Skip to content
itogai Back to itogai.app ↗
itogai·Legal·Data Processing Agreement

Data processing

Data Processing Agreement

Effective May 11, 2026Last modified May 11, 2026Version DPA-2026-05-11 v2.0

This Data Processing Agreement (the “DPA”) is entered into between Itogai LLC, a Florida limited liability company with its principal office in Lake Worth, Florida, United States of America (“itogai” or the “Processor”), and the customer entity identified in the Account or in the executed order form (the “Customer” or the “Controller”). itogai and the Customer are each a “party” and together the “parties.”

This DPA forms part of, and is incorporated into, the Customer Terms of Service between itogai and the Customer (the “Agreement”). It governs itogai’s processing of Personal Data on the Customer’s behalf under the Agreement. In the event of any conflict between this DPA and the Agreement with respect to the processing of Personal Data, this DPA controls.

This DPA is intended to comply with the requirements of:

  • the EU General Data Protection Regulation (Regulation (EU) 2016/679) (the “GDPR”);
  • the United Kingdom General Data Protection Regulation as it forms part of UK domestic law (the “UK GDPR”) and the UK Data Protection Act 2018;
  • the Swiss Federal Act on Data Protection (the “Swiss FADP”);
  • the Lei Geral de Proteção de Dados (Federal Law No. 13,709/2018) of Brazil (the “LGPD”); and
  • the California Consumer Privacy Act, as amended by the California Privacy Rights Act (the “CCPA”), and other comprehensive U.S. state privacy laws,

each as applicable to the parties and to the relevant processing.

By accepting the Agreement, by creating an Account, or by clicking “I agree” or any equivalent button on a click-through DPA acceptance flow, the Customer accepts and agrees to be bound by this DPA.

1. Definitions

Capitalized terms used in this DPA but not defined here have the meanings set out in the Agreement, the Privacy Policy, or the GDPR, as the context indicates.

1.1 “Affiliate” means an entity that controls, is controlled by, or is under common control with a party.

1.2 “Customer Personal Data” means any Personal Data that itogai processes on the Customer’s behalf in the course of providing the Subscription Service or Professional Services under the Agreement. Customer Personal Data is a subset of Customer Data and includes, without limitation, the data described in Annex I to this DPA.

1.3 “Data Protection Laws” means all data-protection and privacy laws applicable to a party’s processing of Personal Data under this DPA, including the GDPR, the UK GDPR, the Swiss FADP, the LGPD, the CCPA, and any other applicable comprehensive consumer-privacy law in the United States.

1.4 “Data Subject” means an identified or identifiable natural person to whom Customer Personal Data relates.

1.5 “Personal Data” has the meaning given in the GDPR (or, where applicable, the equivalent term “personal information” under the CCPA, “dados pessoais” under the LGPD, or the equivalent term under any other applicable Data Protection Law).

1.6 “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data transmitted, stored, or otherwise processed by itogai.

1.7 “Processing” has the meaning given in the GDPR.

1.8 “Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of Personal Data to third countries pursuant to the GDPR, as approved by Commission Implementing Decision (EU) 2021/914 of 4 June 2021, in the version in effect as of the date of the relevant transfer.

1.9 “Sub-processor” means any third party engaged by itogai to process Customer Personal Data on itogai’s behalf in connection with the Agreement.

1.10 “UK Addendum” means the United Kingdom International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner’s Office under section 119A of the Data Protection Act 2018.

2. Roles and Scope

2.1 Roles. The parties acknowledge that, with respect to Customer Personal Data:

  • the Customer is the Controller (and, where applicable under U.S. law, the business) and itogai is the Processor (and, where applicable, the service provider); and
  • where the Customer is itself a Processor for one of its own customers, the Customer is the Processor and itogai is a Sub-processor. In that case, the Customer represents and warrants that the Customer has obtained any necessary authorization from the underlying Controller to engage itogai as a Sub-processor and to bind that Controller to terms substantially equivalent to this DPA.

