Skip to main content

    Data Processing Agreement

    How we process personal data on your behalf when you use our Digital Employees, in compliance with the GDPR and Romanian law.

    Last updated01 July 2026
    Effective from01 July 2026
    Version1.0
    Forms part ofthe Terms of Service

    This Data Processing Agreement ("DPA") is entered into between you, our customer (the "Customer"), and Outcome1 SRL ("Outcome1.AI", "we", "us" or "our"), a company incorporated under Romanian law. Our full company details are in our Privacy Policy.

    It governs our processing of personal data on the Customer's behalf in the course of providing the Outcome1.AI service (the "Service"), and it forms part of the Terms of Service or other agreement between us (the "Agreement"). It is designed to meet the requirements of Article 28 of Regulation (EU) 2016/679 (the "GDPR") and applicable Romanian data protection law, including Law no. 190/2018.

    Who is who

    For the personal data contained in Customer Data that a Digital Employee processes, the Customer is the controller and Outcome1.AI is the processor. Where Outcome1.AI engages another organisation that processes that data, that organisation is a sub-processor. This DPA does not apply to the data that Outcome1.AI processes as a controller in its own right, such as account and billing data, which is covered by our Privacy Policy.

    On this page
    1. Roles, scope and how this DPA applies
    2. Definitions
    3. Processing of personal data
    4. Confidentiality
    5. Security of processing
    6. Sub-processors
    7. International data transfers
    8. Assisting you with your obligations
    9. Personal data breaches
    10. Return and deletion of data
    11. Audits and demonstrating compliance
    12. Liability, term and general terms
    13. Annex 1 · Details of the processing
    14. Annex 2 · Security measures
    15. Annex 3 · Sub-processors

    01 Roles, scope and how this DPA applies

    This DPA applies whenever Outcome1.AI processes Customer Personal Data on the Customer's behalf in providing the Service. As between the parties, the Customer acts as the controller and Outcome1.AI acts as the processor, within the meaning of the GDPR. Where the Customer is itself a processor acting for a third-party controller, the Customer warrants that it has the authority to instruct Outcome1.AI on that controller's behalf.

    This DPA forms part of the Agreement. If there is any conflict on the subject of the processing of personal data, this DPA prevails over the rest of the Agreement, and the Standard Contractual Clauses (where they apply) prevail over this DPA on matters of international transfer.

    ↑ Back to top

    02 Definitions

    Terms such as controller, processor, data subject, personal data, processing, special categories of personal data and personal data breach have the meanings given to them in the GDPR. In addition:

    • "Customer Personal Data" means the personal data contained in Customer Data that Outcome1.AI processes on the Customer's behalf under the Agreement, as described in Annex 1.
    • "Data Protection Law" means the GDPR and all applicable data protection law, including Romanian Law no. 190/2018 and Law no. 506/2004.
    • "Sub-processor" means any third party engaged by Outcome1.AI to process Customer Personal Data.
    • "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses in Commission Implementing Decision (EU) 2021/914.
    • "Supervisory Authority" means the competent authority, which for Outcome1.AI is the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP).
    ↑ Back to top

    03 Processing of personal data

    Processing only on your instructions

    Outcome1.AI will process Customer Personal Data only on the Customer's documented instructions, including with regard to international transfers, unless required to do otherwise by EU or Member State law (in which case we will inform the Customer of that requirement before processing, unless the law prohibits this). The Agreement, this DPA, Annex 1, and the configuration and instructions the Customer gives through the Service constitute the Customer's documented instructions. If we consider that an instruction infringes Data Protection Law, we will inform the Customer.

    Your responsibilities

    The Customer is responsible for the lawfulness of the Customer Personal Data and of the instructions it gives, including having a valid legal basis, providing any required notices to data subjects, and obtaining any necessary consents.

    Use limitation

    We will not use Customer Personal Data for our own purposes. In particular, we do not use Customer Personal Data to train foundation models, and we do not pool or share it across customers. Where the Customer enables features that use third-party foundation-model providers, those providers process Customer Personal Data only through their APIs, under terms that prohibit them from training their models on that data and that do not retain it beyond returning the output. As between the parties, Customer Data and the Contextual Memory learned within the Customer's instance belong to the Customer.

    Special categories of personal data

    The Service is not designed specifically to process special categories of personal data. Where the Customer's use of the Service involves such data (for example, health data), the Customer is responsible for ensuring a valid condition for processing under Article 9 of the GDPR, and we will apply the security measures in Annex 2 to that data.

    ↑ Back to top

    04 Confidentiality

    We will ensure that the persons we authorise to process Customer Personal Data are bound by an appropriate duty of confidentiality, whether a contractual or statutory one, and that access is limited to those who need it to provide the Service.

