etla Data Processing Agreement (DPA)

Established: February 1, 2026
Last Updated: June 29, 2026

This Data Processing Agreement (this “DPA”) applies where REGALI Inc. (“REGALI,” “we,” “us,” or “our”) processes personal data on behalf of Customer, and forms part of the etla Terms of Service.

Article 1 (Definitions)

  1. “GDPR” means the General Data Protection Regulation of the European Union (Regulation (EU) 2016/679).
  2. “EEA” means the European Economic Area, including the EU member states and Iceland, Liechtenstein, and Norway.
  3. “UK GDPR” means the GDPR as incorporated into the laws of the United Kingdom.
  4. “LGPD” means the Brazilian General Data Protection Law (Lei Geral de Proteção de Dados), and “ANPD” means Brazil’s national data protection authority (Autoridade Nacional de Proteção de Dados).
  5. “CCPA” means the California Consumer Privacy Act of 2018, as amended, together with its implementing regulations.
  6. “Applicable Data Protection Laws” means the laws and regulations concerning privacy, personal data protection, and data security applicable to the processing of Customer Personal Data, including, to the extent applicable, the GDPR, the UK GDPR, the Swiss Federal Act on Data Protection, the Act on the Protection of Personal Information of Japan (APPI), the LGPD, the CCPA, and other applicable U.S. state laws.
  7. “Personal Data” means information relating to an identified or identifiable natural person, or any equivalent information under Applicable Data Protection Laws.
  8. “Controller” means an entity that determines the purposes and means of the processing of personal data.
  9. “Processor” means an entity that processes personal data on behalf of a controller.
  10. “Customer Personal Data” means personal data that we process as a processor or sub-processor in the course of providing the Service to Customer.
  11. “Processing” means any operation performed on personal data, including collection, recording, organization, structuring, storage, alteration, retrieval, consultation, use, transmission, disclosure, combination, restriction, or erasure.
  12. “Sub-processor” means a third party engaged by us to process Customer Personal Data.
  13. “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
  14. “EU SCCs” means the standard contractual clauses adopted by European Commission Implementing Decision (EU) 2021/914 for transfers of personal data to countries or regions for which the EEA has not recognized an adequate level of data protection.
  15. “UK Addendum” means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner’s Office (ICO), and “UK IDTA” means the International Data Transfer Agreement (IDTA) issued by the ICO.
  16. “Technical and Organizational Measures” or “TOMs” means the technical and organizational measures used to protect personal data, including encryption, access controls, monitoring, and incident response.

Article 2 (Roles of the Parties)

  1. Customer is the controller of Customer Personal Data, and we are the processor that processes such data on behalf of Customer.
  2. Where Customer acts as a processor on behalf of another controller, we act as a sub-processor.
  3. Each party’s legal role is determined by the actual processing performed, not by title. Where we determine our own purposes and means for processing personal data, we act as an independent controller with respect to that processing.
  4. The subject matter, duration, nature, and purpose of the processing, the types of personal data involved, and the categories of data subjects are set out in Annex A.

Article 3 (Customer’s Instructions)

  1. We process Customer Personal Data only in accordance with the Agreement, Customer’s lawful configuration of the Service, and Customer’s additional written instructions, except where law applicable to us requires otherwise.
  2. Where applicable law requires otherwise, we will notify Customer before undertaking such processing, unless prohibited by law from doing so.
  3. Where we reasonably determine that an instruction from Customer would violate Applicable Data Protection Laws, we may notify Customer and suspend performance of that instruction.
  4. Where an additional instruction exceeds the scope of the Service or requires additional cost, we may request Customer’s prior agreement as to the conditions and cost of implementation.
  5. We will not sell or share Customer Personal Data, use it for third-party advertising purposes, or use it for our own purposes unrelated to providing the Service to Customer, without Customer’s express written instruction.

