// scope
This DPA is incorporated into every Master Services Agreement and Statement of Work under which we process personal data on behalf of a client. Where you have not signed an MSA, this DPA forms part of our Terms of Service for any incidental personal data we process. Where the Standard Contractual Clauses or the UK Addendum apply, they are incorporated by reference and the operative module is the one that matches the transfer.
Last updated: August 16, 2026
1. Scope and roles
This Data Processing Agreement (the "DPA") applies whenever empowered.guru, LLC (the "Company", "we", processor) processes personal data on behalf of a client (the "Client", "you", controller) under an MSA and SoW. The Client is the controller, and the Company is the processor, except where a particular element of processing makes us a controller in our own right (for example, processing of HR data about our own personnel, or aggregated operational telemetry that does not identify your end users).
The subject-matter, duration, nature, and purpose of the processing, the categories of personal data and data subjects, and any specific instructions are described in the applicable SoW and any Data Processing Particulars schedule attached to the MSA.
2. Definitions
Capitalized terms used but not defined here have the meanings given in Regulation (EU) 2016/679 (GDPR), the UK GDPR, the EU-U.S. Data Privacy Framework, or the applicable U.S. privacy law referenced in Section 14. "SCCs" means the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914. "UK Addendum" means the International Data Transfer Addendum issued by the UK ICO (B1.0, 2 February 2022, or as updated). "Subprocessor" means any party engaged by us to process personal data on our behalf.
3. Documented instructions
We process personal data only on documented instructions from the Client, including with regard to international transfers, unless required to do otherwise by EU, UK, or U.S. law to which we are subject. Where we believe an instruction infringes data-protection law, we notify the Client without undue delay. We will not process personal data for our own purposes (including model training) except as expressly permitted in the SoW or required by law; aggregated, anonymized, or pseudonymized operational metrics that do not identify data subjects are not personal data.
4. Personnel confidentiality
We ensure that persons authorized to process personal data are bound by appropriate confidentiality obligations (in our case, employment confidentiality, access controls, and where appropriate NDAs) and that processing is performed only by personnel who need access to perform the Services.
5. Security measures
We implement and maintain the technical and organizational measures required by Article 32 GDPR and by U.S. law, including, as appropriate: encryption in transit (TLS 1.2+) and at rest (AES-256 or stronger); role-based access control and least privilege; logging of access to production data; secure development practices (code review, dependency scanning, secrets management); background checks for personnel with data access; vulnerability management; and an incident-response procedure with notification commitments per Section 8.
The full security posture is at /security and our incident-response procedure is at /legal/incident-response.
6. Subprocessors
The Client authorizes us to engage subprocessors to process personal data, subject to the following:
- We publish the current list of subprocessors at /legal/subprocessors, with the data each one processes and the country in which it is processed.
- We notify the Client in writing (email is sufficient) at least 15 days before adding a new subprocessor.
- The Client may object on reasonable grounds related to data protection within 15 days of the notice. We will work in good faith to resolve the objection; if unresolved, the Client may terminate the affected SoW for convenience without further liability except for fees earned to the date of termination.
- We enter a written contract with each subprocessor that imposes data-protection terms no less protective than this DPA, including the SCCs where the subprocessor is outside the EEA, UK, or an adequacy-jurisdiction.
- We remain liable to the Client for the acts and omissions of our subprocessors.
7. Data-subject requests
We will, taking into account the nature of the processing, assist the Client by appropriate technical and organizational measures (including the data-portability, deletion, and access features we build into the Service) to fulfill the Client's obligations to respond to requests from data subjects exercising their rights under GDPR Chapter III (including access, rectification, erasure, restriction, portability, objection, and automated decision-making). If we receive a data-subject request directly relating to the Client's personal data, we forward it to the Client without undue delay and do not respond except to acknowledge receipt and direct the data subject to the Client, unless instructed otherwise in writing.
