This Data Processing Agreement (“DPA”) forms part of the Standard Terms and Conditions or other agreement between Dome Systems and Customer for the provision of the Platform. Unless otherwise defined in this DPA, capitalized terms used in this DPA will have the meaning given to them in the Agreement.
1. Roles and Scope
1.1 Roles of the Parties. With respect to any Customer Data that constitutes “personal data,” “personal information,” or an analogous term under applicable Data Protection Law (“Customer Personal Data”), (a) Customer is the “controller” and “business”(as such terms are defined under applicable Data Protection Law) and (b) Dome Systems is the “processor” and “service provider” (as such terms are defined under applicable Data Protection Law). Each party will comply with its respective obligations under applicable privacy and data protection law (“Data Protection Law”) in connection with the Platform and Customer Personal Data.
1.2 Scope of Processing. The subject matter, nature, and purpose of Dome Systems’ Processing of Customer Personal Data, the types of Customer Personal Data Processed by Dome Systems, and the categories of “data subjects” (as such term is defined under applicable Data Protection Law) are set out in Schedule I.
1.3 Conflicts in Interpretation. If there is any inconsistency or conflict between terms of this DPA and the other terms of the Agreement, the terms of this DPA will control to the extent of such inconsistency or conflict.
2. Processing of Customer Personal Data
2.1 Documented Instructions. Dome Systems will Process Customer Personal Data only to provide the Platform and in accordance with Customer’s documented instructions, which are as set forth in this DPA, the Agreement, or otherwise provided by Customer to Dome Systems in writing (“Documented Instructions”). Unless prohibited by applicable law, Dome Systems will inform Customer if, in Dome Systems’ opinion, an instruction from Customer violates Data Protection Law, or if Dome Systems is subject to a legal obligation that requires Dome Systems to Process Customer Personal Data in contravention of Customer’s Documented Instructions. Customer will ensure that its Documented Instructions comply with Data Protection Law and is responsible for determining whether the Services are appropriate for the Processing of Customer Personal Data.
2.3 CCPA. Dome Systems will not (a) “sell” or “share” (as such terms are defined in the California Consumer Privacy Act, as amended by the California Privacy Rights Act) Customer Personal Data, (b) retain, use, or disclose Customer Personal Data for any purpose other than in accordance with the Documented Instructions, (c) retain, use, or disclose Customer Personal Data outside of the direct business relationship between Customer and Dome Systems, nor (d) except as otherwise permitted under applicable Data Protection Law, combine Customer Personal Data with personal information that Dome Systems receives from or on behalf of any third party.
2.4 Confidentiality of Personnel. Dome Systems will ensure that personnel authorized to Process Customer Personal Data are subject to an appropriate duty of confidentiality.
3. Subprocessors
3.1 Authorization. Customer provides general authorization for Dome Systems to engage the following subprocessors as described in trust.domesystems.ai/subprocessors (“Subprocessors”). Dome Systems will (a) enter into a contractual agreement with each Subprocessor that imposes data protection obligations that are substantially as protective as Dome System’s obligations under this DPA to the extent applicable to the nature of the services provided by such Subprocessor and (b) remain responsible for the acts and omissions of the Subprocessors’ processing of Customer Personal Data under this DPA.
3.2 Notice of New Subprocessors. Dome Systems will provide Customer reasonable advance notice prior to appointing any new Subprocessor, which notice may be given by posting an update to the Trust Center. Customer may object to the appointment of a new Subprocessor within 15 days of such notice on reasonable privacy or security grounds by providing Dome Systems written notice of its objection. If Customer objects, Customer and Dome Systems will work together in good faith to address any such objection.
4. Assistance
4.1 Data Subject Rights. Dome Systems will (a) promptly forward to Customer any request it receives from a data subject or “consumer” (as such term is defined under applicable Data Protection Law) to exercise their rights under applicable Data Protection Law relating to Customer Personal Data, (b) advise such data subjects and consumers to submit the request directly to Customer, and (c) provide Customer with reasonable assistance, through appropriate technical and organizational measures, insofar as this is possible, for Customer to fulfil its obligations to respond to such requests.
