ROGA AI.

Legal

Data Processing Agreement

Effective date: 26 August 2026

This Data Processing Agreement (“DPA”) forms part of every Statement of Work between ROGA AI LIMITED, registered in Gibraltar under Company No. 125994, Unit G02, Eurocity, Europort Avenue, Gibraltar GX11 1AA (the “Provider”, “we”) and the client (the “Client”, “you”) under which the Provider processes personal data on the Client's behalf. It implements Article 28 of the GDPR.

It applies as published and needs no signature; a Statement of Work may complete Annex I for the engagement and select the options in Annex IV. To execute a countersigned copy, write to contact@rogaai.com.

1. Parties, roles and scope

1.1 For Client Personal Data (defined below) the Client is the controller — or, where the Client itself acts for another controller, a processor whose instructions bind the Provider — and the Provider is the processor. The Provider processes Client Personal Data only on the Client's documented instructions and never for its own purposes.

1.2 This DPA does not apply to the personal data of the Client's own staff with whom we correspond, or to visitors of rogaai.com, for which the Provider is the controller under the Privacy Policy. It does not apply to ROGA Labs products, including The AI CMO, which have their own data processing agreements published on each product's site.

1.3 Where the law applicable to the Client requires processor terms this DPA does not contain, the parties execute a supplemental DPA before the relevant processing begins; the supplemental DPA prevails to the extent of the additional terms.

2. Definitions

Data Protection Laws: the Gibraltar GDPR and Data Protection Act 2004, the EU GDPR (Regulation (EU) 2016/679), the UK GDPR and Data Protection Act 2018, the ePrivacy rules implementing Directive 2002/58/EC, and any other data protection law applicable to the processing.

Client Personal Data: personal data the Client makes available to the Provider for an engagement — customer and contact lists, CRM and transaction records, analytics and behavioural data, support and communication transcripts, datasets supplied for a software build or model training, and personal data contained in briefs, uploads and deliverables.

End Users: the Client's customers, subscribers, leads, website and app users, employees, or other individuals whose data is contained in Client Personal Data.

Sub-processor: a third party engaged by the Provider to process Client Personal Data.

Personal Data Breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Client Personal Data.

Instructions: the Statement of Work, this DPA, and the Client's further documented instructions.

Controller, processor, personal data, processing, data subject and supervisory authority have the meanings in the GDPR.

3. Details of the processing

The subject matter, duration, nature and purpose of the processing, the categories of data subjects and of personal data, and the retention are set out in Annex I and completed for each engagement in its Statement of Work. The Provider processes Client Personal Data for the sole purpose of delivering the services described there.

4. Our obligations as processor

The Provider shall:

  • process Client Personal Data only on the Client's Instructions, unless required to do otherwise by law, in which case it informs the Client of that requirement before processing unless the law prohibits it;
  • inform the Client without delay if, in its opinion, an Instruction infringes Data Protection Laws — without an obligation to review the Client's lawful basis;
  • ensure that every person authorised to process Client Personal Data is bound by confidentiality and trained in data protection on joining and annually;
  • implement and maintain the technical and organisational measures in Annex II, and not reduce their overall level of protection during the term;
  • not use Client Personal Data, or content or models derived from it, to train, fine-tune or improve AI models for its own or any third party's benefit, and engage model providers only under terms that exclude such use — unless the Statement of Work expressly provides for a training arrangement, in which case the resulting model is the Client's;
  • not sell Client Personal Data, combine it with data of other clients, or use it for advertising or any purpose of its own;
  • engage Sub-processors only as Section 6 provides;
  • assist the Client as Sections 8 and 9 provide;
  • delete or return Client Personal Data as Section 11 provides;
  • make available the information necessary to demonstrate compliance with Article 28 GDPR and allow audits as Section 10 provides.

5. Your obligations as controller

The Client is responsible for, and warrants:

  • establishing and documenting a lawful basis for every purpose for which it instructs the Provider to process Client Personal Data;
  • giving End Users the information Articles 12–14 GDPR require — its own privacy notice — including the use of the Provider as processor and any profiling, personalisation or direct marketing the engagement involves;
  • obtaining and recording any consent the law requires: for non-essential cookies and tracking on its properties, for marketing by e-mail, SMS, push or messaging channels, and for any profiling where explicit consent is required;
  • the accuracy and lawfulness of the data it provides, and for not making special categories of personal data available without the Provider's prior written agreement;
  • supplying only the fields the engagement needs, pseudonymised where the purpose allows;
  • carrying out any data protection impact assessment or prior consultation its processing requires (Section 8.3), and the decisions its outcome calls for;
  • responding to data subjects and supervisory authorities as controller, with the Provider's assistance.

