When ROBOCO is entrusted with processing a client’s personal data or other data in the course of a project, we enter into a Data Processing Agreement (DPA) at the client’s request.

📄 Download the standard DPA template: English PDF · 한국어 PDF · 日本語 PDF

What a DPA Is

A DPA is a contract between the client who entrusts the data (the controller) and ROBOCO, which processes it (the processor). It sets out in writing the scope and purpose of the processing along with the protective measures in place. It supports compliance with the processing-delegation provisions of the Personal Information Protection Act of Korea, as well as with any regulations that apply to the client, such as the GDPR.

What Our Standard DPA Covers

  • Scope and purpose of processing: the types of data processed, the purpose of processing, and the processing period
  • Processor obligations: no use beyond the stated purpose, restrictions on sub-processing, and confidentiality
  • Security measures: access controls, encryption, and the technical and administrative safeguards set out in our security policy
  • Incident response: notification procedures and deadlines in the event of a data breach
  • Measures on termination: return or destruction of data, together with confirmation thereof
  • Audit cooperation: cooperation with the client’s security reviews and audit requests

How to Put a DPA in Place

  1. Send a request for a DPA to contact@roboco.io.
  2. We will provide ROBOCO’s standard DPA template. If your organization has its own standard template, we are happy to review and execute that version instead.
  3. We negotiate the clauses to fit the specifics of the project, then sign and execute the agreement.

A non-disclosure agreement (NDA) is separate from a DPA and can be signed at any point before a project begins.

Contact