Data Processing Agreement
Version 1.0
Effective date: Upon acceptance by the Customer
This Data Processing Agreement ("DPA") forms part of the AROG AI Terms of Service between AROG AI sp. z o.o. ("Processor") and the entity accepting these terms ("Controller").
Article 1 — Definitions
- 1.1 "Personal Data" means any information relating to an identified or identifiable natural person processed on behalf of the Controller.
- 1.2 "Processing" has the meaning given in GDPR Article 4(2).
- 1.3 "Sub-processor" means any third party engaged by the Processor to process Personal Data on behalf of the Controller.
- 1.4 "Services" means the document extraction and analysis services provided by AROG AI.
Article 2 — Scope and Purpose
- 2.1 The Processor processes Personal Data solely for the purpose of providing the Services as described in the Terms of Service.
- 2.2 Categories of data subjects: tenants, landlords, guarantors, authorized representatives named in commercial lease documents.
- 2.3 Types of Personal Data: names, addresses, contact details, financial terms, identification numbers contained in uploaded documents.
- 2.4 Duration: For the term of the service agreement plus the data retention period specified in the Privacy Policy.
- 2.5 Indirect Data Subjects. The Controller acknowledges that uploaded documents may contain Personal Data of third parties (e.g., tenants, guarantors, authorized representatives) who have not directly provided their data to the Processor. The Controller is solely responsible for ensuring a lawful basis for processing such data and for fulfilling its transparency obligations to these data subjects under GDPR Articles 13–14, including informing them that their data will be processed by AROG AI as a sub-processor.
Article 3 — Processor Obligations (Art. 28(3))
- 3.1 Process Personal Data only on documented instructions from the Controller (uploading a document constitutes instruction to process).
- 3.2 Ensure persons authorized to process have committed to confidentiality.
- 3.3 Implement appropriate technical and organizational security measures (see Article 5 below).
- 3.4 Not engage another processor without prior written authorization (general authorization given; see Article 4 for sub-processors).
- 3.5 Assist the Controller in responding to data subject requests (access, rectification, erasure, portability, restriction, objection).
- 3.6 Assist the Controller with DPIA obligations and prior consultation.
- 3.7 Delete or return all Personal Data upon termination of Services, unless EU/Polish law requires retention.
- 3.8 Make available all information necessary to demonstrate compliance and allow for audits (with 30 days written notice, during business hours, at Controller’s cost, max 1 audit per year).
Article 4 — Sub-Processors
- 4.1 The Controller provides general authorization for sub-processors disclosed contractually before service activation. The current schedule is provided privately to affected customers and updated by written notice.
- 4.2 The Processor will notify the Controller 30 days before adding or replacing a sub-processor via email notification.
- 4.3 The Controller may object within 14 days. If objection is not resolved, the Controller may terminate the Services.
- 4.4 The Processor remains fully liable for sub-processor compliance.
Article 5 — Security Measures (Art. 32)
- 5.1 Encryption in transit (TLS 1.3) and at rest (AES-256).
- 5.2 Access controls with role-based permissions.
- 5.3 Document auto-deletion within 7 days of processing.
- 5.4 Regular security testing and vulnerability management.
- 5.5 Employee confidentiality obligations.
- 5.6 Regional hosting and storage controls are selected according to the contracted service scope and documented before processing begins.
Article 6 — International Transfers
- 6.1 Some approved sub-processors may process data outside the EEA. Applicable locations and safeguards are disclosed contractually before processing begins.
- 6.2 Transfers are governed by EU Standard Contractual Clauses (SCCs) incorporated by reference.
- 6.3 The Processor monitors legal developments affecting transfer mechanisms and will notify the Controller of material changes.
Article 7 — Data Breach Notification
- 7.1 The Processor will notify the Controller without undue delay and no later than 48 hours after becoming aware of a Personal Data breach.
- 7.2 Notification will include: nature of breach, categories and number of data subjects affected, likely consequences, and measures taken.
- 7.3 The Processor will cooperate with the Controller’s notification to UODO and affected data subjects.
Article 8 — Termination and Data Return
- 8.1 Upon termination, the Processor will delete all Personal Data within 30 days unless instructed to return it.
- 8.2 The Controller may request data return in JSON or CSV format before deletion.
- 8.3 The Processor will certify deletion upon request.
Article 9 — Liability
- 9.1 The Processor’s liability under this DPA is subject to the limitations set out in the Terms of Service.
- 9.2 The Processor is liable for damage caused by processing only where it has not complied with GDPR obligations specifically directed to processors or has acted outside or contrary to lawful instructions.
Article 10 — Governing Law
- 10.1 This DPA is governed by Polish law.
- 10.2 Disputes shall be resolved by the courts of Warsaw, Poland.
Important Notice: AI Processing & Legal Privilege
AI-Generated Content Disclaimer: All document extraction and analysis results produced by AROG AI are generated by contracted AI and document-processing services. Results may contain errors and must be independently verified by qualified professionals before any decision-making. AROG AI does not provide legal, financial, or professional advice.
Attorney-Client Privilege Notice: Documents processed through AROG AI may be transmitted to contracted AI and document-processing providers for analysis. Under current legal precedent (United States v. Heppner, S.D.N.Y. 2026), communications with AI systems may not be protected by attorney-client privilege or work-product doctrine. Customers who are legal professionals should consider this when processing privileged or confidential documents. We recommend consulting with your legal counsel regarding privilege implications before processing sensitive materials.
For data retention details, see our Privacy Policy. To request a Zero Data Retention arrangement, use .
Related documents: Privacy Policy · Terms of Service