    ↑ Back to top

    05 Security of processing

    Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing, as well as the risks to data subjects, we implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by Article 32 of the GDPR. Those measures are described in Annex 2. We may update them over time, provided the level of protection is not reduced.

    ↑ Back to top

    06 Sub-processors

    The Customer gives Outcome1.AI general authorisation to engage Sub-processors to help provide the Service. The Sub-processors currently engaged are listed in Annex 3.

    We will impose on each Sub-processor, by written contract, data protection obligations that are no less protective than those in this DPA, in particular regarding security. We remain responsible to the Customer for the performance of each Sub-processor's obligations.

    We will inform the Customer of any intended addition or replacement of a Sub-processor at least 30 days in advance, giving the Customer the opportunity to object on reasonable data-protection grounds. If the Customer objects and we cannot offer a reasonable alternative, the Customer may terminate the affected part of the Service.

    ↑ Back to top

    07 International data transfers

    We process Customer Personal Data within the European Economic Area (EEA). Where providing the Service requires a transfer of Customer Personal Data to a country outside the EEA, we will ensure that an appropriate safeguard under Chapter V of the GDPR is in place before the transfer. In practice this means one of the following:

    • the destination is covered by a European Commission adequacy decision, or the recipient is certified under a recognised framework such as the EU-US Data Privacy Framework; or
    • the transfer is governed by the Standard Contractual Clauses, with the relevant module, together with any additional measures needed to ensure an essentially equivalent level of protection.

    Where the SCCs apply, they are incorporated into this DPA by reference and, by entering into the Agreement, the parties are deemed to have signed them. The location of each Sub-processor and the transfer mechanism that applies to it are set out in Annex 3.

    ↑ Back to top

    08 Assisting you with your obligations

    Data subject requests

    Taking into account the nature of the processing, we will assist the Customer by appropriate technical and organisational measures, insofar as this is possible, to respond to requests from data subjects exercising their rights under Chapter III of the GDPR. If we receive such a request directly, we will not respond to it ourselves (except to confirm that the request should be directed to the Customer) and will forward it to the Customer without undue delay.

    Other compliance obligations

    Taking into account the nature of the processing and the information available to us, we will assist the Customer in ensuring compliance with its obligations under Articles 32 to 36 of the GDPR, namely the security of processing, notification of personal data breaches, communication of breaches to data subjects, data protection impact assessments, and prior consultation with the Supervisory Authority.

    ↑ Back to top

    09 Personal data breaches

    We will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. The notification will describe, to the extent known and as it becomes available, the nature of the breach, the likely consequences, and the measures taken or proposed to address it, so that the Customer can meet its own notification obligations. We will cooperate with the Customer and take reasonable steps to mitigate and remediate the breach.

    ↑ Back to top

    10 Return and deletion of data

    On termination or expiry of the Agreement, and at the Customer's choice, we will delete or return all Customer Personal Data, and delete existing copies, unless EU or Member State law requires us to retain it. Reflecting how the Service is built:

    • we operate on the basis of no retention of Customer Data after the contract ends;
    • we make the Customer's data available for export through a time-limited download link, available for 30 days, consistent with the Customer's right to data portability and Article 17 of the GDPR; and
    • the Customer may request complete deletion at its discretion.

    On request, we will confirm in writing that deletion has taken place. The Contextual Memory learned within the Customer's instance is treated as Customer Data for the purposes of this Section.

    ↑ Back to top

    11 Audits and demonstrating compliance

    We will make available to the Customer the information necessary to demonstrate compliance with the obligations in Article 28 of the GDPR, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates.

    To keep audits proportionate, the Customer will give reasonable prior notice, audits will take place during business hours and no more than once a year (unless required by the Supervisory Authority or following a breach), the parties will agree the scope in advance, any auditor will be bound by confidentiality, and the Customer will bear its own costs. We may satisfy an audit request in whole or in part by providing relevant certifications, audit reports or a completed security questionnaire, where these reasonably address the Customer's request.

    ↑ Back to top

    12 Liability, term and general terms

    Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement. Liability between controller and processor for damage caused by processing is allocated in accordance with Article 82 of the GDPR.

    This DPA takes effect when the Agreement does and continues for as long as we process Customer Personal Data on the Customer's behalf. The obligations relating to return, deletion and confidentiality survive termination. This DPA is governed by Romanian law, and disputes are subject to the jurisdiction or dispute-resolution mechanism set out in the Agreement. The Supervisory Authority competent for Outcome1.AI is the ANSPDCP.

    ↑ Back to top

    Annex 1

    13 Details of the processing

    This Annex sets out the details of the processing as required by Article 28(3) of the GDPR.

