Back to home

Data Processing Agreement

Article 28 GDPR processor agreement, incorporated by reference into the Terms of Service.

v1.1, 28 September 2026We are continuing to refine these documents based on customer feedback and ongoing review.

Data Processing Agreement

This is v1.1, corrected 28 September 2026.

Effective from: 1 June 2026 (v1); accuracy-corrected 28 September 2026 (v1.1)

This Data Processing Agreement ("DPA") is intended to form part of the Terms of Service (or Master Subscription Agreement) ("Agreement") between you, our customer ("Customer"), and Network Sunday Global Limited, company number 07832813, incorporated in England and Wales and trading as CogniScale ("CogniScale", "we"). Its registered office is Queensbury House, 106 Queens Road, Brighton, BN1 3XF. This DPA governs CogniScale's processing of personal data on Customer's behalf as part of the Formula AI Control Centre ("Service").

This is the published Data Processing Agreement. Ask [email protected] to confirm how it applies to your specific contract and sign-up flow. Where Customer requires a signed copy of this DPA on their letterhead, please email [email protected].


1. Definitions

Terms in this DPA have the meaning set out below. Capitalised terms not defined here have the meaning given in the Agreement, or, failing that, in the UK GDPR or EU GDPR.

  • "Applicable Data Protection Law" means the UK Data Protection Act 2018 and UK GDPR, the EU GDPR, and any other data protection or privacy law applicable to processing of Customer Personal Data under this DPA, including the CCPA where Customer's data subjects are California residents.
  • "Controller", "Processor", "Sub-processor", "Data Subject", "Personal Data", "Personal Data Breach", and "Processing" have the meanings given in the UK GDPR.
  • "Customer Personal Data" means Personal Data that CogniScale processes on Customer's behalf in connection with the Service.
  • "Sub-processor" means any third-party processor engaged by CogniScale that processes Customer Personal Data in connection with the Service.
  • "Standard Contractual Clauses" or "SCCs" means the EU Standard Contractual Clauses, Module 2 (Controller to Processor), adopted by the European Commission Decision 2021/914 (4 June 2021), available at https://eur-lex.europa.eu/eli/dec_impl/2021/914.
  • "UK IDTA Addendum" means the United Kingdom's International Data Transfer Addendum to the EU Standard Contractual Clauses, issued by the Information Commissioner's Office under section 119A of the UK Data Protection Act 2018.
  • "EU-US DPF" means the EU-US Data Privacy Framework and its UK Extension.
  • "Personal Brain" has the meaning given in the Privacy Policy: data stored on the user's own device. Content used in an AI task may be processed by the selected AI service for that task.

2. Roles and scope

2.1 Roles

CogniScale acts as a Processor of Customer Personal Data. Customer is the Controller. Where Customer's own customers (or data subjects) are not directly Customer's employees, Customer warrants that it has the right to instruct CogniScale to process that data, and that all required notices, consents and legal bases are in place.

CogniScale separately acts as a Controller for a limited set of data relating to Customer's users, including account-administration data, billing data and platform telemetry. The terms of that controller relationship are set out in CogniScale's Privacy Policy, not in this DPA.

2.2 Scope of processing

CogniScale will process Customer Personal Data only:

  • For the duration of the Agreement (plus any post-termination retention required by Applicable Data Protection Law or expressly agreed in writing)
  • For the purpose of providing and supporting the Service
  • On Customer's documented instructions, which are deemed to include the Agreement, this DPA, and Customer's reasonable, lawful, in-product configuration and use of the Service
  • In compliance with Applicable Data Protection Law

CogniScale will immediately inform Customer if, in CogniScale's opinion, an instruction from Customer infringes Applicable Data Protection Law.

2.3 What CogniScale will NOT do with Customer Personal Data

CogniScale will not:

  • Use Customer Personal Data to train CogniScale's own AI or machine-learning models.
  • Sell, lease or share Customer Personal Data with anyone outside the Sub-processor list in Annex III, except as required by law.
  • Treat Personal Brain files as stored anywhere other than the user's own machine. Content the user selects for an AI task may be processed by the AI service handling that task, as explained in the Privacy Policy.

