Data Processing Agreement

Data Processing Agreement (Draft for legal review)

Last updated: August 5, 2026

Status: Rough draft for counsel. Enterprise customers should execute a signed DPA; this page is informational until countersigned.

1. Parties

Controller: The MAMA customer (you)

Processor: OliWoods LLC (“MAMA”)

2. Subject matter

MAMA processes Personal Data on behalf of Controller to provide AI agent orchestration, integrations, marketplace packs, billing support, and related services described in the Terms.

3. Duration

For the term of the subscription / services agreement, plus deletion/return periods below.

4. Nature and purpose

Routing prompts to LLM providers (or customer-specified endpoints); storing conversation/task context as configured; usage and cost analytics; task orchestration; security and abuse prevention.

5. Types of data & data subjects

May include identifiers, contact data, workspace metadata, content you submit, and usage data relating to customers’ end users / employees / contractors as determined by Controller.

6. Controller obligations

Controller warrants it has a lawful basis to process and instruct Processor; will not instruct unlawful processing; remains responsible for notices to data subjects where required.

7. Processor obligations

  • Process only on documented instructions
  • Confidentiality for personnel
  • Appropriate technical and organizational measures
  • Assist with data subject requests (reasonable)
  • Assist with DPIAs / breach notices as required by law
  • Delete or return Personal Data after end of services (subject to legal retention)
  • Make available information to demonstrate compliance

8. Sub-processors

Processor may engage sub-processors (e.g. hosting, auth/DB, LLM, payments, Slack/Asana when connected). Material changes — counsel: notification / objection mechanism. Current categories listed in /security and Privacy Policy.

9. International transfers

Transfers outside the EEA/UK use appropriate safeguards (e.g. SCCs) — counsel to attach modules.

10. Security

See /security. Breach notification timelines — counsel: e.g. without undue delay / 72h where required.

11. Audits

Reasonable audits under NDA, limited to once per year unless material incident — counsel to refine.

12. Liability & order of precedence

As between DPA and Terms, DPA controls for data protection conflicts — counsel. Liability caps may mirror Terms unless prohibited.

13. Contact

privacy@oliwoods.ai

Anchors used in footer

<a id="gdpr"></a>

GDPR: Processor assists Controller with GDPR obligations for in-scope processing.

<a id="soc2"></a>

SOC 2: Any SOC 2 status should be confirmed via current attestation — do not claim certification on this page unless an active report exists.