Data Processing Agreement (DPA)

Template for customers who require a DPA for the processing of personal data

Template version: June 2026

1. Parties & Scope

This Data Processing Agreement ("DPA") supplements and forms part of the agreement between the parties for use of VirtualBackroom.ai (the "Principal Agreement"):

  • Processor: Koala Tea with Neel LLC (doing business as Koalat.ai), operator of VirtualBackroom.ai, 2520 Wolfe Drive, Woodridge, IL 60517, United States ("we", "us", "Processor").
  • Controller / Customer: [ Customer legal name and registered address ] ("Customer", "Controller").

This DPA applies only where and to the extent we process personal data on the Customer's behalf as a processor in connection with the Service. Where the Customer's use does not cause us to process personal data on its behalf, this DPA does not apply. In the event of a conflict, this DPA prevails over the Principal Agreement with respect to the processing of personal data.

2. Definitions

Capitalized terms not defined here have the meaning given in applicable data protection law (e.g., the EU/UK GDPR and the CCPA/CPRA, as applicable).

  • "Personal Data" means information relating to an identified or identifiable natural person that the Customer submits to or generates within the Service.
  • "Processing" means any operation performed on Personal Data.
  • "Data Subject" means the individual to whom Personal Data relates.
  • "Sub-processor" means a third party engaged by us to process Personal Data on the Customer's behalf.
  • "Applicable Data Protection Law" means all privacy and data protection laws applicable to the processing under this DPA.
  • "Standard Contractual Clauses" (SCCs) means the clauses approved for the lawful transfer of Personal Data to third countries.

3. Details of Processing (Annex I)

Subject matterProvision of the VirtualBackroom.ai regulatory compliance platform and its AI features.
DurationFor the term of the Principal Agreement, plus any period required for deletion/return as set out below.
Nature & purposeHosting, storage, AI-assisted analysis, generation of compliance content, audit-trail logging, billing, and email notification.
Types of Personal DataAccount data (name, email, organization, authentication identifiers); content submitted for analysis; usage and audit-trail records; technical data (IP, logs). Customers are instructed not to submit PHI or special-category data.
Categories of Data SubjectsThe Customer's authorized users and any individuals referenced in content the Customer submits.

4. Our Obligations as Processor

  • Documented instructions. We process Personal Data only on the Customer's documented instructions, including the Principal Agreement and this DPA, unless required by law (in which case we notify the Customer unless the law prohibits it).
  • Confidentiality. Personnel authorized to process Personal Data are bound by confidentiality obligations.
  • Security. We implement appropriate technical and organizational measures, described in Annex II below.
  • Sub-processors. The Customer provides a general authorization for the sub-processors listed in Annex III. We remain responsible for their performance and will give the Customer at least 30 days’ prior notice of any intended addition or replacement of a sub-processor, so the Customer may object on reasonable data-protection grounds.
  • Assistance with Data Subject requests. Taking into account the nature of the processing, we assist the Customer with responding to Data Subject rights requests.
  • Assistance with security & DPIAs. We assist the Customer with security, breach notification, and data protection impact assessments to the extent reasonably required.
  • Personal Data breach. We notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data breach affecting the Customer's data, with information reasonably available to us.
  • Deletion or return. On termination, at the Customer's choice, we delete or return Personal Data and delete existing copies, except where retention is required by law. Content is deleted within 30 days of account closure; compliance audit-trail records are retained for 24 months; billing records are retained for approximately 7 years.

5. Sub-processors (Annex III)

We engage the following sub-processors to process Personal Data on the Customer's behalf:

Sub-processorPurposeLocation
OpenRouterRouting AI prompts to model providers (configured so providers do not train on or collect your data).United States
OpenAIDirect API for voice transcription, text-to-speech, and certain fallback features.United States
GoogleDirect AI provider API used for certain features/fallbacks.United States
MicrosoftSingle sign-on (Microsoft / Azure AD) for users who sign in with a Microsoft account.United States
Google FirebaseAuthentication (Google and Microsoft sign-in) and related identity services.United States
ReplitApplication hosting, sign-in (Replit Auth), and managed database infrastructure.United States
StripeSubscription billing and payment processing.United States
ResendTransactional and alert email delivery.United States
VirusTotalMalware scanning of uploaded files.United States

[ Exact legal entity names, locations, and links to each sub-processor's own DPA to be confirmed with counsel before execution. ]

6. International Transfers

Where Personal Data is transferred outside the Customer's jurisdiction (including to the United States), the transfer is made under the European Commission's Standard Contractual Clauses (Module Two, controller-to-processor) and, for UK data, the UK International Data Transfer Addendum (IDTA), together with any supplementary measures required by Applicable Data Protection Law. [ Applicability to specific data flows, and any Swiss addendum, to be confirmed with counsel. ]

7. Technical & Organizational Measures (Annex II)

We maintain measures appropriate to the risk, currently including:

  • Encryption of Personal Data in transit (TLS 1.2+) and encryption of stored credentials/secrets.
  • Access controls and authenticated access (OAuth / SSO) with least-privilege principles.
  • Automated PII/PHI sanitization of text before it is sent to AI providers, where applicable.
  • Malware scanning of uploaded files prior to processing.
  • Tamper-evident, ALCOA+ audit logging for traceability of AI output.
  • Rate limiting and CSRF protection on application endpoints.
  • Vendor/sub-processor selection favoring commercial API tiers that do not train on submitted data.

8. Audits, Liability, Term & Governing Law

  • Audits. We make available information reasonably necessary to demonstrate compliance with this DPA and allow for audits on reasonable prior notice, subject to confidentiality and reasonable scope. [ Audit frequency/scope to be confirmed with counsel. ]
  • Liability. Each party's liability under this DPA is subject to the limitations and exclusions set out in the Principal Agreement. [ Liability interplay and any cap to be confirmed with counsel. ]
  • Term. This DPA remains in effect for as long as we process Personal Data on the Customer's behalf.
  • Governing law. [ Governing law and venue to be confirmed with counsel — likely the State of Illinois, USA. ]

9. Signatures

Processor

Koala Tea with Neel LLC (dba Koalat.ai)

Name: __________________
Title: __________________
Date: __________________

Controller / Customer

[ Customer legal name ]

Name: __________________
Title: __________________
Date: __________________

To request a countersigned copy, contact neel@qms.coach.