This Data Processing Agreement (“Agreement”) forms part of the Terms of Service (“Principal Agreement”) between:
You (the “Company” or “Controller”) and Alleo.ai Corporation, 16192 Coastal Highway, Lewes, Delaware 19958 USA (the “Processor”), together the “Parties”.
WHEREAS: (A) the Company acts as a Data Controller. (B) The Company wishes to use Services provided by the Processor, which involve the processing of personal data. (C) The Parties seek to implement a data processing agreement that complies with applicable data protection laws, including the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and applicable U.S. state privacy laws. It is agreed as follows.
1. DEFINITIONS
1.1 “Company Personal Data” means any Personal Data processed by Processor on behalf of Company pursuant to the Principal Agreement.
1.2 “Data Protection Laws” means the GDPR and, to the extent applicable, U.S. state privacy laws including the California Consumer Privacy Act.
1.3 “Subprocessor” means any third party appointed by Processor to process Personal Data on behalf of the Company.
1.4 The terms “Controller”, “Data Subject”, “Personal Data”, “Personal Data Breach”, and “Processing” shall have the same meaning as in the GDPR.
2. PROCESSING OF COMPANY PERSONAL DATA
2.1 Processor shall:
- (a) comply with all applicable Data Protection Laws in the Processing of Company Personal Data; and
- (b) not Process Company Personal Data other than on the Company's documented instructions, unless required by law.
2.2 The Company instructs Processor to process Company Personal Data to provide the AI assistant and agent services described in the Principal Agreement, including reading from and acting within the third-party applications the Company connects to the Service.
2.3 Processor shall not sell or share Company Personal Data for advertising or marketing purposes.
2.4 Processor shall not use Company Personal Data to train artificial intelligence or machine learning models, and shall contractually prohibit its Subprocessors from doing so.
3. PROCESSOR PERSONNEL
Processor shall ensure that persons authorized to process Company Personal Data are subject to confidentiality obligations and that access is limited to those who need it to perform the Services.
4. SECURITY
4.1 Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- (a) encryption of Personal Data at rest (AES-256) and in transit (TLS 1.2+);
- (b) access controls and authentication measures, including strict per-user scoping of data access; and
- (c) regular testing and assessment of security measures.
4.2 Processor executes each agent task inside an isolated, ephemeral sandbox that is destroyed on completion, and does not retain Company Personal Data drawn from connected applications beyond the task for which it was fetched.
4.3 A full description of Processor's technical and organizational measures is available on our Security page.
5. SUBPROCESSING
5.1 Company authorizes Processor to engage Subprocessors. A current list of Subprocessors is available on our Security page.
5.2 Processor shall impose data protection obligations on each Subprocessor that are no less protective than those set out in this Agreement, and remains liable for the performance of its Subprocessors.
6. DATA SUBJECT RIGHTS
6.1 Processor shall promptly notify Company if it receives a request from a Data Subject and shall not respond except as instructed by Company or required by law.
6.2 Processor shall assist Company in responding to Data Subject requests, taking into account the nature of the Processing.
7. PERSONAL DATA BREACH
7.1 Processor shall notify Company without undue delay upon becoming aware of a Personal Data Breach affecting Company Personal Data.
7.2 Processor shall cooperate with Company and take reasonable steps to assist in the investigation and remediation of each such breach.
8. DATA TRANSFERS
8.1 Company Personal Data may be transferred to and processed in the United States.
8.2 For transfers of Personal Data from the EEA, the Parties agree to rely on the EU Standard Contractual Clauses as the transfer mechanism.
9. DELETION OF COMPANY PERSONAL DATA
Upon termination of the Services, Processor shall delete all Company Personal Data within 24 hours, unless retention is required by law. Backup copies shall be deleted within 7 days (up to 14 days during active incident investigations).
10. GENERAL TERMS
10.1 This Agreement is governed by the laws of the State of Delaware, USA.
10.2 This Agreement shall remain in effect for as long as Processor processes Company Personal Data.
10.3 In the event of any conflict between this Agreement and the Principal Agreement with respect to data protection, this Agreement shall prevail.
Contact
For questions about this Agreement or to request security documentation, contact us: