Legal
Version 1.0 · Effective Date: September 22, 2026
Version 1.0 · Effective Date: September 22, 2026
Contents
This Account Lookups Addendum (the "Lookups Addendum") forms part of the Data Processing Agreement (the "DPA") between ROGA AI LIMITED ("Provider", "we") and the customer identified in the applicable Order Form or account ("Customer", "you") for the use of The AI CMO (the "Services"). It sits on top of the AI Support Agent Addendum (the "Support Addendum"): everything the Support Addendum says about the support agent continues to apply, and this document adds one capability to it. Terms defined in the DPA and in the Support Addendum carry the same meaning here. Where this Lookups Addendum and the Support Addendum differ on the processing described below, this one prevails.
1.1 This Lookups Addendum describes one thing the support agent can do that the Support Addendum does not cover: reading facts about one End User's account in the Customer's own systems, through a web browser, in order to answer that End User. Each of these is called a lookup.
1.2 It takes effect for an organisation in the Customer's account when an administrator of that organisation confirms it in the Services, in Settings. Where the account carries no organisation, the account owner confirms it and is the administrator for the purposes of this Lookups Addendum. An organisation that has not confirmed the Support Addendum cannot confirm this one, and until a confirmation of this one is on record no lookup runs and no model call is made for one.
1.3 The confirmation is the Customer's documented instruction under Section 4 of the DPA and Article 28(3)(a) GDPR for the processing described here.
1.4 We record each confirmation in the way the Support Addendum describes, and we keep the record rather than the checkbox:
1.5 Withdrawal, and every later change to the settings this Lookups Addendum governs, is written as a new record of the same kind. Records are added, never altered or removed, and administrators can read the history in the Services.
1.6 Confirmation is the organisation's act and covers the organisation. Each brand is then switched on separately by an administrator, and a brand runs no lookup while no confirmation is on record.
2.1 A lookup exists because the Customer's own team wrote it down first. Each one names the system it reads, where in that system to start, how the End User is found there – a customer number, an e-mail address, a telephone number or a name – and, in plain words, which facts to read.
2.2 The agent runs only lookups defined that way. It does not browse the Customer's systems freely, it does not decide for itself where else to look, and we ship no lookups of our own.
2.3 A lookup can be rewritten, switched off or removed by the Customer's team at any time, and takes effect at once.
3.1 Every lookup is instructed to read and nothing else. The instruction forbids submitting a form, saving, editing, deleting, approving, refunding, messaging anyone and changing anything at all. Where the only way to continue would change something, the lookup is instructed to stop, report that it was blocked, and leave the case to a person.
3.2 We say plainly what that is: an instruction given to an automated browser, not a technical lock. A browser that is signed in can in principle do whatever the account it is signed in as is allowed to do, and an instruction is followed rather than enforced.
3.3 The control that cannot be argued with is the Customer's own. The account a lookup runs under should be one with read-only rights in the Customer's system. The Customer decides which account that is and what it may do there; we cannot grant or restrict rights in a system that is not ours.
4.1 A lookup runs in one of two places:
4.2 Where the Customer has stored no login for a system, only the first way is available for that system, and a lookup that nobody's browser picks up does not run.
4.3 A login the Customer stores with us is held under the technical and organisational measures in Annex II of the DPA – among them encryption in transit and at rest, connection tokens held in a separate encrypted store, managed key services with access logged, and least-privilege access for our staff. This Lookups Addendum adds no measure of its own and claims none beyond that Annex.
5.1 This is the reason this document is separate from the Support Addendum, and it is stated without softening. Everything the Support Addendum describes happens on conversation text with identifiers replaced by placeholders. A lookup cannot work that way. A real identifier of the End User – the one the lookup searches by: a customer number, an e-mail address, a telephone number or a name – and the content of that End User's page in the Customer's system are read by a model. A browser cannot find a person by a placeholder.
5.2 What is given. The browser is given that one identifier and the lookup's own instructions. It is not given the conversation, the rest of what we hold about that End User, or anything about any other End User. It is told to report only the facts the lookup asks for.
5.3 What comes back. What the lookup read is brought back to our servers, and identifiers in it are replaced with placeholders as Section 4 of the Support Addendum provides before any of it is used to write a reply. The measures and the limits of Section 4 of the Support Addendum, including its regulated-topics rule, apply here too.
5.4 Providers. The material described here reaches model providers through the same arrangement as the rest of the Services. Those providers, and the basis on which they are listed, are set out in Annex III of the DPA. This Lookups Addendum adds no provider and changes nothing about how they are engaged; what changes is the material they receive, which here includes one End User's real identifier and the content of that End User's page.
5.5 No training. Nothing read by a lookup, and nothing generated from it, is used to train, fine-tune or improve models, ours or any third party's, as Section 4 of the DPA requires.
The support agent works at one of three stages on a brand, as the Support Addendum describes. A lookup follows the stage:
7.1 What a lookup read is kept on the conversation it was run for, so that the Customer's desk can see what an answer was based on. It is deleted when that conversation is deleted.
7.2 It is part of the record of the agent's work, and the period in Section 6.1 of the Support Addendum applies to it – the period in force for the organisation, which an administrator sets in the same place as the confirmation. Shortening the period deletes what falls outside it at the next scheduled purge.
7.3 Confirmation records are kept as Section 6.3 of the Support Addendum provides.
7.4 Section 11 of the DPA applies on termination to everything in this Section.
8.1 An administrator can withdraw this confirmation at any time, where it was given. Withdrawal stops lookups immediately and switches them off for every brand in the organisation. It takes no notice period and no reason. The Support Addendum is unaffected and the agent goes on working without lookups.
8.2 Withdrawing the Support Addendum withdraws this one with it, because there is no agent left for a lookup to serve. Confirming the Support Addendum again does not bring this one back; it is confirmed again separately.
8.3 A single lookup can be switched off or removed by the Customer's team at any time, without withdrawing anything and without an administrator.
8.4 The Customer remains responsible, as controller, for its right to have the systems it names read this way, and for the rights it gives the account each lookup runs under.
8.5 Nothing in this Section limits the Customer's rights under Sections 8 and 11 of the DPA, or under Section 7 of the Support Addendum.
9.1 A materially new kind of processing – a new category of data read, a new purpose, or a new recipient of what a lookup reads – requires a new version of this Lookups Addendum and a new confirmation before that processing runs. What was already confirmed keeps running in the meantime.
9.2 Other changes are published as a new version, dated, and Section 13.5 of the DPA applies to them.
9.3 Every published version of this page is archived with the date it was captured and a hash of its text, so the wording a given confirmation refers to can be retrieved in full.
Questions about this Addendum
Write to privacy@theaicmo.com. Data Protection Officer: dpo@theaicmo.com.