Article 4 (Customer’s Obligations)

  1. Customer will ensure it has the legal basis, notices, consents, and authority necessary to provide Customer Personal Data to us and to instruct us to process it.
  2. Customer is responsible for ensuring that the purposes of processing, categories of data subjects, data elements, retention periods, and configuration of the Service comply with Applicable Data Protection Laws.
  3. Customer will ensure accuracy and data minimization, and will not input into the Service any data for which we have not expressly indicated support in the applicable Order.
  4. Where Customer represents multiple controllers, Customer represents and warrants that it has the authority necessary to appoint us as a sub-processor and to enter into this DPA.

Article 5 (Confidentiality and Personnel)

  1. We limit access to Customer Personal Data to personnel who require such access to provide the Service.
  2. We impose confidentiality obligations on such personnel under law or contract, and provide them with appropriate training on data protection and security.
  3. We periodically review access privileges and promptly remove privileges that are no longer needed.

Article 6 (Security Measures)

  1. Taking into account the nature, scope, context, and purposes of the processing, and the risks to the rights of data subjects, we maintain the technical and organizational measures (TOMs) set out in Annex B.
  2. We may update the security measures, provided that doing so does not materially degrade the overall security of the Service.
  3. Customer implements security measures for the accounts, devices, networks, integrations, permissions, and configurations that Customer controls.

Article 7 (Personal Data Breach)

  1. Upon becoming aware of a Personal Data Breach, we will notify Customer without undue delay, and in any event no later than 72 hours after becoming aware.
  2. To the extent known, we will provide the following information, and will provide additional information as material updates become available:
    1. The nature of the breach and the period during which it is known to have occurred
    2. The categories and approximate number of affected data subjects and data records
    3. The likely consequences
    4. The containment, investigation, and remedial measures we have taken or plan to take
    5. Contact details for further information
  3. We will provide reasonable cooperation with Customer’s notifications to supervisory authorities and data subjects and any other legally required response. Where Customer is the controller, Customer retains ultimate responsibility for determining whether, how, and when to notify.
  4. Our notification does not constitute an admission of fault or of any violation of law on our part.

Article 8 (Sub-processors)

  1. Customer generally authorizes our engagement of sub-processors as necessary to provide the Service.
  2. The current sub-processors, their countries of location, the processing they perform, and the method by which changes are notified are set out in the Sub-processor List made available by REGALI to Customer (including, where applicable, as an annex to the Order) (the “Sub-processor List”).
  3. Where we add a new sub-processor or materially change the primary country in which Customer Personal Data is processed, we will, as a general rule, notify Customer at least 30 days in advance.
  4. Customer may object within 15 days of such notice by providing specific and reasonable grounds relating to Applicable Data Protection Laws. The parties will discuss alternative measures in good faith. If the parties are unable to agree on a reasonable alternative measure within 30 days after such discussion begins, Customer may terminate the Agreement, solely with respect to the portion of the Service affected by the use of that sub-processor, upon written notice to us. In that event, we will refund the prepaid fees corresponding to the unused period following termination.
  5. We impose data protection obligations on each sub-processor by contract that are substantially equivalent to, or more protective than, those under this DPA, and remain responsible to Customer for each sub-processor’s performance of its obligations.

Article 9 (Rights of Data Subjects)

  1. Where we receive a request directly from a data subject regarding Customer Personal Data, we will, unless prohibited by law, direct the data subject to Customer and will not substantively respond without Customer’s instruction.
  2. We will assist Customer, through the standard functionality of the Service and reasonable technical measures, in responding to requests to exercise data subject rights, including access, rectification, erasure, restriction of processing, objection, and data portability.
  3. For assistance beyond standard functionality, we may charge a reasonable, pre-agreed fee, except where the request results from our breach of this DPA.

Article 10 (Impact Assessments and Cooperation with Supervisory Authorities)

We will provide the information reasonably necessary for Customer to conduct data protection impact assessments, legitimate interest assessments, AI impact assessments, or prior consultations with supervisory authorities required under Applicable Data Protection Laws, to the extent consistent with the nature of the processing and the information available to us.