For the avoidance of doubt: with respect to Account Data, Billing Data, Usage Data, Device and Log Data, Communications, and the other categories of Personal Data identified as such in itogai’s Privacy Policy, itogai acts as a Controller in its own right. The processing of those categories is governed by the Privacy Policy and is outside the scope of this DPA.

2.2 Subject Matter, Duration, Nature, and Purpose. The subject matter, duration, nature, and purpose of the processing under this DPA, as well as the categories of Data Subjects and Personal Data, are described in Annex I.

2.3 Customer Instructions. itogai shall process Customer Personal Data only on the Customer’s documented instructions, which are set out in:

  • the Agreement (including the Customer’s configuration of the Subscription Service);
  • this DPA;
  • itogai’s Documentation; and
  • any further written instructions agreed between the parties.

If itogai believes that an instruction violates Data Protection Law, itogai shall promptly inform the Customer (unless prohibited from doing so by applicable law) and may suspend the affected processing until the instruction is amended or withdrawn.

2.4 Customer Responsibilities. The Customer represents and warrants that:

  • the Customer has the legal right and authority to provide Customer Personal Data to itogai for the processing contemplated by the Agreement;
  • the Customer has provided all notices and obtained all consents required under applicable Data Protection Laws to enable itogai to process Customer Personal Data lawfully on the Customer’s behalf; and
  • the Customer’s instructions to itogai comply with applicable Data Protection Laws.

The Customer is responsible for the accuracy, quality, and legality of Customer Personal Data and the means by which the Customer acquired Customer Personal Data.

3. itogai’s Obligations as Processor

3.1 Compliance. itogai shall process Customer Personal Data in accordance with applicable Data Protection Laws and this DPA.

3.2 Confidentiality of Personnel. itogai shall ensure that any person authorized to process Customer Personal Data has committed themselves to confidentiality or is under an appropriate statutory obligation of confidentiality. Access to Customer Personal Data is limited to itogai personnel and approved Sub-processors who need it to provide the Subscription Service.

3.3 Security. itogai shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including the measures described in Annex II of this DPA.

3.4 Sub-processors. itogai’s engagement of Sub-processors is governed by Section 5 of this DPA.

3.5 Assistance with Data Subject Requests. itogai shall, taking into account the nature of the processing, assist the Customer by appropriate technical and organizational measures, insofar as possible, to fulfill the Customer’s obligations to respond to requests for the exercise of Data Subjects’ rights under Data Protection Law (including rights of access, rectification, erasure, restriction, portability, and objection). Where a Data Subject contacts itogai directly with such a request, itogai shall, except where prohibited by law, promptly forward the request to the Customer and shall not respond to the Data Subject other than to acknowledge receipt and direct the Data Subject to the Customer.

3.6 Assistance with Compliance Obligations. itogai shall, taking into account the nature of the processing and the information available to itogai, assist the Customer in ensuring compliance with the Customer’s obligations under Articles 32 to 36 of the GDPR (security of processing, breach notification, data-protection impact assessments, and prior consultation), and equivalent provisions under other applicable Data Protection Laws.

3.7 Personal Data Breach Notification. itogai shall notify the Customer without undue delay, and where feasible within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. Where notification within seventy-two (72) hours is not feasible, itogai shall provide notification as soon as reasonably possible together with reasons for the delay. The notification shall, to the extent then known, include:

  • the nature of the Personal Data Breach, including, where possible, the categories and approximate number of Data Subjects and records concerned;
  • the likely consequences of the Personal Data Breach;
  • the measures taken or proposed to address the Personal Data Breach and to mitigate its possible adverse effects; and
  • a point of contact at itogai from which the Customer may obtain further information.

itogai may provide information in phases as it becomes available. itogai’s notification of a Personal Data Breach is not, by itself, an admission of fault or liability.

