On this page
- Roles, scope and how this DPA applies
- Definitions
- Processing of personal data
- Confidentiality
- Security of processing
- Sub-processors
- International data transfers
- Assisting you with your obligations
- Personal data breaches
- Return and deletion of data
- Audits and demonstrating compliance
- Liability, term and general terms
- Annex 1 · Details of the processing
- Annex 2 · Security measures
- Annex 3 · Sub-processors
01 Roles, scope and how this DPA applies
This DPA applies whenever Outcome1.AI processes Customer Personal Data on the Customer's behalf in providing the Service. As between the parties, the Customer acts as the controller and Outcome1.AI acts as the processor, within the meaning of the GDPR. Where the Customer is itself a processor acting for a third-party controller, the Customer warrants that it has the authority to instruct Outcome1.AI on that controller's behalf.
This DPA forms part of the Agreement. If there is any conflict on the subject of the processing of personal data, this DPA prevails over the rest of the Agreement, and the Standard Contractual Clauses (where they apply) prevail over this DPA on matters of international transfer.
↑ Back to top02 Definitions
Terms such as controller, processor, data subject, personal data, processing, special categories of personal data and personal data breach have the meanings given to them in the GDPR. In addition:
- "Customer Personal Data" means the personal data contained in Customer Data that Outcome1.AI processes on the Customer's behalf under the Agreement, as described in Annex 1.
- "Data Protection Law" means the GDPR and all applicable data protection law, including Romanian Law no. 190/2018 and Law no. 506/2004.
- "Sub-processor" means any third party engaged by Outcome1.AI to process Customer Personal Data.
- "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses in Commission Implementing Decision (EU) 2021/914.
- "Supervisory Authority" means the competent authority, which for Outcome1.AI is the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP).
03 Processing of personal data
Processing only on your instructions
Outcome1.AI will process Customer Personal Data only on the Customer's documented instructions, including with regard to international transfers, unless required to do otherwise by EU or Member State law (in which case we will inform the Customer of that requirement before processing, unless the law prohibits this). The Agreement, this DPA, Annex 1, and the configuration and instructions the Customer gives through the Service constitute the Customer's documented instructions. If we consider that an instruction infringes Data Protection Law, we will inform the Customer.
Your responsibilities
The Customer is responsible for the lawfulness of the Customer Personal Data and of the instructions it gives, including having a valid legal basis, providing any required notices to data subjects, and obtaining any necessary consents.
Use limitation
We will not use Customer Personal Data for our own purposes. In particular, we do not use Customer Personal Data to train foundation models, and we do not pool or share it across customers. Where the Customer enables features that use third-party foundation-model providers, those providers process Customer Personal Data only through their APIs, under terms that prohibit them from training their models on that data and that do not retain it beyond returning the output. As between the parties, Customer Data and the Contextual Memory learned within the Customer's instance belong to the Customer.
Special categories of personal data
The Service is not designed specifically to process special categories of personal data. Where the Customer's use of the Service involves such data (for example, health data), the Customer is responsible for ensuring a valid condition for processing under Article 9 of the GDPR, and we will apply the security measures in Annex 2 to that data.
↑ Back to top04 Confidentiality
We will ensure that the persons we authorise to process Customer Personal Data are bound by an appropriate duty of confidentiality, whether a contractual or statutory one, and that access is limited to those who need it to provide the Service.
↑ Back to top05 Security of processing
Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing, as well as the risks to data subjects, we implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by Article 32 of the GDPR. Those measures are described in Annex 2. We may update them over time, provided the level of protection is not reduced.
↑ Back to top06 Sub-processors
The Customer gives Outcome1.AI general authorisation to engage Sub-processors to help provide the Service. The Sub-processors currently engaged are listed in Annex 3.
We will impose on each Sub-processor, by written contract, data protection obligations that are no less protective than those in this DPA, in particular regarding security. We remain responsible to the Customer for the performance of each Sub-processor's obligations.
