Data Processing Agreement
GDPR Article 28 agreement between Chipo (Processor) and enterprise clients (Controller).
Last updated: [EFFECTIVE_DATE]
1. Parties & Purpose
Chipo acts as data processor for enterprise clients and as data controller for contributors. This DPA governs the processor relationship under GDPR Article 28.
This Data Processing Agreement ("DPA") is entered into between:
- Processor: [COMPANY_LEGAL_NAME], a private limited company registered in the Netherlands (KvK [COMPANY_REGISTRATION_NUMBER]), [COMPANY_ADDRESS] ("Chipo"); and
- Controller: the enterprise client identified in the applicable Order Form ("Client").
This DPA forms part of the agreement between Chipo and Client for the provision of dataset licensing services ("Main Agreement") and is incorporated into that agreement by reference. In the event of conflict, this DPA prevails with respect to data protection matters.
This DPA is entered into pursuant to Article 28 of the GDPR, which requires that processing by a processor be governed by a binding contract.
Dual-role note: Chipo operates in two distinct data controller/processor capacities: (a) Chipo is an independent data controller with respect to the personal data of its contributors, who submit content under GDPR consent; and (b) Chipo acts as a data processor with respect to the Client when delivering, storing, and providing access to licensed datasets on the Client's behalf. This DPA governs only the latter relationship. Client processes the licensed datasets as an independent data controller for its own AI training purposes.
2. Subject Matter
The subject matter is audio, video, images, text, and metadata in licensed datasets. Chipo stores and delivers; Client does the AI training as controller.
The subject matter of the processing under this DPA is:
- Data categories: audio recordings, video recordings, images, text submissions, and associated metadata (language, dialect, accent, geographic region, contributor age group, task category, timestamp) contained in datasets licensed to Client.
- Data subjects: Chipo contributors who have consented to the inclusion of their submissions in datasets for the use case categories applicable to Client's licence.
- Nature and purpose of processing: storage, hosting, delivery, and access control for licensed datasets. Client receives access to datasets via the Chipo API or secure download portal. Client is the independent data controller for all AI training, model development, and related processing it performs on the licensed datasets.
- Duration: the duration of the Main Agreement, plus any retention period required by applicable law or as set out in Section 11 of this DPA.
3. Processing Instructions
Chipo processes personal data only on documented instructions from Client. If an instruction breaches GDPR, Chipo will notify Client before proceeding.
Chipo shall process personal data only on the documented instructions of Client, including with regard to transfers of personal data to a third country or international organisation, unless required to do so by EU or EU Member State law to which Chipo is subject. In such cases, Chipo shall inform Client of that legal requirement before processing, unless that law prohibits such information on grounds of public interest.
Client's instructions are set out in this DPA and in the applicable Order Form. Client may issue further written instructions from time to time. Chipo shall:
- process data only for the purposes described in Section 2;
- notify Client without undue delay if, in Chipo's opinion, an instruction infringes the GDPR or other applicable EU or Member State data protection provisions; and
- not process data for any purpose beyond the scope of this DPA without Client's prior written consent.
4. Confidentiality
All Chipo personnel authorised to process Client's data are bound by written confidentiality obligations.
Chipo shall ensure that all personnel authorised to process personal data under this DPA are subject to written confidentiality obligations that survive termination of their employment or engagement.
Chipo shall limit access to personal data to those personnel who require access to fulfil Chipo's obligations under the Main Agreement and this DPA on a need-to-know basis.
Chipo shall not disclose personal data to any third party (other than sub-processors as permitted under Section 6) without Client's prior written consent, except as required by applicable law.
5. Security
We use AES-256 at rest, TLS 1.2+ in transit, RBAC, MFA for admins, audit logging, and an incident response plan.
Chipo shall implement and maintain appropriate technical and organisational security measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include, at a minimum:
- Encryption at rest: all dataset storage is encrypted using AES-256 encryption.
- Encryption in transit: all data transmitted between Chipo systems and Client systems is encrypted using TLS 1.2 or higher.
- Access control: role-based access control (RBAC) is implemented to ensure that only authorised personnel can access datasets and systems.
- Multi-factor authentication (MFA): MFA is enforced for all administrative access to production systems containing personal data.
- Audit logging: access to datasets is logged. Logs are retained for a minimum of 12 months and are available for audit purposes.
- Incident response: Chipo maintains a documented incident response plan. Personnel are trained on data breach identification and response.
- Vulnerability management: regular security assessments and penetration testing are conducted on production infrastructure.
6. Sub-processors
Current sub-processors are listed in this section. We give 30 days' notice before adding or replacing any sub-processor and impose equivalent data protection obligations on all of them.
Client provides Chipo with general authorisation to engage sub-processors, subject to the conditions set out in this Section.
Current sub-processors engaged by Chipo include:
- [SUB_PROCESSOR_LIST]
By entering into this DPA, Client approves the sub-processors listed above as at the DPA effective date.
Changes: Chipo shall give Client at least 30 days' written notice before adding or replacing a sub-processor. Client may object to the proposed change within 14 days of the notice by sending written notice to legal@chipo.ai specifying the grounds for objection. If Client objects and the parties cannot resolve the objection, Client may terminate the Main Agreement on reasonable notice without penalty.