3.8 Return or Deletion at End of Processing. Upon termination of the Agreement or upon the Customer’s earlier written request, itogai shall, at the Customer’s election, return or delete Customer Personal Data, subject to:

  • itogai’s standard thirty (30)-day post-termination export window described in the Customer Terms of Service;
  • backup-retention schedules described in the Privacy Policy (under which backup copies are overwritten on rolling cycles, generally within ninety (90) days); and
  • itogai’s right to retain Customer Personal Data to the extent and for so long as required by applicable law, in which case itogai shall continue to protect that data in accordance with this DPA.

Upon written request, itogai shall provide written confirmation of deletion to the Customer.

3.9 Records and Audit. itogai shall maintain records of its processing activities to the extent required by Article 30(2) of the GDPR. Upon written request from the Customer, and no more than once in any twelve (12)-month period (except where required by a supervisory authority or where reasonably necessary to investigate a suspected Personal Data Breach), itogai shall make available to the Customer such information as is reasonably necessary to demonstrate itogai’s compliance with this DPA. itogai’s responses may take the form of written summaries, completed security questionnaires, third-party audit reports, or certifications, where available. Where the Customer reasonably requires further information after reviewing the foregoing, the parties shall agree in good faith on the scope, timing, and cost of any on-site audit, which shall be conducted at the Customer’s expense, during itogai’s regular business hours, and subject to a written confidentiality undertaking from the auditor satisfactory to itogai.

3.10 Generative-AI and Akai™ Processing. Customer Personal Data processed by Akai™ (itogai’s relationship-intelligence co-pilot) and by other generative-AI features of the Subscription Service is subject to the same data-processing posture set out in this DPA. In particular: (a) Akai™ does not send messages on the Customer’s behalf and does not take any external action without a User’s review and explicit click-to-send; (b) the generative-AI Sub-processors listed on the Sub-processor Page (currently Anthropic, PBC and OpenAI, L.L.C.) are each engaged under a contractual AI-training opt-out, meaning Customer Personal Data is not used to train those Sub-processors’ general-purpose models; (c) content channels (Slack messages, meeting transcripts, replies to messages sent through TrustReach™) are processed and discarded as described in Annex II; and (d) Akai™’s outputs are probabilistic and are intended to support, not replace, the Customer’s own business judgment, as further described in the Customer Terms of Service Section 14.2.

4. Customer’s Obligations as Controller

The Customer shall, in its capacity as Controller:

  • determine the purposes and means of the processing of Customer Personal Data;
  • provide notices to Data Subjects and obtain any necessary consents under applicable Data Protection Laws;
  • maintain its own records of processing activities to the extent required by applicable Data Protection Laws; and
  • respond to communications from Data Subjects and supervisory authorities, with itogai’s assistance as set out in Section 3.

5. Sub-processors

5.1 General Authorization. The Customer provides itogai with general written authorization to engage Sub-processors to process Customer Personal Data, subject to the requirements of this Section 5.

5.2 List of Sub-processors. itogai’s current Sub-processors are listed at itogai.app/legal/sub-processors (the “Sub-processor Page”). The list is incorporated into this DPA by reference.

5.3 Notice and Right to Object. itogai shall notify the Customer of any intended addition or replacement of a Sub-processor as described in the Sub-processor Page (with at least thirty (30) days’ advance notice for material additions). The Customer may object in writing to legal@itogai.com within thirty (30) days of receiving notice. itogai and the Customer shall discuss the objection in good faith. If the parties cannot agree on a path forward within a further thirty (30) days, the Customer may terminate the affected portion of the Subscription Service for material breach of this DPA, and itogai shall refund any prepaid fees attributable to the period after termination.

5.4 Sub-processor Obligations. itogai shall enter into a written agreement with each Sub-processor that imposes data-protection obligations substantially equivalent to those imposed on itogai under this DPA. itogai remains responsible to the Customer for the acts and omissions of each Sub-processor that affect itogai’s compliance with this DPA, to the same extent as for itogai’s own acts and omissions.

6. International Data Transfers

6.1 Locations of Processing. itogai is based in the United States and processes Customer Personal Data in the United States and, where Sub-processors operate in the European Union, in the European Union, as described on the Sub-processor Page.

