Legal

Data Processing Agreement

Version 1.0 · Effective Date: August 26, 2026

Data Processing Agreement

Version 1.0 · Effective Date: August 26, 2026

This Data Processing Agreement ("DPA") forms part of the agreement between ROGA AI LIMITED, registered in Gibraltar under Company No. 125994, Unit G02, Eurocity, Europort Avenue, Gibraltar GX11 1AA ("Provider", "we") and the customer identified in the applicable Order Form or account ("Customer", "you") for the use of The AI CMO (the "Services") under the Terms of Service or a signed agreement (together, the "Agreement"). It applies whenever the Services process Personal Data on the Customer's behalf.

1. Parties, roles and scope

1.1 For Customer Personal Data (defined below) the Customer is the controller – or, where the Customer itself acts for another controller, a processor whose instructions bind the Provider – and the Provider is the processor. The Provider processes Customer Personal Data only on the Customer's documented instructions and never for its own purposes.

1.2 This DPA does not apply to the personal data of the Customer's own users of the Services (account holders and team members), for which the Provider is the controller under the Privacy Policy.

1.3 This DPA applies as published and is incorporated into the Agreement through the Privacy Policy; it is accepted by using the Services to process Customer Personal Data, and no separate signature is needed. An Order Form may complete Annex I for the Customer and select the options in Annex IV. Where the law applicable to the Customer requires processor terms this DPA does not contain, the parties execute a supplemental DPA before the relevant production processing begins; the supplemental DPA prevails to the extent of the additional terms.

2. Definitions

  • Data Protection Laws: the Gibraltar GDPR and Data Protection Act 2004, the EU GDPR (Regulation (EU) 2016/679), the UK GDPR and Data Protection Act 2018, the ePrivacy rules implementing Directive 2002/58/EC, and any other data protection law applicable to the processing.
  • Customer Personal Data: personal data the Customer or its End Users make available to the Services and that the Provider processes on the Customer's behalf – contact lists, customer and order records, events from connected shops and platforms, website visitor data collected by the SDK, and personal data contained in briefs, uploads and generated content.
  • End Users: the Customer's customers, subscribers, leads, website visitors, app users and, for gaming operators, players.
  • Sub-processor: a third party engaged by the Provider to process Customer Personal Data.
  • Personal Data Breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.
  • Instructions: the Agreement, this DPA, the Customer's configuration of the Services (audiences, journeys, approval rules, consent settings, connections), and the Customer's further written instructions.

Controller, processor, personal data, processing, data subject and supervisory authority have the meanings in the GDPR.

3. Details of the processing

The subject matter, duration, nature and purpose of the processing, the categories of data subjects and of personal data, and the retention are set out in Annex I. The Provider processes Customer Personal Data for the sole purpose of providing the Services as configured by the Customer.

4. Our obligations as processor

The Provider shall:

  1. process Customer Personal Data only on the Customer's Instructions, unless required to do otherwise by law, in which case it informs the Customer of that requirement before processing unless the law prohibits it;
  2. inform the Customer without delay if, in its opinion, an Instruction infringes Data Protection Laws – without an obligation to review the Customer's lawful basis;
  3. ensure that every person authorised to process Customer Personal Data is bound by confidentiality and trained in data protection;
  4. implement and maintain the technical and organisational measures in Annex II, and not reduce their overall level of protection during the term;
  5. not use Customer Personal Data, or content generated from it, to train, fine-tune or improve AI models, its own or any third party's, and engage model providers only under terms that exclude such use – unless the Customer has agreed to a training arrangement expressly and in writing;
  6. not sell Customer Personal Data, combine it with data of other customers for the Provider's own purposes, or use it for advertising;
  7. engage Sub-processors only as Section 6 provides;
  8. assist the Customer as Sections 8 and 9 provide;
  9. delete or return Customer Personal Data as Section 11 provides;
  10. make available the information necessary to demonstrate compliance with Article 28 GDPR and allow audits as Section 10 provides.