When CogniScale sends Customer content to an AI provider using CogniScale's own business accounts, Anthropic's and OpenAI's published business terms say they do not use that content to train their models. If a user connects their own AI subscription instead, that subscription's own terms apply, including any training setting the user has chosen.


3. Description of processing (Annex I)

See Annex I: Description of Processing at the end of this document.


4. CogniScale's obligations as Processor

4.1 Processing only on instruction

CogniScale will process Customer Personal Data only on Customer's documented instructions (as defined in section 2.2), unless required to do otherwise by UK, EU, or member-state law. Where CogniScale is required to process by law, it will inform Customer in advance unless the law prohibits such notification.

4.2 Confidentiality

CogniScale will ensure that personnel authorised to process Customer Personal Data are bound by appropriate confidentiality obligations, whether contractual or statutory.

4.3 Security

CogniScale will implement and maintain the technical and organisational measures ("TOMs") set out in Annex II: Technical and Organisational Measures sufficient to ensure a level of security appropriate to the risk.

4.4 Sub-processors

CogniScale uses the Sub-processors listed in Annex III: Sub-processor List to provide the Service.

Customer grants CogniScale general written authorisation to engage the current Sub-processors in Annex III, and to engage further Sub-processors subject to the notification and objection process below.

Notification of new Sub-processors. CogniScale will give Customer at least 30 days' prior written notice before engaging a new Sub-processor that will process Customer Personal Data. Notice will be by email to Customer's nominated security contact, plus an update to the public Sub-processor list at https://cogniscale.com/sub-processors.

Right to object. Customer may object to the engagement of a new Sub-processor on reasonable data-protection grounds during the 30-day notice period. If the parties cannot resolve the objection within 30 days of CogniScale receiving it, Customer may terminate the affected portion of the Service on 30 days' written notice without penalty, with pro-rata refund of prepaid fees for the unused portion of the Service.

Flow-down. CogniScale will impose data-protection obligations on each Sub-processor that are no less protective than those in this DPA. CogniScale remains liable to Customer for the acts and omissions of each Sub-processor as if they were CogniScale's own acts and omissions.

4.5 Assistance with Data Subject requests

CogniScale will provide reasonable technical and organisational assistance to Customer in responding to requests by Data Subjects to exercise their rights under Applicable Data Protection Law (access, rectification, erasure, restriction, portability, objection). Where a Data Subject makes a request directly to CogniScale relating to Customer Personal Data, CogniScale will direct them to Customer and notify Customer.

4.6 Assistance with DPIAs and consultation

Taking into account the nature of the processing and the information available to CogniScale, CogniScale will provide reasonable assistance to Customer with:

  • Data Protection Impact Assessments under Article 35 UK GDPR / EU GDPR
  • Prior consultation with a supervisory authority under Article 36 UK GDPR / EU GDPR
  • Notification of Personal Data Breaches to supervisory authorities and Data Subjects

4.7 Breach notification

CogniScale will notify Customer of a Personal Data Breach affecting Customer Personal Data without undue delay and in any event within 24 hours of confirming the incident affects Customer Personal Data. The notification will include, to the extent available:

  • The nature of the breach, including categories and approximate number of Data Subjects and Personal Data records affected
  • The likely consequences of the breach
  • The measures CogniScale has taken or proposes to take to address the breach and mitigate its effects
  • A name and contact point for further information

Within 5 working days of notification, CogniScale will deliver a root-cause analysis. Within 10 working days, CogniScale will deliver a written incident report.

