Data Processing Agreement

    Last updated: September 8, 2026

    1. Parties & Scope

    Summary

    This DPA applies between you (the Controller) and Pocodot (the Processor) whenever we process personal data on your behalf.

    This Data Processing Agreement ("DPA") forms part of the Terms of Service between Pocodot Labs, Inc. ("Processor", "we", "us") and the customer ("Controller", "you") who has agreed to the Terms of Service (the "Agreement").

    This DPA applies to all processing of personal data that the Processor carries out on behalf of the Controller in connection with the services provided under the Agreement. It supplements and is incorporated into the Agreement.

    In the event of any conflict between this DPA and the Agreement, this DPA shall prevail with respect to the processing of personal data.

    2. Definitions

    Summary

    Key terms follow GDPR definitions - 'personal data', 'processing', 'controller', 'processor', and 'data subject' all have their Article 4 meanings.

    Unless otherwise defined herein, capitalised terms have the following meanings:

    • Data Protection Laws - GDPR (EU 2016/679), UK GDPR, and any applicable national implementing legislation.
    • Personal Data - any information relating to an identified or identifiable natural person, as defined in Article 4(1) GDPR.
    • Processing - any operation performed on personal data, as defined in Article 4(2) GDPR.
    • Controller - the entity that determines the purposes and means of processing personal data.
    • Processor - the entity that processes personal data on behalf of the Controller.
    • Sub-Processor - any third party engaged by the Processor to process personal data on behalf of the Controller.
    • Data Subject - the identified or identifiable natural person to whom the personal data relates.
    • Supervisory Authority - an independent public authority responsible for monitoring the application of Data Protection Laws.

    3. Details of Processing

    Summary

    We process account data, usage data, and agent interaction data to deliver the Pocodot platform services you've subscribed to.

    The following details of processing are agreed between the parties:

    • Subject Matter: Provision of AI agent orchestration, automation, and communication services.
    • Duration: For the term of the Agreement plus any retention period required by law.
    • Nature & Purpose: Collection, storage, organisation, retrieval, use, and erasure of personal data as necessary to provide the services.
    • Categories of Data Subjects: Controller's end users, employees, contractors, and business contacts.
    • Types of Personal Data: Names, email addresses, IP addresses, usage logs, agent interaction data, site login credentials and payment card details the Controller's users choose to store (encrypted), cookies held by Cole's browser on a user's behalf, screenshots of pages Cole visits for a user, location pins a user shares, and any personal data submitted by the Controller through the services.

    4. Controller Obligations

    Summary

    You must ensure you have a lawful basis for the personal data you send us and must inform your data subjects about the processing.

    The Controller shall:

    • Ensure that the processing of personal data has a valid legal basis under applicable Data Protection Laws.
    • Provide all required notices to data subjects regarding the processing of their personal data.
    • Ensure that instructions given to the Processor comply with applicable Data Protection Laws.
    • Respond to data subject requests, with the Processor's reasonable assistance as described in Section 5.
    • Conduct data protection impact assessments where required, with the Processor's cooperation.

    5. Processor Obligations

    Summary

    We only process your data per your instructions, maintain confidentiality, assist with data subject requests, and support your compliance obligations.

    The Processor shall:

    • Process personal data only on documented instructions from the Controller, unless required by law.
    • Ensure that persons authorised to process the personal data have committed themselves to confidentiality.
    • Implement appropriate technical and organisational security measures as described in Section 8.
    • Assist the Controller in responding to data subject access requests within the timeframes required by Data Protection Laws.
    • Assist the Controller in ensuring compliance with obligations relating to security, breach notification, impact assessments, and prior consultation.
    • At the Controller's choice, delete or return all personal data upon termination of the Agreement, as described in Section 10.
    • Make available all information necessary to demonstrate compliance and allow for audits as described below.

    Audit Rights: The Controller may audit the Processor's compliance with this DPA once per calendar year, with 30 days' written notice. The Processor may satisfy audit requests by providing a copy of its most recent SOC 2 Type II report or equivalent third-party audit report.

