GDPR Compliant

Data Processing Agreement

How CSOAI processes personal data in compliance with GDPR and global privacy regulations

Version 1.0
Effective: January 2026

1. Parties to This Agreement

This Data Processing Agreement ("DPA") is entered into between:

Data Controller

The organization or individual ("Customer") who has entered into a service agreement with CSOAI for AI safety training, certification, or compliance services.

Data Processor

CSOAI LTD
Companies House No: 16939677
Registered in England & Wales

2. Definitions

Personal Data:Any information relating to an identified or identifiable natural person ('data subject')
Processing:Any operation performed on personal data, including collection, storage, use, disclosure, or deletion
Data Subject:An identified or identifiable natural person whose personal data is processed
Sub-processor:Any third party engaged by CSOAI to process personal data on behalf of the Customer
GDPR:General Data Protection Regulation (EU) 2016/679
UK GDPR:The GDPR as incorporated into UK law by the Data Protection Act 2018

3. Details of Data Processing

3.1 Categories of Data Subjects

  • Employees and contractors of Customer organizations
  • AI Safety Analyst certification candidates
  • Users of CSOAI training platform
  • Representatives of member organizations

3.2 Types of Personal Data

  • Name, email address, job title
  • Organization affiliation
  • Training progress and certification status
  • Assessment scores and completion records
  • Payment information (processed via Stripe)
  • IP addresses and usage analytics

3.3 Purpose of Processing

  • Providing AI safety training and certification services
  • Managing user accounts and access
  • Processing payments and subscriptions
  • Issuing and verifying certifications
  • Sending service-related communications
  • Improving platform functionality

3.4 Duration of Processing

Personal data will be processed for the duration of the service agreement plus a retention period of 7 years for certification records (as required for professional certification integrity) and 3 years for other data, unless longer retention is required by law.

4. CSOAI's Obligations as Data Processor

CSOAI commits to:

Process personal data only on documented instructions from the Customer
Ensure persons authorized to process data are bound by confidentiality
Implement appropriate technical and organizational security measures
Assist the Customer in responding to data subject requests
Assist with data protection impact assessments when required
Delete or return all personal data upon termination of services
Make available all information necessary to demonstrate compliance
Allow for and contribute to audits conducted by the Customer
Notify the Customer of any data breach within 72 hours

5. Sub-processors

CSOAI uses the following sub-processors to deliver our services. By entering into this DPA, the Customer provides general authorization for the use of these sub-processors:

Sub-processorPurposeLocation
Stripe, Inc.Payment processingUSA (EU SCCs)
OpenAIAI council processingUSA (EU SCCs)
AnthropicAI council processingUSA (EU SCCs)
Google CloudAI council processingEU/USA
VercelApplication hostingGlobal CDN
PostgreSQL (Neon)Database hostingEU

CSOAI will notify Customers of any intended changes to sub-processors, allowing 30 days to object. Where transfers occur outside the EEA, appropriate safeguards (Standard Contractual Clauses) are in place.

6. Technical and Organizational Security Measures

CSOAI implements the following security measures:

Encryption

  • TLS 1.3 for data in transit
  • AES-256 for data at rest
  • End-to-end encryption for sensitive data

Access Control

  • Role-based access control (RBAC)
  • Multi-factor authentication
  • Regular access reviews

Infrastructure

  • SOC 2 Type II compliant hosting
  • Regular security audits
  • Automated vulnerability scanning

Operations

  • 24/7 monitoring and alerting
  • Incident response procedures
  • Regular backup and recovery testing

7. Data Subject Rights

CSOAI will assist Customers in fulfilling their obligations to respond to data subject requests, including:

Right of Access

Obtain confirmation of processing and access to data

Right to Rectification

Correct inaccurate personal data

Right to Erasure

Request deletion of personal data

Right to Restriction

Limit processing of personal data

Right to Portability

Receive data in machine-readable format

Right to Object

Object to processing based on legitimate interests

To exercise any data subject rights, contact: [email protected]

8. Data Breach Notification

In the event of a personal data breach, CSOAI will:

  • 1.Notify the Customer without undue delay and in any event within 72 hours of becoming aware
  • 2.Provide the nature of the breach, categories and approximate number of data subjects affected
  • 3.Describe the likely consequences of the breach
  • 4.Describe measures taken or proposed to address the breach
  • 5.Cooperate fully with the Customer's breach response and regulatory notification obligations

Contact Information

For questions about this DPA or data protection matters:

Data Protection Contact

[email protected]

Legal Inquiries

[email protected]

CSOAI LTD | Companies House No: 16939677 | Registered in England & Wales