Skip to main content

Data Processing Agreement

Last Updated: September 10, 2026

This agreement is already in force. It takes effect automatically when you use the Platform to process personal data for which you are the controller. You do not need to sign anything, and there is no negotiation queue to join before you can buy.

If your procurement process requires an executed copy, email privacy@theartofcto.com and we will countersign this document as presented. We will also review a reasonable customer paper DPA, but this one is the standard offering.

This Data Processing Agreement ("DPA") forms part of, and is subject to, the Terms of Service between you ("Customer", the controller) and [TO CONFIRM: registered legal entity name], ABN [TO CONFIRM: Australian Business Number] ("The Art of CTO", the processor). Capitalised terms not defined here have the meaning given in the Terms of Service. "Data Protection Law" means the EU General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Australian Privacy Act 1988 (Cth), the California Consumer Privacy Act as amended, and any other data protection law applicable to the processing.

1. Roles of the parties

For personal data that Customer submits to, or generates within, the Platform — for example team member records in the 1:1 Assistant, named contacts and owners in the Command Center, stakeholders in Foundry plans, and personal data contained in uploaded files — Customer is the controller and The Art of CTO is the processor. That data is referred to below as "Customer Personal Data".

For personal data we process about the Customer's own account holders as our users — account registration, billing, support correspondence, our own product analytics and marketing — The Art of CTO is the controller, and our Privacy Policy governs instead of this DPA.

2. Processing instructions

  • We process Customer Personal Data only on Customer's documented instructions, including in relation to international transfers, unless required to do otherwise by law. Where the law requires it, we will inform Customer before processing unless the law prohibits that notice.
  • The Terms of Service, this DPA, and Customer's use of the Platform's features constitute Customer's complete documented instructions.
  • We will inform Customer if, in our opinion, an instruction infringes Data Protection Law. We may suspend the affected processing until the instruction is amended or confirmed.
  • We do not sell Customer Personal Data, do not share it for cross-context behavioural advertising, and do not use it for our own purposes, including training our own or any third party's AI models.

3. Confidentiality

Access to Customer Personal Data is limited to personnel who need it to deliver or support the Platform. All such personnel are bound by written confidentiality obligations that survive the end of their engagement, and access is provisioned on a need-to-know basis and revoked on departure.

4. Security

We implement and maintain the technical and organisational measures described in Annex B, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing, as required by Article 32 GDPR. We may update those measures over time provided the level of protection is not reduced.

5. Sub-processors

  • Customer gives general written authorisation for us to engage sub-processors. The current list is published at theartofcto.com/subprocessors.
  • We give at least 30 days' notice before a new sub-processor begins processing Customer Personal Data, by updating that page and notifying account holders by email.
  • Customer may object on reasonable data-protection grounds within that notice period. If we cannot offer a workable alternative, Customer may terminate the affected subscription and receive a refund of the unused portion.
  • We impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain fully liable to Customer for each sub-processor's performance.

6. International transfers

Customer Personal Data may be processed outside the EEA, the UK and Australia by the sub-processors listed in Annex C. Where personal data is transferred out of the EEA or the UK to a country without an adequacy decision, the transfer is made under the European Commission's Standard Contractual Clauses (Module Two, controller to processor, and Module Three where onward transfer to a sub-processor applies), together with the UK International Data Transfer Addendum where the UK GDPR applies. Those clauses are incorporated into this DPA by reference and prevail over it in the event of conflict. Copies of the transfer terms we rely on with each sub-processor are available on request.

For the purposes of the Standard Contractual Clauses: the data exporter is Customer; the data importer is The Art of CTO; the details of processing are in Annex A; the security measures are in Annex B; and the governing law and forum are those of [TO CONFIRM: Member State for SCC clauses 17 and 18 — typically the EEA country of the data exporter or Ireland].

7. Assistance with data subject rights

The Platform allows Customer to access, correct, export and delete Customer Personal Data directly. Where a data subject contacts us instead of Customer, we will not respond to the substance of the request; we will refer them to Customer and notify Customer promptly. Taking into account the nature of the processing, we will provide reasonable assistance with requests under Articles 12 to 23 GDPR that Customer cannot fulfil through the Platform itself, at no additional charge for requests of ordinary volume.

8. Personal data breaches

  • We will notify Customer without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach affecting Customer Personal Data.
  • The notification will describe the nature of the breach, the categories and approximate number of data subjects and records affected so far as known, the likely consequences, and the measures taken or proposed.
  • We will provide reasonable assistance with Customer's own notification obligations under Articles 33 and 34 GDPR, and with data protection impact assessments and prior consultations under Articles 35 and 36.
  • Notification is not an acknowledgement of fault or liability.

