Enterprise

Data Processing Agreement

GDPR Article 28 agreement between Chipo (Processor) and enterprise clients (Controller).

Last updated: [EFFECTIVE_DATE]

1. Parties & Purpose

Chipo acts as data processor for enterprise clients and as data controller for contributors. This DPA governs the processor relationship under GDPR Article 28.

2. Subject Matter

The subject matter is audio, video, images, text, and metadata in licensed datasets. Chipo stores and delivers; Client does the AI training as controller.

3. Processing Instructions

Chipo processes personal data only on documented instructions from Client. If an instruction breaches GDPR, Chipo will notify Client before proceeding.

4. Confidentiality

All Chipo personnel authorised to process Client's data are bound by written confidentiality obligations.

5. Security

We use AES-256 at rest, TLS 1.2+ in transit, RBAC, MFA for admins, audit logging, and an incident response plan.

6. Sub-processors

Current sub-processors are listed in this section. We give 30 days' notice before adding or replacing any sub-processor and impose equivalent data protection obligations on all of them.

7. Data Subject Rights

Chipo forwards data subject requests to Client within 5 business days. We will not respond to requests without Client's consent.

8. Data Breach Notification

We notify you within 72 hours of discovering a breach, including its nature, affected categories, likely consequences, and remediation measures.

9. International Transfers

Primary processing is in the EEA. Any non-EEA transfers are covered by Standard Contractual Clauses, available at legal@chipo.ai.

10. Audit Rights

Client may request an audit with 30 days' written notice, once per year maximum. Documentation review comes first; on-site audits at Client's expense.

11. Deletion on Termination

On termination, Client has 30 days to elect return or deletion of data, and we have 60 days to execute. Written confirmation is provided.

12. Governing Law

This DPA is governed by Dutch law. Disputes go to the courts of Amsterdam. GDPR applies regardless as directly effective EU law.

Questions about this document? Email legal@chipo.ai