Sub-processor obligations: Chipo shall impose data protection obligations on each sub-processor that are equivalent to those set out in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organisational measures. Chipo remains fully liable to Client for the performance of sub-processors' obligations under this DPA.
7. Data Subject Rights
Chipo forwards data subject requests to Client within 5 business days. We will not respond to requests without Client's consent.
Taking into account the nature of the processing, Chipo shall assist Client by appropriate technical and organisational measures to fulfil Client's obligations to respond to requests from data subjects exercising their GDPR rights.
Where a data subject contacts Chipo directly with a request to exercise their rights (e.g., a right of access, erasure, or portability), Chipo shall:
- forward the request to Client within 5 business days of receipt;
- not respond to the request or take any action with respect to it without Client's prior written consent, except where required by applicable law; and
- assist Client in responding to the request to the extent that Chipo has the technical ability to do so.
Client is responsible for ensuring that all data subject requests are handled in compliance with applicable data protection law within the statutory timelines.
8. Data Breach Notification
We notify you within 72 hours of discovering a breach, including its nature, affected categories, likely consequences, and remediation measures.
Chipo shall notify Client without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting data covered by this DPA.
The breach notification shall include, to the extent available at the time of notification:
- a description of the nature of the breach, including, where possible, the categories and approximate number of data subjects concerned, and the categories and approximate number of records concerned;
- the name and contact details of the data protection officer or other point of contact from whom more information can be obtained;
- a description of the likely consequences of the breach; and
- a description of the measures taken or proposed to address the breach, including measures to mitigate its possible adverse effects.
Where it is not possible to provide all information within 72 hours, Chipo will provide the information available and supplement it as soon as practicable thereafter.
Client is responsible for notifying the relevant supervisory authority and affected data subjects in accordance with applicable law, unless Client notifies Chipo that Client will not be making such notifications.
9. International Transfers
Primary processing is in the EEA. Any non-EEA transfers are covered by Standard Contractual Clauses, available at legal@chipo.ai.
Chipo's primary data processing infrastructure is located within the European Economic Area (EEA). Chipo shall not transfer personal data outside the EEA (or to a country not covered by an EU adequacy decision) without Client's prior written consent and the implementation of appropriate transfer safeguards.
Where transfers to non-EEA sub-processors are necessary, Chipo ensures that such transfers are made pursuant to:
- Standard Contractual Clauses (SCCs) adopted by the European Commission; or
- Another lawful transfer mechanism under Chapter V of the GDPR.
Copies of applicable SCCs and transfer impact assessments are available upon written request to legal@chipo.ai. Chipo will respond to such requests within 14 business days.
10. Audit Rights
Client may request an audit with 30 days' written notice, once per year maximum. Documentation review comes first; on-site audits at Client's expense.
Chipo shall make available to Client all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR, and shall allow for and contribute to audits, including inspections, conducted by Client or an auditor mandated by Client, subject to the following conditions:
- Written request: audit requests must be made in writing to legal@chipo.ai with at least 30 days' advance notice.
- Frequency: Client may conduct a maximum of one audit per calendar year, unless there are reasonable grounds to suspect a material data breach or non-compliance.
- Documentation first: Chipo will first provide all requested documentation (security certifications, audit reports, policy documentation). An on-site inspection may be requested only if documentation review does not adequately address Client's concerns.
- Cost: audits are conducted at Client's expense, including reasonable time costs for Chipo personnel required to support the audit.
- Confidentiality: audit findings must be kept confidential and may only be used by Client for compliance purposes under this DPA.
11. Deletion on Termination
On termination, Client has 30 days to elect return or deletion of data, and we have 60 days to execute. Written confirmation is provided.
Upon expiry or termination of the Main Agreement, Chipo shall, at Client's election:
- Return: transfer to Client a complete copy of all personal data held by Chipo on Client's behalf in a structured, commonly used, machine-readable format; or
- Delete: securely delete all personal data held by Chipo on Client's behalf, including all copies held by sub-processors.
Client must notify Chipo of its election within 30 days of the termination date. Chipo shall execute the return or deletion within 60 days of receiving Client's election, and shall provide written confirmation of completion.
To the extent that Chipo is required by applicable EU or Member State law to retain personal data beyond the deletion period, Chipo shall inform Client of such requirements and the legal basis, and shall continue to protect the retained data under the terms of this DPA.
Chipo's obligations as an independent controller with respect to contributor personal data (consent records, identity data, financial records) are not affected by the termination of the Main Agreement.
12. Governing Law
This DPA is governed by Dutch law. Disputes go to the courts of Amsterdam. GDPR applies regardless as directly effective EU law.
This DPA and any non-contractual obligations arising out of or in connection with it are governed by the laws of the Netherlands, without regard to its conflict of law principles.
Any dispute arising out of or in connection with this DPA shall be subject to the exclusive jurisdiction of the courts of Amsterdam, the Netherlands.
GDPR (Regulation (EU) 2016/679) applies as directly effective EU law regardless of any governing law choice made in this DPA or the Main Agreement.
For DPA-related questions, contact legal@chipo.ai.
