Data Processing Agreement
Version 1.0 · 22 July 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Use between Centre for AI Leadership Ltd. ("C4AIL," "Processor") and the organisation using the Services ("Customer," "Controller"). It applies wherever C4AIL processes personal data on the Customer's behalf. A countersigned copy is available on request.
1. Roles, and where they change
For assessment data, the Customer is the Controller and C4AIL is the Processor. C4AIL processes personal data only on the Customer's documented instructions, of which this DPA and the Terms are the complete set, except where required by law - in which case C4AIL will notify the Customer first unless the law forbids it.
One exception, stated plainly rather than buried. C4AIL maintains benchmarks derived from assessments. For that purpose - and only in anonymised, aggregated form from which no individual or organisation can be identified - C4AIL acts as a Controller in its own right. This is genuinely a different role, and a DPA that claimed C4AIL was only ever a Processor would contradict how the Services actually work. A Customer may request exclusion from benchmarks at any time by writing to [email protected], and exclusion is applied without affecting the Services in any other way.
2. Details of processing
- Subject matter: operating the AI Maturity Diagnostic for the Customer.
- Duration: for as long as the Customer uses the Services, plus the retention period in section 9.
- Nature and purpose: collecting assessment responses, interpreting free-text answers into structured values, scoring them deterministically, producing results and audit records, and sending assessment-related email.
- Categories of data subject: the Customer's personnel who are invited to answer, and the individual who authorises or signs off an assessment.
- Types of personal data: name and email address of respondents and signatories; job function or "seat"; assessment answers and any free text written by the respondent; and the name of the person giving consent or sign-off. The Services do not require, and Customers are asked not to submit, special categories of personal data.
3. Client Materials - beyond personal data
Where an assessment is answered from the Customer's own documents, C4AIL receives a citation containing the document's name, a locator, and a quoted extract of up to 600 characters ("Client Materials"). C4AIL never receives the documents themselves and does not connect to Customer systems.
Client Materials frequently contain no personal data at all, and would therefore fall outside a data protection agreement entirely - while being, in commercial terms, among the most sensitive information the Customer sends. C4AIL therefore treats Client Materials as the Customer's confidential information regardless of whether they constitute personal data: they are used solely to deliver and evidence the Customer's own assessment, are never used for benchmarks, product development or model training, are encrypted at rest, and are disclosed to no third party except the sub-processors in section 6. The Customer's obligations in the Terms not to submit privileged, personal or otherwise restricted material continue to apply.
4. Confidentiality
C4AIL ensures that personnel authorised to process personal data are bound by confidentiality obligations, and limits access to those who need it to deliver the Services. Access by C4AIL personnel to an individual respondent's answers is logged.
5. Security
C4AIL implements appropriate technical and organisational measures, described in the Annex below. These are the measures actually in force, not a statement of intent.
6. Sub-processors
The Customer authorises the sub-processors listed at /subprocessors, which is maintained as a standing list. C4AIL imposes data protection obligations on each sub-processor no less protective than this DPA, and remains liable for their performance.
Notice of change: C4AIL will give at least 30 days' notice before a new sub-processor begins processing Customer personal data, by updating that page and notifying the Customer's registered contact. The Customer may object on reasonable data protection grounds within that period; if the objection cannot be resolved, the Customer may terminate the affected Services and receive a pro-rata refund of prepaid fees.
7. International transfers
The Services are hosted in Germany (Hetzner, Nuremberg).
Free-text interpretation, and the check of whether a cited extract is a record or a rule, are performed by Google Asia Pacific Pte. Ltd. via Google Cloud Vertex AI (Gemini 2.5 Flash). Requests are made on the Vertex AI asia-southeast1 (Singapore) regional endpoint, which keeps data at rest and model processing within that single region, so processing takes place in Singapore. Google does not use content submitted to Vertex AI to train its models.
Where transfers are subject to GDPR, they are made under the European Commission's Standard Contractual Clauses, which are incorporated into this DPA by reference and completed as follows: Module Two (Controller to Processor); Clause 7 (docking) applies; Clause 9(a) option 2 (general authorisation) with the 30-day notice period in section 6; Clause 11 optional redress does not apply; Clause 17 governed by Irish law; Clause 18(b) courts of Ireland. Where transfers are subject to the Singapore PDPA, C4AIL ensures a comparable standard of protection as required by section 26.