Article 11 (Requests from Government Authorities)

  1. Where we receive a request from a government or law enforcement authority for disclosure of Customer Personal Data, we will promptly notify Customer, unless prohibited by law from doing so.
  2. We will reasonably assess the legality and scope of the request, and will challenge requests that are manifestly unlawful or excessive where we have a reasonable legal basis to do so.
  3. We will disclose only the minimum data legally required.

Article 12 (International Data Transfers)

  1. We will identify the countries in which Customer Personal Data is processed and the primary regions in which it is stored, in the applicable Order or the Sub-processor List.
  2. We and Customer will use adequacy decisions, standard contractual clauses, binding corporate rules, certification mechanisms, or other transfer mechanisms valid under Applicable Data Protection Laws for international data transfers.
  3. Where an adequacy decision is available for transfers from the EEA to Japan, that adequacy decision will be used. Where it is unavailable, or is suspended or invalidated, the EU SCCs will apply.
  4. The following terms apply to transfers requiring the EU SCCs:
    1. Where Customer is the controller and we are the processor, Module Two (Controller to Processor) will apply.
    2. Where Customer is the processor and we are the sub-processor, Module Three (Processor to Processor) will apply.
    3. The docking clause under Clause 7 of the EU SCCs will apply, allowing affiliates or other parties to accede to the EU SCCs at a later date as necessary.
    4. Clause 9 of the EU SCCs will apply Option 2 (general written authorization), meaning that Customer provides general prior authorization for our engagement of sub-processors and we provide advance notice of changes, with the notice period governed by Article 8, Section 3 of this DPA.
    5. No optional mechanism for an independent dispute resolution body under Clause 11 of the EU SCCs is adopted. This does not restrict a data subject’s right to lodge a complaint with a supervisory authority or a court.
    6. For the governing law and choice of forum under Clauses 17 and 18 of the EU SCCs, the law and courts of the EEA member state in which the data exporter is established are selected. Where such selection is not permitted, the laws of Ireland and the courts of Ireland will apply.
    7. Annex I (List of Parties and Description of Transfer), Annex II (Technical and Organizational Measures), and Annex III (List of Sub-processors) to the EU SCCs are supplemented with the corresponding information set out in this DPA, the applicable Order, Annex A, Annex B, and the Sub-processor List. Where required by law or upon the other party’s reasonable request, a separately executed, duly completed copy of the EU SCCs will be entered into.
  5. Where contractual safeguards are required for transfers from the United Kingdom, the UK Addendum or the UK IDTA will apply, duly completed as necessary.
  6. For transfers from Switzerland, references in the EU SCCs to the GDPR, EU member states, and supervisory authorities are read, to the extent necessary, as references to the Swiss Federal Act on Data Protection and the competent Swiss supervisory authority.
  7. Where an adequacy decision or other valid transfer mechanism is unavailable for transfers from Brazil, the standard contractual clauses adopted by the ANPD will apply, duly completed as necessary.
  8. We will provide reasonable cooperation with transfer impact assessments or data protection tests where required by applicable law, and will implement supplementary measures such as encryption and access controls.
  9. Where mandatory transfer clauses conflict with this DPA or the Agreement, the mandatory transfer clauses will prevail with respect to the relevant transfer.

Article 13 (U.S. State Privacy Laws)

  1. Where the CCPA applies to Customer Personal Data, we confirm that Customer is disclosing personal information to us for the limited and specified business purposes set out in Annex A.
  2. Except as permitted under the CCPA, we will not do any of the following with respect to such personal information. For purposes of the CCPA, “sale” means providing personal information in exchange for monetary or other valuable consideration, and “share” means providing personal information primarily for cross-context behavioral advertising across businesses:
    1. Sell or share such personal information under the CCPA
    2. Retain, use, or disclose it outside the direct business relationship between us and Customer
    3. Retain, use, or disclose it for any purpose other than the business purposes set out in Annex A
    4. Combine personal information received from Customer with personal information received from another source or from a data subject’s direct interaction with us, except as permitted for a service provider or contractor under the CCPA
  3. We provide a level of protection comparable to that required under the CCPA, and afford Customer reasonable means to verify our compliance and the right to stop and remediate any unauthorized use.
  4. Where we act in a capacity equivalent to a “processor” or “service provider” under other U.S. state laws, this Article will be construed to conform to such laws.

