Version 1.0 · In force from 4 August 2026
SCHEDULE C
DATA PROCESSING AGREEMENT
(Article 28 GDPR) Version 1.0 · Effective Date: 4 August 2026
This Data Processing Agreement ("DPA") forms an integral part of the Terms of Service (the "Agreement") accepted electronically by the Customer (including by clickwrap acceptance during account registration or online checkout). This document is published at a permanent URL on ONLYAI’s website and is incorporated into the Agreement by reference. It applies between Dostart Ventures Limited ("Processor") and the Customer identified in the applicable electronic Order Form ("Controller").
Capitalized terms not otherwise defined herein shall have the meanings assigned in the Agreement.
1. PURPOSE
1.1 Purpose of this Agreement
The Parties acknowledge that, in connection with the provision of the Services, Processor may Process Personal Data on behalf of Controller.
This DPA establishes the rights and obligations of the Parties in accordance with:
- Article 28 GDPR;
- Chapter V GDPR;
- applicable national implementing legislation;
- other Applicable Data Protection Laws.
The Parties expressly intend that this DPA constitutes the written contract required under Article 28(3) GDPR.
1.2 Contractual Relationship
This DPA supplements the Agreement.
Except where expressly modified herein, all provisions of the Agreement remain in full force and effect.
In the event of conflict:
- Mandatory Data Protection Laws
- This DPA
- Master SaaS Agreement
- remaining Schedules.
2. DEFINITIONS
For purposes of this DPA:
Applicable Data Protection Laws
means all laws governing the Processing of Personal Data applicable to either Party, including GDPR, UK GDPR and applicable national implementing legislation.
Controller
shall have the meaning assigned under Article 4 GDPR.
Processor
shall have the meaning assigned under Article 4 GDPR.
Subprocessor
means any third party engaged by Processor to Process Personal Data on behalf of Controller.
Personal Data Breach
shall have the meaning assigned under Article 4 GDPR.
Processing
shall have the meaning assigned under Article 4 GDPR.
Supervisory Authority
shall have the meaning assigned under Article 4 GDPR.
3. ROLES OF THE PARTIES
3.1 Allocation of Roles
The Parties expressly acknowledge and agree that:
Customer acts exclusively as Data Controller.
ONLYAI acts exclusively as Data Processor.
Nothing contained in the Agreement, this DPA or the Services shall be interpreted as creating:
- Joint Controllers;
- Independent Controllers;
- Agency;
- Fiduciary relationship.
3.2 Controller Responsibilities
Controller shall remain solely responsible for:
determining:
- purposes of Processing;
- legal basis;
- categories of Personal Data;
- categories of Data Subjects;
- retention periods;
- AI configuration;
- communication strategy;
- monetization workflows;
- automated decision parameters;
- compliance with Supported Platform rules.
Processor shall not independently determine any of the foregoing matters.
3.3 No Independent Decision Making
Processor shall not determine:
- why Personal Data is processed;
- whether Personal Data should be collected;
- which individuals should be contacted;
- how long Customer retains Personal Data;
- commercial objectives of Processing.
Processor merely provides configurable software.
4. SUBJECT MATTER OF PROCESSING
Processor Processes Personal Data solely for purposes of providing the Services described in the Agreement.
Processing activities include only those technically necessary for operation of the Services, including:
- hosting;
- storage;
- indexing;
- retrieval;
- organization;
- transmission;
- AI inference;
- workflow execution;
- analytics;
- monitoring;
- backup;
- deletion.
5. DOCUMENTED INSTRUCTIONS
Processor shall Process Personal Data solely:
(a) on Controller's documented instructions;
(b) pursuant to the Agreement;
(c) pursuant to this DPA;
(d) pursuant to Customer configuration settings;
(e) pursuant to documented support requests;
(f) where required by Applicable Law.
The Parties agree that Customer's use of the Services, including Customer-configured workflows, automation rules, prompts, escalation settings, retention settings and operational parameters, shall constitute documented instructions for the purposes of Article 28(3)(a) GDPR.
If Processor reasonably believes that an instruction infringes Applicable Data Protection Laws, Processor shall promptly inform Controller before carrying out such instruction unless prohibited by law.