4.8 Return or deletion at end of service

On termination or expiry of the Agreement, at Customer's choice (expressed in writing within 30 days of termination):

  • CogniScale will return Customer Personal Data to Customer in a structured, commonly-used, machine-readable format; or
  • CogniScale will delete Customer Personal Data, except where Applicable Data Protection Law or other applicable law requires CogniScale to retain the data, in which case CogniScale will retain only the minimum data required by law and protect it as required by this DPA.

Customer Personal Data will be removed from active systems within 30 days of the chosen action, and from rolling backups within 90 days thereafter. CogniScale will provide written confirmation of deletion on request.

4.9 Records of processing

CogniScale maintains records of processing activities under Article 30(2) UK GDPR / EU GDPR and will make these available to Customer or to a supervisory authority on reasonable request, redacted to the extent necessary to protect commercially sensitive third-party information.

4.10 Audit rights: Certification in Lieu of Audit

Customer may audit CogniScale's compliance with this DPA once per calendar year on 30 days' prior written notice. In lieu of physical or on-site audit, Customer will accept the following documentation as satisfying its audit rights:

  • An independent third-party audit report such as SOC 2 Type II or ISO 27001, once available (CogniScale does not currently hold either certification)
  • The current Annex II (TOMs)
  • The current Sub-processor list
  • A summary of an independent penetration test, once one has been completed
  • Written responses to Customer's reasonable, written follow-up questions

Where Customer requires an on-site audit despite the above (for example, by mandate of a supervisory authority), the parties will cooperate in good faith to schedule the audit during normal business hours, with reasonable notice, at Customer's cost. CogniScale may require Customer's auditors to sign appropriate confidentiality undertakings.

Audit rights do not extend to Sub-processors' own infrastructure beyond the documentation CogniScale itself can provide; Customer may not direct audits at CogniScale's Sub-processors.


5. International transfers

5.1 Mechanism

For transfers of Customer Personal Data from the UK or EEA to a Sub-processor in a country not covered by an adequacy decision, the parties rely on the following mechanisms, in order of priority:

  1. EU-US Data Privacy Framework (DPF) and its UK Extension, where the Sub-processor is self-certified under the DPF.
  2. EU Standard Contractual Clauses, Module 2 (Controller-to-Processor), incorporated by reference into this DPA. The parties select the optional clauses as follows:
    • Docking clause (Clause 7): not used
    • Clause 9 (sub-processor authorisation): Option 2 (general written authorisation) with a notice period of 30 days as set out in section 4.4
    • Clause 11 (Redress): the optional independent dispute resolution body is not used
    • Clause 17 (Governing law): the law of Ireland
    • Clause 18 (Choice of forum and jurisdiction): Ireland
    • Annex I.A (Parties): Customer is the data exporter (Controller); CogniScale is the data importer (Processor)
    • Annex I.B (Description of transfer): as set out in Annex I to this DPA
    • Annex I.C (Competent supervisory authority): the supervisory authority of the EEA member state in which Customer is established, or where Customer is not established in the EEA, the Irish Data Protection Commission
    • Annex II (Technical and Organisational Measures): as set out in Annex II to this DPA
    • Annex III (Sub-processors): as set out in Annex III to this DPA
  3. The UK International Data Transfer Addendum (IDTA Addendum) is incorporated by reference, modifying the SCCs as required for transfers subject to the UK GDPR. Table 1 (Parties), Table 2 (Selected Modules and Clauses), Table 3 (Annexes) and Table 4 (Ending This Addendum) of the UK IDTA Addendum are deemed to be completed consistently with the corresponding sections of the SCCs above.

5.2 Transfer Impact Assessment

We will identify the transfer mechanism and, where a Transfer Impact Assessment applies, the available assessment summary for each service that processes Customer Personal Data outside the UK or EEA, on request.

5.3 Government access requests

CogniScale will resist any unlawful or overbroad request for Customer Personal Data from a government authority and, to the extent legally permitted, will notify Customer before disclosing data in response to a government request.


