Skip to main content

    GDPR at Outcome1.AI

    Our commitment to the GDPR, and where to find the documents behind it.

    Last updated01 July 2026
    Version1.0

    The General Data Protection Regulation (Regulation (EU) 2016/679, the "GDPR") sets the standard for how personal data is handled in Europe, and we build to it. This page is a short guide to how we approach the GDPR and a map to the documents that set out the detail. It does not replace those documents; where there is any difference, the Privacy Policy and the Data Processing Agreement govern.

    On this page
    1. Our commitment
    2. The two roles: controller and processor
    3. Your data protection rights
    4. International data transfers
    5. Sub-processors
    6. Security
    7. Our Data Processing Agreement
    8. Our documents
    9. Contact

    01 Our commitment

    We are committed to handling personal data lawfully, fairly and transparently, and to the GDPR principles of purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality. Two commitments are worth stating plainly here, because they shape the product: we do not train foundation models on customer data, and customers own their data and the Contextual Memory their Digital Employees learn.

    ↑ Back to top

    02 The two roles: controller and processor

    We act in two distinct roles, and which one applies depends on the data:

    Controller and processor

    For the data we handle in running our own business, such as account, billing and website data, we are the controller, and our Privacy Policy explains how we process it. For the data contained in the content your Digital Employees process on your behalf, you are the controller and we are the processor, and our Data Processing Agreement governs that processing under Article 28 of the GDPR.

    ↑ Back to top

    03 Your data protection rights

    The GDPR gives individuals rights over their personal data, including the rights of access, rectification, erasure, restriction of processing, data portability, and objection. How to exercise these, and the details of how we handle personal data we control, are set out in our Privacy Policy. Where we process personal data on a customer's behalf, we assist that customer in responding to requests from individuals, as described in our Data Processing Agreement.

    ↑ Back to top

    04 International data transfers

    We process personal data within the European Economic Area wherever we can. Where a transfer outside the EEA is necessary, we put an appropriate safeguard in place under Chapter V of the GDPR, such as an adequacy decision or the European Commission's Standard Contractual Clauses. The specifics are set out in our Data Processing Agreement.

    ↑ Back to top

    05 Sub-processors

    We engage carefully selected sub-processors to help provide the service, and we bind them by contract to data-protection obligations consistent with our own. The current list, with each sub-processor's location and transfer mechanism, is maintained in Annex 3 of our Data Processing Agreement.

    ↑ Back to top

    06 Security

    Protecting personal data depends on strong security. Our Security overview describes the technical and organisational measures we have in place, and the security measures specific to our role as a processor are set out in Annex 2 of our Data Processing Agreement.

    ↑ Back to top

    07 Our Data Processing Agreement

    We offer a GDPR-compliant Data Processing Agreement to our customers. It forms part of our Terms of Service for the data we process on your behalf, and it is available for signature on request for customers who need a separately executed copy. You can review it here: Data Processing Agreement.

    ↑ Back to top

    08 Our documents

    The documents that set out how we handle data and protect it:

    • Privacy PolicyHow we process personal data we control, and how to exercise your rights.
    • Data Processing AgreementHow we process personal data on your behalf, under GDPR Article 28, with annexes on processing details, security measures and sub-processors.
    • Cookie PolicyHow we use cookies and similar technologies on our website.
    • Security overviewThe technical and organisational measures we use to protect data.
    • Sub-processor listThe third parties that process data on our behalf, and where.
    ↑ Back to top

    09 Contact

    For any data protection question, or to exercise your rights, contact us:

    Outcome1 SRL · Data protection

    Email: privacy@outcome1.ai · full company details in our Privacy Policy

    You also have the right to lodge a complaint with the Romanian supervisory authority, the National Supervisory Authority for Personal Data Processing (ANSPDCP).