This Data Processing Agreement (“DPA”) forms part of the agreement between Corha Technologies Ltd (“Corha”, the “Processor”), a company registered in England and Wales under company number 17248901, with its registered office at Office 1, 1 Coldbath Square, London, England, EC1R 5HL, and the customer (the “Controller”), and it governs Corha’s processing of personal data on the Controller’s behalf. It is incorporated into and subject to the Terms of Service. Where this DPA conflicts with the Terms on the subject of data protection, this DPA prevails. We will provide a counter-signed copy on request via info@corha.app.
In this DPA, “data protection law” means the UK GDPR, the Data Protection Act 2018, and the EU GDPR, each to the extent it applies. Terms such as “controller”, “processor”, “personal data”, “processing”, and “personal data breach” have the meanings given to them in that law.
1. Roles of the parties
The Controller determines the purposes and means of processing the personal data it uploads to Corha. Corha acts as processor and processes that personal data only on the Controller’s documented instructions, including the instructions set out in the Terms, in this DPA, and through the Controller’s configuration and use of the service. Corha will inform the Controller if, in its opinion, an instruction infringes data protection law.
2. Subject matter, duration, nature, and purpose
Corha processes personal data for the duration of the agreement in order to provide the service: ingesting the Controller’s customer evidence (such as calls, interviews, tickets, surveys, and documents), organising it into personas, evidence, and insights, and providing the related AI features. Further details are set out in Annex 1.
3. Categories of data subjects and personal data
The data subjects are the Controller’s own customers, prospects, and research participants, and the Controller’s personnel who use the service. The personal data is whatever the Controller chooses to upload or connect, as described in Annex 1. The Controller must not upload special-category personal data unless the parties have agreed to that in writing.
4. Controller obligations
The Controller confirms that it has a lawful basis to process the personal data it uploads, that it has provided any notices and obtained any consents required from its data subjects, and that its instructions to Corha comply with data protection law.
5. Confidentiality
Corha ensures that people authorised to process the personal data are bound by an appropriate duty of confidentiality and access it only as needed to provide the service.
6. Security
Corha implements and maintains appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Those measures are described in Annex 2.
7. Sub-processors
The Controller gives Corha general authorisation to engage the sub-processors listed on the Sub-processorspage (Annex 3). Corha imposes data protection obligations on each sub-processor that are no less protective than those in this DPA, and remains responsible to the Controller for each sub-processor’s performance. Corha will give the Controller notice before adding or replacing a sub-processor, and the Controller may object on reasonable data-protection grounds.
8. International transfers
Where processing involves transferring personal data outside the UK or the EEA, Corha relies on an appropriate transfer mechanism, including the UK International Data Transfer Addendum and the EU Standard Contractual Clauses, together with any supplementary measures required.
9. Assistance to the Controller
Taking into account the nature of the processing and the information available to it, Corha will assist the Controller with: responding to requests from data subjects exercising their rights; keeping personal data secure; notifying and communicating personal data breaches; and carrying out data protection impact assessments and prior consultations. Corha will promptly pass on any data-subject request it receives directly.
10. Personal data breaches
Corha will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller’s personal data, and will provide the information the Controller reasonably needs to meet its own breach-notification obligations.
11. Deletion and return
On termination of the service, and at the Controller’s choice, Corha will delete or return the Controller’s personal data within the period stated in the Privacy Policy, except where Corha is required by law to retain a copy. Backups are deleted on their ordinary expiry cycle.
12. Audits
Corha will make available the information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates, on reasonable prior notice and subject to confidentiality. Where available, Corha may satisfy this obligation by providing relevant third-party certifications or reports.
13. Liability and term
Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Terms. This DPA takes effect when the Controller begins using the service and continues for as long as Corha processes personal data on the Controller’s behalf.
Annex 1: Details of the processing
- Subject matter: provision of the Corha customer-understanding service.
- Duration: the term of the agreement, plus the deletion window in the Privacy Policy.
- Nature and purpose: storage, organisation, analysis, retrieval, and AI-assisted synthesis of the Controller’s customer data into personas, evidence, and insights.
- Categories of data subjects: the Controller’s customers, prospects, and research participants, and the Controller’s own personnel who use the service.
- Categories of personal data: contact details; recorded or transcribed conversations and calls; interview and survey responses; support interactions; documents, images, and PDFs the Controller uploads; and account and profile details of the Controller’s users.
- Special-category data: not intended to be processed, and only if the parties agree in writing.
Annex 2: Technical and organisational measures
- Encryption: personal data is encrypted in transit (TLS) and at rest. Secrets and integration tokens are encrypted with keys held outside the database.
- Tenant isolation: workspace data is separated using row-level security so one workspace cannot read another’s data.
- Access control: access to production systems is restricted on a least-privilege basis, protected by multi-factor authentication, and reviewed periodically.
- Logging and monitoring: security-relevant events are recorded in an append-only audit log, and errors are monitored so faults can be detected and fixed.
- Resilience and backups: data is backed up by our infrastructure providers, and the service is designed to recover from provider outages.
- Secure development: changes to production follow a controlled change-management process.
Annex 3: Approved sub-processors
The current list of approved sub-processors, with the purpose, data processed, and location of each, is maintained on our Sub-processors page and forms part of this DPA.