6.2 Transfers from the EEA, the UK, and Switzerland. Where itogai’s processing of Customer Personal Data involves a transfer to a country that has not been recognized as providing an adequate level of data protection under the GDPR, the UK GDPR, or the Swiss FADP:

  • the parties incorporate the Standard Contractual Clauses (Module Two: Controller to Processor) into this DPA by reference, with the Customer as data exporter and itogai as data importer, and complete them as set out in Annex III;
  • where the Customer is itself a Processor, the parties incorporate the Standard Contractual Clauses (Module Three: Processor to Processor) instead;
  • for transfers from the United Kingdom, the parties incorporate the UK Addendum to the SCCs;
  • for transfers from Switzerland, the parties adopt the SCCs with the modifications described by the Swiss Federal Data Protection and Information Commissioner; and
  • where there is any conflict between the SCCs and this DPA with respect to a transfer, the SCCs prevail.

6.3 Transfers from Brazil. Transfers of Customer Personal Data from Brazil rely on the legal bases set out in Article 33 of the LGPD, including the use of standard contractual clauses, the necessity of the transfer for the performance of a contract with the Data Subject, and the consent of the Data Subject where applicable. Where the Brazilian National Data Protection Authority (the ANPD) issues standard contractual clauses or other approved transfer instruments, the parties shall amend this DPA to incorporate them.

6.4 Transfer-Impact Assessment Cooperation. Upon the Customer’s reasonable written request, itogai shall provide reasonable assistance to the Customer in conducting any transfer-impact assessment required under applicable Data Protection Law.

7. CCPA Service-Provider Provisions

To the extent itogai processes Personal Information (as defined under the CCPA) on the Customer’s behalf and the CCPA applies, the parties acknowledge and agree as follows:

  • itogai is a “service provider” of the Customer under the CCPA.
  • itogai shall not (a) sell or share Personal Information; (b) retain, use, or disclose Personal Information outside the direct business relationship with the Customer for any purpose other than the specific business purpose of providing the Subscription Service or Professional Services described in the Agreement; (c) combine the Personal Information that itogai receives from the Customer with Personal Information that itogai receives from another business or collects from its own interaction with a Data Subject, except as permitted under the CCPA; or (d) retain, use, or disclose Personal Information for any commercial purpose other than the specific business purpose of providing the Services.
  • itogai shall comply with applicable obligations under the CCPA, shall provide the same level of privacy protection as is required of businesses by the CCPA, and shall notify the Customer if itogai determines that itogai can no longer meet its CCPA obligations.
  • The Customer may, upon written notice, take reasonable and appropriate steps to stop and remediate any unauthorized use of Personal Information by itogai.

8. LGPD-Specific Provisions

To the extent itogai processes Personal Data subject to the LGPD on the Customer’s behalf:

  • itogai is the “operador” (operator) and the Customer is the “controlador” (controller) under the LGPD;
  • itogai shall process Personal Data only as instructed by the Customer and shall maintain records of processing in accordance with Article 37 of the LGPD;
  • itogai shall notify the Customer of any incident affecting Personal Data within the timeframes set out in Section 3.7; and
  • the Customer remains responsible for fulfilling Data Subjects’ rights under Articles 17 to 22 of the LGPD, with itogai’s assistance as set out in Section 3.5.

The privacy contact (encarregado / DPO contact) at itogai for LGPD purposes is privacy@itogai.com.

9. Liability

The liability of each party under this DPA is subject to the limitations of liability set out in the Agreement. The aggregate liability of each party arising out of or in connection with this DPA, when combined with the party’s liability arising out of or in connection with the Agreement, shall not exceed the cap set out in the Agreement, except to the extent prohibited by applicable Data Protection Law.

For the avoidance of doubt, claims by Data Subjects under the SCCs are not subject to the cap in the Agreement to the extent the SCCs themselves provide a separate basis for liability to a Data Subject as a third-party beneficiary.

10. Term and Termination

10.1 Term. This DPA takes effect on the Effective Date and continues for the duration of the Agreement.

10.2 Effect of Termination. Termination of this DPA does not affect the obligations of the parties that, by their nature, survive termination, including the obligations in Sections 3.7, 3.8, 3.9, 6, 9, and 11.

