Data Processing Agreement
1. Parties and roles
Controller: the Customer (the organisation or professional entering into the Terms of Service).
Processor: Column Seven (8 The Green, Ste B, Dover DE 19901, USA), operating the TeamOffice platform.
This DPA prevails over the Terms of Service for all data-protection matters.
2. Subject matter, duration, nature and purpose
- Subject matter: processing of Workspace Content — files, documents, drafts, deliberations, voice captures and transcripts, conversation history, collaborator details, and connected-app data.
- Duration: term of the Customer's subscription.
- Nature and purpose: storage, retrieval, display, AI-assisted analysis and generation, transcription, export, and integration actions — solely as initiated by the Customer in the app.
- Categories of data subjects: the Customer's personnel and collaborators; the Customer's clients; other individuals appearing in workspace materials.
- Categories of personal data: identity and contact data; matter-related information of any kind contained in documents. Workspace Content may include special-category data (Art. 9 GDPR), which is processed only as embedded in Customer content and never extracted or used independently.
3. Processor obligations (GDPR Art. 28(3)(a)–(h))
- Documented instructions only. The Customer's in-app actions constitute the instructions. No use of Workspace Content for model training, product analytics on content, or any independent purpose.
- Confidentiality. Processor personnel with access to Workspace Content are bound by confidentiality. Access is restricted to what service operation strictly requires. There is no routine human access to Workspace Content.
- Security (Art. 32). See Annex II for technical and organisational measures.
- Sub-processors. General written authorisation is given in advance (see Annex III). The Processor will notify the Customer at least 30 days before adding a material new sub-processor. The Customer may object; if the objection is unresolved within 30 days, the Customer may terminate without penalty.
BYOK carve-out: AI providers the Customer connects using their own API keys are not Processor sub-processors — they are the Customer's own vendors under the Customer's agreements. In BYOK mode, only the providers the Customer chose receive Workspace Content. - Data-subject rights assistance. In-app search, export (full account export), and deletion let the Customer handle requests directly. Requests received directly by Processor are forwarded to the Customer promptly.
- Breach notification. Processor will notify the Customer without undue delay, targeting 72 hours from awareness of a personal data breach, including the known scope and remediation status.
- Deletion or return. Full self-service export is available at any time. Workspace Content is deleted within 30 days of account termination. Backups purge on a rolling 30-day cycle.
- Audit. Processor will provide documentation (this DPA, security annex, sub-processor list) on request. On-site or technical audits may be arranged by agreement. A completed security questionnaire is available on request.
4. AI-specific terms
- No training on Workspace Content, by Processor or its sub-processors.
- Prompts and content sent to LLM providers only to fulfil the Customer's request in the moment. Platform-credit providers are contractually bound to no-training terms.
- BYOK mode: routing occurs under the Customer's own provider agreement. Processor stores keys encrypted and transmits them only to the chosen provider.
- Local-model mode (Ollama, LM Studio): content leaves neither the Customer's machine nor their control. No sub-processor is involved.
- AI output is generated content, not professional advice. The Customer is responsible for professional review (cross-reference Terms §2).
5. International transfers
Where Workspace Content is processed outside the EU/UK, the Processor relies on the Standard Contractual Clauses (EU Commission Decision 2021/914, Module 2) incorporated by reference, and the UK Addendum for UK customers. Sub-processors are bound to equivalent safeguards (see Annex III).
6. Liability
Each party's liability under this DPA is subject to the same aggregate cap as set out in the Terms of Service §10. This DPA does not increase aggregate liability. Nothing in this DPA excludes liability that cannot be excluded by applicable law.
7. Annexes
Annex I — Description of processing
As described in Section 2 above (subject matter, nature, purpose, duration, categories of data and data subjects).
Annex II — Technical and organisational measures
- Encryption in transit: TLS 1.2+ for all data in transit between customer and service.
- Encryption at rest: Workspace Content, API keys, and OAuth tokens are encrypted at rest.
- API key storage: Customer-provided API keys are encrypted using AES-256-GCM before persistence.
- Workspace isolation: per-workspace access controls ensure one customer cannot access another's content.
- Credential security: passwords hashed with scrypt; no plaintext credential storage.
- Access controls: least-privilege administration; personnel access audited.
- Logging: authentication events and administrative actions are logged.
- Infrastructure security: managed by Replit (Google Cloud infrastructure); platform-level security controls apply.
Annex III — Sub-processor list
| Provider | Purpose | Location | Safeguards |
|---|---|---|---|
| Replit / Google Cloud | Application hosting and server infrastructure | US | DPA, SCCs |
| PostgreSQL (Replit managed) | Database storage | US | DPA |
| OpenRouter (and partner LLM networks) | AI request routing (platform-credit mode only) | US | DPA, no-training terms |
| Composio | Third-party app integration layer | US | DPA |
| Stripe | Payment processing (independent controller) | US | Listed for transparency; independent controller, SCCs |
| Transactional email provider | Service and account emails | To be confirmed | DPA |
The BYOK carve-out in Section 3(4) applies: AI providers the Customer connects using their own API keys are not sub-processors under this DPA.
To request a countersignable PDF or a completed security questionnaire, contact privacy@teamoffice.ai.