5. Your obligations as controller

The Customer is responsible for, and warrants:

  1. establishing a lawful basis for every purpose for which it uses the Services on Customer Personal Data, and documenting it;
  2. giving End Users the information Articles 12–14 GDPR require – its own privacy notice – including the use of the Provider as processor, the SDK, behavioural analytics, profiling for personalisation, and direct marketing;
  3. obtaining and recording any consent the law requires: for non-essential cookies and the SDK on its websites, for marketing by e-mail, SMS, push or messaging channels, and for any profiling-based personalisation where explicit consent is required. The Provider makes the SDK's consent mode and the consent ledger available; the Customer decides whether and how to use them, and must not activate non-essential tracking before consent where consent is required;
  4. the accuracy and lawfulness of the data it imports or connects, and for not making special categories of personal data available without the Provider's prior written agreement;
  5. configuring the Services – audiences, approval rules, human review, suppression and self-exclusion lists, frequency caps, retention – in line with the laws and sector rules that apply to it;
  6. carrying out any data protection impact assessment or prior consultation its processing requires (Section 8.3), and the decisions its outcome calls for;
  7. responding to data subjects and supervisory authorities as controller, with the Provider's assistance.

6. Sub-processors

6.1 The Customer gives a general authorisation for the Provider to engage the Sub-processors listed in Annex III (also published at theaicmo.com/privacy, Section 7.1).

6.2 The Provider gives the Customer at least 30 days' notice before adding or replacing a Sub-processor that will process Customer Personal Data, by e-mail to the account owner and by updating the published register, stating the name, location, purpose and categories of processing.

6.3 The Customer may object within that period on reasonable, documented data-protection grounds. The parties will discuss the objection in good faith; if the Provider cannot offer a reasonable alternative within 30 days, the Customer may terminate the affected Services, or the Agreement if the affected Services are essential to it, without penalty and with a pro-rata refund of prepaid fees for the remaining term.

6.4 The Provider imposes on each Sub-processor, by written contract, data-protection obligations equivalent to those in this DPA, and remains fully liable to the Customer for the Sub-processor's performance.

7. International transfers

The Provider is established in Gibraltar; the application database runs in the EU. Where Customer Personal Data is transferred to a Sub-processor in a country without an adequacy decision, the transfer is made under the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914, with the UK International Data Transfer Addendum where UK GDPR applies) or under the EU–US Data Privacy Framework where the Sub-processor is certified, together with the measures in Annex II. Where the Customer transfers Customer Personal Data to the Provider from the EEA or the UK, the parties incorporate the Standard Contractual Clauses (Module Two: controller to processor) by reference, with the Customer as data exporter, the Provider as data importer, the optional docking clause, the option 2 general authorisation of Sub-processors with the notice period in Section 6.2, Gibraltar law and courts for clause 17 and 18 unless the Customer's establishment requires an EU Member State, and Annexes I–III of this DPA as the Clauses' annexes. Copies of the executed mechanisms are available on request.

8. Assistance: data subject requests, impact assessments

8.1 Requests from End Users

If an End User addresses a request to the Provider concerning Customer Personal Data, the Provider forwards it to the Customer within three business days, does not respond to the End User on the substance unless the Customer instructs it or the law requires it, and provides the technical assistance the Customer needs to answer within the legal time limit: exports of a person's data, deletion, restriction, correction, an explanation of any segmentation or scoring applied to the person, and enforcement of an objection to direct marketing through the suppression lists.

8.2 Articles 32–36

The Provider assists the Customer in meeting its obligations on security, breach notification, data protection impact assessments and prior consultation, taking into account the nature of the processing and the information available to the Provider.

8.3 Data protection impact assessments

Where the Customer's intended use – systematic monitoring of behaviour, profiling, personalisation for a vulnerable or regulated audience, or large-scale combination of data sets – calls for a data protection impact assessment, the Provider supplies, on request and before go-live, a description of the processing operations, data flows, model providers, retention and security measures sufficient for the assessment, and reasonable cooperation with any consultation of a supervisory authority.

9. Personal data breaches

9.1 The Provider notifies the Customer of a Personal Data Breach without undue delay and no later than 48 hours after confirming it, by e-mail to the account owner and the security contact named in the Order Form.

9.2 The notification describes, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a point of contact; information not yet available is provided as it becomes available. The Provider cooperates with the Customer and takes reasonable steps to contain and remedy the breach.

9.3 Notification is not an admission of fault or liability. The Customer is responsible for any notification to supervisory authorities and data subjects; the Provider does not notify them on the Customer's behalf unless instructed or required by law.

10. Audits and evidence

10.1 The Provider makes available, on request and under confidentiality, its current SOC 2 Type II report (or, until the first report is issued, the auditor's letter of engagement and the policies in force), its Trust Center, penetration test summaries, and answers to reasonable security questionnaires. This evidence satisfies the audit right in the ordinary course.