    6. Sub-Processing

    Summary

    We use approved sub-processors listed on our Subprocessors page. We'll notify you 30 days before adding new ones, and you can object.

    The Controller provides general written authorisation for the Processor to engage sub-processors. The current list of approved sub-processors is maintained at pocodot.ai/subprocessors.

    The Processor shall notify the Controller at least 30 days before adding or replacing any sub-processor, giving the Controller an opportunity to object. If the Controller objects on reasonable grounds, the parties shall discuss the concern in good faith. If no resolution is reached within 30 days, the Controller may terminate the affected services.

    The Processor shall impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and shall remain fully liable for the acts and omissions of its sub-processors.

    7. International Data Transfers

    Summary

    We use EU Standard Contractual Clauses (SCCs) and supplementary security measures for any transfers outside the EEA.

    Where personal data is transferred outside the European Economic Area (EEA), the United Kingdom, or Switzerland, the Processor shall ensure that appropriate safeguards are in place, including:

    • EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module 2 (Controller-to-Processor).
    • UK International Data Transfer Addendum, where applicable.
    • Supplementary technical measures including encryption in transit (TLS 1.2+) and at rest (AES-256).
    • Transfer impact assessments documenting the legal framework of the recipient country.

    The Processor shall not transfer personal data to any country or international organisation without ensuring that adequate safeguards are in place as required by Chapter V of the GDPR.

    8. Technical & Organizational Measures

    Summary

    We implement encryption, access controls, monitoring, and regular testing to protect your data - detailed in our Security page.

    The Processor implements and maintains the following technical and organisational measures to ensure a level of security appropriate to the risk:

    • Encryption: TLS 1.2+ for data in transit; AES-256 for data at rest.
    • Access Control: Role-based access with least-privilege principles; multi-factor authentication for all administrative access.
    • Network Security: Firewalls, intrusion detection, and DDoS protection.
    • Logging & Monitoring: Centralised audit logging with anomaly detection and alerting.
    • Availability: Redundant infrastructure with automated failover and regular backups.
    • Personnel: Background checks, confidentiality agreements, and regular data protection training.
    • Testing: Regular vulnerability assessments and penetration testing.
    • Incident Response: Documented incident response procedures with defined escalation paths.

    For additional details, contact us at security@pocodot.ai.

    9. Data Breach Notification

    Summary

    We'll notify you of any personal data breach within 48 hours with full details so you can meet your 72-hour GDPR reporting deadline.

    In the event of a personal data breach, the Processor shall:

    • Notify the Controller without undue delay and in any event within 48 hours of becoming aware of the breach.
    • Provide the following information (to the extent available):
      • The nature of the breach, including categories and approximate number of data subjects and records affected.
      • The likely consequences of the breach.
      • Measures taken or proposed to address the breach and mitigate its effects.
      • The name and contact details of the Processor's data protection contact.
    • Cooperate with the Controller and take reasonable steps to assist in the investigation, mitigation, and remediation of the breach.
    • Not notify any third party of the breach without the Controller's prior written consent, unless required by law.

    10. Term & Data Deletion

    Summary

    This DPA lasts as long as our Agreement. After termination, we delete your data within 90 days unless legally required to retain it.

    This DPA shall remain in effect for the duration of the Agreement and shall automatically terminate upon termination or expiry of the Agreement, subject to the following:

    • Upon termination, the Processor shall, at the Controller's written request, either return or securely delete all personal data within 90 calendar days, unless retention is required by applicable law.
    • The Processor shall provide written confirmation of deletion upon the Controller's request.
    • Obligations relating to confidentiality, data protection, and liability shall survive termination of this DPA.

    Where the Processor is required by law to retain personal data beyond the deletion period, it shall inform the Controller of the legal requirement and limit processing to the minimum necessary to comply with that obligation.

    Questions about this policy? Email us at legal@pocodot.ai