This Data Processing Agreement (DPA) forms part of the agreement between a business, public-sector or other organisational customer (Customer) and František Mráz, IČO 07961731, trading as DIRI AI (Processor), where DIRI AI processes Customer Personal Data on the Customer's behalf.
1. Definitions and roles
Applicable Data Protection Law means the GDPR, Czech data-protection law and any other privacy law that applies to the relevant processing. Customer Personal Data means personal data within Customer Content that DIRI AI processes solely on documented Customer instructions. Security Incident has the meaning in section 8.
The Customer is controller or processor, as applicable. DIRI AI is processor or subprocessor for Customer Personal Data. DIRI AI remains an independent controller for its own account, billing, fraud prevention, legal compliance and security administration described in the Privacy Policy.
2. Scope and term
DIRI AI will process Customer Personal Data only to provide, secure, support and delete the service, as described in Annex 1 and documented instructions. This DPA starts with the service agreement and continues until Customer Personal Data is deleted or returned, subject to lawful retention.
The service agreement, settings, support requests and lawful use of documented product functions are instructions. An instruction outside the standard service may require a written change, fee or technical review. DIRI AI will promptly inform the Customer if, in its reasonable opinion, an instruction infringes Applicable Data Protection Law and may pause the affected processing while the parties resolve it.
3. Processor obligations
DIRI AI will:
- process Customer Personal Data only on documented instructions, unless Union or Member-State law requires otherwise; where permitted, it will inform the Customer before that processing;
- ensure persons authorised to process it are bound by confidentiality;
- implement and maintain risk-appropriate measures described in Annex 2;
- assist the Customer, taking account of the nature of processing and available information, with data-subject rights, security, breach assessments, DPIAs and regulator consultations;
- maintain records and information needed to demonstrate compliance with Article 28 GDPR;
- notify the Customer if it receives a binding authority request concerning Customer Personal Data, unless law prohibits notice; and
- not sell Customer Personal Data, use it for third-party advertising, perform biometric identification or emotion recognition, or train a general-purpose model on it without a separate written agreement and lawful basis.
4. Customer obligations
The Customer is responsible for the lawfulness, fairness and accuracy of its instructions and Customer Personal Data. It must:
- provide required notices and establish a valid legal basis;
- configure access, retention and roles proportionately;
- avoid unnecessary special-category, criminal-offence, payment-card, credential, health or real- customer secret data;
- handle employee/worker consultation, monitoring rules, union or works-council duties and human oversight;
- respond to data subjects and complete any required DPIA; and
- ensure that its instructions do not use DIRI AI for prohibited or high-risk purposes.
5. Subprocessors
The Customer gives general authorisation for the subprocessors on the effective Subprocessor List. DIRI AI will bind each subprocessor to data-protection obligations no less protective in substance than the relevant obligations in this DPA and remains responsible for its performance as required by law.
DIRI AI should provide at least 30 days' advance notice of a new subprocessor that will process Customer Personal Data. The Customer may object during that period on reasonable data-protection grounds. The parties will seek a reasonable safeguard or alternative. If none is reasonably available, either party may terminate the affected feature or service without penalty for the unused prepaid affected period.
An urgent replacement needed for security, law or service continuity may be made sooner, with notice as soon as reasonably possible. DIRI AI records and sends these notices through a durable business contact channel.
6. International transfers
DIRI AI will not make a restricted transfer without a lawful mechanism. Depending on the transfer, this may be an adequacy decision, the applicable European Commission Standard Contractual Clauses, the UK Addendum or another valid safeguard. DIRI AI will perform and document a transfer assessment and reasonable supplementary measures where required.
At the Customer's reasonable request, DIRI AI will provide relevant safeguard information, subject to confidentiality and security redactions. The Subprocessor List identifies providers and purposes; DIRI AI's Vendor and Transfer Register records applicable locations and transfer mechanisms. A provider's headquarters or selected region alone is not proof that no transfer occurs.
7. Data-subject requests and assistance
If DIRI AI receives a request concerning Customer Personal Data, it will not respond substantively except on Customer instructions or where legally required. It will promptly forward the request where the Customer can be identified and provide available self-service export, correction and deletion functions.
Standard reasonable assistance is included. Disproportionate, repetitive or custom assistance may be charged at an agreed reasonable rate for business customers where law permits, but DIRI AI will not charge for work caused by its own breach.
8. Security incidents and personal data breaches
A Security Incident is a confirmed accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Personal Data. It excludes unsuccessful attempts that do not compromise Customer Personal Data, such as blocked scans or failed logins.
DIRI AI will notify the Customer without undue delay after becoming aware of a Security Incident. The operational target is an initial notice within 48 hours where reasonably possible, but the legal standard is without undue delay. Notice will include available information about:
- nature, timing and affected systems/data subjects;
- likely consequences;
- containment, mitigation and remediation;
- a contact point; and
- information reasonably needed for the Customer's notification duties.