6. DESCRIPTION OF PROCESSING
Nature of Processing
Processing activities may include:
- collection;
- recording;
- organization;
- storage;
- retrieval;
- consultation;
- AI-assisted generation of communications;
- transmission;
- deletion;
- backup;
- security monitoring.
Purpose
The sole purpose of Processing is to provide the enterprise AI software services described in the Agreement.
Processor shall not Process Personal Data for its own commercial purposes.
Categories of Data Subjects
Depending upon Customer's configuration:
- Customer personnel;
- Authorized Users;
- Creators;
- Fans;
- contractors;
- support personnel.
Categories of Personal Data
Depending upon Customer's use of the Services:
- names;
- usernames;
- profile identifiers;
- communication history;
- uploaded messages;
- uploaded media;
- Creator preferences;
- workflow settings;
- metadata;
- IP addresses;
- browser identifiers;
- device identifiers;
- transaction references;
- system logs.
Special Categories
Controller shall not intentionally submit Special Categories of Personal Data unless strictly necessary and supported by an appropriate legal basis.
Processor does not intentionally require such data for operation of the Services.
7. CONFIDENTIALITY OF PROCESSING
Processor shall ensure that all persons authorized to Process Personal Data:
- are subject to written confidentiality obligations;
or
- are bound by an appropriate statutory duty of confidentiality.
Access to Personal Data shall be limited to personnel with a legitimate business need to perform the Services.
Processor shall maintain role-based access controls and periodically review access privileges.
8. SECURITY OF PROCESSING
Processor shall implement and maintain appropriate technical and organizational measures designed to ensure a level of security appropriate to the risk, taking into account:
- the state of the art;
- implementation costs;
- the nature, scope, context and purposes of Processing;
- the risks to the rights and freedoms of natural persons.
Such measures shall include, where appropriate:
- encryption in transit;
- encryption at rest;
- identity and access management;
- multi-factor authentication;
- logging and monitoring;
- vulnerability management;
- network segmentation;
- secure software development lifecycle;
- backup and disaster recovery;
- security incident response procedures.
The specific measures implemented by Processor are described in the Technical & Organizational Measures Schedule, which forms an integral part of this DPA.
9. ASSISTANCE TO CONTROLLER
9.1 General Assistance
Taking into account the nature of the Processing, the information available to Processor and the functionality of the Services, Processor shall provide commercially reasonable assistance to Controller in enabling Controller to comply with its obligations under Applicable Data Protection Laws.
Such assistance shall be limited to the extent required by Article 28 GDPR and shall not require Processor to assume Controller's statutory responsibilities.
9.2 Data Subject Requests
Where Processor receives a request from a Data Subject relating to Personal Data Processed on behalf of Controller, including requests concerning:
- access;
- rectification;
- erasure;
- restriction of processing;
- portability;
- objection;
- automated decision-making;
- withdrawal of consent,
Processor shall, unless prohibited by Applicable Law:
(a) promptly notify Controller;
(b) refrain from responding directly unless expressly instructed by Controller or legally required to do so;
(c) provide commercially reasonable assistance enabling Controller to respond.
Controller acknowledges that responsibility for determining whether and how to respond to such requests remains solely with Controller.
9.3 Supervisory Authority Communications
Where Processor receives any inquiry, investigation request, audit notice or legally binding communication from a Supervisory Authority relating specifically to Customer Personal Data, Processor shall, unless prohibited by law:
- notify Controller without undue delay;
- cooperate with Controller to the extent reasonably necessary;
- provide information reasonably available to Processor.
Nothing in this Section shall prevent Processor from communicating directly with a Supervisory Authority where required by Applicable Law.
9.4 Data Protection Impact Assessments
Where Controller determines that a Data Protection Impact Assessment ("DPIA") or prior consultation under Articles 35 or 36 GDPR is required, Processor shall provide commercially reasonable information regarding the Services that is reasonably necessary to support Controller's assessment.
Processor shall not be responsible for:
- determining whether a DPIA is required;
- preparing the DPIA;
- determining lawful processing activities;
- making regulatory notifications.
10. PERSONAL DATA BREACHES
10.1 Security Incident Management
Processor shall maintain documented procedures for identifying, investigating, containing and responding to Security Incidents affecting the Services.
