Data Processing Agreement
Last updated August 21, 2026
This Data Processing Agreement (“DPA”) is entered into by and between ArohAI, Inc. d/b/a Atlas (“Data Processor”) and the Customer (“Data Controller”) (collectively referred to as the “Parties”). This DPA forms part of the Terms of Service between the Parties.
1.Definitions
1.1“Data Controller” refers to the party that determines the purposes and means of the processing of personal data.
1.2“Data Processor” refers to the party that processes personal data on behalf of the Data Controller.
1.3“Personal Data” refers to any information relating to an identified or identifiable natural person.
1.4“Processing” refers to any operation performed on personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
1.5“Customer Data” refers to all data, including Personal Data, submitted to or collected by the services on behalf of the Data Controller, including meeting audio, transcripts, and content from systems the Data Controller connects to the services.
2.Sub-processors
2.1The Data Processor utilizes sub-processors to aid in delivering the services, as detailed in Exhibit A.
2.2The Data Processor will provide the Data Controller at least 30 days’ notice before adding or replacing a sub-processor. If the Data Controller objects on reasonable data protection grounds and the Parties cannot resolve the objection, the Data Controller may terminate the affected services.
3.Data Processing Obligations
3.1Compliance with Laws: The Data Processor commits to processing Personal Data in accordance with all applicable data protection laws, regulations, and industry standards.
3.2Confidentiality: The Data Processor ensures that anyone authorized to process Personal Data is committed to confidentiality.
3.3Security Measures: The Data Processor implements and maintains adequate technical and organizational measures to safeguard Personal Data from unauthorized access, loss, disclosure, alteration, or destruction.
3.4Subprocessing: The Data Processor will maintain an up-to-date list of all sub-processors engaged in processing Personal Data and ensure that data protection obligations bind any sub-processor through a written agreement.
3.5Data Subject Rights: The Data Processor will assist the Data Controller in responding to data subject requests, including requests to access, correct, delete, or limit the processing of Personal Data.
3.6Data Breach Notification: In the event of a personal data breach, the Data Processor will notify the Data Controller without undue delay and no later than 72 hours after becoming aware of the breach, and provide all necessary information to assist the Data Controller in fulfilling its obligations under applicable data protection laws.
3.7Data Storage Location: Unless requested by the Customer, all data is stored in the continental US.
3.8No Model Training: The Data Processor will not use Customer Data to train, fine-tune, or improve any generalized machine learning or artificial intelligence model made available to other customers. Customer Data is used solely to provide the services to the Data Controller.
3.9Deletion and Return: Upon termination of the services, the Data Processor will, at the Data Controller’s election, delete or return all Personal Data within 30 days, except where retention is required by law.
4.Data Controller Responsibilities
4.1Lawful Basis: The Data Controller ensures that it has a lawful basis for processing Personal Data and that the necessary permissions or authorizations have been obtained, where applicable. This includes obtaining any consents or providing any notices required for the recording and transcription of meetings.
4.2Instructions: The Data Controller will provide written instructions to the Data Processor regarding processing Personal Data. The Data Processor will not process the Personal Data for any other purpose than as directed by the Data Controller.
4.3Data Subject Rights: The Data Controller is responsible for addressing data subject requests related to exercising their rights under applicable data protection laws.
5.Data Transfer
5.1Data transfers to third countries or international organizations may only occur with the prior written consent of the Data Controller and in compliance with applicable data protection laws, including through the use of Standard Contractual Clauses or another lawful transfer mechanism where required.
6.Term and Termination
6.1This DPA will remain in effect for the duration of the data processing activities or until terminated by the terms set forth herein or in the Terms of Service.
6.2If you have any questions, please contact privacy@selfoperatingcompany.com.
Exhibit A: List of Sub-Processors
The Data Processor maintains a current list of the sub-processors engaged in processing Personal Data. To request it, email privacy@selfoperatingcompany.com. The notice period in Section 2.2 applies to any addition or replacement.