Data Processing Agreement
Last updated: 4 September 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between you (the "Client") and Sarudo ("we," "us," or the "Processor"). This DPA sets out the terms under which Sarudo processes personal data on behalf of the Client in connection with the provision of the AI Employee platform.
The AI employee runs on a server the Client provisions and inside third-party accounts held in the Client's own name. Personal data therefore sits, for the most part, in the Client's own systems and under the Client's own agreements with those vendors. This DPA governs the processing Sarudo performs on the Client's behalf when building, configuring, and supporting that system.
1. Definitions
For the purposes of this Data Processing Agreement:
- Controller: The Client, who determines the purposes and means of processing personal data through the Sarudo AI Employee platform, and who is the account holder for the infrastructure and third-party services on which that processing takes place.
- Processor: Sarudo, who processes personal data on behalf of and under the instructions of the Controller.
- Data Subjects: Identifiable natural persons whose personal data is processed through the AI Employee platform. This may include the Client's customers, employees, partners, vendors, or other individuals who interact with the AI employee.
- Personal Data: Any information relating to an identified or identifiable natural person that is processed through the Sarudo platform. This includes names, email addresses, phone numbers, conversation contents, and any other data that can directly or indirectly identify an individual.
- Processing: Any operation performed on personal data, including collection, storage, retrieval, use, transmission, and deletion, whether by automated or manual means.
- Sub-processor: A third party engaged by Sarudo to process personal data on behalf of the Client. Vendors the Client contracts directly — including the Client's hosting, model, email, and integration providers — are not Sarudo sub-processors. The Client engages those vendors as its own processors, on its own terms, and Sarudo is not a party to those agreements.
2. Scope and Purpose
Sarudo processes personal data solely for the purpose of building, configuring, and supporting the AI Employee platform as described in the Terms of Service. The scope of processing includes:
- Receiving and reviewing the materials the Client supplies during onboarding and scoping, which may contain personal data
- Configuring the AI employee on the Client's server and in the Client's third-party accounts, including the handling of messages received via its configured communication channels (email, messaging platforms, web chat, voice)
- Loading and indexing knowledge base content supplied by the Client into the Client's own systems
- Configuring the generation of responses based on the Client's knowledge base and conversation context
- Configuring the retention of conversation history and context, on the Client's systems, to enable coherent multi-turn interactions
- Connecting the AI employee to third-party services the Client has contracted and configured
- Accessing the Client's systems, using access the Client grants, to perform build and support work — including diagnosing incidents, applying fixes, and configuring or running backups where engaged to do so
- Holding the Client's business contact details, support correspondence, records of hours worked, and billing records
The types of personal data processed and the categories of Data Subjects depend on the Client's use of the AI Employee platform and the content provided to it.
3. Client Obligations
As the Controller, the Client is responsible for:
- Lawful Basis: Ensuring that there is a valid legal basis for the collection and processing of personal data through the AI Employee platform, whether through consent, legitimate interest, contractual necessity, or other applicable legal grounds.
- Client Systems and Vendor Agreements: Contracting with, and acting as the account holder for, the server and the third-party services on which the AI employee runs. The Client is responsible for concluding the data-processing terms each of those vendors requires, for their configuration and security settings, and for their continued operation. Sarudo advises on what is needed during the build and configures what the Client asks it to configure, but is not a party to those agreements and does not control those vendors.
- Informing Data Subjects: Providing appropriate privacy notices to Data Subjects whose personal data will be processed through the AI employee, including information about the use of AI in processing their communications.
- Data Accuracy: Ensuring that personal data provided to Sarudo is accurate, relevant, and not excessive for the purposes of processing.
- Instructions: Providing clear, lawful instructions to Sarudo regarding the processing of personal data. If Sarudo believes an instruction infringes applicable data protection law, we will notify the Client.
- Data Protection Impact Assessment: Conducting data protection impact assessments where required by applicable law, and consulting with relevant authorities as necessary.
4. Sarudo Obligations
As the Processor, Sarudo commits to:
- Processing on Instructions: Processing personal data only in accordance with the Client's documented instructions, unless required to do so by applicable law. In such cases, Sarudo will inform the Client of the legal requirement before processing, unless prohibited by law.
- Confidentiality: Ensuring that all personnel authorized to process personal data are subject to binding confidentiality obligations, whether contractual or statutory.
- Security Measures: Implementing appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as detailed in Section 6 of this DPA.
- Assistance: Assisting the Client in fulfilling its obligations under applicable data protection laws, including responding to Data Subject requests, conducting impact assessments, and notifying authorities of data breaches.
- Data Breach Notification: Notifying the Client without undue delay (and in any event within 72 hours) upon becoming aware of a personal data breach affecting the Client's personal data in systems Sarudo operates, or arising in the course of Sarudo's own processing. Because the Client's infrastructure and vendor accounts are held and monitored by the Client, Sarudo cannot detect a breach occurring there and does not monitor those systems between engagements. The notification will include the nature of the breach, categories of data affected, likely consequences, and measures taken to address it.
5. Sub-processors
Sarudo may engage third-party sub-processors to assist in providing its services. The Client authorizes the use of sub-processors subject to the following conditions:
- Current Sub-processors: A list of current sub-processors is available upon request. The hosting, model, email, and integration providers on which the Client's AI employee runs are contracted by the Client, in the Client's own name, and are therefore not Sarudo sub-processors and do not appear on that list. The terms governing those vendors are the Client's own agreements with them.
- Contractual Obligations: Sarudo ensures that all sub-processors it engages are bound by data processing agreements that impose obligations no less protective than those set out in this DPA.
