Legal
Version 1.0 · Effective Date: August 26, 2026
Version 1.0 · Effective Date: August 26, 2026
Contents
This Data Processing Agreement ("DPA") forms part of the agreement between ROGA AI LIMITED, registered in Gibraltar under Company No. 125994, Unit G02, Eurocity, Europort Avenue, Gibraltar GX11 1AA ("Provider", "we") and the customer identified in the applicable Order Form or account ("Customer", "you") for the use of The AI CMO (the "Services") under the Terms of Service or a signed agreement (together, the "Agreement"). It applies whenever the Services process Personal Data on the Customer's behalf.
1.1 For Customer Personal Data (defined below) the Customer is the controller – or, where the Customer itself acts for another controller, a processor whose instructions bind the Provider – and the Provider is the processor. The Provider processes Customer Personal Data only on the Customer's documented instructions and never for its own purposes.
1.2 This DPA does not apply to the personal data of the Customer's own users of the Services (account holders and team members), for which the Provider is the controller under the Privacy Policy.
1.3 This DPA applies as published and is incorporated into the Agreement through the Privacy Policy; it is accepted by using the Services to process Customer Personal Data, and no separate signature is needed. An Order Form may complete Annex I for the Customer and select the options in Annex IV. Where the law applicable to the Customer requires processor terms this DPA does not contain, the parties execute a supplemental DPA before the relevant production processing begins; the supplemental DPA prevails to the extent of the additional terms.
Controller, processor, personal data, processing, data subject and supervisory authority have the meanings in the GDPR.
The subject matter, duration, nature and purpose of the processing, the categories of data subjects and of personal data, and the retention are set out in Annex I. The Provider processes Customer Personal Data for the sole purpose of providing the Services as configured by the Customer.
The Provider shall:
The Customer is responsible for, and warrants:
6.1 The Customer gives a general authorisation for the Provider to engage the Sub-processors listed in Annex III (also published at theaicmo.com/privacy, Section 7.1).
6.2 The Provider gives the Customer at least 30 days' notice before adding or replacing a Sub-processor that will process Customer Personal Data, by e-mail to the account owner and by updating the published register, stating the name, location, purpose and categories of processing.
6.3 The Customer may object within that period on reasonable, documented data-protection grounds. The parties will discuss the objection in good faith; if the Provider cannot offer a reasonable alternative within 30 days, the Customer may terminate the affected Services, or the Agreement if the affected Services are essential to it, without penalty and with a pro-rata refund of prepaid fees for the remaining term.
6.4 The Provider imposes on each Sub-processor, by written contract, data-protection obligations equivalent to those in this DPA, and remains fully liable to the Customer for the Sub-processor's performance.
The Provider is established in Gibraltar; the application database runs in the EU. Where Customer Personal Data is transferred to a Sub-processor in a country without an adequacy decision, the transfer is made under the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914, with the UK International Data Transfer Addendum where UK GDPR applies) or under the EU–US Data Privacy Framework where the Sub-processor is certified, together with the measures in Annex II. Where the Customer transfers Customer Personal Data to the Provider from the EEA or the UK, the parties incorporate the Standard Contractual Clauses (Module Two: controller to processor) by reference, with the Customer as data exporter, the Provider as data importer, the optional docking clause, the option 2 general authorisation of Sub-processors with the notice period in Section 6.2, Gibraltar law and courts for clause 17 and 18 unless the Customer's establishment requires an EU Member State, and Annexes I–III of this DPA as the Clauses' annexes. Copies of the executed mechanisms are available on request.
If an End User addresses a request to the Provider concerning Customer Personal Data, the Provider forwards it to the Customer within three business days, does not respond to the End User on the substance unless the Customer instructs it or the law requires it, and provides the technical assistance the Customer needs to answer within the legal time limit: exports of a person's data, deletion, restriction, correction, an explanation of any segmentation or scoring applied to the person, and enforcement of an objection to direct marketing through the suppression lists.
The Provider assists the Customer in meeting its obligations on security, breach notification, data protection impact assessments and prior consultation, taking into account the nature of the processing and the information available to the Provider.
Where the Customer's intended use – systematic monitoring of behaviour, profiling, personalisation for a vulnerable or regulated audience, or large-scale combination of data sets – calls for a data protection impact assessment, the Provider supplies, on request and before go-live, a description of the processing operations, data flows, model providers, retention and security measures sufficient for the assessment, and reasonable cooperation with any consultation of a supervisory authority.