Most answers are not transferred at all. Short, unambiguous answers are resolved deterministically on C4AIL's own servers and are never sent to any AI service, and free-text answering is optional throughout.
8. Data subject rights and assistance
Taking into account the nature of the processing, C4AIL assists the Customer by appropriate technical and organisational measures in responding to data subject requests, and in meeting obligations under Articles 32 to 36 GDPR and the equivalent PDPA obligations. The Services provide direct deletion of an individual assessment and of all data for an organisation. Where a request reaches C4AIL directly, C4AIL will refer it to the Customer rather than respond on its behalf.
9. Personal data breach
C4AIL notifies the Customer without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting Customer personal data, providing the information reasonably available at the time, and further information as it emerges. C4AIL does not delay notification in order to complete an investigation first.
10. Deletion and return
On request, or on termination, C4AIL deletes Customer personal data from live systems promptly - the Services provide this directly, and it takes effect immediately.
Backups are the honest exception. C4AIL takes encrypted backups every six hours and retains them for 14 days. Data already captured in a backup persists in that backup until it ages out, so complete erasure across all systems takes up to 14 days from the deletion request. Backups are not used to restore individual records, and any restore of a backup taken before a deletion is followed by re-applying that deletion. C4AIL states a window rather than claiming immediate erasure everywhere, which would not be true of any system that takes backups.
Assessment data not otherwise deleted is retained as described in the Privacy Policy.
11. Audit
C4AIL makes available the information necessary to demonstrate compliance with this DPA, and allows for and contributes to audits by the Customer or an auditor it mandates, on reasonable notice, no more than once in any twelve months unless required by a supervisory authority or following a breach. C4AIL may satisfy an audit request by providing existing documentation and answering questions where that reasonably addresses the Customer's requirements.
12. Precedence and liability
In the event of conflict, this DPA prevails over the Terms of Use in respect of the processing of personal data. Each party's liability under this DPA is subject to the limitations in the Terms of Use or in any separate written agreement between the parties, except where those limitations are not permitted by applicable data protection law.
13. Governing law
This DPA is governed by the laws of Singapore, save that the Standard Contractual Clauses are governed as stated in section 7.
Annex - Technical and organisational measures
These are the measures in force as at the version date above.
- Encryption at rest. Sensitive content is encrypted field by field with AES-256-GCM (authenticated encryption): assessment answers, free text written by respondents, evidence citations and quoted extracts, respondent and invitee email addresses, signatory names, organisation names, and computed results. Non-identifying aggregates are stored unencrypted so that analytics require no access to the key.
- Key management. The encryption key is a 32-byte key held outside the database and outside the application repository, readable only by the service account (file mode 600).
- Database. The database file and its write-ahead log are restricted to the service account (mode 600).
- Credentials are never stored in plaintext. API tokens and single-use assessment invitations are stored only as SHA-256 hashes. A stolen database does not yield a usable token or invitation.
- Respondent separation. In a multi-respondent assessment, each respondent can reach only their own section. Respondents cannot see who else was invited, who has responded, or what anyone else answered. This is enforced server-side.
- Least privilege for AI processing. The credential used for free-text interpretation is scoped to invoking a single model and nothing else. It cannot read, list or modify any other resource.
- Separation of authentication from AI. No authentication or authorisation decision involves a language model, and no identifier - name, email, organisation, session or assessment reference - is included in any request to an AI service. This is enforced by an automated test that fails the build if the two are ever connected.
- Encryption in transit. TLS for all connections to the Services.
- Backups. Encrypted backups every six hours, retained 14 days, restricted to the service account. Each backup is automatically verified as readable after it is written, and the decryption key is backed up alongside the data.
- Auditability. Every answer records what was recorded, who or what mapped it, and where any supporting evidence came from. Access by C4AIL administrators to individual respondent data is logged.
- Deletion. Deletion of an individual assessment, and of all data for an organisation, is available directly through the Services.
Questions: [email protected] · See also Privacy Policy, Terms of Use, Sub-processors.