6. Sub-processors

6.1 The Client gives a general authorisation for the Provider to engage the Sub-processors listed in Annex III and those named in the Statement of Work.

6.2 The Provider gives the Client at least 30 days' notice before adding or replacing a Sub-processor that will process Client Personal Data, by e-mail to the Client's named contact and by updating the published register, stating the name, location, purpose and categories of processing.

6.3 The Client may object within that period on reasonable, documented data-protection grounds. The parties will discuss the objection in good faith; if the Provider cannot offer a reasonable alternative within 30 days, the Client may terminate the affected services without penalty and with a pro-rata refund of prepaid fees for work not performed.

6.4 The Provider imposes on each Sub-processor, by written contract, data-protection obligations equivalent to those in this DPA, checks its security assurance before engagement and annually, and remains fully liable to the Client for the Sub-processor's performance.

7. International transfers

The Provider is established in Gibraltar. Where Client Personal Data is transferred to a Sub-processor in a country without an adequacy decision, the transfer is made under the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914, with the UK International Data Transfer Addendum where UK GDPR applies) or under the EU–US Data Privacy Framework where the Sub-processor is certified, together with the measures in Annex II. Where the Client transfers Client Personal Data to the Provider from the EEA or the UK, the parties incorporate the Standard Contractual Clauses (Module Two: controller to processor; Module Three where the Client is itself a processor) by reference, with the Client as data exporter, the Provider as data importer, the optional docking clause, the option 2 general authorisation of Sub-processors with the notice period in Section 6.2, Gibraltar law and courts for clauses 17 and 18 unless the Client's establishment requires an EU Member State, and Annexes I–III of this DPA as the Clauses' annexes. Every cross-border transfer is recorded with its legal basis in the Provider's processing record. Copies of the executed mechanisms are available on request.

8. Assistance: data subject requests, impact assessments

8.1 Requests from End Users

If an End User addresses a request to the Provider concerning Client Personal Data, the Provider forwards it to the Client within three business days, does not respond to the End User on the substance unless the Client instructs it or the law requires it, and provides the technical assistance the Client needs to answer within the legal time limit: exports of a person's data, deletion, restriction, correction, an explanation of any segmentation or scoring applied to the person, and enforcement of an objection to direct marketing.

8.2 Articles 32–36

The Provider assists the Client in meeting its obligations on security, breach notification, data protection impact assessments and prior consultation, taking into account the nature of the processing and the information available to the Provider.

8.3 Data protection impact assessments

Where the Client's intended use — systematic monitoring of behaviour, profiling, personalisation for a vulnerable or regulated audience, large-scale combination of data sets, or training a model on personal data — calls for a data protection impact assessment, the Provider supplies, on request and before go-live, a description of the processing operations, data flows, model providers, retention and security measures sufficient for the assessment, and reasonable cooperation with any consultation of a supervisory authority.

9. Personal data breaches

9.1 The Provider notifies the Client of a Personal Data Breach without undue delay and no later than 48 hours after confirming it, by e-mail to the Client's named contact and any security contact named in the Statement of Work.

9.2 The notification describes, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a point of contact; information not yet available is provided as it becomes available. The Provider contains affected systems within 30 minutes of confirmation where feasible, preserves evidence, cooperates with the Client, and delivers a post-incident review within 10 business days.

9.3 Notification is not an admission of fault or liability. The Client is responsible for any notification to supervisory authorities and data subjects; the Provider does not notify them on the Client's behalf unless instructed or required by law.

10. Audits and evidence

10.1 The Provider makes available, on request and under confidentiality, its current SOC 2 Type II report (or, until the first report is issued, the auditor's letter of engagement and the policies in force), its Trust Center at trust.inc/roga-ai-limited, penetration test summaries, and answers to reasonable security questionnaires. This evidence satisfies the audit right in the ordinary course.

10.2 Where that evidence is insufficient to demonstrate compliance with this DPA, or after a Personal Data Breach, the Client or an independent auditor bound by confidentiality may audit the Provider's relevant systems and records once in any 12-month period, on at least 30 days' written notice, during business hours, with a scope agreed in advance and without unreasonable disruption. The Client bears the audit's costs unless it reveals a material breach of this DPA. Findings are confidential.

11. Return and deletion

11.1 On termination or expiry of the Statement of Work, the Client may request the return of Client Personal Data in a machine-readable format within 30 days.