9.1 The Provider notifies the Customer of a Personal Data Breach without undue delay and no later than 48 hours after confirming it, by e-mail to the account owner and the security contact named in the Order Form.
9.2 The notification describes, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a point of contact; information not yet available is provided as it becomes available. The Provider cooperates with the Customer and takes reasonable steps to contain and remedy the breach.
9.3 Notification is not an admission of fault or liability. The Customer is responsible for any notification to supervisory authorities and data subjects; the Provider does not notify them on the Customer's behalf unless instructed or required by law.
10.1 The Provider makes available, on request and under confidentiality, its current SOC 2 Type II report (or, until the first report is issued, the auditor's letter of engagement and the policies in force), its Trust Center, penetration test summaries, and answers to reasonable security questionnaires. This evidence satisfies the audit right in the ordinary course.
10.2 Where that evidence is insufficient to demonstrate compliance with this DPA, or after a Personal Data Breach, the Customer or an independent auditor bound by confidentiality may audit the Provider's relevant systems and records once in any 12-month period, on at least 30 days' written notice, during business hours, with a scope agreed in advance and without unreasonable disruption. The Customer bears the audit's costs unless it reveals a material breach of this DPA. Findings are confidential.
11.1 On termination or expiry of the Agreement, the Customer may export Customer Personal Data through the Services for 30 days. On the Customer's written request during that period the Provider returns the data in a machine-readable format.
11.2 After that period – or earlier on the Customer's instruction – the Provider deletes Customer Personal Data from production systems within 30 days, including copies at Sub-processors and data derived from it (segments, scores, generated content), and from backups within 90 days as they expire. The Provider confirms deletion in writing on request.
11.3 The Provider may retain Customer Personal Data only to the extent and for as long as the law requires, and only for that purpose; suppression records are kept so that opted-out persons stay excluded.
Where the Customer operates in a regulated sector – gaming and betting, financial services, health, or another sector with its own marketing or data rules – or where its use of the Services involves systematic monitoring of behaviour or profiling of End Users, the following apply in addition:
13.1 Each party's liability under this DPA is subject to the limitations and exclusions in the Agreement, except that nothing limits liability that cannot be limited under Data Protection Laws.
13.2 This DPA applies for as long as the Provider processes Customer Personal Data, and survives termination of the Agreement until deletion under Section 11 is complete.
13.3 In a conflict, this DPA prevails over the Agreement for the processing of Customer Personal Data; the Standard Contractual Clauses, where they apply, prevail over this DPA.
13.4 This DPA is governed by the laws of Gibraltar and subject to the exclusive jurisdiction of the courts of Gibraltar, consistent with the Terms of Service, save where Data Protection Laws or the Standard Contractual Clauses require otherwise for a data subject or supervisory authority.
13.5 The Provider may update this DPA to reflect changes in law or the Services; changes that reduce the Customer's protections take effect only with 30 days' notice, and each version is dated and archived.
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage – contacts, consent and suppression records, journeys, generated content | EU (Stockholm) |
| ClickHouse Cloud | Analytics warehouse for event data, provisioned per Customer | EU or United States, per Order Form |
| PostHog | Behavioural analytics for the Customer's websites (SDK) | EU or United States, per site |
| Resend | E-mail delivery: recipient address and message content of e-mails sent on the Customer's behalf | United States |
| Railway, Vercel, Cloudflare | Infrastructure the application runs on; data passes through encrypted, none is held at rest, no standing access. |
| OpenRouter, Anthropic, OpenAI, Google, Replicate | AI model providers receive generation requests – briefs, brand profile, campaign data, drafts – never contact records, event logs or identifiers (Privacy Policy §5). OpenRouter is configured to exclude providers that retain or train on inputs. |
| Stripe, Nango, Pipedream | Process the Customer's own account, billing and connection data as our providers – not Customer Personal Data. |
| Platforms the Customer connects (Google, Meta, LinkedIn, X, YouTube, Shopify, Mailchimp, WordPress and others) | Act under the Customer's own authorisation and terms; the Customer's processors or independent controllers, not ours. |
| SMS, WhatsApp, push or e-mail providers the Customer configures with its own credentials | The Customer's processors; the platform hands them the message and recipient under the Customer's account. |
The full register, arranged by what each provider touches and with certifications, is at theaicmo.com/privacy (Section 7.1) and theaicmo.com/security.
Selectable in the Order Form or by the Customer's written instruction, at no change to this DPA:
To execute this DPA with an Order Form
Write to privacy@theaicmo.com. Data Protection Officer: dpo@theaicmo.com.