Docil.ai Data Processing Agreement

Last updated: August 3, 2026 Effective date: August 3, 2026 Version: 1.0


Contents

  1. How this DPA works
  2. 1. Definitions
  3. 2. Roles of the parties
  4. 3. Scope of processing
  5. 4. Confidentiality
  6. 5. Security
  7. 6. Subprocessors
  8. 7. Data isolation and access
  9. 8. Assistance to the Controller
  10. 9. Personal Data Breach
  11. 10. Deletion and return
  12. 11. International transfers
  13. 12. Audits
  14. 13. Liability
  15. 14. Term and general
  16. ANNEX I — Description of the processing
  17. A. List of parties
  18. B. Description of transfer
  19. C. Competent supervisory authority
  20. ANNEX II — Technical and organizational measures
  21. Architecture
  22. Encryption
  23. Access control
  24. Operational security
  25. Data minimization and retention
  26. Personnel
  27. Subprocessor management
  28. ANNEX III — Approved Subprocessors
  29. ANNEX IV — U.S. State Privacy Law terms
  30. Contact

How this DPA works

This Data Processing Agreement (“DPA”) forms part of the Terms of Service (the “Agreement”) between Start and Power LLC (“Processor,” “we,” “us”) and the customer entity that accepts the Agreement (“Controller,” “Customer,” “you”).

It applies whenever we process personal data on your behalf in connection with Docil.ai (the “Service”).

You do not need to sign this DPA for it to apply. It takes effect automatically when you accept the Agreement. If your procurement process requires a countersigned copy, or if you need us to execute your own DPA template, write to privacy@docil.ai.

Order of precedence. In the event of conflict, this DPA controls over the Agreement on matters of data protection. Where this DPA conflicts with the Standard Contractual Clauses incorporated under Section 11, the Standard Contractual Clauses control.


1. Definitions

Terms not defined here have the meaning given in the Agreement or in Applicable Data Protection Law.

  • “Applicable Data Protection Law” means all privacy and data protection laws applicable to the processing under this DPA, including the GDPR (Regulation (EU) 2016/679), the UK GDPR and the UK Data Protection Act 2018, the Swiss FADP, and U.S. State Privacy Laws.
  • “U.S. State Privacy Laws” means the California Consumer Privacy Act as amended by the CPRA, and the comparable laws of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other U.S. states, as applicable.
  • “Customer Personal Data” means personal data contained in Customer Data that we process on your behalf under the Agreement.
  • “Data Subject,” “Controller,” “Processor,” “Processing,” “Personal Data Breach” have the meanings given in the GDPR. Where U.S. State Privacy Laws apply, “Controller” includes “Business” and “Processor” includes “Service Provider” or “Processor” as those terms are defined there.
  • “Standard Contractual Clauses” or “SCCs” means the clauses annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
  • “Subprocessor” means any processor engaged by us to process Customer Personal Data.

2. Roles of the parties

You are the Controller. We are the Processor.

You determine the purposes and means of processing Customer Personal Data. We process it only to provide the Service.

Your responsibilities. You warrant that: – You have a valid legal basis for the collection and processing of all Customer Personal Data, including the data held in the sources you connect to the Service. – You have provided all notices and obtained all consents required under Applicable Data Protection Law. – Your instructions to us comply with Applicable Data Protection Law. – You are responsible for the accuracy, quality, and legality of Customer Personal Data and for how it was acquired.

Why this matters in practice. By design, we cannot see the contents of your isolated container (Section 7 and Annex II). We therefore have no practical means of assessing whether a source you connect contains personal data you are not entitled to process. That assessment is yours, and it must be made before you connect each source.

Separate controller activities. We act as an independent Controller for account, billing, support, and Service usage data. That processing is governed by our Privacy Policy, not by this DPA.


3. Scope of processing

The subject matter, duration, nature, purpose, types of personal data, and categories of data subjects are described in Annex I.

3.1 Documented instructions

We will process Customer Personal Data only on your documented instructions, which consist of: – This DPA and the Agreement; – Your configuration of the Service, including the sources you connect and the scopes you authorize; – The queries and operations you perform within the Platform; – Any further written instructions you give us, provided they are consistent with the Agreement.

