Data Processing Agreement
This Data Processing Agreement (the “DPA”) is concluded between the customer using the Pitch Avatar service (the “Customer”) and ROIFORCIO GmbH, FN 461562v, 15/62 Wallgasse, 1060 Vienna, Austria (“ROIFORCIO”), and forms an integral part of the Terms of Use (the “Agreement”). It is entered into by the Customer upon acceptance of the Agreement and applies where ROIFORCIO processes personal data on behalf of the Customer in the course of providing the Service.
Terms used in this DPA and not defined here have the meaning given to them in Regulation (EU) 2016/679 (the “GDPR”) or in the Agreement.
1. Roles of the parties
1.1. In respect of Customer Personal Data – that is, personal data contained in User Content uploaded to, submitted to or generated through the Service by the Customer or by users acting under the Customer’s account – the Customer acts as controller and ROIFORCIO acts as processor within the meaning of Article 4(7) and 4(8) GDPR.
1.2. In respect of account registration data, billing data, support correspondence, security logs and usage data processed by ROIFORCIO for its own purposes of providing, securing, invoicing, supporting and improving the Service and of complying with its legal obligations, ROIFORCIO acts as controller and processes those data in accordance with its Privacy Policy. Such processing is outside the scope of this DPA.
1.3. The Customer warrants that it has a valid legal basis under Article 6 GDPR and, where applicable, Article 9(2) GDPR for the processing of Customer Personal Data and for its transmission to ROIFORCIO, that it has provided the information required by Articles 13 and 14 GDPR to the data subjects concerned, and that its instructions do not cause ROIFORCIO to breach the GDPR or other applicable data protection law.
1.4. Where the Customer uses the Service to generate or manipulate content reproducing the voice or the likeness of a natural person, the Customer warrants that it has obtained and retained the documented consent required under paragraph 5.6 of the Agreement and, where that consent also constitutes the legal basis under the GDPR, that it satisfies the conditions of Article 7 GDPR.
2. Subject matter and details of the processing
2.1. The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex I to this DPA, which satisfies the requirements of Article 28(3) GDPR.
2.2. The processing lasts for the term of the Agreement and for the additional periods provided for in Section 10.
3. Instructions
3.1. ROIFORCIO shall process Customer Personal Data only on documented instructions from the Customer, including as regards transfers to a third country, unless required to do so by Union or Member State law to which it is subject; in that case ROIFORCIO shall inform the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
3.2. The Agreement, this DPA and the use of the functionality of the Service by the Customer and its users constitute the Customer’s complete documented instructions. Additional instructions shall be given in writing or by e-mail to info@roi4cio.com, marked “data protection instruction” in the subject line; where an additional instruction requires effort exceeding the functionality of the Service, ROIFORCIO may charge the reasonable cost of implementing it, having first informed the Customer.
3.3. ROIFORCIO shall inform the Customer without undue delay if, in its opinion, an instruction infringes the GDPR or other applicable data protection law, and may suspend the execution of that instruction until it is confirmed or amended.
4. Confidentiality
4.1. ROIFORCIO shall ensure that persons authorised to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and shall grant access only to those persons who need it for the performance of the Agreement.
5. Security of processing
5.1. ROIFORCIO shall implement and maintain the technical and organisational measures set out in Annex II, having regard to the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing as well as the risk to the rights and freedoms of natural persons, in accordance with Article 32 GDPR.
5.2. ROIFORCIO may update those measures provided that the level of security is not reduced. The current version of Annex II is published and made available to the Customer on request.
5.3. The Customer is responsible for the secure configuration of its own account, for the management of user seats and credentials and for the assessment of whether the measures in Annex II are appropriate to the risk of the processing it initiates.
6. Sub-processors
6.1. The Customer grants ROIFORCIO general written authorisation to engage sub-processors. The sub-processors engaged at the date of this DPA are listed in Annex III; the current list is published in the Privacy Policy.
6.2. ROIFORCIO shall inform the Customer of any intended addition or replacement of a sub-processor by e-mail and by updating the published list not less than thirty (30) days before the change takes effect. The Customer may object to the change on reasonable grounds related to data protection within that period. If the parties do not reach a solution within thirty (30) days of the objection, the Customer may terminate the affected subscription with effect from the date on which the change takes effect, against a pro rata refund of prepaid fees for the unused period.
6.3. ROIFORCIO shall impose on each sub-processor, by contract, data protection obligations no less protective than those set out in this DPA, and remains fully liable to the Customer for the performance of the sub-processor’s obligations.
