AiCOAG

Data Processing Agreement

General data processing terms for AiCOAG client services

Last updated: September 2026

This Data Processing Agreement ("DPA") sets out the general terms that apply where AiCOAG processes personal data on behalf of a client in connection with AiCOAG services.

It is intended to support the requirements applicable to controller-processor relationships under the General Data Protection Regulation ("GDPR"), including Article 28.

This DPA should be read together with the applicable client agreement, proposal, order form, statement of work or other written agreement governing the relevant AiCOAG services (the "Service Agreement"). Where required for a particular client relationship, the parties may execute or incorporate this DPA into their Service Agreement.

This page presents a general framework. Reading or visiting this page does not by itself create a client service relationship, a signed agreement or a processing arrangement between AiCOAG and the reader. Where applicable, this DPA may be incorporated into or executed as part of a Client's Service Agreement.
Contents

1.Parties and roles

For the purposes of this DPA:

  • "Client" means the business or organisation that has entered into a relevant Service Agreement with AiCOAG.
  • "AiCOAG" means AiCOAG, Amsterdam, Netherlands, KvK 97342467.

Where the Client determines the purposes and means of processing personal data and AiCOAG processes that data on the Client's behalf, the Client acts as Controller and AiCOAG acts as Processor.

Where the Client itself acts as processor for another controller, AiCOAG may act as a subprocessor where applicable. The actual roles depend on the relevant processing activity and applicable law.

AiCOAG may separately act as an independent controller for its own legitimate business operations, such as managing its client relationship, invoicing, security and legal obligations.

2.Definitions

  • Personal Data — any information relating to an identified or identifiable natural person.
  • Processing — any operation performed on personal data, whether or not by automated means.
  • Controller — the party that determines the purposes and means of the processing.
  • Processor — the party that processes personal data on behalf of the controller.
  • Data Subject — the individual to whom the personal data relates.
  • Personal Data Breach — a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
  • Subprocessor — a third party engaged by the processor to carry out processing activities on behalf of the controller.
  • Supervisory Authority — the competent independent public authority responsible for monitoring the application of applicable data protection law.

Terms not specifically defined in this DPA have the meaning given to them under applicable data protection law where relevant.

3.Scope of processing

The nature and extent of processing depend on the AiCOAG services selected by the Client.

Depending on the implementation, processing may relate to services such as:

  • AiCOAG Voice
  • AiCOAG Chat
  • AiCOAG Connect
  • AiCOAG Lead
  • Booking and appointment workflows
  • Integrations
  • Related managed services

Processing should be limited to what is reasonably necessary to provide the agreed services and follow documented Client instructions, except where processing is required by applicable law.

4.Documented instructions

AiCOAG will process personal data on behalf of the Client only on documented instructions from the Client, including instructions contained in:

  • The Service Agreement
  • Agreed configuration
  • Implementation documentation
  • Written Client instructions

unless applicable law requires otherwise.

If AiCOAG believes an instruction infringes applicable data protection law, AiCOAG may inform the Client and, where appropriate, pause the affected processing while the issue is addressed.

5.Details of processing

The details of processing applicable to a Client engagement are set out in Schedule A — Details of Processing. Not all processing purposes apply to every client; the applicable scope depends on the services agreed.

6.Categories of data subjects

Depending on the Client and service, data subjects may include:

  • Client customers
  • Prospective customers
  • Website visitors
  • Callers
  • Chat users
  • Messaging users
  • Leads and prospects
  • Appointment or reservation holders
  • Client employees or representatives
  • Business contacts

7.Types of personal data

Depending on the service, personal data may include:

  • Name
  • Telephone number
  • Email address
  • Business and contact details
  • Enquiry information
  • Appointment or reservation information
  • Conversation content
  • Chat content
  • Voice interaction information
  • Call metadata
  • Transcripts where configured
  • Business relationship information
  • Professional role or company information
  • Technical information necessary to operate integrations
  • Other information voluntarily provided during an interaction

Not every service processes every category of personal data.

8.Special categories of personal data

AiCOAG services are not generally designed to require special categories of personal data unless this has been specifically identified, assessed and agreed as necessary for an appropriate use case.

Clients should not instruct AiCOAG to process special category data unless:

  • It is necessary for the agreed service
  • An appropriate lawful basis and Article 9 condition exist where required
  • Relevant safeguards have been assessed
  • The processing has been specifically agreed

For healthcare or other sensitive environments, additional requirements may apply. AiCOAG should not be assumed to be automatically suitable for processing all categories of health data.