6. AI-specific provisions

6.1 AI sub-processors as Sub-processors

The AI model providers (Anthropic, OpenAI, Google Cloud, Mistral, Fireworks, Cerebras, Groq and any others added to Annex III in future) are Sub-processors of CogniScale under this DPA when they process Customer Personal Data as part of inference requests routed through the Service. They are not joint controllers or independent third-party recipients.

6.2 Anthropic and OpenAI business terms

When CogniScale sends Customer content to an AI provider using CogniScale's own business accounts, Anthropic's and OpenAI's published business terms say they do not use that content to train their models. If a user connects their own AI subscription instead, that subscription's own terms apply, including any training setting the user has chosen.

6.3 EU AI Act: roles and cooperation

CogniScale's and Customer's respective roles under the EU AI Act (Provider, Deployer, or both, depending on the deployment) will be confirmed after a current legal and product check, rather than fixed here as a single position. Whatever the roles turn out to be, Customer and CogniScale will cooperate to fulfil the applicable Article 50 obligations, including:

  • Customer ensuring that its own end-users are informed that they are interacting with AI systems (where Customer has the front-line relationship with those end-users)
  • CogniScale providing the technical means within the Service to support such transparency, to the extent built and available at the time
  • Mutual assistance in responding to regulatory inquiries from the European AI Office or national competent authorities

6.4 Output and content classification

Where the Service generates outputs based on Customer Personal Data (such as wiki entries created by the ingestion classifier from inbound emails or transcripts), Customer remains the Controller of those outputs. CogniScale acts only as Processor of the outputs and applies them only as instructed (publishing to the workspace wiki, surfacing to the workspace admin, deleting on Customer instruction).

Selected ingestion workflows screen content for sensitivity before it is written to the shared organisational knowledge. Coverage depends on the source and workflow; ask us to confirm the controls for a particular data source.


7. Liability

The liability provisions of the Agreement (Master Subscription Agreement / Terms of Service) apply to liability under this DPA. Where the Agreement contains limitations of liability, those limitations apply to claims arising under this DPA except to the extent that Applicable Data Protection Law prohibits a limitation (for example, a Data Subject's direct rights under Article 82 UK GDPR / EU GDPR).

For the avoidance of doubt, where the Agreement contains a "Super Cap" for liability arising from breaches of confidentiality or data protection, that Super Cap applies to liability under this DPA.


8. Conflict and termination

8.1 Conflict

In the event of a conflict between this DPA and the Agreement, this DPA prevails to the extent the conflict relates to the processing of Customer Personal Data.

8.2 Termination

This DPA terminates automatically on termination of the Agreement. Customer's rights and CogniScale's obligations in section 4.8 (Return or deletion) survive termination.


9. Updates to this DPA

CogniScale may update this DPA from time to time to reflect changes in Applicable Data Protection Law, in CogniScale's Sub-processor list, in CogniScale's TOMs, or to address regulatory guidance. Material changes will be notified to Customer at least 30 days in advance. A changelog is published at https://cogniscale.com/dpa/changelog.

If Customer objects to a material change, Customer may terminate the Agreement under the same conditions as in section 4.4 (Right to object to Sub-processor changes).


Annex I: Description of Processing

FieldContent
Subject matter of processingThe provision of the Formula AI Control Centre platform to Customer, including authentication, organisation management, AI-agent operation, workspace knowledge storage, ingestion of content from connected services, and inference routing.
Duration of processingFor the duration of the Agreement, plus the post-termination return/deletion period in section 4.8.
Nature and purpose of processingStorage, structured database storage, transmission (including to Sub-processors), retrieval, organisation, structuring, alteration (in the case of agent edits), classification, and erasure of Customer Personal Data, for the purpose of operating the Service.
Categories of Personal Data processedCustomer's user account data (names, email addresses, organisational role), authentication credentials and logs, workspace metadata, the contents of conversations between Customer's users and AI agents, content from customer-authorised connected services such as emails and Drive documents where that access is enabled, and audit logs of platform actions.
Special categories of dataNone should be processed under normal Service use. If Customer's organisational data inadvertently includes special-category data (for example, an email mentions an employee's health status) and the Workspace Brain is enabled for an organisation (it is not yet active for any customer), the sensitivity classifier excludes that content from the organisational brain at the passage level. Customer is responsible for not deliberately submitting special-category data into the Service for any purpose.
Categories of Data SubjectsCustomer's employees, contractors, and authorised users of the platform; individuals whose data appears in content Customer has authorised the ingestion pipeline to process (for example, individuals named in Customer's customer communications, partners, prospects).
Frequency of processingContinuous, during the term of the Agreement.
Retention period for the Customer Personal DataFor the duration of the Agreement plus the return/deletion period in section 4.8, except where applicable law requires longer retention of specific records.
Sub-processorsAs listed in Annex III.
Transfers outside UK / EEAAs set out in section 5.

