Legal
General data processing terms for AiCOAG client services
Last updated: September 2026
This Data Processing Agreement ("DPA") sets out the general terms that apply where AiCOAG processes personal data on behalf of a client in connection with AiCOAG services.
It is intended to support the requirements applicable to controller-processor relationships under the General Data Protection Regulation ("GDPR"), including Article 28.
This DPA should be read together with the applicable client agreement, proposal, order form, statement of work or other written agreement governing the relevant AiCOAG services (the "Service Agreement"). Where required for a particular client relationship, the parties may execute or incorporate this DPA into their Service Agreement.
For the purposes of this DPA:
Where the Client determines the purposes and means of processing personal data and AiCOAG processes that data on the Client's behalf, the Client acts as Controller and AiCOAG acts as Processor.
Where the Client itself acts as processor for another controller, AiCOAG may act as a subprocessor where applicable. The actual roles depend on the relevant processing activity and applicable law.
AiCOAG may separately act as an independent controller for its own legitimate business operations, such as managing its client relationship, invoicing, security and legal obligations.
Terms not specifically defined in this DPA have the meaning given to them under applicable data protection law where relevant.
The nature and extent of processing depend on the AiCOAG services selected by the Client.
Depending on the implementation, processing may relate to services such as:
Processing should be limited to what is reasonably necessary to provide the agreed services and follow documented Client instructions, except where processing is required by applicable law.
AiCOAG will process personal data on behalf of the Client only on documented instructions from the Client, including instructions contained in:
unless applicable law requires otherwise.
If AiCOAG believes an instruction infringes applicable data protection law, AiCOAG may inform the Client and, where appropriate, pause the affected processing while the issue is addressed.
The details of processing applicable to a Client engagement are set out in Schedule A — Details of Processing. Not all processing purposes apply to every client; the applicable scope depends on the services agreed.
Depending on the Client and service, data subjects may include:
Depending on the service, personal data may include:
Not every service processes every category of personal data.
AiCOAG services are not generally designed to require special categories of personal data unless this has been specifically identified, assessed and agreed as necessary for an appropriate use case.
Clients should not instruct AiCOAG to process special category data unless:
For healthcare or other sensitive environments, additional requirements may apply. AiCOAG should not be assumed to be automatically suitable for processing all categories of health data.
Where applicable to its controller role, the Client is responsible for:
AiCOAG will provide reasonable assistance within its processor role where required.
AiCOAG will ensure that persons authorised to process Client personal data are subject to appropriate confidentiality obligations.
Access should be limited to people who require it for legitimate service purposes.
AiCOAG will implement appropriate technical and organisational measures designed to provide a level of security appropriate to the relevant processing risk, taking into account the nature of the service and applicable requirements.
Measures may include, where appropriate:
Not every measure applies identically to every service. Further detail is set out in Schedule B.
AiCOAG may engage third-party subprocessors where reasonably necessary to provide the agreed services.
Subprocessors may provide categories of technology such as:
AiCOAG should ensure that subprocessors handling Client personal data are subject to data protection obligations appropriate to the processing and consistent with applicable GDPR requirements.
AiCOAG will make relevant information about subprocessors used for Client processing available through an appropriate mechanism.
Where required by the applicable arrangement, AiCOAG will provide reasonable notice of material additions or replacements of subprocessors so that the Client can raise legitimate data protection concerns.
The process for objections and any consequences should be handled reasonably and in accordance with the Service Agreement and applicable law. See Schedule C — Subprocessors.
Some subprocessors or technology infrastructure may involve processing outside the European Economic Area.
Where GDPR Chapter V applies, AiCOAG will use or rely on an appropriate lawful transfer mechanism where required. This may include:
Additional safeguards may be considered where required by applicable law and the relevant transfer circumstances. Transfer mechanisms may differ between providers and processing activities.
Taking into account the nature of processing, AiCOAG will provide reasonable assistance to the Client, where required, in responding to requests relating to:
Where AiCOAG receives a request directly from a data subject relating to Client-controlled data, AiCOAG should generally direct the request to the Client or notify the Client, unless applicable law requires otherwise. AiCOAG should not independently determine the Client's response where the Client is controller.
