Data Processing Agreement (DPA)
Under Art. 28 GDPR · Version 1.0 · 5 August 2026
1. Parties to the agreement
This DPA is entered into between Dokoyo Koyo Holding OÜ ("Data Processor"), a company registered in Estonia under registration number 17432821, with registered office at Harju maakond, Tallinn, Kesklinna linnaosa, Sakala tn 7-2, 10141, and the Customer ("Data Controller"), to the extent that the Customer uses the AgentID.ee Service to process personal data of third-party data subjects.
2. Subject matter and nature of processing
Dokoyo Koyo Holding OÜ processes personal data on behalf of the Customer solely to provide the AI agent registration and audit service, as described in the Terms of Service. Processing consists in the receipt, recording and storage of action logs transmitted by the Customer's AI agents via webhook.
3. Types of data and categories of data subjects
The data processed may include, depending on what the Customer transmits via webhook:
- Identifying data of natural persons (name, email, customer ID)
- Data relating to actions taken by or on behalf of natural persons
- Technical metadata (IP address, timestamps, operation type)
Special categories (Art. 9 GDPR): The Customer must not transmit special categories of data (health, biometric data, political/religious views, etc.) via AI agent webhooks without a specific written agreement with Dokoyo Koyo Holding OÜ.
4. Obligations of the Data Processor (Dokoyo Koyo Holding OÜ)
Dokoyo Koyo Holding OÜ undertakes to:
- Process personal data only on documented instructions from the Customer (the Terms of Service and this DPA constitute such instructions).
- Ensure that persons authorised to carry out processing have committed to confidentiality.
- Implement all security measures required by Art. 32 GDPR (encryption, access controls, audit logs).
- Comply with the conditions for engaging sub-processors (see Section 6).
- Assist the Customer in fulfilling data subject rights requests, to the extent possible given the nature of the processing.
- Delete or return all personal data at the end of the Service provision, at the Customer's choice.
- Make available all information necessary to demonstrate compliance and allow audits.
- Notify the Customer of any personal data breach (data breach) within 72 hours of discovery.
5. Obligations of the Data Controller (Customer)
- Ensure a valid legal basis (Art. 6 GDPR) exists for transmitting data to Dokoyo Koyo Holding OÜ.
- Not transmit special categories of data without prior written agreement.
- Inform data subjects about the processing through their own privacy notice.
- Provide documented instructions for any processing not covered by this DPA.
6. Sub-processors
Dokoyo Koyo Holding OÜ engages the following sub-processors, all GDPR-compliant:
| Sub-processor | Service | Country |
|---|---|---|
| Google Firebase / Firestore | Database and authentication | EU (eu-west1, Belgium) |
| Vercel Inc. | Application hosting | EU (Frankfurt) |
| Resend Inc. | Transactional email | USA (SCCs applicable) |
| Stripe Inc. | Billing and payments | USA (SCCs applicable) |
Dokoyo Koyo Holding OÜ will notify the Customer at least 14 days in advance of any addition or replacement of sub-processors, guaranteeing the Customer the right to object.
7. Data security (Art. 32 GDPR)
Technical and organisational measures implemented:
- TLS 1.2+ encryption for all data in transit
- At-rest encryption on Firestore (AES-256)
- RBAC access controls with least-privilege principle
- Audit logs with SHA-256 hash-chaining (immutable)
- Rate limiting and brute-force attack protection
- Anomaly detection (VPN, clone detection, replay prevention)
- Two-factor authentication (TOTP) available for all accounts
- Daily backup on Google Cloud Storage
8. International transfers
Transfers to non-EEA sub-processors (Resend, Stripe) are carried out in compliance with Art. 46 GDPR via Standard Contractual Clauses (SCCs) adopted by the European Commission.
9. Duration and termination
This DPA has the same duration as the Service agreement. Upon termination, Dokoyo Koyo Holding OÜ will delete all the Customer's personal data within 30 days, except for data whose retention is required by law.
10. Governing law
This DPA is governed by Estonian law and the GDPR (EU Regulation 2016/679). The competent court is the Tallinn Court (Estonia). Dokoyo Koyo Holding OÜ, Reg. 17432821 · Sakala tn 7-2, 10141 Tallinn, Estonia.
Sign the DPA
Business and Enterprise plan customers can obtain a signed version of the DPA. Contact us with your company name and registration number.
Request signed DPA →