DPA
This Data Processing Agreement ("DPA") forms part of and is incorporated into the Terms and Conditions, Master Services Agreement, or other binding agreement (the "Agreement") between Starkien Pty Ltd ("Starkien", "Processor") and the customer entity identified in the applicable Order Form or Agreement ("Customer", "Controller").
This DPA applies where Starkien processes Personal Data on behalf of the Customer in connection with the provision of TheOS, Plato, and related platform services (collectively, the "Platform").
1. Definitions
Capitalized terms not otherwise defined in this DPA have the meanings given in the GDPR or the Agreement.
Personal Data: Any information relating to an identified or identifiable natural person.
Processing: As defined in Article 4(2) of the GDPR.
Customer-Managed Resources: Resources supplied and controlled by the Customer, including API keys, credentials, databases, storage systems, cloud accounts, and third-party service connections.
Sub-processor: A third party engaged by Starkien to process Personal Data on behalf of the Customer.
2. Roles of the Parties
The Customer acts as the Data Controller.
Starkien acts as the Data Processor.
Starkien processes Personal Data solely on documented instructions from the Customer, unless otherwise required by applicable law.
3. Scope, Subject Matter, and Purpose of Processing
3.1 Subject Matter
Provision of an AI-native operating layer, application construction system, automation, orchestration, and governance capabilities.
3.2 Duration
For the duration of the Agreement, unless otherwise agreed in writing.
3.3 Nature of Processing
Processing may include hosting, storage, access, retrieval, transmission, orchestration, logging, and AI-assisted or automated processing, as configured by the Customer.
3.4 Purpose
Personal Data is processed solely to provide, operate, secure, and support the Platform in accordance with the Agreement.
4. Categories of Data Subjects and Personal Data
4.1 Data Subjects
- Customer employees
- Authorized users
- Contractors or agents
- End users determined by the Customer
4.2 Categories of Personal Data
- Identifiers (name, email address, user ID)
- Organizational and account metadata
- Access and usage logs
- Content and data processed within the Platform
The Platform is not intended to process special categories of Personal Data unless expressly agreed in writing.
5. Customer Obligations
The Customer represents and warrants that it:
- Has a lawful basis for Processing Personal Data
- Has provided required notices to data subjects
- Issues instructions compliant with applicable data protection laws
- Configures governance, permissions, and access controls appropriately
The Customer is solely responsible for the security, legality, and configuration of Customer-Managed Resources.
6. Shared Responsibility Model (BYO Configuration)
The Platform supports Bring Your Own (BYO) configurations.
6.1 Customer Responsibilities
- Secure management of API keys, secrets, and credentials
- Security and configuration of Customer-managed databases, storage, and cloud infrastructure
- Lawful authorization of third-party accounts and services
- Access controls and data protection within Customer-controlled environments
6.2 Starkien Responsibilities
- Secure Processing within Starkien-managed Platform components
- Enforcement of Platform-level governance, permissions, and controls
- Protection of Personal Data processed within Starkien-managed boundaries
7. AI, Automation, and Federated Processing
The Platform may include AI-assisted, automated, or federated processing capabilities.
Where federated or Customer-Managed configurations are used:
- Personal Data may remain within Customer-controlled environments
- Model updates or operational signals may be exchanged without centralized aggregation of raw Personal Data
- Customer Personal Data is not used to train shared or global AI models by default
Any use of Customer Personal Data for training beyond the Customer’s environment requires explicit agreement and a lawful basis.
AI outputs are assistive in nature. The Customer remains responsible for decisions and actions taken based on such outputs.
8. Sub-processors
The Customer grants Starkien general authorization to engage Sub-processors.
Starkien ensures Sub-processors are bound by obligations no less protective than those set out in this DPA.
9. International Data Transfers
Where Personal Data is transferred outside the Customer’s jurisdiction, Starkien ensures appropriate safeguards, including Standard Contractual Clauses or other lawful transfer mechanisms.
10. Security Measures
Starkien implements appropriate technical and organizational measures to protect Personal Data processed within Starkien-managed components of the Platform.
Security obligations do not extend to Customer-Managed Resources.
11. Personal Data Breach Notification
Starkien shall notify the Customer without undue delay after becoming aware of a Personal Data breach affecting Customer Personal Data.
12. Assistance With Data Subject Rights
Starkien shall provide reasonable assistance to enable the Customer to respond to data subject requests under applicable data protection laws.
13. Data Retention and Deletion
Upon termination of the Agreement, Starkien shall, at the Customer’s choice and subject to applicable law, delete or return Customer Personal Data.
System-level logs and anonymized telemetry may be retained for security and operational integrity.
14. Audits
The Customer may audit Starkien’s compliance with this DPA no more than once per year, subject to reasonable notice and confidentiality.
15. Liability
Liability under this DPA is subject to the limitations set out in the Agreement.
16. Governing Law
This DPA is governed by the law specified in the Agreement, without prejudice to mandatory data protection laws.
17. Order of Precedence
In the event of conflict, this DPA prevails solely with respect to data protection matters.
18. Contact
For data protection inquiries:
Starkien Pty Ltd
Email: [Insert legal or privacy contact]
End of Data Processing Agreement
Back to Data Protection & Compliance