We will notify you if, in our opinion, an instruction infringes Applicable Data Protection Law, unless prohibited from doing so by law. We may suspend performance of the instruction until it is confirmed, withdrawn, or amended.

3.2 Legally required processing

If a legal obligation requires us to process Customer Personal Data beyond your instructions, we will inform you before processing, unless that law prohibits such notice on important grounds of public interest.

3.3 Restrictions on our use

We will not: – Sell or share Customer Personal Data within the meaning of U.S. State Privacy Laws. – Retain, use, or disclose Customer Personal Data for any purpose other than providing the Service, or outside the direct business relationship between us, except as permitted by Applicable Data Protection Law. – Combine Customer Personal Data with personal data received from other sources, except as permitted for a Service Provider under U.S. State Privacy Laws. – Use Customer Personal Data to train, fine-tune, or improve artificial intelligence or machine learning models, whether ours or third parties’.

We certify that we understand and will comply with these restrictions.


4. Confidentiality

We will ensure that all personnel authorized to process Customer Personal Data are bound by appropriate confidentiality obligations, whether contractual or statutory, and are trained on their data protection responsibilities. Access is granted on a need-to-know basis and revoked when no longer necessary.


5. Security

We implement and maintain the technical and organizational measures set out in Annex II, designed to ensure a level of security appropriate to the risk, in accordance with GDPR Article 32.

We may update these measures over time provided the overall level of security is not materially reduced.


6. Subprocessors

6.1 General authorization

You give us general written authorization to engage Subprocessors. The current list is set out in Annex III and maintained at [SUBPROCESSOR PAGE LINK].

6.2 Notice and objection

We will notify you of any intended addition or replacement of a Subprocessor at least 30 days in advance, by email to your account address or through the subscription mechanism on the subprocessor page.

You may object on reasonable data protection grounds within 15 days of the notice. If you do, we will work with you in good faith to find an alternative. If no reasonable alternative exists, you may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees for the unused portion.

6.3 Our responsibility

We will impose on each Subprocessor, by written contract, data protection obligations no less protective than those in this DPA. We remain fully liable to you for each Subprocessor’s performance of its obligations.


7. Data isolation and access

This section records a structural feature of the Service that materially affects the risk profile of the processing.

  1. Customer Personal Data from your connected sources is stored and processed in a logically isolated container dedicated to your organization, hosted in the European Union.
  2. Our personnel do not access the contents of that container. Processing is performed automatically by the Platform and by the AI subprocessor identified in Annex III.
  3. Access is technically possible only in these circumstances: (a) where you expressly request it to resolve a support issue; (b) where strictly necessary for security purposes, such as investigating abuse or a defect; or (c) where compelled by a binding legal obligation.
  4. Any such access is recorded in an audit log and, unless legally prohibited, notified to you.
  5. All queries at the data and API layer are filtered by organization identifier, so one customer’s environment cannot reach another’s.

8. Assistance to the Controller

8.1 Data subject requests

Taking into account the nature of the processing, we will assist you by appropriate technical and organizational measures, insofar as possible, in responding to requests to exercise data subject rights (access, rectification, erasure, restriction, portability, objection).

The Service provides self-service export and deletion functions that will, in most cases, allow you to respond without our involvement. Where you need further assistance, write to privacy@docil.ai and we will respond within 10 business days.

If we receive a request directly from a data subject relating to Customer Personal Data, we will not respond to it substantively. We will redirect the data subject to you and inform you promptly, unless legally prohibited.

8.2 Other assistance

Taking into account the nature of processing and the information available to us, we will assist you in complying with GDPR Articles 32 to 36, including security of processing, breach notification, data protection impact assessments, and prior consultation with supervisory authorities.

We may charge a reasonable fee for assistance that goes materially beyond the standard functionality of the Service, after telling you in advance.


9. Personal Data Breach

We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.

The notice will include, to the extent known and as it becomes available: – The nature of the breach, including where possible the categories and approximate number of data subjects and records affected; – The likely consequences; – The measures taken or proposed to address it and mitigate its effects; – A contact point for further information.

Where all details are not available immediately, we will provide them in phases without undue further delay. We will cooperate with you and take reasonable steps to mitigate the effects.