Annex II: Technical and Organisational Measures

CogniScale implements and maintains the following technical and organisational measures to protect Customer Personal Data. The full description of CogniScale's security posture is published at https://cogniscale.com/trust (the Trust Centre); the table below is the contractually-binding summary.

This Annex states what is evidenced today. Where a control is designed but not yet checked or not yet active, it says so, rather than asserting a blanket guarantee.

Pseudonymisation and encryption

  • Production connector tokens (API keys, OAuth tokens) are encrypted in the database, with the key held separately from the data
  • Connections to CogniScale's hosted services use HTTPS (TLS)
  • Exact algorithms and coverage for every remaining layer, including the primary application database, are confirmed on request after a current implementation check
  • Pseudonymisation is applied where practicable, for example in aggregated telemetry datasets used for operational reporting

Confidentiality

  • Access rules in the database restrict each organisation to its own data
  • We will describe our current staff sign-in, device-management and offboarding controls on request, rather than asserting a fixed rule for every member of staff on this page

Integrity

  • Changes to the Control Centre application must pass required automated checks before they can be merged. Our practice is that each code change is read before merge by a reviewer other than its author, often a separate AI review agent; GitHub does not enforce this as a formal approval.
  • We do not currently assert that every access to Customer Personal Data, every administrative action and every credential decryption is individually audit-logged; ask us for the current logging coverage for the systems in scope

Availability and resilience

  • An encrypted, EU-jurisdiction off-site backup of the production database exists, with a tested restore path
  • Retention periods, backup frequency and multi-region deployment claims are confirmed on request after a current measured review, rather than stated here as fixed targets
  • Incident response runbook with defined roles, escalation paths, and notification procedures

Restoration after physical or technical incident

  • A Disaster Recovery approach exists for the primary database's off-site backup. Specific Recovery Time and Recovery Point Objectives are confirmed on request after a current measured review

Testing and evaluation

  • An independent third-party penetration test and formal SOC 2 monitoring remain to be completed; ask us for the current security review evidence
  • Vulnerability management practices are in development; specific patch-timing commitments are confirmed on request rather than asserted here as an operating fact

Sub-processor management

  • Sub-processors selected against documented security criteria
  • We intend each Sub-processor's terms to be no less protective than this DPA; this is confirmed provider by provider on request
  • Sub-processor changes notified to Customer under the process in section 4.4

Specific to AI agents

  • Agents use the permissions available to their session and connected tools
  • The co-CEO and Connected Colleagues act on the user's instructions, within the access the user has connected. Task-scoped access tokens are not active.
  • Selected ingestion workflows screen content for sensitivity before it is written to shared organisational knowledge; coverage depends on the source and workflow, and a complete provenance tag on every passage is not asserted

Specific to CogniScale Helper

  • CogniScale Helper is designed to listen on the user's own computer, not on a public network address
  • CogniScale Helper's source code is not publicly available
  • The CogniScale Helper runs on macOS and Windows. The macOS version is signed and notarised through Apple. The Windows version is not yet code-signed, so Windows shows an 'unknown publisher' prompt during installation; code signing is being set up.
  • The local AI runtime's access beyond the platform's own folders depends on the runtime, the local account and the granted connectors; a per-folder permissions panel with instant revocation is designed but not built yet
  • Personal Brain files are stored on the user's own machine. Content selected for an AI task may be processed by that task's AI service

Annex III: Sub-processor List

The current Sub-processor list is published at https://cogniscale.com/sub-processors. The published list at that address is authoritative; this Annex is a summary and is reconciled to match it.

