Data Processing Agreement
Last Updated: February 2, 2026
Jump to section
1. Introduction and Scope
1.1 Purpose
This Data Processing Agreement ("DPA") forms part of and supplements the Terms of Service and governs the processing of Personal Data by Kokorick Ltd, trading as Warmo ("Warmo", "we", "us", or "our"), on behalf of customers using the Services.
The purpose of this DPA is to establish the parties' respective rights and obligations with respect to the processing of Personal Data and to ensure compliance with applicable data protection laws.
1.2 Scope of Application
This DPA applies where Warmo processes Personal Data on behalf of a customer in connection with the provision of the Services and where such processing is subject to applicable data protection laws, including the United Kingdom General Data Protection Regulation ("UK GDPR"), the European Union General Data Protection Regulation ("EU GDPR"), and other applicable data protection and privacy laws.
This DPA applies solely to Personal Data processed by Warmo in its capacity as a processor acting on behalf of the customer.
1.3 Acceptance of this DPA
By accepting the Terms of Service, creating an account, accessing the Services, purchasing a subscription, or otherwise using the Services, the customer agrees to be bound by this DPA.
If an individual accepts this DPA on behalf of a company, organization, or other legal entity, such individual represents and warrants that they have the authority to bind that entity to this DPA.
1.4 Relationship to Other Agreements
This DPA forms part of the agreement between the customer and Warmo governing the use of the Services.
In the event of a conflict between: (a) a separately executed enterprise, commercial, or custom agreement between the parties; (b) this DPA; (c) the Terms of Service; and (d) the Privacy Policy, the order of precedence shall be as listed above, solely with respect to the subject matter governed by each document.
1.5 Customer Data
For purposes of this DPA, Customer Data may include Personal Data submitted, uploaded, imported, stored, transmitted, generated, managed, or otherwise processed through the Services by or on behalf of the customer, including account information, contact information, communications, campaign content, and other user-submitted data.
The specific categories of Personal Data and processing activities covered by this DPA are further described in the applicable provisions of this DPA.
1.6 Parties
This DPA is entered into between Kokorick Ltd, 86-90 Paul Street, London EC2A 4NE, England and the customer accepting the Terms of Service and using the Services.
This DPA remains in effect for so long as Warmo processes Personal Data on behalf of the customer in connection with the Services.
2. Definitions
For purposes of this DPA, the following terms shall have the meanings set forth below:
2.1 Agreement
"Agreement" means this Data Processing Agreement, including any schedules, appendices, exhibits, or amendments incorporated herein.
2.2 Applicable Data Protection Laws
"Applicable Data Protection Laws" means all applicable laws, regulations, and governmental requirements relating to privacy, data protection, the processing of Personal Data, data security, and electronic communications, including, where applicable, the UK GDPR, the EU GDPR, and any implementing or supplementary legislation.
2.3 Controller
"Controller" means the entity that determines the purposes and means of the Processing of Personal Data, or any equivalent term under Applicable Data Protection Laws.
2.4 Customer
"Customer" means any individual, company, organization, or other legal entity that accesses, purchases, subscribes to, or uses the Services and is party to the Terms of Service.
2.5 Customer Data
"Customer Data" means any data, content, information, or material submitted, uploaded, transmitted, imported, stored, generated, or otherwise processed through the Services by or on behalf of the Customer, including Personal Data contained therein.
2.6 Data Subject
"Data Subject" means an identified or identifiable natural person to whom Personal Data relates, or any equivalent term under Applicable Data Protection Laws.
2.7 EU GDPR
"EU GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, as amended, replaced, or superseded from time to time.
2.8 Personal Data
"Personal Data" means any information relating to an identified or identifiable natural person that is protected as personal data, personal information, or a similar term under Applicable Data Protection Laws.
2.9 Personal Data Breach
"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data transmitted, stored, or otherwise processed by Warmo.
2.10 Process, Processing, or Processed
"Process," "Processing," or "Processed" means any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, transmission, dissemination, restriction, deletion, or destruction.
2.11 Processor
"Processor" means the entity that Processes Personal Data on behalf of a Controller, or any equivalent term under Applicable Data Protection Laws.
2.12 Security Incident
"Security Incident" means a confirmed event resulting in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data processed by Warmo on behalf of the Customer. For the avoidance of doubt, Security Incidents do not include unsuccessful attempts or activities that do not compromise the security, confidentiality, integrity, or availability of Personal Data.
