On this page
01 Our commitment
We are committed to handling personal data lawfully, fairly and transparently, and to the GDPR principles of purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality. Two commitments are worth stating plainly here, because they shape the product: we do not train foundation models on customer data, and customers own their data and the Contextual Memory their Digital Employees learn.
↑ Back to top02 The two roles: controller and processor
We act in two distinct roles, and which one applies depends on the data:
Controller and processor
For the data we handle in running our own business, such as account, billing and website data, we are the controller, and our Privacy Policy explains how we process it. For the data contained in the content your Digital Employees process on your behalf, you are the controller and we are the processor, and our Data Processing Agreement governs that processing under Article 28 of the GDPR.
03 Your data protection rights
The GDPR gives individuals rights over their personal data, including the rights of access, rectification, erasure, restriction of processing, data portability, and objection. How to exercise these, and the details of how we handle personal data we control, are set out in our Privacy Policy. Where we process personal data on a customer's behalf, we assist that customer in responding to requests from individuals, as described in our Data Processing Agreement.
↑ Back to top04 International data transfers
We process personal data within the European Economic Area wherever we can. Where a transfer outside the EEA is necessary, we put an appropriate safeguard in place under Chapter V of the GDPR, such as an adequacy decision or the European Commission's Standard Contractual Clauses. The specifics are set out in our Data Processing Agreement.
↑ Back to top05 Sub-processors
We engage carefully selected sub-processors to help provide the service, and we bind them by contract to data-protection obligations consistent with our own. The current list, with each sub-processor's location and transfer mechanism, is maintained in Annex 3 of our Data Processing Agreement.
↑ Back to top06 Security
Protecting personal data depends on strong security. Our Security overview describes the technical and organisational measures we have in place, and the security measures specific to our role as a processor are set out in Annex 2 of our Data Processing Agreement.
↑ Back to top07 Our Data Processing Agreement
We offer a GDPR-compliant Data Processing Agreement to our customers. It forms part of our Terms of Service for the data we process on your behalf, and it is available for signature on request for customers who need a separately executed copy. You can review it here: Data Processing Agreement.
↑ Back to top08 Our documents
The documents that set out how we handle data and protect it:
- Privacy PolicyHow we process personal data we control, and how to exercise your rights.
- Data Processing AgreementHow we process personal data on your behalf, under GDPR Article 28, with annexes on processing details, security measures and sub-processors.
- Cookie PolicyHow we use cookies and similar technologies on our website.
- Security overviewThe technical and organisational measures we use to protect data.
- Sub-processor listThe third parties that process data on our behalf, and where.
09 Contact
For any data protection question, or to exercise your rights, contact us:
Outcome1 SRL · Data protection
Email: privacy@outcome1.ai · full company details in our Privacy Policy
You also have the right to lodge a complaint with the Romanian supervisory authority, the National Supervisory Authority for Personal Data Processing (ANSPDCP).