11.2 After that period — or earlier on the Client's instruction — the Provider deletes Client Personal Data from its systems within 30 days, including copies at Sub-processors and data derived from it (segments, scores, generated content, working files), and from backups within 90 days as they expire, using secure-wipe or crypto-erasure. Each disposal is logged. The Provider confirms deletion in writing on request.

11.3 The Provider may retain Client Personal Data only to the extent and for as long as the law requires, and only for that purpose; opt-out records are kept so that opted-out persons stay excluded.

12. Regulated sectors and high-risk processing

Where the Client operates in a regulated sector — gaming and betting, financial services, health, or another sector with its own marketing or data rules — or where the engagement involves systematic monitoring of behaviour, profiling of End Users, or training a model on personal data, the following apply in addition:

  • Lawful basis and consent. The Client determines and documents the lawful basis for personalisation and profiling, including explicit consent where Article 22 GDPR or sector rules require it.
  • Human oversight. No automated action reaches End Users without review by an accountable person where the law, a regulator or the Client's own policies require it. Every deliverable that affects individuals is reviewed by a named person before use.
  • Exclusions. Self-exclusion, cooling-off, unsubscribe and other suppression lists supplied by the Client are honoured in every campaign and system the Provider operates; the Client keeps them current.
  • Model, region and retention. The Client may fix in the Statement of Work the model provider, the model, the processing region and zero-retention routing (Annex IV).
  • Impact assessment before go-live. The parties cooperate under Section 8.3 before profiling-based personalisation or a model trained on personal data goes into production.
  • No special-category inference. Models and systems are not instructed to infer special categories of personal data, including health or financial vulnerability, and the Client must not instruct them to.

13. Liability, term, precedence, governing law

13.1 Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service and the Statement of Work, except that nothing limits liability that cannot be limited under Data Protection Laws.

13.2 This DPA applies for as long as the Provider processes Client Personal Data, and survives termination of the Statement of Work until deletion under Section 11 is complete.

13.3 In a conflict, this DPA prevails over the Statement of Work and the Terms of Service for the processing of Client Personal Data; the Standard Contractual Clauses, where they apply, prevail over this DPA.

13.4 This DPA is governed by the laws of Gibraltar and subject to the exclusive jurisdiction of the courts of Gibraltar, save where Data Protection Laws or the Standard Contractual Clauses require otherwise for a data subject or supervisory authority.

13.5 The Provider may update this DPA to reflect changes in law or its services; changes that reduce the Client's protections take effect only with 30 days' notice, and each version is dated and archived.

Annex I. Description of the processing

Completed for each engagement in its Statement of Work. The standard description:

ItemROGA Marketing engagementsROGA Technology engagements
Subject matterStrategy, content, campaigns, performance marketing, SEO, automation and analytics delivered for the ClientDesign, development, training, deployment and operation of AI-native applications, autonomous systems and custom models for the Client
DurationTerm of the Statement of Work plus the return and deletion period in Section 11Same
Nature and purposeCollection, organisation, analysis, segmentation, generation of content, transmission (sends), reporting and deletion, for the Client's marketing and customer communicationCollection, storage, structuring, analysis, training and evaluation, inference, transmission and deletion, to build and operate the systems the Client commissioned
Data subjectsThe Client's customers, subscribers, leads, website and app visitors; the Client's staff insofar as they appear in the dataIndividuals whose data is contained in the datasets, systems and workflows in scope — customers, users, employees, suppliers
Personal dataIdentifiers (name, e-mail, phone, customer IDs, pseudonymous identifiers); contact and profile attributes; transactional data; behavioural and engagement data; consent, preference and suppression records; content of communicationsAs defined in the Statement of Work — typically identifiers, business records, interaction logs and free-text content; special categories only where expressly agreed in writing
Special categoriesNone, unless expressly agreed in writingNone, unless expressly agreed in writing
FrequencyContinuous, for the durationContinuous, for the duration
RetentionAs set in the Statement of Work and Section 11As set in the Statement of Work and Section 11; models trained on Client data are delivered to the Client and deleted from the Provider's systems
Sub-processorsAnnex III plus those named in the Statement of WorkAnnex III plus those named in the Statement of Work

Statement of Work fields: named Client contact and security contact; processing region; model provider, model and retention option; sector-specific requirements; special categories, if any; engagement-specific tools and Sub-processors.