10.2 Where that evidence is insufficient to demonstrate compliance with this DPA, or after a Personal Data Breach, the Customer or an independent auditor bound by confidentiality may audit the Provider's relevant systems and records once in any 12-month period, on at least 30 days' written notice, during business hours, with a scope agreed in advance and without unreasonable disruption. The Customer bears the audit's costs unless it reveals a material breach of this DPA. Findings are confidential.

11. Return and deletion

11.1 On termination or expiry of the Agreement, the Customer may export Customer Personal Data through the Services for 30 days. On the Customer's written request during that period the Provider returns the data in a machine-readable format.

11.2 After that period – or earlier on the Customer's instruction – the Provider deletes Customer Personal Data from production systems within 30 days, including copies at Sub-processors and data derived from it (segments, scores, generated content), and from backups within 90 days as they expire. The Provider confirms deletion in writing on request.

11.3 The Provider may retain Customer Personal Data only to the extent and for as long as the law requires, and only for that purpose; suppression records are kept so that opted-out persons stay excluded.

12. Regulated sectors and high-risk processing

Where the Customer operates in a regulated sector – gaming and betting, financial services, health, or another sector with its own marketing or data rules – or where its use of the Services involves systematic monitoring of behaviour or profiling of End Users, the following apply in addition:

  1. Lawful basis and consent. The Customer determines and documents the lawful basis for personalisation and profiling of End Users, including explicit consent where Article 22 GDPR or sector rules require it, and configures the Services so that personalisation is applied only to End Users for whom that basis exists.
  2. Human oversight. The Customer configures approval rules so that no automated action reaches End Users without review by an accountable person where the law, a regulator or the Customer's own policies require it. The Provider's approval and review controls are described in the documentation.
  3. Exclusions. Self-exclusion, cooling-off, unsubscribe and other suppression lists supplied by the Customer are honoured on every send path of the Services; the Customer keeps them current.
  4. Model, region and retention. The Customer may fix in the Order Form the model provider, the model, the processing region and zero-retention routing for its account (Annex IV), and the region of its analytics warehouse and behavioural analytics.
  5. Pseudonymous identifiers. Visitor and device identifiers produced by the SDK, and identifiers linked to End User accounts, are personal data; the Provider processes them only on Instructions and does not use them to link End Users across customers.
  6. Impact assessment before go-live. The parties cooperate under Section 8.3 before the Customer puts profiling-based personalisation of End Users into production.
  7. No special-category inference. The Services are not instructed to infer special categories of personal data, including health or financial vulnerability, and the Customer must not instruct them to.

13. Liability, term, precedence, governing law

13.1 Each party's liability under this DPA is subject to the limitations and exclusions in the Agreement, except that nothing limits liability that cannot be limited under Data Protection Laws.

13.2 This DPA applies for as long as the Provider processes Customer Personal Data, and survives termination of the Agreement until deletion under Section 11 is complete.

13.3 In a conflict, this DPA prevails over the Agreement for the processing of Customer Personal Data; the Standard Contractual Clauses, where they apply, prevail over this DPA.

13.4 This DPA is governed by the laws of Gibraltar and subject to the exclusive jurisdiction of the courts of Gibraltar, consistent with the Terms of Service, save where Data Protection Laws or the Standard Contractual Clauses require otherwise for a data subject or supervisory authority.

13.5 The Provider may update this DPA to reflect changes in law or the Services; changes that reduce the Customer's protections take effect only with 30 days' notice, and each version is dated and archived.

Annex I – Description of the processing

  • Subject matter: the provision of The AI CMO – AI-assisted marketing content, customer data management, segmentation and scoring, journeys and sends across e-mail, SMS, push and messaging channels, website analytics and personalisation through the SDK, and reporting – to the Customer.
  • Duration: the term of the Agreement plus the return and deletion period in Section 11.
  • Nature and purpose: collection, storage, organisation, analysis, segmentation, scoring, personalisation, transmission (sends), generation of content, and deletion, for the Customer's marketing and customer communication.
  • Categories of data subjects: the Customer's customers, subscribers, leads, website and app visitors, and, for gaming operators, players; the Customer's staff insofar as they appear in the data.
  • Categories of personal data: identifiers (name, e-mail address, phone number, customer identifiers, pseudonymous visitor and device identifiers); contact and profile attributes supplied by the Customer; transactional data (orders, amounts, products, dates); behavioural and engagement data (page views, events, opens, clicks, replies); consent, preference and suppression records; content of communications sent to or received from End Users.
  • Special categories: none, unless expressly agreed in writing in the Order Form.
  • Frequency: continuous, for the duration.
  • Retention: as configured by the Customer within the Services and as set out in Section 11; warehouse event data is purged automatically once a subscription has lapsed for 30 days.
  • Sub-processors: Annex III.
  • Order Form fields (enterprise): named security contact; processing region; model provider, model and retention option; warehouse region; sector-specific requirements; special categories, if any.