2.13 Services
"Services" means the software products, applications, platforms, websites, tools, features, and related services made available by Warmo pursuant to the Terms of Service or any applicable agreement between the parties.
2.14 Subprocessor
"Subprocessor" means any third party engaged by Warmo to Process Personal Data on behalf of the Customer in connection with the provision of the Services.
2.15 Supervisory Authority
"Supervisory Authority" means an independent public authority responsible for monitoring the application of Applicable Data Protection Laws, including any successor authority.
2.16 UK GDPR
"UK GDPR" means the General Data Protection Regulation as incorporated into the laws of the United Kingdom and amended from time to time.
3. Roles of the Parties
3.1 Customer as Controller
With respect to the Processing of Customer Data subject to this DPA, the Customer acts as the Controller and retains sole responsibility for determining the purposes and means of such Processing.
The Customer is solely responsible for determining: (a) what Personal Data is submitted, uploaded, imported, transmitted, stored, or otherwise made available through the Services; (b) the categories of Data Subjects whose Personal Data is Processed; (c) the purposes for which Personal Data is Processed; (d) the recipients of any communications, campaigns, messages, or other activities conducted through the Services; and (e) compliance with Applicable Data Protection Laws and any other laws applicable to the Customer's use of the Services.
3.2 Warmo as Processor
In connection with the Processing of Customer Data subject to this DPA, Warmo acts solely as a Processor on behalf of the Customer.
Warmo shall Process Customer Data only: (a) to provide, maintain, support, secure, and improve the Services; (b) in accordance with the Customer's documented instructions; (c) as necessary to fulfill its obligations under the Terms of Service, this DPA, or any applicable agreement between the parties; or (d) as otherwise required by Applicable Data Protection Laws.
Except as expressly set forth in this DPA or required by Applicable Data Protection Laws, Warmo shall not determine the purposes or means of Processing Customer Data.
3.3 Customer Instructions
The parties acknowledge and agree that the Customer's use of the Services, including the configuration of account settings, submission of Customer Data, management of users, creation of communications, and operation of the Services, constitutes documented instructions to Warmo regarding the Processing of Customer Data.
Warmo may decline any instruction that would require Warmo to violate Applicable Data Protection Laws or materially interfere with the operation, security, integrity, or functionality of the Services.
3.4 Compliance Responsibilities
The Customer is responsible for ensuring that: (a) it has all necessary rights, permissions, authorizations, notices, and legal bases required to collect, use, disclose, and otherwise Process Personal Data; (b) its instructions to Warmo comply with Applicable Data Protection Laws; (c) its use of the Services complies with Applicable Data Protection Laws and other applicable legal requirements; and (d) any communications, campaigns, outreach activities, or other Processing activities conducted through the Services are lawful.
3.5 Legal Requirements
If Applicable Data Protection Laws or another applicable law requires Warmo to Process Customer Data in a manner not otherwise authorized by the Customer's instructions, Warmo may do so to the extent required by law.
3.6 No Transfer of Controller Responsibilities
Nothing in this DPA shall be interpreted as transferring the Customer's responsibilities as Controller to Warmo.
4. Scope of Processing
4.1 General Scope
Warmo shall Process Customer Data solely for the purposes of providing, maintaining, securing, supporting, and improving the Services, and in accordance with the Customer's documented instructions, this DPA, the Terms of Service, and Applicable Data Protection Laws.
4.2 Nature of Processing
The nature of the Processing may include: (a) receiving and storing Customer Data; (b) organizing, structuring, categorizing, and maintaining Customer Data; (c) retrieving and making Customer Data available to authorized users; (d) transmitting and synchronizing Customer Data as necessary to provide the Services; (e) facilitating communications and activities initiated by the Customer; (f) monitoring, troubleshooting, and securing the Services; (g) performing analytics and reporting necessary to provide and improve the Services; and (h) deleting, anonymizing, or restricting Customer Data in accordance with the Customer's instructions or Applicable Data Protection Laws.
4.3 Purpose of Processing
Warmo may Process Customer Data for the following purposes: (a) providing access to and operation of the Services; (b) administering Customer accounts and user access; (c) facilitating communications and activities initiated by the Customer; (d) providing customer support and service-related communications; (e) maintaining the security, availability, integrity, and performance of the Services; (f) detecting, preventing, and responding to security incidents, fraud, or misuse; (g) complying with legal obligations; and (h) improving and developing the Services.