Notification to authorities and data subjects is your responsibility as Controller. We will not notify a supervisory authority or a data subject on your behalf unless you instruct us in writing or we are legally required to do so.

Our notification of a breach is not an acknowledgment of fault or liability.


10. Deletion and return

On termination of the Agreement, or at any time on your instruction:

  • Your container and all Customer Personal Data it holds are deleted. Deletion is immediate in live systems and complete in backups within a maximum of 30 days.
  • Disconnecting an individual source deletes the data from that source without affecting the rest.
  • Before deletion you may export your data at any time using the Service’s export function. On written request made before the effective termination date, we will keep your container available in read-only mode for an additional 30 days to allow export.

We will retain Customer Personal Data only to the extent and for as long as required by applicable law, and in that case will continue to protect it under this DPA.

On written request we will certify deletion.


11. International transfers

11.1 Data location

The Service infrastructure and all customer containers are hosted in the European Union.

11.2 Transfers outside the EEA

Two categories of transfer occur, and both are covered by the mechanisms below:

(a) Access from the United States by us. We are a U.S. entity, and our administration, billing, and support personnel access account, billing, support, and operational metadata from the United States. As set out in Section 7, this access does not extend to the contents of your container.

(b) Subprocessors established outside the EEA, as identified in Annex III.

11.3 Standard Contractual Clauses

Where the transfer of Customer Personal Data from the EEA is not covered by an adequacy decision, the SCCs are incorporated into this DPA by reference and apply as follows:

  • Module Two (Controller to Processor) applies where you act as Controller.
  • Module Three (Processor to Processor) applies where you act as Processor on behalf of a third-party controller.
  • Clause 7 (docking clause) applies.
  • Clause 9: Option 2, general written authorization, with the notice period set out in Section 6.2.
  • Clause 11: the optional independent dispute resolution language does not apply.
  • Clause 17: the SCCs are governed by the law of [Ireland — or the EU Member State of your EU representative].
  • Clause 18(b): disputes will be resolved before the courts of that same Member State.
  • Annex I, II, and III of the SCCs are populated by Annexes I, II, and III of this DPA.

11.4 United Kingdom

For transfers subject to the UK GDPR, the UK International Data Transfer Addendum issued by the ICO is incorporated by reference and applies to the SCCs, with Tables 1 to 3 populated by the Annexes to this DPA and Table 4 selecting “neither party” as the party that may terminate.

11.5 Switzerland

For transfers subject to the Swiss FADP, the SCCs apply with the following adaptations: references to the GDPR are read as references to the FADP; the competent authority is the Federal Data Protection and Information Commissioner; and the term “Member State” does not prevent data subjects in Switzerland from enforcing their rights in Switzerland.

11.6 Data Privacy Framework

If we certify under the EU-U.S. Data Privacy Framework and its UK Extension or Swiss-U.S. framework, we may rely on that certification for the relevant transfers in place of the SCCs, and will state so at [DPF STATUS LINK].

11.7 Government access requests

If we receive a legally binding request from a public authority for disclosure of Customer Personal Data, we will: – Notify you promptly, unless legally prohibited; – Where prohibited, use reasonable efforts to obtain a waiver of that prohibition; – Challenge requests that appear unlawful or overbroad, or where there is a legally sound basis to do so; – Disclose only the minimum amount of data legally required.

We will maintain records of such requests and make them available to you on request, to the extent permitted by law.


12. Audits

12.1 Information

We will make available to you all information reasonably necessary to demonstrate compliance with this DPA, including our security documentation and, where available, third-party audit reports and certifications.

12.2 Audit rights

Where the information provided under Section 12.1 is not sufficient, you may conduct an audit, subject to the following: – Audits take place no more than once per calendar year, except where required by a supervisory authority or following a Personal Data Breach affecting your data. – You give at least 30 days’ written notice. – The audit is conducted during business hours, without unreasonable disruption, and under confidentiality obligations. – Any third-party auditor must not be our competitor and must sign a confidentiality agreement. – The scope is limited to systems and documentation relevant to the processing of your Customer Personal Data. It does not extend to other customers’ environments or data. – You bear the cost of the audit, unless it reveals a material breach of this DPA on our part.


