Agent Dojo
Back to app
← All legal documents

Data Processing Agreement

Effective June 21, 2026·v2026.06.21-draft·Last updated June 30, 2026
DRAFT — LAWYER REVIEW REQUIRED

This is an unreviewed engineering stub. The wording is not legal advice and is not binding. Every [BRACKETED]item needs counsel's input. It is not enforced against customers until reviewed and this banner is removed.

This document is a draft pending final legal review. It reflects our current practices and is provided for transparency.

Effective date: 2026-06-21 · Version: 2026.06.21-draft

This Data Processing Agreement ("DPA") forms part of the Terms of Service and applies where 30th Century Media Holdings Corp ("Agent Dojo," "Processor") processes personal data on behalf of the Customer ("Controller") in providing the Service. Capitalized terms not defined here have the meaning in the Terms; "personal data," "processing," "controller," "processor," and "data subject" have the meaning in the GDPR.

1. Roles and scope

The Customer is the controller (or a processor acting for its own customers) and Agent Dojo is the processor. Subject matter: provision of the Service. Duration: the term of the Terms. Nature/purpose: hosting, processing, and analysis of Customer Data to deliver AI-powered voice roleplay, learning management, call quality assurance, and communication-practice features, including scoring and feedback. Data subjects: the Customer's Users and trainees. Categories: account and contact data, usage data, learning and assessment data, and voice recordings/transcripts the Customer submits or uploads.

2. Processing instructions

Agent Dojo will process personal data only on the Customer's documented instructions (including the Terms and Customer's use of the Service), unless required by law, in which case it will notify the Customer where legally permitted. Agent Dojo will inform the Customer if, in its opinion, an instruction infringes data-protection law.

3. Confidentiality

Agent Dojo ensures that personnel authorized to process personal data are bound by appropriate confidentiality obligations.

4. Security measures

Agent Dojo implements and maintains the technical and organizational measures in Schedule 1, appropriate to the risk.

5. Subprocessors

The Customer provides general authorization for Agent Dojo to engage the subprocessors listed at /legal/subprocessors (Schedule 2). Agent Dojo will impose data-protection terms on each subprocessor no less protective than this DPA and remains responsible for their performance. Agent Dojo will give notice of any intended addition or replacement of a subprocessor; the Customer may object on reasonable data-protection grounds within 30 days, and the parties will work in good faith to resolve the objection.

6. Data subject requests

Taking into account the nature of the processing, Agent Dojo will assist the Customer by appropriate technical and organizational measures, insofar as possible, to respond to data-subject requests, and will promptly forward any request it receives directly to the Customer rather than responding itself (except to confirm receipt).

7. Assistance

Agent Dojo will provide reasonable assistance to the Customer with data-protection impact assessments, prior consultations, and security obligations, taking into account the information available to it.

8. Audit rights

Agent Dojo will make available information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates — no more than once per 12 months (unless required by a supervisory authority), on at least 30 days' notice, during business hours, subject to confidentiality, and not unreasonably interfering with operations. Agent Dojo may satisfy audit requests by providing then-current third-party reports/certifications where available.

9. International transfers

Agent Dojo processes Customer personal data in the United States. The following apply to transfers of personal data into the United States:

  • Philippines and other non-EEA jurisdictions. Where the transfer is subject to the Philippine Data Privacy Act (RA 10173) or a similar law, the Customer (as controller) remains accountable for the cross-border transfer, and Agent Dojo (as processor) protects the transferred data under this DPA — including the Schedule 1 security measures, confidentiality, and subprocessor flow-downs — consistent with that law.
  • EEA, Switzerland, and the UK. Where Agent Dojo, as importer, receives personal data transferred from the EEA, Switzerland, or the UK to a country without an adequacy decision (the United States currently has no general EU adequacy decision), the transfer is governed by the European Commission's Standard Contractual Clauses (Module 2 (controller-to-processor) or Module 3 (processor-to-processor) as applicable), incorporated by reference, and the UK International Data Transfer Addendum for UK transfers, together with any supplementary measures.

10. Personal data breach

Agent Dojo will notify the Customer without undue delay and in any event within 72 hours after becoming aware of a personal data breach affecting Customer personal data, with the information then available, and will provide updates and reasonable cooperation as the investigation proceeds.

11. Return and deletion

On expiry or termination, Agent Dojo will, at the Customer's choice, return or delete Customer personal data within 30 days, and delete existing copies, except to the extent retention is required by law (in which case this DPA continues to apply to the retained data). Backups are purged on the 7-day backup cycle.

12. Liability

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms.


Schedule 1 — Technical and organizational security measures

  • Encryption — TLS 1.2+ in transit; encryption at rest for databases, object storage, and backups.
  • Access control — role-based access, least privilege, unique accounts, and multi-factor authentication for administrative access; row-level tenant isolation in the application database.
  • Network security — segmentation, firewalling, and restricted administrative access.
  • Logging and monitoring — audit logging of administrative and security- relevant events; alerting and observability.
  • Vulnerability management — dependency monitoring, timely patching, and periodic review.
  • Backups and resilience — regular encrypted backups with a defined retention and restore process.
  • Personnel — confidentiality obligations and security awareness.
  • Incident response — a documented process for detection, containment, and notification.
  • Sub-processor management — contractual data-protection terms and review.

Schedule 2 — Subprocessors

The current list is maintained at /legal/subprocessors and is the controlling, append-only record.

Previous versions
  • v2026.06.01-draft — effective June 1, 2026
Agent Dojo · legal
Terms·Privacy·DPA·Subprocessors·Cookie
·