8. Personal data breach
We notify the Client of a "personal data breach" (as defined in Article 4(12) GDPR) without undue delay and in any event within 48 hours of confirmation. The notification includes the information required by Article 33(3), to the extent known at the time, and we provide updates as the investigation progresses. We cooperate to enable the Client to meet its obligations under Articles 33 and 34. Our incident-response commitments are described at /legal/incident-response.
9. Audits and inspections
We make available to the Client all information necessary to demonstrate compliance with Article 28 GDPR and this DPA, and allow audits, including inspections, conducted by the Client or an auditor the Client mandates (subject to a reasonable confidentiality undertaking), with reasonable prior notice, during Business Hours, no more than once per year (except for cause), at the Client's cost, and in a manner that does not interfere with our operations. We may satisfy an audit request by providing a current SOC 2 Type II report, ISO 27001 certification, or comparable third-party assessment that covers the relevant systems.
10. International transfers
10.1 EU SCCs
Where personal data is transferred from the EEA to us in the U.S. (or to a subprocessor outside an adequacy jurisdiction), the parties incorporate Module Two (controller-to-processor) or Module Three (processor-to-processor) of the SCCs (Commission Implementing Decision (EU) 2021/914). Annexes I, II, and III are completed in the applicable SoW or its Data Processing Particulars schedule.
10.2 UK Addendum
Where personal data is transferred from the United Kingdom to a country not covered by a UK adequacy decision, the UK Addendum applies, with the SCCs incorporated as the "approved EU clauses" referenced in the Addendum.
10.3 U.S. Data Privacy Framework
Where the Company or a subprocessor relies on the EU-U.S. Data Privacy Framework, the UK Extension, or the Swiss-U.S. Data Privacy Framework to receive transfers, the receiving party self-certifies (or has self-certified) and the transfer is governed by the applicable Framework Principles, with this DPA supplementing (not replacing) them.
10.4 Transfer impact assessment
Where required by Schrems II and its progeny, we will provide the Client with reasonable assistance to conduct a transfer impact assessment, including details of our supplementary measures (encryption, access control, minimization, contractual safeguards, and transparency reports).
11. Return and deletion
At the Client's choice upon termination of the Services, we delete or return all personal data processed under this DPA, and delete existing copies, within 30 days (or sooner if the SoW requires), unless retention is required by applicable law. We will confirm deletion in writing.
12. DPIAs and prior consultation
We provide reasonable assistance to the Client in fulfilling its obligations under Article 35 GDPR (data-protection impact assessments) and Article 36 (prior consultation with the supervisory authority), taking into account the nature of the processing and the information available to us.
13. Changes to GDPR / UK law
If the SCCs or the UK Addendum are replaced or amended by a competent authority, we will work in good faith to update this DPA on the effective date of the new instrument so that transfers continue to have a valid legal basis.
14. US-specific terms
14.1 HIPAA
Where the Services involve Protected Health Information, the parties enter a Business Associate Agreement (BAA) that incorporates this DPA by reference. Our support for HIPAA is described at /legal/regulatory.
14.2 GLBA / SOX
Where the Services involve non-public personal information subject to the Gramm-Leach-Bliley Act or financial-reporting controls subject to the Sarbanes-Oxley Act, the SoW will describe the additional safeguards, retention rules, and audit cooperation we commit to.
14.3 State privacy laws
For processing subject to the California Consumer Privacy Act / CPRA, the Virginia CDPA, the Colorado CPA, the Connecticut CTDPA, and other U.S. state privacy laws, we honor the role allocations and request handling described in our Privacy Policy and treat the Client as the controller with respect to its consumers.
15. Order of precedence
If there is a conflict between this DPA and the MSA or SoW, this DPA controls for data-protection matters; for all other matters the MSA and SoW control. If there is a conflict between this DPA and the SCCs / UK Addendum with respect to the subject-matter of the SCCs / UK Addendum, the SCCs / UK Addendum control.
16. Contact
Our Data Protection Officer can be reached at dpo@empowered.guru.