- Notification of Changes: Sarudo will notify the Client at least 30 days before engaging a new sub-processor or replacing an existing one. The notification will include the identity and role of the proposed sub-processor.
- Right to Object: The Client may object to the engagement of a new sub-processor within 14 days of receiving notification. If the Client objects and the parties cannot reach a mutually acceptable resolution, the Client may terminate the affected services.
- Liability: Sarudo remains fully liable to the Client for the performance of its sub-processors' obligations under this DPA. Sarudo is not liable for the acts or omissions of vendors the Client contracts directly.
6. Data Security
Sarudo implements and maintains the following technical and organizational security measures to protect personal data:
- Separation: Each Client's AI employee runs on infrastructure the Client holds, so the data it works with is physically and logically separate from that of other clients. One exception, stated plainly: when a support ticket is raised, its text and the diagnostic bundle attached to it are stored in a support system Sarudo operates, which is shared across clients. Nothing else leaves the Client's own infrastructure.
- Encryption: Personal data is encrypted in transit using TLS 1.2 or higher. Data at rest is not encrypted by default — the AI employee runs on the Client's standard hosting volume, and credentials sit in a configuration file on that server. Where the Client's hosting provider offers volume-level encryption, or where the Client requires encryption at rest, Sarudo will configure it as scoped build or support work. It is not enabled unless agreed in writing.
- Access Controls: Sarudo accesses the Client's systems only with credentials the Client grants, on a need-to-know basis, and the Client may revoke that access at any time. Within Sarudo, access to personal data is restricted to authorized personnel, authenticated, and logged.
- Network Security: Firewalls, intrusion detection, and security updates are configured on the Client's infrastructure during the build. Keeping them current after handover is the Client's responsibility, or work the Client can purchase in a support block.
- Incident Notification: In the event of a security incident that compromises personal data and that Sarudo becomes aware of, Sarudo will notify the Client within 72 hours, providing the details available to us and recommended remediation steps.
- Regular Testing: Sarudo conducts regular security assessments and vulnerability testing of its own systems and tooling to identify and address potential security weaknesses.
7. Data Subject Rights
Because personal data is held in systems the Client controls, the Client can act on most Data Subject requests directly. Sarudo assists the Client in responding to requests from Data Subjects exercising their rights under applicable data protection laws:
- Right of Access: Sarudo will provide the Client with the technical means to retrieve personal data relating to a specific Data Subject upon request.
- Right to Rectification: Sarudo will correct or update personal data as instructed by the Client.
- Right to Erasure: Sarudo will delete personal data relating to a specific Data Subject as instructed by the Client, or provide the means for the Client to do so in its own systems, except where retention is required by law.
- Right to Data Portability: Sarudo will provide personal data in a structured, commonly used, and machine-readable format upon the Client's request.
- Right to Restriction: Sarudo will restrict the processing of personal data as instructed by the Client.
Sarudo will respond to the Client's instructions regarding Data Subject requests within 10 business days unless a shorter timeframe is required by applicable law. Where acting on an instruction requires engineering work after handover, that work is drawn from the Client's support hours.
8. Data Transfer
Personal data is stored and processed on infrastructure the Client provisions, in the region the Client selects when opening those accounts:
- Primary Location: The Client's infrastructure is provisioned in the geographic region the Client selects with its hosting provider. Data remains in this region during normal operations, subject to that provider's terms.
- Cross-Border Transfers: Where the Client's chosen vendors transfer personal data outside the Client's jurisdiction, the applicable safeguards are those in the Client's own agreements with those vendors. For the processing Sarudo itself performs, Sarudo will ensure that appropriate safeguards are in place, such as Standard Contractual Clauses or equivalent mechanisms.
- Backups: Backups are written daily to the instance itself. Copying them to storage the Client provisions, in a location of the Client’s choosing, is available and is configured during the build on request; it is not enabled by default. Where it is enabled, the Client can inspect and change those locations in its own accounts at any time.
9. Audit Rights
The Client has the right to verify Sarudo's compliance with this Data Processing Agreement:
- Security Documentation: Upon request, Sarudo will provide the Client with relevant security documentation, including descriptions of technical and organizational measures, third-party audit reports or certifications, and data processing records.
- Audit Requests: The Client may request an audit of Sarudo's data processing activities once per year, with at least 30 days' advance notice. Audits will be conducted during normal business hours and in a manner that minimizes disruption to Sarudo's operations.
- Costs: The Client bears the costs of any audit, unless the audit reveals material non-compliance with this DPA, in which case Sarudo will bear the reasonable costs of the audit.
10. Term and Deletion
This Data Processing Agreement is effective for as long as Sarudo processes personal data on the Client's behalf — that is, during a build, and during any period in which the Client holds unused support hours or Sarudo is performing support work:
- During an Engagement: Personal data is processed and retained as necessary to perform the work the Client has engaged Sarudo to do.
- On Conclusion: Within 30 days of the end of the engagement, Sarudo will delete the personal data it holds, including its own backups of that data, and remove its access to the Client's systems, unless retention is required by applicable law. The Client may request an export before deletion.
- Data in the Client's Systems: Personal data held on the Client's own server and in the Client's own third-party accounts is not deleted by Sarudo. It stays where it is, under the Client's control, and is deleted when the Client deletes it.
- Immediate Deletion: The Client may request immediate deletion of specific personal data held by Sarudo at any time during an engagement. Sarudo will process such requests within 14 business days.
- Certification: Upon the Client's request, Sarudo will provide written certification confirming the deletion of all personal data it held.
11. Contact
For any questions or requests related to this Data Processing Agreement, please contact us at:
- Email: hello@sarudo.com