Article 14 (Return and Deletion)

  1. During the term of the Agreement, Customer may access, retrieve, or delete Customer Personal Data using the standard functionality of the Service.
  2. Upon termination of the Agreement, we will return or delete Customer Personal Data in accordance with Customer’s election. If Customer does not notify its election within 30 days after termination, we may delete such data.
  3. For data subject to a legal retention requirement, we may retain the data, with access and processing restricted, for as long as that requirement continues to apply.
  4. Data contained in backups will be deleted or rendered unrecoverable in accordance with our normal update cycle, generally within 90 days.
  5. Upon Customer’s reasonable request, we will provide written confirmation that deletion has been completed.

Article 15 (Information and Audits)

  1. We will provide Customer with information reasonably necessary to demonstrate compliance with this DPA, giving priority, where available, to independent third-party audit reports, certifications, security documentation, or responses to questionnaires.
  2. Where the materials described in the preceding paragraph do not provide reasonable assurance and an audit is required under Applicable Data Protection Laws, Customer may conduct an audit, no more than once per year, upon at least 30 days’ prior notice, during our normal business hours, provided that this limitation does not apply in the case of a Personal Data Breach, an order from a supervisory authority, or a reasonable suspicion of a material breach.
  3. Audits will be conducted in a manner that does not unreasonably harm the information, security, confidentiality, or business of our other customers, and the auditor will be bound by confidentiality obligations as an independent professional.
  4. Customer bears the cost of the audit, provided that if the audit identifies a material breach on our part, we will bear the reasonable cost of the audit.

Article 16 (Liability, Survival, and Amendment)

  1. Liability under this DPA is subject to the limitations of liability set out in the etla Terms of Service, provided that this does not limit any rights or liabilities owed to data subjects or supervisory authorities that cannot be limited under the EU SCCs or other applicable law.
  2. This DPA remains in effect for as long as we hold or process Customer Personal Data.
  3. We may amend this DPA to address changes in Applicable Data Protection Laws or requirements imposed by supervisory authorities. Amendments that materially reduce Customer’s protections will follow the amendment procedure set out in the etla Terms of Service.

Annex A Details of Processing

1. Subject Matter and Duration of Processing

Provision, configuration, maintenance, security, support, incident response, and return or deletion upon termination, of the Service. The processing period is the term of the Agreement and the deletion period set out in Article 14.

2. Nature of Processing

Collection, receipt, recording, organization, segmentation, OCR, structuring, storage, embedding generation, indexing, retrieval, consultation, classification, summarization, generation, inference, speech recognition, speech synthesis, conversion, transmission, integration with external systems, logging, access control, and deletion.

3. Purpose of Processing

  1. Providing the Service and support that Customer has contracted to use
  2. Search, response generation, workflow automation, and integration with external systems based on Customer’s instructions
  3. Communications, voice processing, and response support that Customer has enabled
  4. Authentication, permission management, security, incident response, and fraud prevention
  5. Return and deletion of data based on Customer’s instructions

4. Categories of Data Subjects

Officers, employees, applicants, contractors, business partner personnel, customers, prospective customers, users of Customer’s website or app, inquirers, participants in calls or chats, and any other individuals whose data Customer includes in its knowledge base or integrated data, in each case of Customer and its affiliates.