Annex II – Technical and organisational measures

  • Encryption: TLS 1.2+ for all data in transit, including service-to-service traffic; AES-256 at rest for databases, the analytics warehouse, object storage and backups; keys managed by the hosting providers' managed key services, with access logged.
  • Tenant isolation: row-level security policies on every customer-data table, enforced by the database; the analytics warehouse provisioned per customer; connection tokens held in a separate, encrypted token store.
  • Identity and access: role-based access within the Customer's organisation (owner, admin, member, confined data seats); least-privilege access for the Provider's staff, protected by multi-factor authentication, granted on need, reviewed quarterly and logged; production access limited to named engineers.
  • Secure development: version-controlled code with review; dependency and vulnerability scanning; environment separation; penetration testing for major releases and at least annually; remediation on a severity-based timeline.
  • Logging and monitoring: application, access and security logs retained up to 90 days; alerting on errors, availability and anomalous access.
  • Backups and continuity: encrypted backups, stored in the EU where the primary data is in the EU; restore tests; a maintained business continuity and disaster recovery plan.
  • Incident response: a documented process with roles, severity levels, containment, customer notification under Section 9 and post-incident review.
  • Vendor management: Sub-processors assessed before engagement and annually; critical vendors must hold SOC 2 Type II or equivalent assurance.
  • People: confidentiality undertakings; security and privacy training on joining and annually; offboarding with access revocation.
  • Data handling: data classification; retention schedules applied to production and backups; deletion and return under Section 11; consent ledger and suppression enforcement built into every send path.
  • Assurance: a SOC 2 Type II examination in progress under a continuous compliance programme, with evidence published to the Trust Center.

Annex III – Sub-processors

Sub-processorPurposeLocation
SupabaseDatabase, authentication, file storage – contacts, consent and suppression records, journeys, generated contentEU (Stockholm)
ClickHouse CloudAnalytics warehouse for event data, provisioned per CustomerEU or United States, per Order Form
PostHogBehavioural analytics for the Customer's websites (SDK)EU or United States, per site
ResendE-mail delivery: recipient address and message content of e-mails sent on the Customer's behalfUnited States

Not Sub-processors of Customer Personal Data

Railway, Vercel, CloudflareInfrastructure the application runs on; data passes through encrypted, none is held at rest, no standing access.
OpenRouter, Anthropic, OpenAI, Google, ReplicateAI model providers receive generation requests – briefs, brand profile, campaign data, drafts – never contact records, event logs or identifiers (Privacy Policy §5). OpenRouter is configured to exclude providers that retain or train on inputs.
Stripe, Nango, PipedreamProcess the Customer's own account, billing and connection data as our providers – not Customer Personal Data.
Platforms the Customer connects (Google, Meta, LinkedIn, X, YouTube, Shopify, Mailchimp, WordPress and others)Act under the Customer's own authorisation and terms; the Customer's processors or independent controllers, not ours.
SMS, WhatsApp, push or e-mail providers the Customer configures with its own credentialsThe Customer's processors; the platform hands them the message and recipient under the Customer's account.

The full register, arranged by what each provider touches and with certifications, is at theaicmo.com/privacy (Section 7.1) and theaicmo.com/security.

Annex IV – Enterprise options

Selectable in the Order Form or by the Customer's written instruction, at no change to this DPA:

  • Processing region: EU-only processing for the database, the analytics warehouse and behavioural analytics.
  • Model pinning: a named model provider and model for the account; zero-retention routing at the provider; exclusion of specific providers.
  • Human oversight: mandatory approval by named roles for sends, campaign changes and personalisation; audit log export.
  • Sector controls: self-exclusion list synchronisation, cooling-off enforcement, frequency caps, and content review rules for regulated advertising.
  • Assurance: annual SOC 2 Type II report delivery, penetration test summaries, and a named security contact on each side.
  • Deletion: written certificate of deletion at termination.

To execute this DPA with an Order Form

Write to privacy@theaicmo.com. Data Protection Officer: dpo@theaicmo.com.