9.Client responsibilities

Where applicable to its controller role, the Client is responsible for:

  • Establishing a lawful basis for processing
  • Providing required privacy information
  • Ensuring its instructions are lawful
  • Responding to data subject rights as controller
  • Determining appropriate retention requirements
  • Ensuring data supplied to AiCOAG is appropriate
  • Identifying sector-specific legal requirements
  • Determining whether call recording or transcription is appropriate
  • Obtaining required notices or consent where applicable

AiCOAG will provide reasonable assistance within its processor role where required.

10.Confidentiality

AiCOAG will ensure that persons authorised to process Client personal data are subject to appropriate confidentiality obligations.

Access should be limited to people who require it for legitimate service purposes.

11.Security of processing

AiCOAG will implement appropriate technical and organisational measures designed to provide a level of security appropriate to the relevant processing risk, taking into account the nature of the service and applicable requirements.

Measures may include, where appropriate:

  • Access controls
  • Authentication controls
  • Least-privilege principles
  • Data minimisation
  • Secure transmission where supported
  • System and configuration controls
  • Logging and monitoring
  • Backup and recovery measures where applicable
  • Incident management processes
  • Appropriate provider management
  • Organisational confidentiality measures

Not every measure applies identically to every service. Further detail is set out in Schedule B.

12.Subprocessors

AiCOAG may engage third-party subprocessors where reasonably necessary to provide the agreed services.

Subprocessors may provide categories of technology such as:

  • Cloud infrastructure
  • AI processing
  • Voice and speech technology
  • Telephony
  • Messaging
  • Website infrastructure
  • Booking and calendar systems
  • CRM and integration infrastructure
  • Communication services
  • Security or technical infrastructure

AiCOAG should ensure that subprocessors handling Client personal data are subject to data protection obligations appropriate to the processing and consistent with applicable GDPR requirements.

13.Subprocessor information and changes

AiCOAG will make relevant information about subprocessors used for Client processing available through an appropriate mechanism.

Where required by the applicable arrangement, AiCOAG will provide reasonable notice of material additions or replacements of subprocessors so that the Client can raise legitimate data protection concerns.

The process for objections and any consequences should be handled reasonably and in accordance with the Service Agreement and applicable law. See Schedule C — Subprocessors.

14.International data transfers

Some subprocessors or technology infrastructure may involve processing outside the European Economic Area.

Where GDPR Chapter V applies, AiCOAG will use or rely on an appropriate lawful transfer mechanism where required. This may include:

  • An adequacy decision
  • Standard Contractual Clauses
  • Another legally recognised mechanism

Additional safeguards may be considered where required by applicable law and the relevant transfer circumstances. Transfer mechanisms may differ between providers and processing activities.

15.Data subject rights

Taking into account the nature of processing, AiCOAG will provide reasonable assistance to the Client, where required, in responding to requests relating to:

  • Access
  • Rectification
  • Deletion
  • Restriction
  • Portability
  • Objection
  • Other applicable data subject rights

Where AiCOAG receives a request directly from a data subject relating to Client-controlled data, AiCOAG should generally direct the request to the Client or notify the Client, unless applicable law requires otherwise. AiCOAG should not independently determine the Client's response where the Client is controller.

16.Assistance with GDPR obligations

Taking into account the nature of processing and the information available to AiCOAG, AiCOAG will provide reasonable assistance where required in relation to applicable obligations such as:

  • Security of processing
  • Personal data breach assessment
  • Data protection impact assessments
  • Prior consultation with supervisory authorities where applicable

The scope of assistance may depend on the relevant service and processing activity.

17.Personal data breaches

If AiCOAG becomes aware of a personal data breach affecting personal data processed on behalf of the Client, AiCOAG will notify the Client without undue delay as required by applicable law.

Where information is available, the notification should provide information reasonably necessary for the Client to assess and meet its obligations. AiCOAG may provide information in phases where complete information is not immediately available.

AiCOAG's notification obligation to the Client is separate from the Client's own obligations as controller to notify a supervisory authority or affected data subjects where required.

18.Audits and compliance information

AiCOAG will make available information reasonably necessary to demonstrate compliance with applicable processor obligations.

Where legally required and reasonably necessary, AiCOAG should permit and contribute to appropriate audits or inspections relating to the relevant processing.

Audit arrangements should:

  • Protect confidentiality
  • Minimise unnecessary disruption
  • Avoid exposing information belonging to other clients
  • Be proportionate to the processing and risk

Where appropriate, the parties may agree reasonable practical arrangements for audits.

19.Return and deletion of data

At the end of the relevant services, AiCOAG will, at the Client's choice and where applicable, delete or return personal data processed on the Client's behalf and delete remaining copies, unless:

  • Applicable law requires retention
  • Limited backup retention applies as part of ordinary technical processes
  • Another lawful contractual arrangement applies

Any retained data should remain protected and should not be used for unrelated purposes.