13. Liability

Each party’s liability under this DPA is subject to the exclusions and limitations of liability set out in the Agreement, to the extent permitted by Applicable Data Protection Law.

Nothing in this DPA limits a data subject’s rights under Applicable Data Protection Law or under the SCCs.


14. Term and general

This DPA takes effect on the date you accept the Agreement and continues until all Customer Personal Data has been deleted in accordance with Section 10.

We may update this DPA where necessary to reflect changes in Applicable Data Protection Law, in the Service, or in our Subprocessors. Material changes will be notified at least 30 days in advance. Where a change materially reduces your protections and you object in writing within that period, you may terminate the affected part of the Service with a pro-rata refund.

Governing law. Except as provided in Section 11.3, this DPA is governed by the law stated in the Agreement.


ANNEX I — Description of the processing

A. List of parties

Data exporter (Controller): the Customer entity that accepted the Agreement. Contact details are those held in the Customer’s account. Role: Controller (or Processor, where Module Three applies).

Data importer (Processor): Start and Power LLC, 1621 Central Ave, Cheyenne, WY 82001, United States. Contact: privacy@docil.ai. Role: Processor.

B. Description of transfer

Categories of data subjects. Determined by the Customer through the sources it connects. Typically: – The Customer’s employees, contractors, and Platform users – The Customer’s customers and end users – The Customer’s leads, prospects, and business contacts – The Customer’s suppliers and partners – Authors and recipients of documents, tickets, and messages in the connected sources

Categories of personal data. Determined by the Customer. Typically: – Identification and contact data: name, email, telephone, job title, company – Account and authentication data: user identifiers, roles, access logs – Transactional and financial data: invoices, payments, subscriptions, amounts (from Stripe) – Commercial and CRM data: leads, opportunities, deals, activity history (from HubSpot, Salesforce) – Content data: documents, spreadsheets, pages, messages, tickets and their contents (from Google Drive, Google Sheets, Slack, Notion, Zendesk, Dropbox, OneDrive, SharePoint, Teams, Jira, Confluence) – Marketing and web analytics data: campaigns, metrics, queries, conversions (from Google Ads, Analytics, Search Console) – Technical data: IP addresses, timestamps, device and browser information – Data generated by the Service: summaries, analyses, insights, and chat responses derived from the above

Special categories of data. None intended. The Customer undertakes not to connect sources containing special categories of personal data, protected health information under HIPAA, or payment card data subject to PCI-DSS, without our prior written agreement. Where such data is nevertheless present, the safeguards in Annex II apply, and the Customer remains responsible for establishing a valid legal basis.

Frequency of transfer. Continuous, for the duration of the Agreement and while sources remain connected.

Nature and purpose of processing. Collection, storage, structuring, indexing, retrieval, analysis, and generation of derived outputs, exclusively for the purpose of providing AI-assisted business analysis to the Customer.

Duration. For the term of the Agreement and while each source remains connected. Deletion follows Section 10.

Subprocessors. See Annex III. Duration of their processing matches the duration above.

C. Competent supervisory authority

The supervisory authority of the EU Member State in which the Customer is established or, where the Customer is not established in the EU, of the Member State in which our EU representative under GDPR Article 27 is established.


ANNEX II — Technical and organizational measures

Architecture

  • Dedicated container per organization. Customer Personal Data from connected sources is stored and processed in a logically isolated container dedicated to a single organization. Data is never commingled between customers.
  • Application-level tenant isolation. All database queries and API calls are filtered by organization identifier.
  • No human access by default. Our personnel do not access container contents. Exceptions are limited to those in Section 7 and are logged.

Encryption

  • In transit: HTTPS/TLS 1.2 or higher for all communications, internal and external.
  • At rest: AES-256 encryption for sensitive data, credentials, and integration tokens, using an application key managed separately from the database.
  • Credentials: passwords stored only as salted hashes using a strong algorithm ([bcrypt/argon2 — specify]). Plaintext passwords are never stored or recoverable.
  • OAuth tokens: encrypted at rest and revoked on disconnection or account deletion.

