Back to home

Data Processing Agreement

Last updated

This Data Processing Agreement ("DPA") forms part of the Application Terms of Service (https://www.thecompany.company/legal/application-terms) or other written agreement (the "Agreement") between The Company Company Inc. ("Company," "Co," "we," or "us") and the customer identified in the Agreement ("Customer"). It applies to the extent we process Personal Information contained in Customer Data on Customer's behalf in providing the Application. It takes effect when Customer accepts the Agreement, whether by clicking to accept the Application Terms or by signing a separate written agreement that incorporates this DPA. Capitalized terms not defined here have the meaning given in the Agreement.

Scope note on training. Section 5 of the Application Terms grants us a license to use Customer Data for model training and improvement unless Customer opts out as described in Section 5.3 of the Application Terms (by email to legal@thecompany.company). Processing under that license is performed for our own purposes and is governed by our Privacy Policy and Section 4 of this DPA, not by the processor obligations in Section 3. Customers that require processor-only handling of all Customer Data should opt out before connecting data.

1. Definitions

  • "Applicable Data Protection Law" means the U.S. state privacy laws that apply to the processing of Personal Information under this DPA, including the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA"), and their implementing regulations.
  • "Personal Information" means information within Customer Data that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked with a particular consumer or household, as defined under Applicable Data Protection Law.
  • "Processing," "Sell," "Share," "Service Provider," "Business," "Consumer," and "Business Purpose" have the meanings given under Applicable Data Protection Law.
  • "Security Incident" means a confirmed unauthorized access to, or acquisition, disclosure, or loss of, Personal Information in our possession or control.
  • "Sub-processor" means a third party we engage to process Personal Information on Customer's behalf, as listed at https://www.thecompany.company/legal/sub-processors.

2. Roles and Details of Processing

  • Service delivery. When we process Personal Information solely to provide the Application to Customer as configured by Customer, Customer is the Business and we are the Service Provider.
  • Training and our own purposes. When we retain and use Customer Data for model training and improvement, security, legal compliance, and our own business operations under the Agreement and Privacy Policy, we are a Business for that processing, and Section 3 does not apply to it.
  • Nature and purpose. Hosting, storing, and processing Customer Data; running agents that read from and write to Connected Services at Customer's direction; generating outputs; providing support; and the purposes described in the Privacy Policy.
  • Categories of data subjects. Customer's Authorized Users, employees, contractors, customers, prospects, vendors, and other individuals whose information Customer or its Connected Services include in Customer Data.
  • Categories of Personal Information. Identifiers and contact details, professional information, communications content, commercial and transaction information, internet activity, source code and files, and any other category Customer chooses to connect. Customer must not connect Sensitive Personal Information requiring specific safeguards (for example protected health information) without a separate written agreement.
  • Duration. For the term of the Agreement and thereafter as described in Section 7.

3. Service Provider Obligations

For processing described in Section 2 as service delivery, we will:

  1. Process Personal Information only on Customer's documented instructions, which are the Agreement, this DPA, and the configurations and instructions Customer and its Authorized Users provide through the Application, including instructions to agents. Actions agents take within the tools, integrations, and approval settings Customer configured are Customer's instructions.
  2. Not Sell or Share Personal Information.
  3. Not retain, use, or disclose Personal Information for any purpose other than the Business Purposes specified in the Agreement, or outside the direct business relationship with Customer, except as permitted by Applicable Data Protection Law.
  4. Not combine Personal Information received from Customer with Personal Information received from another source, except as permitted by Applicable Data Protection Law.
  5. Comply with Applicable Data Protection Law and provide the same level of privacy protection as it requires of Customer. We will notify Customer if we determine we can no longer meet our obligations under Applicable Data Protection Law, and Customer may then take reasonable and appropriate steps to stop and remediate unauthorized use.
  6. Ensure that personnel with access to Personal Information are bound by confidentiality obligations.
  7. Assist Customer in responding to Consumer requests as described in Section 6.
  8. Allow Customer to take reasonable steps to ensure we use Personal Information consistently with Customer's obligations, as described in Section 8.