    Subject matterThe provision of the Outcome1.AI Service, namely Digital Employees that perform a configured role for the Customer.
    DurationFor the term of the Agreement and until the return or deletion of Customer Personal Data in accordance with Section 10.
    Nature & purposeProcessing Customer Data so that a Digital Employee can carry out the role and tasks the Customer configures, on the Customer's instructions and under its oversight.
    Types of dataDetermined by the Customer's configuration and the data it provides. Typically: identification and contact details, professional and employment information, communications content, and transactional or financial data. May include special categories (for example health data) only where the Customer's use involves them.
    Data subjectsDetermined by the Customer. Typically: the Customer's employees and personnel, its customers and prospects, its suppliers and partners, and other individuals whose data the Customer includes in Customer Data.
    FrequencyContinuous, for the duration of the Agreement.
    ↑ Back to top

    Annex 2

    14 Security measures

    This Annex describes the technical and organisational measures we implement under Article 32 of the GDPR. We keep these under review and may update them, provided the overall level of protection is not reduced.

    Encryption

    • all external traffic is served over HTTPS, with TLS (version 1.2 or higher) terminated at the edge gateway, automated certificate management, and forced redirection from HTTP to HTTPS so no data is served in plaintext;
    • Customer Personal Data is encrypted at rest with AES-256 at the infrastructure layer; the Contextual Memory store additionally has AES-256-GCM application-level envelope encryption with per-tenant keys;
    • encryption keys are managed in a self-hosted key-management system (HashiCorp Vault Transit engine), with per-tenant data-encryption keys wrapped by tenant-scoped key-encryption keys held by Outcome1.AI.

    Confidentiality and access control

    • access to Customer Personal Data on a need-to-know, least-privilege basis, with individual accounts and multi-factor authentication for administrative access;
    • role-based access controls and prompt removal of access when no longer needed;
    • administrative and security-relevant actions are written to an append-only, integrity-chained audit log, with the audit event stream retained for 90 days.

    Tenant isolation

    • each Customer's data is logically isolated at the database layer using PostgreSQL row-level security, enforced on every tenant-scoped table so that it cannot be bypassed, with every service connecting under a non-owner role; cross-tenant access is structurally prevented.

    Application and infrastructure security

    • changes reach production only after automated build, test, container and lint checks on a protected main branch; container images are cryptographically signed with software bill-of-materials (SBOM) attestation and verified at deploy time;
    • automated dependency updates and nightly container-image vulnerability scanning for high and critical issues;
    • services are instrumented with OpenTelemetry and emit structured logs;
    • secure software development practices and review of changes.

    Availability and resilience

    • use of reputable cloud infrastructure with its own security and resilience measures;
    • daily automated database backups, with the ability to restore from them, and protection against malicious code.

    Governance

    • due diligence on Sub-processors before engagement;
    • confidentiality obligations and security awareness for personnel;
    • an incident response process covering detection, escalation and notification.
    ↑ Back to top

    Annex 3

    15 Sub-processors

    The following third parties process Customer Personal Data to help us provide the Service. Components that we host within our own infrastructure, such as our orchestration and integration layers, the database (self-hosted PostgreSQL) and object storage, are part of our processing environment and are not third-party sub-processors; only third parties that process Customer Personal Data are listed here. Our foundation-model providers are engaged through their APIs, are used to process Customer Personal Data only for features the Customer enables, and operate under terms that prohibit training on Customer Personal Data and do not retain it beyond returning the output. The telephony and voice providers below apply only where the Customer uses the voice feature.

    Sub-processorPurposeLocationTransfer mechanism
    AI model providers (engaged via API; used on Customer Personal Data only for features the Customer enables; no-training and zero-retention terms)
    Anthropic Foundation-model processing that powers the reasoning and outputs of Digital Employees, accessed via AWS Bedrock. European Union (AWS Bedrock, Stockholm) No transfer (EEA)
    OpenAI (via Azure OpenAI) Additional foundation-model processing, depending on the task. European Union (Azure OpenAI, Frankfurt) No transfer (EEA)
    Infrastructure and hosting
    Microsoft Azure Cloud infrastructure and compute for the Service, including the hosting of the database and object storage. European Union (Germany West Central, Frankfurt) No transfer (EEA)
    Amazon Web Services Model gateway (AWS Bedrock) through which Anthropic models are accessed. European Union (Stockholm) No transfer (EEA)
    Voice feature (only where the Customer uses voice)
    Twilio Telephony for the voice feature: connects calls and carries caller and callee phone numbers and live call audio. United States Standard Contractual Clauses
    ElevenLabs Voice processing for the voice feature: speech-to-text of inbound audio and text-to-speech of agent output. United States Standard Contractual Clauses