Sub-processorRoleRegionTransfer mechanism (where applicable)
Anthropic PBCProcesses prompts for Claude responses through CogniScale's own platform routeUnited StatesEU-US DPF + UK Extension; SCCs / IDTA as fallback
OpenAI, L.L.C.Processes prompts for GPT responses on selected routesUnited StatesEU-US DPF + UK Extension; SCCs / IDTA as fallback
Google LLCLLM inference (Gemini), configured route; production customer use not yet confirmedUS / EUEU-US DPF + UK Extension; SCCs / IDTA as fallback
Mistral AI SASLLM inference, configured route; production customer use not yet confirmedEUNo transfer outside EU
Fireworks AI, Inc.Open-weight inference, configured route; production customer use not yet confirmedUSEU-US DPF + UK Extension; SCCs / IDTA as fallback
Cerebras Systems, Inc.High-speed inference, configured route; production customer use not yet confirmedUSEU-US DPF + UK Extension; SCCs / IDTA as fallback
Groq, Inc.High-speed inference, configured route; production customer use not yet confirmedUSEU-US DPF + UK Extension; SCCs / IDTA as fallback
Supabase, Inc.Main application database, authentication and file storageLondon, United Kingdom (AWS eu-west-2)EU-US DPF + UK Extension; SCCs / IDTA as fallback
Railway CorpClient-facing services and AI routing. Task content passes through the AI router to the AI provider the customer chooses.Railway's EU region in Amsterdam for every client-facing service, measured 28 September 2026 at 12:52EU-US DPF + UK Extension; SCCs / IDTA as fallback
Netlify, Inc.Web hosting and application functionsUK, as last configuredEU-US DPF + UK Extension; SCCs / IDTA as fallback
GitHub, Inc. (Microsoft)Organisation workspace and colleague content storageUS / EU availableEU-US DPF + UK Extension; SCCs / IDTA as fallback
Arcade.dev, Inc.Third-party connector authenticationUS / EUEU-US DPF + UK Extension; SCCs / IDTA as fallback
Cloudflare R2 (Cloudflare, Inc.)Encrypted database backupsEUEU-US DPF + UK Extension; SCCs / IDTA as fallback
Resend, Inc.Transactional email, where configuredUSEU-US DPF + UK Extension; SCCs / IDTA as fallback
StripeSubscription and payment processing, where that route is usedEU / USEU-US DPF + UK Extension; SCCs / IDTA as fallback
Google Workspace (Google LLC)CogniScale internal communicationsEUEU-US DPF + UK Extension; SCCs / IDTA as fallback
Zoom Video Communications, Inc.Meetings with CogniScale staff, where customers meet our staff through ZoomLocation depends on account settingsProvider terms and transfer safeguards depend on the account used; ask us for current details
Slack Technologies, LLCMessages with CogniScale staff, where customers message our staff through SlackLocation depends on account settingsProvider terms and transfer safeguards depend on the account used; ask us for current details

Document control

FieldValue
Versionv1.1, 28 September 2026 accuracy correction
Effective from1 June 2026 (v1); accuracy-corrected 28 September 2026 (v1.1)
Change logv1.1, 28 September 2026: clarified provider training terms, code review practice, Helper signing, supplier details and security statements.
ProcessorNetwork Sunday Global Limited (trading as CogniScale)
Company number07832813
Registered officeQueensbury House, 106 Queens Road, Brighton, BN1 3XF
Contact[email protected]
Next reviewTo be confirmed