4.2 Cooperation. Taking into account the nature of the Processing and the information available to Dome Systems, Dome Systems will provide Customer with reasonable assistance as necessary for Customer to fulfil its obligations under applicable Data Protection Law, including to conduct data protection impact assessments and, where required, consultations with supervisory authorities. Dome Systems may charge Customer a reasonable fee for such assistance under this Section 4.2.
5. Security
5.1 Security Measures. Dome Systems will use commercially reasonable efforts to implement and maintain technical and organizational security measures designed to protect the security of Customer Personal Data (“Security Measures”), as described at Dome Systems’ Trust Center trust.domesystems.ai. Dome Systems may update or modify the Security Measures, provided that any such update or modification does not materially decrease the overall security of the Platform. Dome Systems maintains the following audits and certifications, details of which are available Dome Systems’ Trust Center trust.domesystems.ai (e.g., SOC2 Type II, ISO 27001, or substantially similar industry standards).
5.2 Security Incident. Dome Systems will notify Customer without undue delay, and in any case within 72 hours after becoming aware any accidental or unauthorized access to, or disclosure or use of, Customer Personal Data (“Security Incident”). Dome Systems will assist Customer in complying with Customer’s obligations under applicable Data Protection Law by making reasonable efforts to provide Customer with information relating to the Security Incident. Dome Systems will also use reasonable efforts to investigate the Security Incident and mitigate the effects and remediate the causes of the Security Incident.
5.3 Audits. Upon Customer’s written request, no more than once every 12 months (except following a Security Incident or as required by a supervisory authority), Dome Systems will permit Customer to conduct an audit of Dome Systems’ controls applicable to its Processing of Customer Personal Data and compliance with this DPA to the extent required by applicable Data Protection Law (“Audit”), provided that the Audit is (a) conducted by Customer or a third-party auditor designated by Customer that has executed an appropriate confidentiality agreement with Dome Systems, (b) conducted at Customer’s sole cost, (c) during normal business hours, (d) carried out in a manner that causes minimal disruption to Dome Systems’ business, and (e) in accordance with mutually agreed upon scope and terms, including the start date, scope and duration of, and security and confidentiality controls applicable to, such audit. In lieu of an on-site or document-based Audit, Dome Systems may satisfy its obligations under this Section 5.3 by providing Customer with a copy of a then-current third-party audit report (e.g., SOC 2 Type II) and a completed information security questionnaire addressing substantially the same subject matter, to the extent such materials are available. Customer may use the results of an Audit only to meet its regulatory audit requirements or confirm Dome Systems’ compliance with this DPA.
6. International Data Transfers
6.1 Data Transfers. Customer authorizes Dome Systems to conduct transfers of Customer Personal Data to countries deemed to have an adequate level of data protection by the European Commission or the applicable competent regulatory authority on the basis of adequate safeguards in accordance with Data Protection Law or pursuant to (a) the contractual clauses annexed to the European Commission’s Implementing Decision 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of Personal Data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council, as amended, superseded, or replaced from time to time (“EU SCCs”) or (b) the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner, Version B1.0, in force 21 March 2022, as amended, superseded or replaced from time to time (“UK Addendum”).
6.2 EU Data Transfers. For transfers of Customer Personal Data from the European Union, Dome Systems and Customer conclude Module 2 (controller-to-processor) of the EU SCCs and, if Customer is a processor on behalf of a third-party controller, Module 3 (Processor-to-Subprocessor) of the EU SCCs, which are incorporated herein and completed as follows: (a) the “data exporter” is Customer, (b) the “data importer” is Dome Systems, (c) the optional docking clause in Clause 7 is implemented, (d) option 2 of Clause 9(a) is implemented and the time period therein is specified in Section 3.2, (e) the optional redress clause in Clause 11(a) is struck, (f) option 1 in Clause 17 is implemented, (g) the governing law is the law of Ireland and the courts in Clause 18(b) are the Courts of Dublin, Ireland, and (h) Annex I and Annex II to Module 2 and 3 of the EU SCCs are Schedule I and the Security Measures respectively. For transfers of Customer Personal Data from Switzerland, any dispute arising from these EU SCCs relating to Swiss Data Protection Laws will be resolved by the courts of Switzerland and data subjects who have their habitual residence in Switzerland may bring claims under the EU SCCs before the courts of Switzerland.
