C4AIL AI Maturity Diagnostic

Data Processing Agreement

Version 1.0 · 22 July 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Use between Centre for AI Leadership Ltd. ("C4AIL," "Processor") and the organisation using the Services ("Customer," "Controller"). It applies wherever C4AIL processes personal data on the Customer's behalf. A countersigned copy is available on request.

1. Roles, and where they change

For assessment data, the Customer is the Controller and C4AIL is the Processor. C4AIL processes personal data only on the Customer's documented instructions, of which this DPA and the Terms are the complete set, except where required by law - in which case C4AIL will notify the Customer first unless the law forbids it.

One exception, stated plainly rather than buried. C4AIL maintains benchmarks derived from assessments. For that purpose - and only in anonymised, aggregated form from which no individual or organisation can be identified - C4AIL acts as a Controller in its own right. This is genuinely a different role, and a DPA that claimed C4AIL was only ever a Processor would contradict how the Services actually work. A Customer may request exclusion from benchmarks at any time by writing to [email protected], and exclusion is applied without affecting the Services in any other way.

2. Details of processing

3. Client Materials - beyond personal data

Where an assessment is answered from the Customer's own documents, C4AIL receives a citation containing the document's name, a locator, and a quoted extract of up to 600 characters ("Client Materials"). C4AIL never receives the documents themselves and does not connect to Customer systems.

Client Materials frequently contain no personal data at all, and would therefore fall outside a data protection agreement entirely - while being, in commercial terms, among the most sensitive information the Customer sends. C4AIL therefore treats Client Materials as the Customer's confidential information regardless of whether they constitute personal data: they are used solely to deliver and evidence the Customer's own assessment, are never used for benchmarks, product development or model training, are encrypted at rest, and are disclosed to no third party except the sub-processors in section 6. The Customer's obligations in the Terms not to submit privileged, personal or otherwise restricted material continue to apply.

4. Confidentiality

C4AIL ensures that personnel authorised to process personal data are bound by confidentiality obligations, and limits access to those who need it to deliver the Services. Access by C4AIL personnel to an individual respondent's answers is logged.

5. Security

C4AIL implements appropriate technical and organisational measures, described in the Annex below. These are the measures actually in force, not a statement of intent.

6. Sub-processors

The Customer authorises the sub-processors listed at /subprocessors, which is maintained as a standing list. C4AIL imposes data protection obligations on each sub-processor no less protective than this DPA, and remains liable for their performance.

Notice of change: C4AIL will give at least 30 days' notice before a new sub-processor begins processing Customer personal data, by updating that page and notifying the Customer's registered contact. The Customer may object on reasonable data protection grounds within that period; if the objection cannot be resolved, the Customer may terminate the affected Services and receive a pro-rata refund of prepaid fees.

7. International transfers

The Services are hosted in Germany (Hetzner, Nuremberg).

Free-text interpretation, and the check of whether a cited extract is a record or a rule, are performed by Google Asia Pacific Pte. Ltd. via Google Cloud Vertex AI (Gemini 2.5 Flash). Requests are made on the Vertex AI asia-southeast1 (Singapore) regional endpoint, which keeps data at rest and model processing within that single region, so processing takes place in Singapore. Google does not use content submitted to Vertex AI to train its models.

Where transfers are subject to GDPR, they are made under the European Commission's Standard Contractual Clauses, which are incorporated into this DPA by reference and completed as follows: Module Two (Controller to Processor); Clause 7 (docking) applies; Clause 9(a) option 2 (general authorisation) with the 30-day notice period in section 6; Clause 11 optional redress does not apply; Clause 17 governed by Irish law; Clause 18(b) courts of Ireland. Where transfers are subject to the Singapore PDPA, C4AIL ensures a comparable standard of protection as required by section 26.

Most answers are not transferred at all. Short, unambiguous answers are resolved deterministically on C4AIL's own servers and are never sent to any AI service, and free-text answering is optional throughout.

8. Data subject rights and assistance

Taking into account the nature of the processing, C4AIL assists the Customer by appropriate technical and organisational measures in responding to data subject requests, and in meeting obligations under Articles 32 to 36 GDPR and the equivalent PDPA obligations. The Services provide direct deletion of an individual assessment and of all data for an organisation. Where a request reaches C4AIL directly, C4AIL will refer it to the Customer rather than respond on its behalf.

9. Personal data breach

C4AIL notifies the Customer without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting Customer personal data, providing the information reasonably available at the time, and further information as it emerges. C4AIL does not delay notification in order to complete an investigation first.

10. Deletion and return

On request, or on termination, C4AIL deletes Customer personal data from live systems promptly - the Services provide this directly, and it takes effect immediately.

Backups are the honest exception. C4AIL takes encrypted backups every six hours and retains them for 14 days. Data already captured in a backup persists in that backup until it ages out, so complete erasure across all systems takes up to 14 days from the deletion request. Backups are not used to restore individual records, and any restore of a backup taken before a deletion is followed by re-applying that deletion. C4AIL states a window rather than claiming immediate erasure everywhere, which would not be true of any system that takes backups.

Assessment data not otherwise deleted is retained as described in the Privacy Policy.

11. Audit

C4AIL makes available the information necessary to demonstrate compliance with this DPA, and allows for and contributes to audits by the Customer or an auditor it mandates, on reasonable notice, no more than once in any twelve months unless required by a supervisory authority or following a breach. C4AIL may satisfy an audit request by providing existing documentation and answering questions where that reasonably addresses the Customer's requirements.

12. Precedence and liability

In the event of conflict, this DPA prevails over the Terms of Use in respect of the processing of personal data. Each party's liability under this DPA is subject to the limitations in the Terms of Use or in any separate written agreement between the parties, except where those limitations are not permitted by applicable data protection law.

13. Governing law

This DPA is governed by the laws of Singapore, save that the Standard Contractual Clauses are governed as stated in section 7.


Annex - Technical and organisational measures

These are the measures in force as at the version date above.

Questions: [email protected] · See also Privacy Policy, Terms of Use, Sub-processors.