9. Deletion and return

Customer may export or delete Customer Personal Data at any time through the Platform. On termination or expiry of the subscription, we will delete Customer Personal Data within 30 days of the request or of account closure, except where retention is required by law. Data in encrypted backups is overwritten in the ordinary backup rotation, within 90 days of primary deletion. On request, we will confirm deletion in writing.

10. Audit

We will make available to Customer the information reasonably necessary to demonstrate compliance with Article 28 GDPR. In the first instance this is satisfied by our published security documentation, this DPA, the sub-processor list, and our responses to Customer's security questionnaire. We will also contribute to an audit or inspection conducted by Customer or an auditor Customer mandates, no more than once in any 12-month period unless required by a supervisory authority or following a personal data breach, on at least 30 days' notice, during business hours, subject to confidentiality, and without unreasonable disruption to our operations. Customer bears its own costs and reimburses our reasonable costs of an on-site audit.

Stated plainly: we are not currently certified under ISO 27001 or audited under SOC 2, and we have not commissioned an independent penetration test. Our security page sets out what we actually operate and where the gaps are. If your policy requires a third-party attestation before onboarding a vendor, we would rather you know that now than at contract stage.

11. California and other US state privacy laws

Where the CCPA applies, we act as a "service provider" in respect of Customer Personal Data. We do not sell or share that data as those terms are defined by the CCPA, we do not retain, use or disclose it for any purpose other than performing the services specified in the Terms of Service, and we do not combine it with personal information received from other sources except as permitted by the CCPA. We will notify Customer if we determine we can no longer meet those obligations.

12. Liability and precedence

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service. Where this DPA conflicts with the Terms of Service in relation to the processing of Customer Personal Data, this DPA prevails. Where the Standard Contractual Clauses conflict with this DPA, the Standard Contractual Clauses prevail.

Annex A — Details of processing

Subject matterProvision of The Art of CTO platform: content, interactive tools, the Command Center, Foundry, SplitCause, the 1:1 Assistant and related services.
DurationFor the term of the Customer's subscription or account, plus the deletion periods in Section 9.
Nature and purposeHosting, storage, structuring, retrieval, display, transmission and deletion of Customer Personal Data, and generation of AI-assisted suggestions where Customer uses those features.
Categories of data subjectsCustomer's employees, contractors, direct reports, team members, internal stakeholders, and any individuals named in records or files Customer creates or uploads.
Types of personal dataNames, job titles, work email addresses, team and reporting relationships, meeting notes and mood ratings recorded in the 1:1 Assistant, ownership assignments on services and systems, and any personal data Customer chooses to place in free-text fields or uploaded files.
Special category dataNone. The Platform is not designed for special category data under Article 9 GDPR, health data, payment card numbers or government identifiers, and Customer must not submit them.
FrequencyContinuous, for the duration of the subscription.

Annex B — Technical and organisational measures

  • Encryption in transit: TLS 1.2 or higher enforced site-wide, HSTS with includeSubDomains and preload.
  • Encryption at rest: all Postgres databases and object storage encrypted at rest with provider-managed keys.
  • Access control: OAuth 2.0 / OIDC authentication, AES-GCM encrypted session cookies with HKDF-SHA256 key derivation, role-based access to administrative functions, need-to-know provisioning and revocation within 24 hours of departure.
  • Application security: CSRF double-submit tokens on state-changing endpoints, parameterised database queries, content sanitisation on rendered content, per-endpoint rate limiting, malware scanning of uploaded files.
  • Network isolation: separate Workers for public, admin and API surfaces; database reachable only through a private connection pool; worker-to-worker endpoints protected by per-prefix shared secrets.
  • Logging: server logs pass through a sanitiser that masks email addresses, phone numbers and card-number patterns before they reach the log sink. Security logs retained for 12 months.
  • Resilience: daily automated database snapshots with point-in-time recovery, documented and periodically exercised restore procedure.
  • Vulnerability management: automated dependency scanning, daily static analysis with findings tracked to remediation, daily secret scanning of repository history, and a published vulnerability disclosure policy with a 48-hour acknowledgement commitment.
  • Pseudonymisation: IP addresses collected for security and consent purposes are deleted after 30 days. Audience measurement uses a hash of your IP address under a secret that rotates daily, so it cannot be reversed or linked across days; it also uses a short-lived session identifier stored in your browser, which rotates after 30 minutes of inactivity and is never linked to your account unless you are signed in.

The current, more detailed statement of these measures is maintained at theartofcto.com/security, which also names the controls we do not yet operate.

Annex C — Authorised sub-processors

The current list, including what each sub-processor receives and where it processes, is maintained at theartofcto.com/subprocessors and is incorporated into this DPA by reference.

Contact

Data protection enquiries, execution requests and audit requests: privacy@theartofcto.com. We have not appointed a Data Protection Officer; we are not required to under Article 37 GDPR, and privacy@theartofcto.com is the single point of contact for all data protection matters.