative access; row-level tenant isolation in the application database.
- Network security — segmentation, firewalling, and restricted administrative access.
- Logging and monitoring — audit logging of administrative and security- relevant events; alerting and observability.
- Vulnerability management — dependency monitoring, timely patching, and periodic review.
- Backups and resilience — regular encrypted backups with a defined retention and restore process.
- Personnel — confidentiality obligations and security awareness.
- Incident response — a documented process for detection, containment, and notification.
- Sub-processor management — contractual data-protection terms and review.
Schedule 2 — Subprocessors
The current list is maintained at /legal/subprocessors and is the controlling, append-only record.
⚑ Needs your input
[CONFIRM]Legal entity name.[CONFIRM]Schedule 1 — Engineering + counsel verify each security measure (and add SOC 2 / ISO status if applicable).[CONFIRM]Subprocessor objection window (default 30 days) and audit terms (default once/12 months, report-first).- Confirm the breach-notice window (72h), deletion window (30 days), and SCC/IDTA modules with counsel.
- v2026.06.21-draft — effective June 21, 2026