Annex II. Technical and organisational measures

  • Encryption: TLS 1.2+ for all data in transit, weak ciphers and protocols disabled, HSTS enabled where supported; provider-managed encryption at rest for storage, databases and backups; keys generated and held in a managed key service, never in source control, rotated at least annually or on suspected compromise, with access logged.
  • Identity and access: least-privilege, role-based access for the Provider's staff protected by multi-factor authentication; access to Client Personal Data granted on need, reviewed quarterly and logged; administrative access to Restricted data logged; access revoked within 48 hours at offboarding.
  • Data classification and handling: four-level scheme (Public, Internal, Confidential, Restricted); Client Personal Data handled as Confidential or Restricted; transfers only over TLS, SFTP, VPN or end-to-end encrypted channels; external sharing of Restricted data only under contract and with management approval; outbound transfers of Restricted data logged and retained one year.
  • Secure development: version-controlled code with review; dependency and vulnerability scanning in the pipeline; environment separation; monthly external and quarterly internal vulnerability scans; severity-based patch timelines (critical within 7 days, high within 30, medium within 90); penetration testing at least annually and for major releases.
  • Secure configuration: documented baselines for cloud services and endpoints; configuration backed up before changes; full-disk encryption on all devices that access Client Personal Data.
  • Logging and monitoring: centralised security logging with alerting; logs retained 90 days online and one year in archive; quarterly log review.
  • Backups and continuity: daily encrypted backups of critical data retained 30 days online in a geographically separate location; restore permissions limited to named roles and every restore logged; quarterly restore tests against documented RTO/RPO targets; a maintained business continuity and disaster recovery plan with an appointed Incident Commander, exercised annually.
  • Incident response: a documented process with Incident Commander, Technical Lead, Communications Lead and Scribe; internal reporting within one hour of discovery; containment within 30 minutes of confirmation; Client notification under Section 9; post-incident review within 10 business days with tracked corrective actions.
  • Vendor management: central vendor inventory tiered by risk; Sub-processors assessed before engagement and annually; providers that handle Client or Restricted data must hold SOC 2 Type II or equivalent assurance; contracts include confidentiality, breach-notification, audit and data-return clauses; integrations and tokens removed within 48 hours at offboarding.
  • People: confidentiality undertakings; background screening proportionate to role; security and privacy training on joining and annually with completion tracked; a documented sanctions process; offboarding with access revocation.
  • Data lifecycle: a retention schedule by record type; quarterly reviews with anything past retention queued for disposal within 30 days; secure-wipe or crypto-erasure for electronic data, certified destruction for media; every disposal logged.
  • Privacy operations: a record of processing activities; a data-subject request workflow with identity verification and a restricted log; consent records with timestamp and method; preference changes propagated within five business days.
  • Governance and assurance: a designated Security & Privacy Owner with a documented backup; annual policy review and sign-off; risk register reviewed quarterly; a SOC 2 Type II examination in progress under a continuous compliance programme, with evidence published to the Trust Center.

Annex III. Sub-processors

Standing Sub-processors that may process Client Personal Data in any engagement:

Sub-processorPurposeLocationAssurance
Google Cloud / Google WorkspaceCloud infrastructure, storage, e-mail, documents and collaboration used to deliver engagementsEU and United StatesSOC 2 Type II, ISO 27001
Vercel Inc.Hosting of web properties and applications built or operated for the Client, where the Statement of Work so providesUnited States (edge network worldwide)SOC 2 Type II, ISO 27001
AI model providers — Anthropic, OpenAI, GoogleModel requests during engagements, limited to the fields the task needs, under terms excluding retention beyond the request and any training; provider and region selectable under Annex IVUnited States / EU, per engagementSOC 2 Type II

Engagement-specific tools — the Client's CRM, advertising and analytics platforms, e-mail and messaging providers, cloud accounts, and any additional model or data provider — are named in the Statement of Work. Platforms the Client connects under its own account act under the Client's own authorisation and terms and are the Client's processors, not ours. Comp AI (our compliance platform) processes the Provider's staff and control data, not Client Personal Data.

Annex IV. Enterprise options

Selectable in the Statement of Work or by the Client's written instruction, at no change to this DPA:

  • Processing region: EU-only processing and storage for the engagement.
  • Model pinning: a named model provider and model; zero-retention routing at the provider; exclusion of specific providers; or no use of third-party models at all.
  • Human oversight: mandatory approval by named Client roles for sends, campaign changes, personalisation and production deployments; audit log export.
  • Sector controls: self-exclusion list synchronisation, cooling-off enforcement, frequency caps, and content review rules for regulated advertising.
  • Client-hosted delivery: systems built and operated inside the Client's own cloud accounts, so Client Personal Data never leaves the Client's environment.
  • Assurance: annual SOC 2 Type II report delivery, penetration test summaries, and a named security contact on each side.
  • Deletion: written certificate of deletion at termination.

To execute this DPA with a Statement of Work, or to request a countersigned copy, write to contact@rogaai.com.