11. Miscellaneous

11.1 Order of Precedence. In the event of a conflict between this DPA and the Agreement, this DPA prevails with respect to the processing of Customer Personal Data. In the event of a conflict between this DPA and the SCCs, the SCCs prevail with respect to the relevant transfer.

11.2 Amendments. itogai may modify this DPA from time to time to reflect changes in the Subscription Service, applicable Data Protection Law, or its sub-processor list. Material changes will be notified as described in the Customer Terms of Service.

11.3 Governing Law. This DPA is governed by the law selected in the Agreement, except to the extent that applicable Data Protection Law or the SCCs require otherwise. Disputes arising out of or in connection with this DPA are subject to the dispute-resolution provisions of the Agreement, except to the extent the SCCs require otherwise.

11.4 Severability. If any provision of this DPA is held invalid or unenforceable, that provision will be modified to the minimum extent necessary to make it enforceable, and the remaining provisions will continue in full force and effect.

11.5 Counterparts and Electronic Signatures. This DPA may be executed in counterparts, each of which is an original. Electronic signatures and acceptance through click-through interfaces are deemed valid and effective.

Annex I: Description of the Processing

Subject matter: Provision of the itogai Subscription Service and any Professional Services to the Customer, as described in the Agreement.

Duration: For the duration of the Agreement, plus the post-termination export window and backup-retention period described in Section 3.8.

Nature of the processing: Hosting, storing, organizing, structuring, analyzing, and surfacing Customer Personal Data through the TrustGraph™ scoring algorithm, the TrustCircles™ network organization, the TrustReach™ warm-network action layer, and Akai™ (itogai’s relationship-intelligence co-pilot, which drafts messages, surfaces warm-introduction paths, and generates context briefs for the User to review and send); receiving Customer Personal Data from authorized Data Sources via OAuth and other documented integration mechanisms; computing relationship signals; and supporting User-initiated, click-to-send outbound communications. Akai™ and the other generative-AI features do not send messages on the Customer’s behalf and require the User’s explicit click-to-send for any outbound communication.

Purpose of the processing: To provide the Subscription Service in accordance with the Customer’s documented instructions and the Agreement.

Categories of Data Subjects: (a) Authorized Users of the Customer; (b) Customer’s contacts (including business prospects, customers, partners, candidates, and other relationship counterparts) whose details are imported into the Subscription Service or read from authorized Data Sources; and (c) other natural persons referenced in messages, calendar events, or other content accessed through authorized Data Sources.

Categories of Personal Data: Names, work email addresses, phone numbers, employer, role, location, profile metadata, message metadata (sender, recipient, timestamp, subject), calendar metadata, and structured signals derived from interactions, as further described in itogai’s Privacy Policy. Body content of email messages is not stored. Body content of Slack messages, meeting transcripts, and replies to messages the Customer’s Users send through TrustReach™ is processed and discarded as described in the Privacy Policy.

Special categories of Personal Data: None. The Customer agrees not to submit special categories of Personal Data (under Article 9 GDPR) or sensitive Personal Information (under the CCPA), other than what is incidentally present in process-and-discard pipelines and is therefore not retained.

Frequency of the transfer: Continuous for the duration of the Agreement.

Retention period: As set out in Section 10 of the Privacy Policy and Section 3.8 of this DPA.

Annex II: Technical and Organizational Measures

itogai maintains the following technical and organizational measures, which it may update from time to time, provided that any update does not materially decrease the overall level of security:

Encryption. Encryption of Customer Personal Data in transit and at rest using industry-standard encryption (currently TLS 1.2 or higher in transit and AES-256 at rest). itogai may update the specific encryption algorithms or protocols from time to time, provided that any update does not materially decrease the overall level of security.

Access controls. Role-based access controls; least-privilege provisioning of itogai personnel; multi-factor authentication for itogai administrative access; periodic access reviews; immediate revocation of access on personnel offboarding.