Such procedures shall form part of Processor's Information Security Management System.
10.2 Personal Data Breach Notification
Where Processor becomes aware of a confirmed Personal Data Breach affecting Customer Personal Data, Processor shall notify Controller without undue delay after becoming aware of the breach.
The notification shall include, to the extent reasonably available at the time:
(a) a description of the nature of the Personal Data Breach;
(b) the categories of Personal Data affected;
(c) the categories of affected Data Subjects;
(d) the likely consequences of the breach;
(e) measures taken or proposed to address the breach;
(f) contact details for further information.
Where complete information cannot reasonably be provided simultaneously, Processor may provide information in phases as it becomes available.
10.3 Regulatory Notifications
Processor shall not notify any Supervisory Authority or affected Data Subjects regarding Customer Personal Data without Controller's prior written instructions unless such notification is independently required by Applicable Law.
Controller remains solely responsible for determining whether regulatory notification obligations arise under Articles 33 or 34 GDPR.
11. SUBPROCESSORS
11.1 General Authorization
Controller hereby grants Processor a general authorization to engage Subprocessors for the performance of the Services in accordance with Article 28(2) GDPR.
The current list of authorized Subprocessors is maintained in the Subprocessor Register incorporated into the Agreement.
For the avoidance of doubt, Subprocessors may include providers of cloud infrastructure, managed databases, object storage, Supported Platform connectivity, external API services, artificial intelligence routing and inference services, queueing and caching infrastructure, monitoring services and other technical services that Process Customer Personal Data on behalf of Processor.
11.2 Appointment of New Subprocessors
Processor may appoint additional Subprocessors where reasonably necessary for the provision of the Services.
Processor shall provide prior notice of any intended material change to the Subprocessor Register through the Customer Portal, electronic mail or other designated communication channel.
Unless otherwise agreed in the Agreement, Controller shall have thirty (30) calendar days from receipt of such notice to object on reasonable data protection grounds.
If the Parties are unable to resolve Controller's reasonable objections, Controller may terminate the affected Services upon written notice without penalty in respect of the affected Services only.
11.3 Flow-Down Obligations
Processor shall ensure that each Subprocessor is bound by written contractual obligations providing a level of protection for Personal Data that is substantially equivalent to the obligations imposed upon Processor under this DPA.
Processor shall remain responsible for the performance of its Subprocessors to the extent required by Article 28(4) GDPR.
12. INTERNATIONAL TRANSFERS
12.1 General Principle
Processor shall not transfer Personal Data outside the European Economic Area unless such transfer is carried out in accordance with Applicable Data Protection Laws.
12.2 Appropriate Safeguards
Where Personal Data is transferred internationally, Processor shall implement one or more appropriate transfer mechanisms, including where applicable:
- an adequacy decision adopted by the European Commission;
- the Standard Contractual Clauses adopted pursuant to Article 46 GDPR;
- the UK International Data Transfer Addendum;
- another lawful transfer mechanism recognized under Applicable Data Protection Laws.
12.3 Supplementary Measures
Where required by Applicable Data Protection Laws or following applicable regulatory guidance, Processor shall implement supplementary technical, organizational and contractual safeguards appropriate to the risks associated with the relevant international transfer.
13. RETURN AND DELETION OF PERSONAL DATA
13.1 Return of Data
Upon termination or expiration of the Agreement, Controller may, within thirty (30) calendar days, request that Processor make Customer Data available for export in a commercially reasonable electronic format supported by the Services.
The Parties acknowledge that certain system-generated metadata, audit logs, security records and backup archives may not be technically capable of immediate extraction.
13.2 Deletion
Following expiration of the applicable export period, Processor shall securely delete or render permanently inaccessible Customer Personal Data, unless continued retention is required by:
- Applicable Law;
- regulatory obligations;
- legal proceedings;
- legitimate security backup retention cycles.
Deletion shall be performed in accordance with Processor's documented data retention and deletion procedures.
13.3 Residual Copies
Controller acknowledges that Personal Data may continue to exist temporarily within encrypted backup media maintained exclusively for disaster recovery purposes.
Such backup copies:
- shall not be restored except where necessary for disaster recovery;
- shall remain subject to this DPA;
- shall be securely deleted in accordance with Processor's backup retention schedule.
