Data Processing Agreement
Data Processing Agreement (Draft for legal review)
Last updated: August 5, 2026
Status: Rough draft for counsel. Enterprise customers should execute a signed DPA; this page is informational until countersigned.
1. Parties
Controller: The MAMA customer (you)
Processor: OliWoods LLC (“MAMA”)
2. Subject matter
MAMA processes Personal Data on behalf of Controller to provide AI agent orchestration, integrations, marketplace packs, billing support, and related services described in the Terms.
3. Duration
For the term of the subscription / services agreement, plus deletion/return periods below.
4. Nature and purpose
Routing prompts to LLM providers (or customer-specified endpoints); storing conversation/task context as configured; usage and cost analytics; task orchestration; security and abuse prevention.
5. Types of data & data subjects
May include identifiers, contact data, workspace metadata, content you submit, and usage data relating to customers’ end users / employees / contractors as determined by Controller.
6. Controller obligations
Controller warrants it has a lawful basis to process and instruct Processor; will not instruct unlawful processing; remains responsible for notices to data subjects where required.
7. Processor obligations
- Process only on documented instructions
- Confidentiality for personnel
- Appropriate technical and organizational measures
- Assist with data subject requests (reasonable)
- Assist with DPIAs / breach notices as required by law
- Delete or return Personal Data after end of services (subject to legal retention)
- Make available information to demonstrate compliance
8. Sub-processors
Processor may engage sub-processors (e.g. hosting, auth/DB, LLM, payments, Slack/Asana when connected). Material changes — counsel: notification / objection mechanism. Current categories listed in /security and Privacy Policy.
9. International transfers
Transfers outside the EEA/UK use appropriate safeguards (e.g. SCCs) — counsel to attach modules.
10. Security
See /security. Breach notification timelines — counsel: e.g. without undue delay / 72h where required.
11. Audits
Reasonable audits under NDA, limited to once per year unless material incident — counsel to refine.
12. Liability & order of precedence
As between DPA and Terms, DPA controls for data protection conflicts — counsel. Liability caps may mirror Terms unless prohibited.
13. Contact
privacy@oliwoods.ai
Anchors used in footer
<a id="gdpr"></a>
GDPR: Processor assists Controller with GDPR obligations for in-scope processing.
<a id="soc2"></a>
SOC 2: Any SOC 2 status should be confirmed via current attestation — do not claim certification on this page unless an active report exists.