4.4 Categories of Personal Data
The categories of Personal Data Processed by Warmo may vary depending on the Customer's use of the Services and may include: (a) account and user information; (b) contact and business-related information; (c) communications and communication content; (d) Customer-submitted content and materials; (e) usage, activity, and service interaction information; and (f) any other Personal Data submitted or otherwise made available by or on behalf of the Customer through the Services.
4.5 Categories of Data Subjects
The categories of Data Subjects whose Personal Data may be Processed under this DPA may include: (a) Customer personnel and authorized users; (b) customers, prospects, contacts, vendors, and other individuals whose Personal Data is submitted to the Services by or on behalf of the Customer; and (c) other individuals whose Personal Data is Processed through the Customer's use of the Services.
4.6 Duration of Processing
Warmo shall Process Customer Data for the duration of the Customer's use of the Services and thereafter only for such period as required to comply with applicable contractual obligations, legal requirements, security obligations, dispute resolution requirements, or data deletion and retention provisions set forth in this DPA, the Terms of Service, or Applicable Data Protection Laws.
4.7 No Independent Processing Purpose
Except as otherwise permitted or required by Applicable Data Protection Laws, Warmo shall not use Customer Data Processed on behalf of the Customer to train third-party foundation artificial intelligence models unless expressly authorized by the Customer.
5. Customer Instructions
5.1 Processing on Customer Instructions
Warmo shall Process Customer Data only on behalf of and in accordance with the Customer's documented instructions, except where otherwise required by Applicable Data Protection Laws.
The parties agree that the Customer's instructions are documented and communicated through: (a) the Terms of Service; (b) this DPA; (c) the Customer's use of the Services; (d) account settings, configurations, and preferences; (e) actions performed by authorized users; (f) requests submitted through supported integrations or APIs; and (g) written instructions separately provided by the Customer and accepted by Warmo.
5.2 Authorized Users and Account Administration
The Customer is responsible for managing user access, permissions, administrator roles, account settings, and other controls made available through the Services. Warmo may rely upon instructions, permissions, and actions performed by individuals authorized by the Customer to access or use the Services.
5.3 Additional Instructions
The Customer may provide additional documented instructions regarding the Processing of Customer Data where such instructions are: (a) consistent with the Services; (b) technically feasible; (c) lawful; (d) reasonable in scope; and (e) compatible with Warmo's contractual and operational obligations.
5.4 Unlawful, Unsafe, or Infeasible Instructions
Warmo may decline, suspend, or refuse to implement any instruction that: (a) violates Applicable Data Protection Laws; (b) would compromise the security, integrity, or performance of the Services; (c) would create a material risk to Warmo or its customers; or (d) is technically infeasible.
5.5 Legal Compliance
If Warmo reasonably believes that a Customer instruction may violate Applicable Data Protection Laws, Warmo may suspend implementation of the instruction pending clarification from the Customer.
5.6 Responsibility for Customer Data
The Customer remains solely responsible for: (a) the accuracy, quality, completeness, and legality of Customer Data; (b) the lawfulness of the collection, use, disclosure, and Processing of Customer Data; (c) ensuring that Customer instructions comply with Applicable Data Protection Laws; and (d) obtaining any notices, permissions, authorizations, consents, or other legal bases required for the Processing of Customer Data.
5.7 No Independent Determination of Customer Activities
Warmo does not independently determine the recipients, purposes, timing, content, or objectives of communications, campaigns, outreach activities, or other Customer-directed activities conducted through the Services. Such decisions remain the sole responsibility of the Customer.
6. Categories of Personal Data
6.1 General
The categories of Personal Data Processed by Warmo on behalf of the Customer may vary depending on the Customer's use of the Services, the nature of the Customer Data submitted, and the functionality utilized by the Customer.
6.2 User and Account Information
Personal Data may include information relating to users of the Services, including: (a) names; (b) business email addresses; (c) usernames and account identifiers; (d) authentication and account-related information; and (e) other information submitted in connection with Customer accounts.
6.3 Business Contact Information
Personal Data may include information relating to business contacts and professional relationships, including: (a) names; (b) business email addresses; (c) job titles; (d) company affiliations; (e) professional contact details; and (f) other business-related contact information.
6.4 Company and Organization Information
Personal Data may include information relating to organizations and business entities, including: (a) company names; (b) business addresses; (c) organizational information; (d) industry information; and (e) other business-related information submitted by or on behalf of the Customer.