14. AUDITS AND COMPLIANCE INFORMATION
14.1 Demonstration of Compliance
Processor shall make available to Controller information reasonably necessary to demonstrate compliance with Article 28 GDPR.
Such information may include:
- security certifications;
- audit summaries;
- compliance reports;
- independent assurance reports;
- responses to standardized security questionnaires.
Processor may satisfy this obligation by providing generally available compliance documentation where appropriate.
14.2 Customer Audits
Where Controller reasonably believes additional verification is necessary to satisfy its obligations under Applicable Data Protection Laws, Controller may request an audit of Processor's Processing activities.
Any such audit shall:
(a) be conducted no more than once in any twelve (12) month period, unless required by Applicable Law or following a confirmed Personal Data Breach;
(b) be conducted during normal business hours;
(c) be subject to reasonable advance written notice of not less than thirty (30) days;
(d) avoid unreasonable disruption to Processor's business operations;
(e) be limited to information reasonably necessary to verify compliance with this DPA.
Processor may satisfy audit requests through the provision of independent third-party audit reports, certifications or equivalent assurance documentation where such documentation reasonably addresses Controller's audit objectives.
14.3 Confidentiality of Audit Information
All information disclosed during any audit or compliance review shall constitute Processor's Confidential Information and shall be used solely for purposes of verifying compliance with this DPA.
15. LIABILITY
15.1 Application of the Agreement
Except as expressly modified by this DPA, the limitation of liability, exclusion of damages, indemnification provisions and other risk allocation mechanisms contained in the Agreement shall apply equally to this DPA.
Nothing contained in this DPA shall be construed as increasing or expanding Processor's liability beyond that expressly set forth in the Agreement unless such limitation is prohibited under Applicable Data Protection Laws.
15.2 Allocation of Regulatory Responsibilities
The Parties acknowledge that Applicable Data Protection Laws allocate distinct statutory responsibilities between Controllers and Processors.
Accordingly:
(a) Controller shall remain solely responsible for determining the lawfulness of Processing;
(b) Controller shall remain solely responsible for identifying the appropriate legal basis for Processing;
(c) Controller shall remain solely responsible for compliance with transparency obligations under Articles 13 and 14 GDPR;
(d) Controller shall remain solely responsible for responding to Data Subject Requests except to the extent Processor is expressly required to assist under this DPA;
(e) Processor shall remain responsible only for those obligations expressly imposed upon Processors under Applicable Data Protection Laws.
15.3 Regulatory Fines
Each Party shall remain responsible for any administrative fines, penalties or enforcement measures imposed upon that Party by a competent Supervisory Authority to the extent such sanctions arise from that Party's own breach of Applicable Data Protection Laws.
Nothing contained herein shall prevent either Party from pursuing contractual remedies otherwise available under the Agreement.
16. TERM AND TERMINATION
16.1 Commencement
This DPA shall enter into force on the Effective Date of the Agreement.
16.2 Duration
This DPA shall remain in force for so long as Processor Processes Personal Data on behalf of Controller.
16.3 Survival
The following provisions shall survive termination of the Agreement for so long as Processor retains Personal Data pursuant to Applicable Law or Section 13 of this DPA:
- Confidentiality;
- Security of Processing;
- Return and Deletion;
- Liability;
- Audit Information Confidentiality;
- Governing Law;
- Dispute Resolution.
17. CHANGES IN LAW
If any amendment to Applicable Data Protection Laws materially affects the rights or obligations of either Party under this DPA, the Parties shall cooperate in good faith to amend this DPA to the extent reasonably necessary to ensure continued compliance.
Processor may propose reasonable amendments where necessary to reflect:
- new legislation;
- regulatory guidance;
- decisions of the Court of Justice of the European Union;
- decisions of competent Supervisory Authorities;
- approved certification mechanisms;
- new international transfer mechanisms.
No amendment shall materially diminish Controller's statutory rights under Applicable Data Protection Laws.
18. ORDER OF PRECEDENCE
In the event of inconsistency between this DPA and the Agreement solely with respect to matters governed by Applicable Data Protection Laws, this DPA shall prevail.
For all other matters, the Agreement shall prevail.