We will inform the Customer of any intended addition or replacement of a Sub-processor at least 30 days in advance, giving the Customer the opportunity to object on reasonable data-protection grounds. If the Customer objects and we cannot offer a reasonable alternative, the Customer may terminate the affected part of the Service.
↑ Back to top07 International data transfers
We process Customer Personal Data within the European Economic Area (EEA). Where providing the Service requires a transfer of Customer Personal Data to a country outside the EEA, we will ensure that an appropriate safeguard under Chapter V of the GDPR is in place before the transfer. In practice this means one of the following:
- the destination is covered by a European Commission adequacy decision, or the recipient is certified under a recognised framework such as the EU-US Data Privacy Framework; or
- the transfer is governed by the Standard Contractual Clauses, with the relevant module, together with any additional measures needed to ensure an essentially equivalent level of protection.
Where the SCCs apply, they are incorporated into this DPA by reference and, by entering into the Agreement, the parties are deemed to have signed them. The location of each Sub-processor and the transfer mechanism that applies to it are set out in Annex 3.
↑ Back to top08 Assisting you with your obligations
Data subject requests
Taking into account the nature of the processing, we will assist the Customer by appropriate technical and organisational measures, insofar as this is possible, to respond to requests from data subjects exercising their rights under Chapter III of the GDPR. If we receive such a request directly, we will not respond to it ourselves (except to confirm that the request should be directed to the Customer) and will forward it to the Customer without undue delay.
Other compliance obligations
Taking into account the nature of the processing and the information available to us, we will assist the Customer in ensuring compliance with its obligations under Articles 32 to 36 of the GDPR, namely the security of processing, notification of personal data breaches, communication of breaches to data subjects, data protection impact assessments, and prior consultation with the Supervisory Authority.
↑ Back to top09 Personal data breaches
We will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. The notification will describe, to the extent known and as it becomes available, the nature of the breach, the likely consequences, and the measures taken or proposed to address it, so that the Customer can meet its own notification obligations. We will cooperate with the Customer and take reasonable steps to mitigate and remediate the breach.
↑ Back to top10 Return and deletion of data
On termination or expiry of the Agreement, and at the Customer's choice, we will delete or return all Customer Personal Data, and delete existing copies, unless EU or Member State law requires us to retain it. Reflecting how the Service is built:
- we operate on the basis of no retention of Customer Data after the contract ends;
- we make the Customer's data available for export through a time-limited download link, available for 30 days, consistent with the Customer's right to data portability and Article 17 of the GDPR; and
- the Customer may request complete deletion at its discretion.
On request, we will confirm in writing that deletion has taken place. The Contextual Memory learned within the Customer's instance is treated as Customer Data for the purposes of this Section.
↑ Back to top11 Audits and demonstrating compliance
We will make available to the Customer the information necessary to demonstrate compliance with the obligations in Article 28 of the GDPR, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates.
To keep audits proportionate, the Customer will give reasonable prior notice, audits will take place during business hours and no more than once a year (unless required by the Supervisory Authority or following a breach), the parties will agree the scope in advance, any auditor will be bound by confidentiality, and the Customer will bear its own costs. We may satisfy an audit request in whole or in part by providing relevant certifications, audit reports or a completed security questionnaire, where these reasonably address the Customer's request.
↑ Back to top12 Liability, term and general terms
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement. Liability between controller and processor for damage caused by processing is allocated in accordance with Article 82 of the GDPR.
This DPA takes effect when the Agreement does and continues for as long as we process Customer Personal Data on the Customer's behalf. The obligations relating to return, deletion and confidentiality survive termination. This DPA is governed by Romanian law, and disputes are subject to the jurisdiction or dispute-resolution mechanism set out in the Agreement. The Supervisory Authority competent for Outcome1.AI is the ANSPDCP.