4. Training and Improvement Processing

Unless Customer's organization has opted out, Customer acknowledges and agrees that:

  1. We retain Customer Data, including Personal Information in it, and use it to train, fine-tune, evaluate, test, benchmark, and improve models, agents, prompts, tools, safety systems, and the Application, and to develop new products and services, as a Business. Customer discloses Personal Information to us for these purposes and, to the extent Applicable Data Protection Law treats that disclosure as a sale or sharing, this Section 4 is the contract required by Cal. Civ. Code 1798.100(d) and 11 CCR 7053 for it.
  2. For Personal Information we receive for the purposes in Section 4.1, we will: (a) use it only for those purposes and the other purposes disclosed in our Privacy Policy; (b) provide the level of privacy protection Applicable Data Protection Law requires of Customer; (c) not sell or share it onward; (d) notify Customer if we determine we can no longer meet our obligations under Applicable Data Protection Law, after which Customer may take reasonable steps to stop and remediate unauthorized use; and (e) honor Consumer requests directed to us as described in Section 6 and our Privacy Policy. Each party is responsible for its own notice and Consumer-choice obligations under Applicable Data Protection Law, and Customer represents that it has provided the notices and obtained the consents it is required to provide or obtain before disclosing Personal Information to us for these purposes.
  3. We exclude from training the data described in Section 5.2 of the Application Terms, including data obtained through Google API scopes and secrets.
  4. An opt-out applies prospectively. It does not require us to delete or stop using Customer Data collected before the change, to retrain or delete models, or to remove aggregated or de-identified information.
  5. Models and other artifacts we create are our property and are not Personal Information subject to Customer's instructions.

5. Sub-processors

Customer authorizes us to engage the Sub-processors listed at https://www.thecompany.company/legal/sub-processors. We will impose data protection obligations on Sub-processors that are no less protective than those in this DPA, and we remain responsible for their performance. We may add or replace Sub-processors from time to time and will update that list when we do. Customer may object to a new Sub-processor on reasonable data protection grounds by writing to legal@thecompany.company; if we cannot resolve the objection, Customer may terminate the Agreement.

Connected Services that Customer instructs agents to act in are not our Sub-processors.

6. Consumer Requests

If we receive a request from a Consumer to exercise rights concerning Personal Information we process as Customer's Service Provider, we will direct the Consumer to Customer and will not respond except to acknowledge receipt or as required by law. We will provide Customer reasonable assistance through the Application's deletion and disconnection features and, for access, correction, or export requests, through legal@thecompany.company.

Requests concerning our processing as a Business (Section 4) are handled by us under the Privacy Policy. Deletion of Personal Information does not require deletion or retraining of models already created, as permitted by Applicable Data Protection Law.

7. Deletion and Return

On termination of the Agreement or on Customer's written request, we will delete Personal Information processed as Service Provider from our primary databases within a reasonable period, except where retention is required by law or permitted by the Agreement. Personal Information retained under Section 4 is deleted according to the Privacy Policy. Customer may request an export of its Customer Data by emailing legal@thecompany.company before termination or within 30 days after it, and we will use reasonable efforts to provide it in a commonly used machine-readable format.

8. Security, Audits, and Incidents

  • Security measures. We maintain administrative, technical, and physical safeguards appropriate to the risk, including encryption in transit and at rest, role-based access controls, logging and monitoring, isolated sandbox environments, secret management, and incident response procedures.
  • Assessments. No more than once per 12 months, Customer may request a written summary of our security practices. Where Applicable Data Protection Law gives Customer a right to assess our compliance, Customer may do so at its own expense, limited to the Personal Information processed for Customer, on reasonable notice, during business hours, and subject to confidentiality; a written summary satisfies that right unless the law requires more.
  • Security Incidents. We will notify Customer without undue delay after confirming a Security Incident affecting Customer's Personal Information, as required by Applicable Data Protection Law, and will provide the information reasonably available to us that Customer needs to meet its own notification obligations.

9. Customer Obligations

Customer represents and warrants that it has, and will maintain, all rights, notices, and consents required to connect Customer Data to the Application and to authorize the processing described in this DPA, including processing under Section 4, and that its instructions comply with Applicable Data Protection Law. Customer is responsible for the security of its own credentials, devices, and Connected Services, and for configuring permissions, tool policies, and approval requirements appropriate to the sensitivity of the data it connects.

10. General

  • Precedence. This DPA controls over conflicting terms of the Agreement with respect to Personal Information. Section 5 of the Application Terms controls over this DPA with respect to training.
  • Liability. Each party's liability under this DPA is subject to the exclusions and limitations in the Agreement.
  • Changes. We may update this DPA to reflect changes in Applicable Data Protection Law or our practices. Material changes follow the notice process in the Agreement.
  • Governing law and disputes. As stated in the Agreement.
  • Jurisdictions outside the United States. The Application is offered to customers in the United States. We do not represent that this DPA satisfies the requirements of laws outside the United States, including the GDPR or UK GDPR. Customers subject to those laws should not connect data governed by them without a separate written agreement.

Contact