19. GOVERNING LAW
This DPA shall be governed by the governing law specified in the Agreement unless Applicable Data Protection Laws require otherwise.
20. ANNEXES
The following Annexes form an integral part of this DPA.
- Annex I — Description of Processing Activities
- Annex II — Technical & Organizational Measures
- Annex III — Approved Subprocessors
- Annex IV — International Data Transfers (where applicable)
ANNEX I
DESCRIPTION OF PROCESSING ACTIVITIES
(Article 28(3) GDPR)
A. Parties
Controller
The Customer identified in the applicable electronic Order Form and associated account records.
Processor
Dostart Ventures Limited.
B. Subject Matter of Processing
Provision of enterprise AI-assisted communication software and related cloud services.
C. Duration of Processing
For the duration of the Agreement and any applicable retention period required under this DPA.
D. Nature and Purpose of Processing
Processing activities may include:
- hosting Customer Data;
- storage;
- indexing;
- AI-assisted message generation;
- workflow execution;
- analytics;
- notification processing;
- system administration;
- technical support;
- disaster recovery;
- security monitoring;
- deletion.
The Processing is performed solely to provide the Services described in the Agreement.
E. Categories of Data Subjects
Depending on Customer's use of the Services:
- Customer personnel;
- Authorized Users;
- Creator accounts;
- Fans interacting with Customer through Supported Platforms;
- Contractors;
- Support personnel.
F. Categories of Personal Data
The categories of Personal Data may include:
Identification Data
- Name
- Username
- Profile ID
- Account Identifier
Communication Data
- Chat messages
- Conversation history
- Communication preferences
- Creator configuration
Media Data
- Images
- Videos
- Uploaded files
Technical Data
- IP address
- Browser information
- Device identifiers
- Session identifiers
- Authentication logs
- API logs
Operational Data
- Workflow settings
- AI configuration
- Prompt parameters
- Metadata
- Audit logs
Processor Processes only those categories of Personal Data submitted by Controller.
G. Special Categories of Data
Processor does not intentionally require Special Categories of Personal Data.
Controller shall not intentionally submit such data unless supported by an appropriate legal basis.
H. Processing Operations
Processing operations may include:
- collection;
- recording;
- organization;
- structuring;
- storage;
- retrieval;
- consultation;
- use;
- AI-assisted generation;
- transmission;
- restriction;
- deletion;
- destruction.
ANNEX II
TECHNICAL & ORGANIZATIONAL MEASURES
The Technical & Organizational Measures applicable to the Services are described in the standalone Technical & Organizational Measures Schedule, which forms part of the Agreement.
ANNEX III
APPROVED SUBPROCESSORS
Processor may engage the Subprocessors identified in the current Subprocessor Register maintained under the Agreement.
The current register includes, where applicable:
- cloud and hosting infrastructure providers;
- Supported Platform integration and API connectivity providers;
- managed database providers;
- object storage and media storage providers;
- artificial intelligence routing, orchestration and inference providers;
- underlying AI model providers;
- queueing, caching and asynchronous task processing providers;
- network security and content delivery providers;
- monitoring and diagnostics providers;
- communications providers;
- analytics providers; and
- other infrastructure providers Processing Customer Personal Data on behalf of Processor.
The register shall be maintained separately to facilitate operational updates without requiring amendment of this DPA.
ANNEX IV
INTERNATIONAL DATA TRANSFERS
Where Processor transfers Personal Data outside the European Economic Area, Processor shall implement an appropriate transfer mechanism recognized under Applicable Data Protection Laws, including where applicable:
- European Commission Standard Contractual Clauses (2021/914/EU);
- UK International Data Transfer Addendum;
- adequacy decisions;
- other lawful transfer mechanisms.
ACCEPTANCE AND ELECTRONIC FORM
This Data Processing Agreement is incorporated into and forms part of the Terms of Service. The Parties agree that this DPA is concluded “in writing, including in electronic form” within the meaning of Article 28(9) GDPR.
Customer’s electronic acceptance of the Agreement (including ticking the acceptance checkbox during account registration or checkout) or electronic submission of the applicable Order Form constitutes acceptance of this DPA. ONLYAI’s electronic acceptance records (timestamp, IP address, account identifier and accepted document version) evidence the conclusion of this DPA.