5. Types of Personal Data

  1. Name, employer, job title, contact information, and account identifiers
  2. Information contained in documents, FAQs, procedure manuals, tickets, CRM records, databases, and external systems
  3. Inquiries, chats, forms, emails, call audio, transcripts, summaries, and response history
  4. Prompts, instructions, generated outputs, feedback, and approval records
  5. Information relating to IP addresses, devices, browsers, authentication, access, operations, and system events
  6. Other data expressly specified in the applicable Order

6. Special Categories of Data

Except as expressly agreed in the applicable Order, no special categories of personal data, special care-required personal information (as defined under the APPI), criminal history data, biometric identification data, children’s data, health information, government-issued identification numbers, or payment card information are anticipated to be processed.

7. Frequency of Processing

Continuous or as needed, depending on Customer’s use of the Service.

Annex B Technical and Organizational Measures (TOMs)

This Annex sets out the TOMs required under Applicable Data Protection Laws and the EU SCCs. Depending on the configuration of the Service and the content of the applicable Order, we reasonably implement the following measures, or measures of equivalent or greater effectiveness, to the extent applicable to the Service. The specific implementation and scope of application are set out in the security specifications or the applicable Order.

  1. Security Governance
    Designated information security responsibility, policies, risk assessments, personnel training, and periodic review.
  2. Access Control
    Unique accounts, role-based permissions, least privilege, restriction of privileged access, periodic access reviews, and removal of access upon termination or change of role.
  3. Authentication
    Multi-factor authentication for administrative and critical operational access, and secure management of credentials.
  4. Encryption
    Encryption of data in transit using industry-standard methods, encryption of data at rest where technically supported, and restricted access to encryption keys.
  5. Tenant and Environment Separation
    Logical tenant separation and appropriate separation of production, development, and test environments.
  6. Logging and Monitoring
    Logging, protection, monitoring, and retention for a reasonable period of records relating to critical access, administrative operations, authentication, and security events.
  7. Vulnerability and Change Management
    Collection of vulnerability information, risk-based remediation, dependency management, change review, and production deployment procedures.
  8. Secure Development
    Development processes including code review, testing, management of secrets, and pre-release verification.
  9. Malware and Infrastructure Protection
    Risk-based protection of endpoints, networks, cloud environments, and administrative devices.
  10. Backup and Recovery
    Backups, restoration testing, and business continuity and disaster recovery procedures appropriate to the applicable contract.
  11. Incident Response
    Response procedures including detection, reporting, containment, investigation, recovery, evidence preservation, and prevention of recurrence.
  12. Sub-processor Management
    Selection, contracting, change management, and ongoing oversight relating to security and data protection.
  13. Data Lifecycle
    Procedures for the collection, storage, export, return, and deletion of data, and prevention of data recovery upon disposal of media.
  14. Physical Security
    Access control for facilities we operate, and reasonable oversight of cloud and data center providers.

Annex C Region-Specific Terms

  1. EEA
    For transfers for which an adequacy decision is unavailable, the EU SCCs under Article 12 and any necessary supplementary measures will apply.
  2. United Kingdom
    For restricted transfers, the UK IDTA, or the UK Addendum to the EU SCCs, and any necessary data protection test will apply.
  3. Switzerland
    The EU SCCs will be supplemented to conform to the Swiss Federal Act on Data Protection and the competent Swiss supervisory authority.
  4. Japan
    Under the APPI, we will fulfill the requirements relating to the provision of personal data to third parties located outside Japan, oversight of subcontractors, security measures, and disclosure of information to data subjects, in accordance with the actual data flows involved.
  5. Brazil
    Where the LGPD and the ANPD’s international transfer rules apply, we will use adequacy decisions, the ANPD’s standard contractual clauses, or other valid mechanisms.
  6. United States
    Where the CCPA or other state laws apply, the use restrictions, assistance with data subject requests, and audit and remediation rights set out in Article 13 will apply.
  7. Regions Requiring Data Localization
    Available only where we have expressly agreed, in the applicable Order, to support the applicable region and processing configuration. Any necessary security assessments, standard contracts, certifications, data localization, or government filings will be allocated between the parties in the applicable Order.