Data Processing Agreement (DPA)
Template for customers who require a DPA for the processing of personal data
Template version: June 2026
DRAFT TEMPLATE — Pending Legal Review
This is a working template provided for transparency. It has not been reviewed or
approved by legal counsel and is not an executed agreement. Items marked [ ] require
confirmation. To request a countersigned DPA for your organization, contact
neel@qms.coach.
1. Parties & Scope
This Data Processing Agreement ("DPA") supplements and forms part of the agreement between the parties for use of VirtualBackroom.ai (the "Principal Agreement"):
- Processor: Koala Tea with Neel LLC (doing business as Koalat.ai), operator of VirtualBackroom.ai, 2520 Wolfe Drive, Woodridge, IL 60517, United States ("we", "us", "Processor").
- Controller / Customer:
[ Customer legal name and registered address ]("Customer", "Controller").
This DPA applies only where and to the extent we process personal data on the Customer's behalf as a processor in connection with the Service. Where the Customer's use does not cause us to process personal data on its behalf, this DPA does not apply. In the event of a conflict, this DPA prevails over the Principal Agreement with respect to the processing of personal data.
2. Definitions
Capitalized terms not defined here have the meaning given in applicable data protection law (e.g., the EU/UK GDPR and the CCPA/CPRA, as applicable).
- "Personal Data" means information relating to an identified or identifiable natural person that the Customer submits to or generates within the Service.
- "Processing" means any operation performed on Personal Data.
- "Data Subject" means the individual to whom Personal Data relates.
- "Sub-processor" means a third party engaged by us to process Personal Data on the Customer's behalf.
- "Applicable Data Protection Law" means all privacy and data protection laws applicable to the processing under this DPA.
- "Standard Contractual Clauses" (SCCs) means the clauses approved for the lawful transfer of Personal Data to third countries.
3. Details of Processing (Annex I)
| Subject matter | Provision of the VirtualBackroom.ai regulatory compliance platform and its AI features. |
|---|---|
| Duration | For the term of the Principal Agreement, plus any period required for deletion/return as set out below. |
| Nature & purpose | Hosting, storage, AI-assisted analysis, generation of compliance content, audit-trail logging, billing, and email notification. |
| Types of Personal Data | Account data (name, email, organization, authentication identifiers); content submitted for analysis; usage and audit-trail records; technical data (IP, logs). Customers are instructed not to submit PHI or special-category data. |
| Categories of Data Subjects | The Customer's authorized users and any individuals referenced in content the Customer submits. |
4. Our Obligations as Processor
- Documented instructions. We process Personal Data only on the Customer's documented instructions, including the Principal Agreement and this DPA, unless required by law (in which case we notify the Customer unless the law prohibits it).
- Confidentiality. Personnel authorized to process Personal Data are bound by confidentiality obligations.
- Security. We implement appropriate technical and organizational measures, described in Annex II below.
- Sub-processors. The Customer provides a general authorization for the sub-processors listed in Annex III. We remain responsible for their performance and will give the Customer at least 30 days’ prior notice of any intended addition or replacement of a sub-processor, so the Customer may object on reasonable data-protection grounds.
- Assistance with Data Subject requests. Taking into account the nature of the processing, we assist the Customer with responding to Data Subject rights requests.
- Assistance with security & DPIAs. We assist the Customer with security, breach notification, and data protection impact assessments to the extent reasonably required.
- Personal Data breach. We notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data breach affecting the Customer's data, with information reasonably available to us.
- Deletion or return. On termination, at the Customer's choice, we delete or return Personal Data and delete existing copies, except where retention is required by law. Content is deleted within 30 days of account closure; compliance audit-trail records are retained for 24 months; billing records are retained for approximately 7 years.
5. Sub-processors (Annex III)
We engage the following sub-processors to process Personal Data on the Customer's behalf:
| Sub-processor | Purpose | Location |
|---|---|---|
| OpenRouter | Routing AI prompts to model providers (configured so providers do not train on or collect your data). | United States |
| OpenAI | Direct API for voice transcription, text-to-speech, and certain fallback features. | United States |
| Direct AI provider API used for certain features/fallbacks. | United States | |
| Microsoft | Single sign-on (Microsoft / Azure AD) for users who sign in with a Microsoft account. | United States |
| Google Firebase | Authentication (Google and Microsoft sign-in) and related identity services. | United States |
| Replit | Application hosting, sign-in (Replit Auth), and managed database infrastructure. | United States |
| Stripe | Subscription billing and payment processing. | United States |
| Resend | Transactional and alert email delivery. | United States |
| VirusTotal | Malware scanning of uploaded files. | United States |
[ Exact legal entity names, locations, and links to each sub-processor's own DPA to be confirmed with counsel before execution. ]
6. International Transfers
Where Personal Data is transferred outside the Customer's jurisdiction (including to the United States), the transfer is made under the European Commission's Standard Contractual Clauses (Module Two, controller-to-processor) and, for UK data, the UK International Data Transfer Addendum (IDTA), together with any supplementary measures required by Applicable Data Protection Law. [ Applicability to specific data flows, and any Swiss addendum, to be confirmed with counsel. ]
7. Technical & Organizational Measures (Annex II)
We maintain measures appropriate to the risk, currently including:
- Encryption of Personal Data in transit (TLS 1.2+) and encryption of stored credentials/secrets.
- Access controls and authenticated access (OAuth / SSO) with least-privilege principles.
- Automated PII/PHI sanitization of text before it is sent to AI providers, where applicable.
- Malware scanning of uploaded files prior to processing.
- Tamper-evident, ALCOA+ audit logging for traceability of AI output.
- Rate limiting and CSRF protection on application endpoints.
- Vendor/sub-processor selection favoring commercial API tiers that do not train on submitted data.
8. Audits, Liability, Term & Governing Law
- Audits. We make available information reasonably necessary to demonstrate compliance with this DPA and allow for audits on reasonable prior notice, subject to confidentiality and reasonable scope. [ Audit frequency/scope to be confirmed with counsel. ]
- Liability. Each party's liability under this DPA is subject to the limitations and exclusions set out in the Principal Agreement. [ Liability interplay and any cap to be confirmed with counsel. ]
- Term. This DPA remains in effect for as long as we process Personal Data on the Customer's behalf.
- Governing law.
[ Governing law and venue to be confirmed with counsel — likely the State of Illinois, USA. ]
9. Signatures
Processor
Koala Tea with Neel LLC (dba Koalat.ai)
Name: __________________
Title: __________________
Date: __________________
Controller / Customer
[ Customer legal name ]
Name: __________________
Title: __________________
Date: __________________
To request a countersigned copy, contact neel@qms.coach.