Skip to content

Data Processing Agreement

Version 1.0 · Effective from 5 October 2026

§ 1. Parties and conclusion of the agreement

1. This Agreement is concluded between the customer using a team Workspace, training products, the API or embedding (the "Controller") and Custom Service Arleta Marczyńska, ul. Bielska 107, 32-652 Bulowice, Poland, NIP (tax ID) 5492373228 (the "Processor").

2. The Agreement is concluded upon acceptance of the Terms of Service by a person acting on behalf of the Controller and remains in force for as long as the Processor processes personal data on behalf of the Controller. The Agreement forms part of the contract for the provision of services (the Terms). At the Controller's request, the parties may sign it in documentary or written form.

3. Matters not governed by this Agreement are subject to Regulation (EU) 2016/679 (GDPR) and the Terms. In the event of a conflict concerning data protection, this Agreement prevails.

§ 2. Subject matter, nature and purpose of processing

1. The Controller entrusts the Processor with the processing of personal data for the purpose and to the extent necessary to provide the services of the Service: running Workspaces, conducting exercises with the AI Counterpart, preparing Reports and certificates, assigning exercises, reporting results, sharing content via link, embedding and the API, and sending webhooks to the address specified by the Controller.

2. Nature of processing: collection, storage, organisation, consultation, analysis using artificial intelligence models, disclosure to persons authorised by the Controller, erasure.

3. Categories of data subjects: members of the Controller's Workspaces, Learners, participants in training embedded on the Controller's websites, persons whose data is contained in uploaded materials or recordings.

4. Types of data: email address, display name, first name and surname on a certificate, role in the Workspace, content of practice conversations and transcripts, results, Reports and comments, assignments and deadlines, the person identifier assigned by the Controller (e.g. in an integration), data from materials and recordings uploaded by the Controller. The Agreement does not cover special categories of data. The Controller does not enter them into the Service.

5. Duration of processing: for the period during which the services are used, taking into account the retention periods set by the Controller in the Workspace (by default: transcripts 365 days, uploaded recordings 30 days) and § 9.

§ 3. Obligations of the Processor

The Processor:

  1. processes data only on documented instructions from the Controller. The instructions consist of the Terms, this Agreement, the Workspace settings and the actions of persons authorised by the Controller in the Service and via the API. If an instruction infringes the law, the Processor informs the Controller without delay,
  2. ensures that persons authorised to process the data have committed themselves to confidentiality or are under a statutory obligation of confidentiality,
  3. applies the measures under Article 32 GDPR described in the annex,
  4. does not use the data for its own purposes, including for training artificial intelligence models, and does not transfer the data to subprocessors for such purposes,
  5. assists the Controller in responding to requests from data subjects (Articles 15-22 GDPR), in particular through the data export and deletion features in the Service, and forwards to the Controller without undue delay any request mistakenly addressed to the Processor,
  6. assists the Controller in complying with its obligations under Articles 32-36 GDPR, including in data protection impact assessments, by providing the information it holds about how the Service works,
  7. makes available to the Controller the information necessary to demonstrate compliance with Article 28 GDPR.

§ 4. Obligations of the Controller

1. The Controller ensures a legal basis for the processing and fulfils its information obligations towards data subjects, including informing team members of the visibility settings and the purpose of the exercises.

2. If the Controller uses results from the Service in employment matters, it ensures human involvement in the decision and compliance with obligations under employment law and Regulation (EU) 2024/1689 (Artificial Intelligence Act, AI Act). The Service is not intended for making automated decisions in employment matters.

3. The Controller is responsible for the security of API keys, webhook secrets and the addresses to which it directs data, and for the further processing of data received from the Service.

§ 5. Subprocessors

1. The Controller gives general authorisation for the Processor to engage the subprocessors listed on the Subprocessors page.

2. The Processor informs the Workspace owner by email at least 14 days in advance of any intended addition or replacement of a subprocessor. During that time the Controller may raise a reasoned objection. If the parties do not reach agreement, the Controller may terminate the contract for the provision of services with effect from the day before the change and receive a refund of a proportionate part of the fee for the unused period.

3. The Processor imposes on subprocessors data protection obligations no less protective than those in this Agreement and is liable for their actions as for its own.

4. Data is transferred outside the EEA on the basis of an adequacy decision or standard contractual clauses (Articles 45-46 GDPR).

§ 6. Personal data breaches

1. The Processor notifies the Controller of a personal data breach without undue delay, and no later than 48 hours after becoming aware of it, at the email address of the Workspace owner.

2. The notification contains, as far as available: a description of the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken and proposed. Information not available immediately is provided by the Processor in phases.

3. The Processor documents breaches and cooperates with the Controller in remedying them and notifying the supervisory authority.

§ 7. Audit

1. The Controller may verify compliance with this Agreement, in the first instance by means of written questions and documentation, to which the Processor responds within 14 days.

2. Where this is insufficient or a supervisory authority so requires, the Controller may carry out an audit, itself or through an independent auditor bound by confidentiality, with 14 days' prior notice, on business days, no more than once a year unless a breach has occurred. The audit does not cover other customers' data or access to providers' infrastructure, in respect of which the Processor makes available their reports and certifications. The costs of the audit are borne by the Controller.

§ 8. Liability

The liability of the parties is governed by Article 82 GDPR and the Terms. The limitations of liability in the Terms do not apply to fines imposed by a supervisory authority through the fault of the party concerned.

§ 9. End of processing

1. After the provision of services ends, the Controller may export the data within 30 days (export in the Service or on request). The Processor then deletes the data, except for data it is required to retain by law (e.g. billing), and confirms the deletion on request.

2. Data deleted from the database disappears from backups as they rotate at the infrastructure provider.

Annex. Technical and organisational security measures

  • Customer isolation: row-level access policies in the database (Row Level Security) for every table containing Workspace data, tested automatically with every code change.
  • Authentication: sign-in with a one-time email link (passwordless), sessions in HttpOnly and Secure cookies, roles and permissions in the Workspace.
  • Secrets: API keys and invitation, share link and shop tokens stored only as cryptographic hashes. API keys with scopes, expiry dates and automatic invalidation when their author leaves.
  • Encryption: connections over HTTPS only (HSTS), encryption of data at rest by the database and file storage provider.
  • Location: database and serverless functions in the EU (Frankfurt).
  • Application protection: Content Security Policy, a ban on embedding outside permitted domains, rate limits, SSRF protection when sending webhooks and fetching URLs, webhook signatures (HMAC) with replay protection.
  • Confidentiality of scenario content: the hidden instructions of the AI Counterpart never reach the participant's browser.
  • Minimisation: no analytics or tracking, hashes of IP and email addresses in rate-limit counters, logs with automatic removal of secrets and email addresses, voice not recorded.
  • Retention: automatic deletion of conversation content and recordings according to Workspace settings, and of technical data according to fixed periods.
  • Accountability: a log of administrative actions (who, what, when) kept for 2 years.
  • Continuity: daily database backups, ability to roll back application deployments.
  • Changes: code review and automated tests (including security and isolation tests) before every deployment.