Tenant isolation. Multi-tenant architecture with logical tenant isolation; strict separation of Customer accounts within shared infrastructure.

Architecture controls. Metadata-only architecture for restricted Google API scopes; process-and-discard architecture for content channels (Slack messages, meeting transcripts, replies to messages sent by the Customer’s Users through TrustReach™); the body of email messages from Gmail is not stored. itogai’s metadata-only architecture is the subject of itogai’s App Defense Alliance Tier 2 CASA verification.

Logging and monitoring. Audit logging of administrative and security-relevant events; alerting on anomalous behavior.

Vendor management. Security review of Sub-processors before engagement; continuous monitoring of public security disclosures; preference for Sub-processors that publish independent audit reports.

Incident response. Documented incident-response procedure; defined roles and responsibilities; obligation to notify the Customer of Personal Data Breaches as set out in Section 3.7.

Personnel. Confidentiality obligations on all personnel with access to Customer Personal Data; security-awareness training on hire and periodically thereafter.

Backups and disaster recovery. Encrypted backups with rolling retention as described in the Privacy Policy.

itogai is not, as of the Effective Date of this DPA, certified under SOC 2 Type II or ISO/IEC 27001. itogai tracks these certifications as future roadmap items.

Annex III: Standard Contractual Clauses Configuration

For transfers subject to Section 6.2 of this DPA, the parties complete the SCCs as follows:

  • Module: Module Two (Controller to Processor) where the Customer is a Controller, or Module Three (Processor to Processor) where the Customer is a Processor.
  • Clause 7 (Docking Clause): Not used unless agreed in writing.
  • Clause 9 (Use of Sub-processors): Option 2 (general written authorization), with the time period for advance notification of changes set as described in Section 5.3 of this DPA.
  • Clause 11 (Redress): Optional independent dispute-resolution body language is not used.
  • Clause 17 (Governing Law): The law of Ireland.
  • Clause 18 (Choice of Forum and Jurisdiction): The courts of Ireland.
  • Annex I.A (List of parties): itogai is the data importer; the Customer (and its authorized Affiliates) is the data exporter. Contact details: for itogai, privacy@itogai.com; for the Customer, the address used in the Account.
  • Annex I.B (Description of the transfer): As set out in Annex I to this DPA.
  • Annex I.C (Competent supervisory authority): Determined under Clause 13 of the SCCs.
  • Annex II (Technical and organisational measures): As set out in Annex II to this DPA.
  • Annex III (List of sub-processors): As published at itogai.app/legal/sub-processors.

For UK transfers, the UK Addendum is incorporated, with the parties’ details as set out in Annex I to this DPA, the version of the SCCs as set out above, and an end date corresponding to the termination of the Agreement. For Swiss transfers, references to “Member State” are read as “Switzerland” (or as appropriate), references to “GDPR” include references to the Swiss FADP, and the supervisory authority is the Swiss Federal Data Protection and Information Commissioner.

Contact

Questions about this DPA, requests to execute a counterpart, sub-processor objections, and audit requests: legal@itogai.com. Data-subject requests: privacy@itogai.com.

Postal address: Itogai LLC Attn: Privacy Office 4821 Jumping Way Lake Worth, Florida 33467 United States of America

Related documents

Customer Terms of ServiceThe agreementPrivacy PolicyData & privacyAcceptable Use PolicyUsing itogaiCookie PolicyCookies & trackingSub-processorsOur vendorsTrademark Notice and Usage GuidelinesBrand & trademarks
itogai

itogai is the relationship intelligence platform that makes the Trustbound™ motion real.

Built with care. Backed by trust.

Products

TrustGraph™TrustCircles™TrustReach™ Akai™Pricing

Trustbound™

Manifesto Our Principles Trustbound Podcast Revenue Program

Company

About Us Contact Us Help Center Legal

Follow us

© 2026 Itogai LLC. All rights reserved. itogai, the itogai logo, Trustbound, TrustGraph, TrustCircles, TrustReach, and Akai are trademarks of Itogai LLC.