6.4. ROIFORCIO shall contractually ensure that no sub-processor providing generative artificial intelligence capabilities uses Customer Personal Data or Customer content to train, fine-tune or improve models made available to other customers or to the public.
7. International transfers
7.1. Customer Personal Data processed for the purposes of hosting and of retrieval-augmented generation is stored within the European Economic Area.
7.2. Where a transfer of Customer Personal Data to a third country is necessary, ROIFORCIO shall ensure that it takes place only on the basis of an adequacy decision under Article 45 GDPR or of appropriate safeguards under Article 46 GDPR, in particular the standard contractual clauses set out in Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor) or Module Three (processor to processor) as applicable, supplemented where necessary by additional measures identified in a transfer impact assessment.
7.3. By entering into this DPA the parties are deemed to have signed those standard contractual clauses, which are incorporated by reference, with the Customer as data exporter and ROIFORCIO as data importer in respect of any transfer from the Customer to ROIFORCIO outside the European Economic Area, and with Annexes I, II and III to this DPA serving as Annexes I, II and III to the clauses. The optional docking clause applies; in Clause 17 the law of Austria is chosen and in Clause 18(b) the courts of Austria are designated.
8. Assistance to the Customer
8.1. Taking into account the nature of the processing, ROIFORCIO shall assist the Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Customer’s obligation to respond to requests for exercising the data subject’s rights under Chapter III GDPR. Where ROIFORCIO receives such a request directly, it shall not respond to it on the merits and shall forward it to the Customer without undue delay.
8.2. ROIFORCIO shall assist the Customer in ensuring compliance with the obligations under Articles 32 to 36 GDPR, taking into account the nature of the processing and the information available to it, including by providing the information necessary for a data protection impact assessment in respect of the Service.
8.3. Where the Customer carries out a data protection impact assessment or a fundamental rights impact assessment in connection with the use of artificial intelligence features of the Service, ROIFORCIO shall provide, on reasoned request, the information about the AI systems concerned which it is required to make available under Articles 13 and 50 of Regulation (EU) 2024/1689.
9. Personal data breaches
9.1. ROIFORCIO shall notify the Customer without undue delay and in any event within forty-eight (48) hours after becoming aware of a personal data breach affecting Customer Personal Data.
9.2. The notification shall describe, to the extent known, the nature of the breach including the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed to address the breach, and a contact point for further information. Where the information cannot be provided at the same time, it shall be provided in phases without undue further delay.
9.3. ROIFORCIO shall not notify a supervisory authority or data subjects on behalf of the Customer unless instructed to do so, and shall cooperate with the Customer in the investigation, mitigation and remediation of the breach.
10. Deletion and return of data
10.1. Upon termination of the Agreement the Customer may export Customer Personal Data through the functionality of the Service for a period of thirty (30) days.
10.2. After the expiry of that period ROIFORCIO shall delete Customer Personal Data, including existing copies, within a further sixty (60) days, unless Union or Member State law requires its storage. Data contained in backup media are deleted in accordance with the backup rotation cycle, which does not exceed ninety (90) days, and remain subject to this DPA until deletion.
10.3. ROIFORCIO shall confirm the deletion in writing upon request.
10.4. Voice samples, facial images, avatars and other material reproducing the voice or the likeness of a natural person submitted by the Customer are deleted upon deletion of the corresponding item in the account, and in any event in accordance with paragraph 10.2.
11. Audits and records
11.1. ROIFORCIO shall make available to the Customer all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR, including the current version of Annexes II and III and, where available, third-party certifications and audit reports.
11.2. The Customer may, at its own cost, audit compliance with this DPA not more than once in any period of twelve (12) months, upon thirty (30) days’ prior written notice, during normal business hours, subject to the signature of a confidentiality undertaking and without disrupting the operations of ROIFORCIO or the confidentiality of data of other customers. An additional audit may be carried out where required by a supervisory authority or following a personal data breach affecting the Customer.
11.3. The Customer may appoint an independent auditor who is not a competitor of ROIFORCIO. ROIFORCIO may satisfy an audit request by providing an existing audit report or certification where that report reasonably addresses the scope of the request.
12. Liability and miscellaneous
12.1. Liability under this DPA is governed by Article 82 GDPR and, as between the parties, by the limitation of liability set out in the Agreement, to the extent permitted by that Article.
12.2. In the event of a conflict between this DPA and the Agreement, this DPA prevails in matters of the processing of personal data. In the event of a conflict between this DPA and the standard contractual clauses incorporated under Section 7, those clauses prevail.