Information may be supplied in phases. DIRI AI will preserve relevant evidence, cooperate with the Customer and provide appropriate updates. Notification is not an admission of fault or liability. The Customer decides whether it must notify a regulator or affected persons, unless DIRI AI has an independent legal duty.
The 48-hour period is an operational target, not a guaranteed deadline, and does not delay any earlier notification required by law or this DPA.
9. Return and deletion
During the subscription and the documented export window, the Customer may export available Customer Content in a commonly used, machine-readable format. At termination or written request, DIRI AI will delete or return Customer Personal Data, at the Customer's choice, unless law requires retention.
Active-system deletion should complete within 30 days after the applicable closure/export window. Isolated encrypted backups may persist until the verified provider expiration cycle; they remain protected, are not restored for ordinary use and will be deleted again if restored for disaster recovery. Billing, security, fraud, claim and legal-hold records are retained only under DIRI AI's controller purposes and the Retention Policy.
DIRI AI maintains lifecycle controls for the applicable export window, deletion jobs and provider backup expiration cycle and reviews them after a material lifecycle or provider change.
10. Audit and evidence
On reasonable written request no more than once per year, DIRI AI will provide information needed to demonstrate compliance, such as this DPA, subprocessor information, security documentation and available independent reports. Additional requests are allowed after a material Security Incident or regulator requirement.
If that information is insufficient, the Customer may request a proportionate remote audit by an independent qualified auditor bound by confidentiality. An on-site audit is a last resort, during normal business hours, without access to other customers' data or compromising security. The Customer bears reasonable audit costs unless the audit identifies a material DIRI AI breach. No provider certification is represented as a DIRI AI certification.
11. Liability and precedence
Liability under this DPA follows the service agreement, except to the extent Applicable Data Protection Law does not permit a limitation. If this DPA conflicts with the service agreement on processing Customer Personal Data, this DPA prevails. Mandatory law and any applicable executed Standard Contractual Clauses prevail over both.
12. Contact and execution
Privacy contact: privacy@diriai.com. This DPA becomes part of a contract only when exact version 1.2.0 is made available before ordering and incorporated through a valid service agreement or signed order.
Version: 1.2.0. Date: 30 August 2026.
Annex 1 — Processing details
| Item | Description |
|---|---|
| Subject matter | Hosting and operating an AI-assisted voice/text conversation training, reporting, team administration, support, security, export and deletion service |
| Duration | Subscription term plus the documented export/deletion window and lawful exceptions |
| Nature | Collection, recording where enabled, structuring, storage, retrieval, transmission to approved providers, analysis, generation, scoring, support, restriction, export and deletion |
| Purposes | Provide customer-requested simulations and reports; administer workspace and limits; secure, support and maintain the service |
| Data subjects | Customer users, administrators, trainees, employees/contractors represented in content, and other persons whose data the Customer lawfully submits |
| Data types | Names, work contact and account data, roles, identifiers, scenarios, text/voice input, optional audio, transcripts, annotations, reports, scores, usage, device/network and audit data, support messages |
| Special data | Not intended or authorised in standard plans. The Customer must not submit it unless a separate written instruction and Article 9/10 basis, assessment and safeguards are agreed |
| Frequency | On demand and continuously for account, security and service administration |
| Return/deletion | Self-service/requested export followed by deletion under section 9 and the Retention Policy |
Annex 2 — Technical and organisational measures
These are minimum contractual design requirements, not a certification:
- Access control: unique accounts, role-based and tenant-scoped authorisation, least privilege, administrator-controlled membership and privileged-access review.
- Authentication and sessions: protected session cookies, secure transport, rate limiting, credential/secret separation and multi-factor authentication where offered.
- Tenant separation: tenant identifiers and server-side authorisation on Customer Content and administrative actions; tests for cross-tenant access.
- Encryption: TLS for supported data in transit and provider-managed encryption at rest where verified; keys and secrets excluded from source and logs.
- Data minimisation: recording off by default, controlled telemetry, restricted production debugging, no full card data, content filtering from logs and configurable/short retention.
- Logging and monitoring: auditable security/admin events, sanitised error monitoring, alerting and protected evidence with access and retention limits.
- Availability and recovery: service-health monitoring, queues and retries where appropriate, provider backups, restoration procedures and periodic recovery review; standard plans include no contractual recovery objective unless expressly agreed.
- Secure development: change review, automated tests, dependency and secret checks, environment separation and controlled production changes.
- Incident response: documented triage, containment, evidence, notification and lessons-learned process with contact ownership.
- Vendor management: DPA/security review, region and transfer assessment, least-data configuration and offboarding/deletion review.
- Deletion and continuity: lifecycle jobs for content, exports, logs and provider objects; backup expiration and legal holds documented separately.
- Personnel and governance: confidentiality, need-to-know access, periodic access review, privacy/security training and records of processing.
Annex 3 — Approved subprocessors
The effective list at https://diriai.com/en/legal/subprocessors is incorporated by reference. A provider is authorised by this Annex only for the listed function that DIRI AI actually uses under an applicable provider agreement.