↑ Back to topAnnex 1
13 Details of the processing
This Annex sets out the details of the processing as required by Article 28(3) of the GDPR.
Annex 2
14 Security measures
This Annex describes the technical and organisational measures we implement under Article 32 of the GDPR. We keep these under review and may update them, provided the overall level of protection is not reduced.
Encryption
- all external traffic is served over HTTPS, with TLS (version 1.2 or higher) terminated at the edge gateway, automated certificate management, and forced redirection from HTTP to HTTPS so no data is served in plaintext;
- Customer Personal Data is encrypted at rest with AES-256 at the infrastructure layer; the Contextual Memory store additionally has AES-256-GCM application-level envelope encryption with per-tenant keys;
- encryption keys are managed in a self-hosted key-management system (HashiCorp Vault Transit engine), with per-tenant data-encryption keys wrapped by tenant-scoped key-encryption keys held by Outcome1.AI.
Confidentiality and access control
- access to Customer Personal Data on a need-to-know, least-privilege basis, with individual accounts and multi-factor authentication for administrative access;
- role-based access controls and prompt removal of access when no longer needed;
- administrative and security-relevant actions are written to an append-only, integrity-chained audit log, with the audit event stream retained for 90 days.
Tenant isolation
- each Customer's data is logically isolated at the database layer using PostgreSQL row-level security, enforced on every tenant-scoped table so that it cannot be bypassed, with every service connecting under a non-owner role; cross-tenant access is structurally prevented.
Application and infrastructure security
- changes reach production only after automated build, test, container and lint checks on a protected main branch; container images are cryptographically signed with software bill-of-materials (SBOM) attestation and verified at deploy time;
- automated dependency updates and nightly container-image vulnerability scanning for high and critical issues;
- services are instrumented with OpenTelemetry and emit structured logs;
- secure software development practices and review of changes.
Availability and resilience
- use of reputable cloud infrastructure with its own security and resilience measures;
- daily automated database backups, with the ability to restore from them, and protection against malicious code.
Governance
- due diligence on Sub-processors before engagement;
- confidentiality obligations and security awareness for personnel;
- an incident response process covering detection, escalation and notification.
Annex 3
15 Sub-processors
The following third parties process Customer Personal Data to help us provide the Service. Components that we host within our own infrastructure, such as our orchestration and integration layers, the database (self-hosted PostgreSQL) and object storage, are part of our processing environment and are not third-party sub-processors; only third parties that process Customer Personal Data are listed here. Our foundation-model providers are engaged through their APIs, are used to process Customer Personal Data only for features the Customer enables, and operate under terms that prohibit training on Customer Personal Data and do not retain it beyond returning the output. The telephony and voice providers below apply only where the Customer uses the voice feature.
| Sub-processor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| AI model providers (engaged via API; used on Customer Personal Data only for features the Customer enables; no-training and zero-retention terms) | |||
| Anthropic | Foundation-model processing that powers the reasoning and outputs of Digital Employees, accessed via AWS Bedrock. | European Union (AWS Bedrock, Stockholm) | No transfer (EEA) |
| OpenAI (via Azure OpenAI) | Additional foundation-model processing, depending on the task. | European Union (Azure OpenAI, Frankfurt) | No transfer (EEA) |
| Infrastructure and hosting | |||
| Microsoft Azure | Cloud infrastructure and compute for the Service, including the hosting of the database and object storage. | European Union (Germany West Central, Frankfurt) | No transfer (EEA) |
| Amazon Web Services | Model gateway (AWS Bedrock) through which Anthropic models are accessed. | European Union (Stockholm) | No transfer (EEA) |
| Voice feature (only where the Customer uses voice) | |||
| Twilio | Telephony for the voice feature: connects calls and carries caller and callee phone numbers and live call audio. | United States | Standard Contractual Clauses |
| ElevenLabs | Voice processing for the voice feature: speech-to-text of inbound audio and text-to-speech of agent output. | United States | Standard Contractual Clauses |
