Agent Dojo
Back to app
← All legal documents

Data Processing Agreement

Effective June 1, 2026·v2026.06.01-draft·Last updated June 14, 2026
You're viewing a superseded version (v2026.06.01-draft). View the current version.
DRAFT — LAWYER REVIEW REQUIRED

This is an unreviewed engineering stub. The wording is not legal advice and is not binding. Every [BRACKETED]item needs counsel's input — 6 placeholders on this page. It is not enforced against customers until reviewed and this banner is removed.

⚠️ DRAFT — PENDING LEGAL REVIEW

Standard boilerplate, not reviewed by counsel and not legal advice. The security measures (Schedule 1) are a reasonable starting list that Engineering + counsel must confirm. Items marked [CONFIRM: …] need your decision.

Effective date: 2026-06-01 · Version: 2026.06.01-draft

This Data Processing Agreement ("DPA") forms part of the Terms of Service and applies where [CONFIRM: legal entity — "Agent Dojo, Inc."] ("Agent Dojo," "Processor") processes personal data on behalf of the Customer ("Controller") in providing the Service. Capitalized terms not defined here have the meaning in the Terms; "personal data," "processing," "controller," "processor," and "data subject" have the meaning in the GDPR.

1. Roles and scope

The Customer is the controller (or a processor acting for its own customers) and Agent Dojo is the processor. Subject matter: provision of the Service. Duration: the term of the Terms. Nature/purpose: hosting, processing, and analysis of Customer Data to deliver voice mock-call training and scoring. Data subjects: the Customer's Users and trainees. Categories: account and contact data, usage data, and voice recordings/transcripts the Customer submits.

2. Processing instructions

Agent Dojo will process personal data only on the Customer's documented instructions (including the Terms and Customer's use of the Service), unless required by law, in which case it will notify the Customer where legally permitted. Agent Dojo will inform the Customer if, in its opinion, an instruction infringes data-protection law.

3. Confidentiality

Agent Dojo ensures that personnel authorized to process personal data are bound by appropriate confidentiality obligations.

4. Security measures

Agent Dojo implements and maintains the technical and organizational measures in Schedule 1, appropriate to the risk.

5. Subprocessors

The Customer provides general authorization for Agent Dojo to engage the subprocessors listed at /legal/subprocessors (Schedule 2). Agent Dojo will impose data-protection terms on each subprocessor no less protective than this DPA and remains responsible for their performance. Agent Dojo will give notice of any intended addition or replacement of a subprocessor; the Customer may object on reasonable data-protection grounds within 30 days, and the parties will work in good faith to resolve the objection. [CONFIRM: objection window + notice mechanism — 30 days is common]

6. Data subject requests

Taking into account the nature of the processing, Agent Dojo will assist the Customer by appropriate technical and organizational measures, insofar as possible, to respond to data-subject requests, and will promptly forward any request it receives directly to the Customer rather than responding itself (except to confirm receipt).

7. Assistance

Agent Dojo will provide reasonable assistance to the Customer with data-protection impact assessments, prior consultations, and security obligations, taking into account the information available to it.

8. Audit rights

Agent Dojo will make available information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates — no more than once per 12 months (unless required by a supervisory authority), on at least 30 days' notice, during business hours, subject to confidentiality, and not unreasonably interfering with operations. Agent Dojo may satisfy audit requests by providing then-current third-party reports/certifications where available. [CONFIRM: audit frequency/scope/cost — once-yearly + report-first is common]

9. International transfers

Where Agent Dojo transfers personal data out of the EEA, Switzerland, or the UK to a country without an adequacy decision, the transfer is governed by the European Commission's Standard Contractual Clauses (Module 2 or 3 as applicable), incorporated by reference, and the UK International Data Transfer Addendum for UK transfers, together with any supplementary measures.

10. Personal data breach

Agent Dojo will notify the Customer without undue delay and in any event within 72 hours after becoming aware of a personal data breach affecting Customer personal data, with the information then available, and will provide updates and reasonable cooperation as the investigation proceeds.

11. Return and deletion

On expiry or termination, Agent Dojo will, at the Customer's choice, return or delete Customer personal data within 30 days, and delete existing copies, except to the extent retention is required by law (in which case this DPA continues to apply to the retained data). Backups are purged on the 35-day backup cycle.

12. Liability

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms.


Schedule 1 — Technical and organizational security measures

[CONFIRM: Engineering + counsel to verify each item against current systems.]

  • Encryption — TLS 1.2+ in transit; encryption at rest for databases, object storage, and backups.
  • Access control — role-based access, least privilege, unique accounts, and multi-factor authentication for administrative access; row-level tenant isolation in the application database.
  • Network security — segmentation, firewalling, and restricted administrative access.
  • Logging and monitoring — audit logging of administrative and security- relevant events; alerting and observability.
  • Vulnerability management — dependency monitoring, timely patching, and periodic review.
  • Backups and resilience — regular encrypted backups with a defined retention and restore process.
  • Personnel — confidentiality obligations and security awareness.
  • Incident response — a documented process for detection, containment, and notification.
  • Sub-processor management — contractual data-protection terms and review.

Schedule 2 — Subprocessors

The current list is maintained at /legal/subprocessors and is the controlling, append-only record.


⚑ Needs your input

  • [CONFIRM] Legal entity name.
  • [CONFIRM] Schedule 1 — Engineering + counsel verify each security measure (and add SOC 2 / ISO status if applicable).
  • [CONFIRM] Subprocessor objection window (default 30 days) and audit terms (default once/12 months, report-first).
  • Confirm the breach-notice window (72h), deletion window (30 days), and SCC/IDTA modules with counsel.
Previous versions
  • v2026.06.21-draft — effective June 21, 2026
Agent Dojo · legal
Terms·Privacy·DPA·Subprocessors·Cookie
·