Access control

  • Least privilege for all internal access.
  • Strong authentication required for technical personnel with administrative access.
  • Audit logging of administrative access, retained for [12] months.
  • Access rights reviewed on role change and revoked on departure.
  • Least-privilege OAuth scopes: for Google Drive and Sheets we use per-file access (drive.file), so the Service cannot enumerate or read files the Customer has not explicitly selected.

Operational security

  • Continuous application of security patches and dependency updates.
  • Encrypted backups with periodic restoration testing; [30]-day rotation.
  • Separation of production, staging, and development environments.
  • Logging and monitoring of authentication events and failed access attempts.
  • Documented incident response procedure aligned with Section 9.

Data minimization and retention

  • Only the context strictly necessary to answer a query is transmitted to the AI subprocessor, never the entire container.
  • Retention periods as set out in the Privacy Policy and Section 10 of this DPA.
  • Deletion on disconnection or account closure, effective in backups within 30 days.

Personnel

  • Confidentiality obligations for all personnel with potential access to systems processing Customer Personal Data.
  • Data protection and security awareness training.

Subprocessor management

  • Written data protection agreements with all Subprocessors.
  • Assessment of security posture before engagement.
  • Maintained public list with advance notice of changes.

ANNEX III — Approved Subprocessors

SubprocessorPurposeData processedLocationTransfer mechanism
[HOSTING/VPS PROVIDER]Hosting the application and customer containersAll Customer Personal DataEuropean UnionN/A — data remains in the EEA
Google Cloud (Vertex AI / Gemini API)AI processing of queriesContent fragments transmitted per query[EU region — confirm]SCCs / DPF where applicable
Stripe, Inc.Payment processing and billingBilling and customer identification dataUnited States / EUSCCs / DPF
Google LLCOAuth authentication and API integrationsAccess tokens and authorized API dataUnited States / EUSCCs / DPF
[TRANSACTIONAL EMAIL PROVIDER]Service email deliveryName, email, message content[LOCATION][MECHANISM]
[SUPPORT / HELPDESK PROVIDER]Support ticket managementName, email, inquiry content[LOCATION][MECHANISM]

Not subprocessors. The platforms the Customer connects — HubSpot, Salesforce, Slack, Notion, Zendesk, Dropbox, Microsoft, Atlassian, and others — are the Customer’s own systems, from which the Service reads data under the Customer’s authorization. They are not engaged by us and are governed by the Customer’s own contracts with them.


ANNEX IV — U.S. State Privacy Law terms

This Annex applies where Customer Personal Data is subject to U.S. State Privacy Laws. Terms used here have the meanings given in those laws.

  1. The Customer is the Business or Controller; we are the Service Provider, Processor, or Contractor, as applicable.
  2. Customer Personal Data is disclosed to us solely for the business purpose of providing the Service under the Agreement.
  3. We do not sell or share Customer Personal Data, and we receive no monetary or other valuable consideration in exchange for it.
  4. We will not retain, use, or disclose Customer Personal Data for any purpose other than the business purposes specified in the Agreement, including any commercial purpose, or outside the direct business relationship between the parties, except as permitted by applicable law.
  5. We will not combine Customer Personal Data with personal information received from or on behalf of another person, or collected from our own interactions with consumers, except as permitted for a Service Provider.
  6. We will comply with the applicable obligations of U.S. State Privacy Laws and provide the same level of privacy protection they require.
  7. The Customer may take reasonable and appropriate steps to ensure our use of Customer Personal Data is consistent with its obligations, including through the audit rights in Section 12.
  8. We will notify the Customer if we determine we can no longer meet these obligations, and the Customer may take reasonable steps to stop and remediate any unauthorized use.
  9. We will assist the Customer in responding to verifiable consumer requests as set out in Section 8.
  10. We certify that we understand the restrictions in this Annex and will comply with them.

Contact

Start and Power LLC 1621 Central Ave, Cheyenne, WY 82001, United States

Data protection: privacy@docil.ai General: hello@startandpower.com Web: https://docil.ai

EU Representative (GDPR Art. 27): [NAME, ADDRESS, AND EMAIL]


Draft document. Review by U.S. and EU legal counsel is required before publication or execution.