6.3 UK Data Transfers. For transfers of Customer Personal Data from the United Kingdom, Dome Systems and Customer conclude the UK Addendum, which is incorporated herein and completed as follows: (a) in Table 1, the “Exporter” is Customer and the “Importer” is Dome Systems, their details are set forth in this DPA and the Agreement, (b) in Table 2, the first option is selected and the “Approved EU SCCs” are the EU SCCs referred to in Section 6.2, (c) in Table 3, Annexes 1 (A and B) and II to the “Approved EU SCCs” are Schedule I and the Security Measures respectively; and (d) in Table 4, both the “Importer” and the “Exporter” can terminate the UK Addendum.
7. Deletion and Return
Upon expiration or termination of the Agreement, Dome Systems will promptly return or delete Customer Personal Data retained by Dome Systems, except that Dome Systems may retain Customer Personal Data (a) as expressly agreed by the parties, (b) as necessary to comply with applicable law, or (c) to the extent contained in standard backups, in each case subject to the confidentiality and security obligations of the Agreement until deleted in the ordinary course. Customer may request the return of any such retained Customer Personal Data within 30 days after termination of the Agreement.
Schedule I — Description of Processing
A. List of Parties
Data Exporter:
Name: Customer.
Activities relevant to the transfer: Customer accesses and uses the Platform as described in the Agreement and provides Customer Personal Data to Dome Systems in that context, including by registering Agents, configuring Cedar policy, and routing tool and model calls through the Gateway and Broker.
Role (controller/processor): Controller.
Data Importer:
Name: Dome Systems, Inc.
Activities relevant to the transfer: Dome Systems provides the Platform to Customer as described in the Agreement, including the Agent Registry, Tool Gateway, Model Broker, authorization engine, and Audit Log, and Processes Customer Personal Data on behalf of Customer in that context.
Role (controller/processor): Processor on behalf of Customer.
B. Categories of Data Subjects
- Customer’s employees, contractors, and personnel who configure or operate Agents;
- Customer’s end users on whose behalf an Agent acts (identified via act-as claims propagated through the Gateway and Broker); and
- Individuals whose personal data is contained within tool call arguments, tool call responses, or model prompts/completions submitted to or returned by the Platform (the scope and categories of which are determined and controlled by Customer through its choice of connected tools, backends, and Model Providers).
C. Categories of Customer Personal Data
Any Customer Personal Data that Customer elects to submit to the Platform, the scope of which is determined and controlled by Customer.
D. Sensitive Data
Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialized training), keeping a record of access to the data, restrictions for onward transfers or additional security measures: N/A.
E. Frequency of Transfer
The frequency of the International Data Transfer (e.g. whether the Personal Data is transferred on a one-off or continuous basis): On a continuous basis.
F. Nature of the Processing
The Customer Personal Data will be processed and transferred as described in the Agreement and DPA.
G. Purpose(s) of Transfer and Further Processing
The Customer Personal Data will be transferred and further processed for the provision of the services as described in the Agreement and DPA.
H. Duration of Processing
The period for which the Personal Data will be retained, or, if that is not possible, the criteria used to determine that period: Customer Personal Data will be retained for as long as necessary taking into account the purpose of the processing, and in compliance with applicable laws, including laws on the statute of limitations and Data Protection Law.
I. Subprocessors Transfers
For International Data Transfer to (Sub)Processors, also specify subject matter, nature and duration of the processing: For the subject matter and nature of thep, reference is made to the Agreement and DPA. The processing will take place for the duration of the Agreement.
J. Competent Supervisory Authority
The competent authority for the processing of Customer Personal Data relating to data subjects located in the EEA is the Supervisory Authority of Ireland.
The competent authority for the processing of Customer Personal Data relating to data subjects located in the UK is the UK Information Commissioner.
The competent authority for the processing of Customer Personal Data relating to data subjects located in Switzerland is the Swiss Federal Data Protection and Information Commissioner.
K. Technical and Organizational Measures
Dome Systems will implement security safeguards designed to protect the security, confidentiality and integrity of Customer Personal Data as described in the Trust Center trust.domesystems.ai.