12.3. This DPA is governed by the law of the Republic of Austria and is subject to the jurisdiction agreed in the Agreement, without prejudice to Clauses 17 and 18 of the standard contractual clauses.
12.4. Contact point for all matters under this DPA, including data protection matters: info@roi4cio.com.
Annex I — Description of the processing
Item | Description |
Categories of data subjects | Employees, contractors and other representatives of the Customer using the Service under the Customer’s account; persons whose voice, image or likeness is used to create an avatar, a synthetic voice or a translated or dubbed recording; recipients and viewers of presentations and of content generated by the Customer, including persons interacting with the Chat-avatar; persons whose personal data are contained in documents, presentations, links or other materials uploaded by the Customer. |
Categories of personal data | Identification and contact data (name, job title, e-mail address, telephone number, employer); account and authentication data of the Customer’s users; voice recordings and voice samples; facial images, photographs and video recordings; prompts, questions and other input submitted to the AI features; outputs generated from that input; content of documents and materials uploaded by the Customer; interaction and engagement data relating to viewers of the Customer’s presentations. |
Special categories of data | The Service is not intended for the processing of data referred to in Article 9(1) GDPR. Voice samples and facial images are processed for the purpose of generating the output requested by the Customer and not for the purpose of uniquely identifying a natural person, and therefore do not constitute biometric data within the meaning of Article 4(14) GDPR. The Customer shall not upload data referred to in Article 9(1) GDPR, and shall not configure or use the Service for identification or authentication purposes, without the prior written agreement of ROIFORCIO. |
Nature and purpose of the processing | Hosting, storage, structuring, retrieval, transmission, generation and deletion of Customer Personal Data for the purpose of providing the functionality of the Service: creation and editing of presentations, generation of AI presenters and avatars, voice synthesis and cloning, translation and dubbing, operation of the conversational Chat-avatar, maintenance of a retrieval-augmented generation knowledge base for the Customer, analytics of viewer engagement for the Customer, and provision of technical support. |
Duration of the processing | For the term of the Agreement and for the additional periods provided for in Section 10 of this DPA. |
Frequency of the transfer | Continuous, for the duration of the Agreement. |
Competent supervisory authority | Where the standard contractual clauses apply and the Customer is established in the European Economic Area, the supervisory authority of the Member State in which the Customer is established; in respect of ROIFORCIO, the Austrian Data Protection Authority (Datenschutzbehörde). |
Annex II — Technical and organisational measures
Area | Measures |
Encryption | Encryption in transit (TLS 1.2 / 1.3) and at rest (AES-256); encrypted backups. |
Access control | Role-based access control, unique named accounts, multi-factor authentication for administrative access, least-privilege principle, periodic review of access rights, immediate revocation on termination of employment. |
Separation | Logical separation of customer environments and of the data of individual tenants; separation of production, test and development environments. |
Pseudonymisation | Pseudonymisation and minimisation of data used for testing, analytics and troubleshooting. |
Availability and resilience | Redundant infrastructure, automated backups, documented restoration procedures and periodic restoration tests, business continuity and disaster recovery planning. |
Integrity | Logging of administrative and security-relevant events, protection of logs against alteration, change management and code review, segregation of duties. |
Vulnerability management | Regular vulnerability scanning, timely patching, periodic penetration testing, continuous monitoring and alerting. |
Sub-processor control | Due diligence prior to engagement, contractual data protection obligations, periodic review. |
Organisational measures | Confidentiality undertakings, data protection and security training, documented incident response procedure, record of processing activities, internal policies including the AI Literacy Policy. |
AI-specific measures | Contractual exclusion of the use of Customer content for model training by generative sub-processors; machine-readable marking of generated outputs; content filtering intended to prevent generation of content prohibited under Article 5 of Regulation (EU) 2024/1689. |
Annex III — Sub-processors
Sub-processor | Purpose | Location / safeguard |
Amazon Web Services EMEA SARL | Hosting infrastructure, including the retrieval-augmented generation environment | European Union (Frankfurt); SCC where applicable |
Microsoft Azure | Cloud computing and ancillary services | European Union region; SCC where applicable |
OpenAI | Natural language processing and generation | United States; SCC; no training on Customer content |
Salesforce / HubSpot | Customer relationship management and support communications | SCC |
FastSpring (Bright Market, LLC) | Payment processing as Merchant of Record | United States; independent controller in respect of payment data |
Google Analytics | Website and product analytics | United States; SCC; set only with consent |
Matomo | Product analytics | European Union |
Stonly | In-product user guidance and help content | European Union |
The current list of sub-processors is published in the Privacy Policy at pitchavatar.com and prevails over this Annex where more recent.