Parties
Customer acts as Controller or Business. CoSkip acts as Processor or Service Provider where CoSkip processes personal data on behalf of Customer.
DPA for customer privacy, security, and vendor review
CoSkip’s Data Processing Addendum explains how CoSkip processes personal data on behalf of customers, the roles of the parties, security measures, subprocessors, international transfer safeguards, data subject assistance, incident notification, audit support, and return or deletion obligations.
This summary is provided for convenience. The DPA text below controls.
Customer acts as Controller or Business. CoSkip acts as Processor or Service Provider where CoSkip processes personal data on behalf of Customer.
CoSkip processes personal data to provide, secure, support, and improve the services as described in the DPA and applicable agreement.
CoSkip processes personal data only on documented instructions from Customer, including the Agreement and this DPA.
Technical and organisational measures include access controls, encryption, logging, secure development, vendor management, and incident response, as described in Annex II.
CoSkip may use subprocessors to support the services and maintains the current list at /subprocessors.
International transfers are addressed through appropriate safeguards, including SCCs and the UK Addendum/IDTA where applicable.
CoSkip assists Customer with data subject requests, audits, and compliance support as described in the DPA.
Upon termination or expiry, CoSkip deletes or returns personal data in accordance with Customer instructions and the Agreement, unless retention is required by law.
For most customer use cases covered by this DPA, Customer determines the purposes and means of processing. CoSkip processes personal data on Customer’s behalf to provide the configured services and follows documented instructions in the Agreement and this DPA.
Defines users, workflows, configurations, and instructions. Responds to end-user and customer-side obligations where applicable.
Provides, secures, supports, and improves the services as instructed. Assists Customer with requests and compliance obligations as described in the DPA.
Role labels depend on the processing covered by this DPA and applicable law.
Version 1.0. DPA last updated 15 Oct 2025. The formatting below is designed for review; the legal substance is preserved.
This DPA forms part of the master agreement or other written or electronic terms between CoSkip, Inc., a Delaware corporation (“CoSkip”) and the customer entity (“Customer”) governing Customer’s use of CoSkip’s Services. It applies where CoSkip processes Personal Data on behalf of Customer subject to Applicable Data Protection Law (e.g., GDPR/UK GDPR, CPRA).
Capitalised terms not defined here have the meaning in the Agreement.
“Applicable Data Protection Law” means laws and regulations relating to data protection, privacy, and processing of Personal Data, including GDPR/UK GDPR and CPRA, in each case as amended.
“SCCs” means the Standard Contractual Clauses applicable to international transfers under GDPR (EU 2021/914) and the UK Addendum/IDTA, as applicable.
“Personal Data”, “Controller/Processor”, “Data Subject”, and “Processing” have the meanings set out in GDPR/UK GDPR.
Customer is the Controller (or Business); CoSkip is the Processor (or Service Provider). CoSkip will process Personal Data only on documented instructions from Customer, including as set out in this DPA and the Agreement.
CoSkip processes Personal Data to provide, secure, and improve the Services (e.g., voice guidance, optional AR overlays, automated proof-of-work capture), to provide support, and to meet legal obligations. Details are set out in Annex I.
CoSkip implements appropriate technical and organisational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, as described in Annex II. CoSkip ensures personnel are bound by confidentiality obligations.
Customer authorises CoSkip to engage Subprocessors to support the Services. CoSkip will impose data protection terms on Subprocessors no less protective than this DPA and will remain responsible for their performance. The current list is available at coskip.com/subprocessors. CoSkip will provide notice of changes and allow Customer to object on reasonable grounds.
Where CoSkip transfers Personal Data internationally, CoSkip will ensure appropriate safeguards, including SCCs (EU Modules 2/3 as applicable) and the UK Addendum/IDTA, and implement supplementary measures if required.
Taking into account the nature of processing, CoSkip will assist Customer by appropriate technical and organisational measures to fulfil Data Subject requests (access, deletion, etc.) as required by law.
CoSkip will notify Customer without undue delay after becoming aware of a Personal Data Breach, and provide information reasonably required for Customer to meet its obligations.
Upon request and subject to confidentiality, CoSkip will make available information necessary to demonstrate compliance and allow for audits (including by an independent auditor mandated by Customer) no more than annually, unless required by a competent authority or following a material incident.
Upon termination or expiry of the Services, CoSkip will delete or return Personal Data in accordance with Customer’s instructions and the Agreement, unless retention is required by law. Where offered, Customer may enable zero-retention settings for specific features.
This DPA remains in effect while CoSkip processes Personal Data for Customer. If there is a conflict between this DPA and the Agreement, this DPA prevails to the extent of the conflict regarding data protection. The SCCs prevail over this DPA where applicable.
CoSkip’s technical and organisational measures are designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, as described in the DPA.
SSO/SAML support; least-privilege; role-based access; MFA for admin access; logging and review.
TLS 1.2+; certificate management; API auth.
Encrypted storage for applicable services; key management via cloud KMS.
Where supported, voice guidance and recognition operate on device/edge.
Admin settings to discard transient audio/images post-processing.
Backups for critical metadata; disaster recovery procedures; redundancy.
Code review, dependency scanning, vulnerability management.
Subprocessor due diligence, DPA/SCCs, least-data principle.
Defined IR plan; detection, response and notification workflow.
Security training; confidentiality agreements.
See coskip.com/subprocessors for the authoritative, always-current list and change log.
This DPA is provided for convenience and may be updated to reflect regulatory changes. Not legal advice.
Legal, privacy, security, and procurement teams can use this page with CoSkip’s related trust resources to review processing roles, data categories, safeguards, subprocessors, transfers, and customer support obligations.
If your organization needs to review CoSkip’s DPA, complete a vendor questionnaire, discuss customer-specific processing, or request procurement documentation, contact CoSkip with the relevant requirements.
CoSkip helps field teams guide work, capture proof, and close out jobs with clearer records. For pilots and customer reviews, CoSkip’s trust resources help teams understand processing roles, data categories, safeguards, subprocessors, and practical deployment requirements before rollout.