Taking into account the nature of processing and the information available to AiCOAG, AiCOAG will provide reasonable assistance where required in relation to applicable obligations such as:
The scope of assistance may depend on the relevant service and processing activity.
If AiCOAG becomes aware of a personal data breach affecting personal data processed on behalf of the Client, AiCOAG will notify the Client without undue delay as required by applicable law.
Where information is available, the notification should provide information reasonably necessary for the Client to assess and meet its obligations. AiCOAG may provide information in phases where complete information is not immediately available.
AiCOAG's notification obligation to the Client is separate from the Client's own obligations as controller to notify a supervisory authority or affected data subjects where required.
AiCOAG will make available information reasonably necessary to demonstrate compliance with applicable processor obligations.
Where legally required and reasonably necessary, AiCOAG should permit and contribute to appropriate audits or inspections relating to the relevant processing.
Audit arrangements should:
Where appropriate, the parties may agree reasonable practical arrangements for audits.
At the end of the relevant services, AiCOAG will, at the Client's choice and where applicable, delete or return personal data processed on the Client's behalf and delete remaining copies, unless:
Any retained data should remain protected and should not be used for unrelated purposes.
Some information may remain temporarily in backup or recovery systems after deletion from active systems.
Where this occurs, such information should remain protected and should be removed or overwritten according to applicable backup lifecycle processes.
Where AI technology is used as part of Client services, personal data may be processed by AI-related infrastructure where necessary to provide the agreed functionality.
AiCOAG will seek to configure such processing consistently with:
Further information is available in the AI Policy.
Where call recording or transcription is enabled for a Client implementation, the Client is responsible for determining the applicable legal basis, transparency and consent requirements within its role as controller.
AiCOAG will process recordings or transcripts according to agreed instructions within its processor role.
Recording and transcription should not be treated as automatically enabled for every Voice implementation.
Following termination, AiCOAG should cease processing Client personal data except where reasonably necessary for:
AiCOAG should not continue using Client-controlled personal data for unrelated purposes.
Liability arising under this DPA should be governed by the applicable Service Agreement and applicable law.
Nothing in this DPA is intended to exclude responsibilities or rights that cannot lawfully be excluded.
For data processing matters, this DPA should apply together with the relevant Service Agreement.
Where there is a conflict specifically concerning processor obligations under applicable data protection law, the parties should interpret the agreements consistently with applicable mandatory data protection requirements.
This DPA is governed by the laws of the Netherlands, subject to applicable mandatory data protection law.
For privacy and data processing matters:
See also our Privacy Policy.
Subject matter: Processing necessary to provide the AiCOAG services agreed with the Client.
Duration: For the duration of the applicable Service Agreement and any limited period thereafter required for appropriate return, deletion, legal obligations or agreed transition.
Nature of processing may include, depending on the service:
Purposes may include:
Not all processing purposes apply to every client engagement.
Categories of data subjects and types of personal data are described in sections 6 and 7 of this DPA.
The following measures are principles-based and apply appropriate to the relevant service, where applicable and depending on the implementation.
Access to Client personal data is limited to authorised persons who require it, applying least-privilege principles where applicable.
Persons authorised to process Client personal data are subject to appropriate confidentiality obligations.
Processing is limited to what is reasonably necessary for the agreed service purposes, depending on the implementation.
Secure transmission methods are used where supported by the relevant service and provider.
Services are configured according to agreed Client instructions and reviewed where appropriate to the relevant service.
Processes are in place to assess and respond to security incidents appropriate to the relevant service.
Recovery and continuity measures apply where supported by the relevant infrastructure and applicable to the service.
Providers handling Client personal data are subject to data protection obligations appropriate to the processing.
Return, deletion and retention are handled in line with agreed instructions and applicable legal requirements, where applicable.
Internal practices support confidentiality, appropriate handling of personal data and responsible use of technology.
This schedule does not assert any specific certification, encryption standard, testing schedule, data centre location or recovery objective. Such details would only be stated once technically verified.
| Provider | Service / Purpose | Processing Location | Transfer Mechanism |
|---|---|---|---|
| No subprocessor entries are published at this time. | |||