20.Backups

Some information may remain temporarily in backup or recovery systems after deletion from active systems.

Where this occurs, such information should remain protected and should be removed or overwritten according to applicable backup lifecycle processes.

21.AI processing

Where AI technology is used as part of Client services, personal data may be processed by AI-related infrastructure where necessary to provide the agreed functionality.

AiCOAG will seek to configure such processing consistently with:

  • Client instructions
  • Applicable data protection requirements
  • Agreed service purposes
  • Data minimisation principles

Further information is available in the AI Policy.

22.Call recording and transcription

Where call recording or transcription is enabled for a Client implementation, the Client is responsible for determining the applicable legal basis, transparency and consent requirements within its role as controller.

AiCOAG will process recordings or transcripts according to agreed instructions within its processor role.

Recording and transcription should not be treated as automatically enabled for every Voice implementation.

23.Processing instructions after termination

Following termination, AiCOAG should cease processing Client personal data except where reasonably necessary for:

  • Return or deletion
  • Legal obligations
  • Resolving agreed transition matters
  • Protecting legal rights where permitted

AiCOAG should not continue using Client-controlled personal data for unrelated purposes.

24.Liability

Liability arising under this DPA should be governed by the applicable Service Agreement and applicable law.

Nothing in this DPA is intended to exclude responsibilities or rights that cannot lawfully be excluded.

25.Order of precedence

For data processing matters, this DPA should apply together with the relevant Service Agreement.

Where there is a conflict specifically concerning processor obligations under applicable data protection law, the parties should interpret the agreements consistently with applicable mandatory data protection requirements.

26.Governing law

This DPA is governed by the laws of the Netherlands, subject to applicable mandatory data protection law.

27.Contact

For privacy and data processing matters:

See also our Privacy Policy.

Schedule A — Details of Processing

Subject matter: Processing necessary to provide the AiCOAG services agreed with the Client.

Duration: For the duration of the applicable Service Agreement and any limited period thereafter required for appropriate return, deletion, legal obligations or agreed transition.

Nature of processing may include, depending on the service:

  • Collection
  • Recording
  • Organisation
  • Structuring
  • Storage
  • Retrieval
  • Consultation
  • Use
  • Transmission
  • Routing
  • Analysis
  • Updating
  • Deletion

Purposes may include:

  • Handling customer enquiries
  • Customer communication
  • Lead capture
  • Lead qualification
  • Booking and appointment support
  • Routing and escalation
  • Managing agreed business information
  • Online presence management
  • Reputation management
  • Business development support
  • Agreed integrations
  • Service operation and support

Not all processing purposes apply to every client engagement.

Categories of data subjects and types of personal data are described in sections 6 and 7 of this DPA.

Schedule B — Technical and Organisational Measures

The following measures are principles-based and apply appropriate to the relevant service, where applicable and depending on the implementation.

1.Access Management

Access to Client personal data is limited to authorised persons who require it, applying least-privilege principles where applicable.

2.Confidentiality

Persons authorised to process Client personal data are subject to appropriate confidentiality obligations.

3.Data Minimisation

Processing is limited to what is reasonably necessary for the agreed service purposes, depending on the implementation.

4.Secure Communications

Secure transmission methods are used where supported by the relevant service and provider.

5.Service Configuration

Services are configured according to agreed Client instructions and reviewed where appropriate to the relevant service.

6.Incident Management

Processes are in place to assess and respond to security incidents appropriate to the relevant service.

7.Business Continuity

Recovery and continuity measures apply where supported by the relevant infrastructure and applicable to the service.

8.Provider Management

Providers handling Client personal data are subject to data protection obligations appropriate to the processing.

9.Data Lifecycle Management

Return, deletion and retention are handled in line with agreed instructions and applicable legal requirements, where applicable.

10.Organisational Practices

Internal practices support confidentiality, appropriate handling of personal data and responsible use of technology.

This schedule does not assert any specific certification, encryption standard, testing schedule, data centre location or recovery objective. Such details would only be stated once technically verified.

Schedule C — Subprocessors

Subprocessor information will be maintained based on the technology providers used in the relevant AiCOAG service configuration. Client-specific information may be provided as part of the applicable service documentation.
Subprocessor register
ProviderService / PurposeProcessing LocationTransfer Mechanism
No subprocessor entries are published at this time.
This public DPA is a general framework. It does not by itself create a client service relationship, and reading this page does not constitute acceptance or execution of an agreement. Where applicable, it may be incorporated into or executed as part of a Client's Service Agreement.