6.5 Communications and Communication Content
Personal Data may include information contained in communications processed through the Services, including: (a) messages; (b) communication content; (c) subject lines; (d) communication metadata; (e) replies and responses; and (f) other information within communications submitted to or processed through the Services.
6.6 Business Preferences and Configuration Information
Personal Data may include information relating to Customer-defined preferences, criteria, configurations, and settings, including: (a) business preferences; (b) account configurations; (c) selection criteria; (d) user-defined parameters; and (e) other information submitted by or on behalf of the Customer to configure or personalize the Services.
6.7 Customer Content
Personal Data may include content and materials submitted by or on behalf of the Customer, including: (a) documents; (b) files; (c) templates; (d) notes; (e) records; (f) uploaded materials; and (g) other Customer-generated content processed through the Services.
6.8 Technical and Usage Information
Personal Data may include information generated through the use of the Services, including: (a) device information; (b) log information; (c) activity information; (d) service interaction information; (e) system usage information; and (f) other information necessary to operate, secure, maintain, and support the Services.
6.9 Integration and Connected Service Information
Where the Customer elects to connect or use third-party services, Personal Data may include information transmitted to or from such connected services in accordance with the Customer's instructions and configuration settings.
6.10 Special Categories of Personal Data
Warmo is not designed for the processing of Special Categories of Personal Data and the Customer shall not use the Services for such Processing without Warmo's prior written authorization. Special Categories include: (a) racial or ethnic origin; (b) political opinions; (c) religious or philosophical beliefs; (d) trade union membership; (e) genetic data; (f) biometric data used for identification purposes; (g) health information; (h) information concerning a person's sex life or sexual orientation; (i) criminal convictions or offences; or (j) any other category of sensitive Personal Data subject to heightened protection under Applicable Data Protection Laws.
7. Categories of Data Subjects
7.1 General
The categories of Data Subjects whose Personal Data may be Processed by Warmo on behalf of the Customer will vary depending on the Customer's use of the Services and the nature of the Customer Data submitted.
7.2 Customer Personnel
Data Subjects may include individuals associated with the Customer, including: (a) employees; (b) administrators; (c) authorized users; (d) contractors; (e) consultants; and (f) other personnel acting on behalf of the Customer.
7.3 Business Contacts and Representatives
Data Subjects may include business contacts and representatives of organizations, including: (a) directors; (b) officers; (c) owners; (d) employees; (e) representatives; and (f) other individuals acting on behalf of organizations.
7.4 Prospects and Potential Customers
Data Subjects may include prospective customers, leads, business prospects, and other individuals identified, managed, or contacted by or on behalf of the Customer through the Services.
7.5 Customers and Clients
Data Subjects may include the Customer's existing customers, clients, users, subscribers, members, and other individuals with whom the Customer maintains a business or professional relationship.
7.6 Vendors, Suppliers, and Service Providers
Data Subjects may include representatives, personnel, and contacts associated with the Customer's vendors, suppliers, service providers, partners, contractors, and other third parties.
7.7 Other Individuals
Data Subjects may also include any other individuals whose Personal Data is submitted, uploaded, imported, transmitted, stored, or otherwise made available to Warmo by or on behalf of the Customer in connection with the use of the Services.
8. Confidentiality
8.1 Confidential Treatment of Customer Data
Warmo shall treat Customer Data as confidential information and shall implement appropriate measures to protect the confidentiality of Customer Data Processed on behalf of the Customer.
Warmo shall not access, use, disclose, or otherwise Process Customer Data except as necessary to provide the Services, comply with this DPA, fulfill its contractual obligations, or as otherwise required by Applicable Data Protection Laws.
8.2 Authorized Personnel
Warmo shall ensure that access to Customer Data is limited to personnel who require such access in order to perform their duties, provide the Services, support Customer accounts, maintain the Services, or comply with legal obligations.
8.3 Confidentiality Obligations
Warmo shall ensure that personnel authorized to access Customer Data are subject to appropriate confidentiality obligations, whether arising under contract, policy, professional duty, or applicable law. Such obligations shall survive the termination of the individual's relationship with Warmo.
8.4 Personnel Awareness and Training
Warmo shall maintain reasonable measures designed to promote awareness of confidentiality, privacy, and security responsibilities among personnel who may have access to Customer Data.
8.5 Third-Party Access
Where Customer Data is accessed by authorized contractors, consultants, or other individuals acting on behalf of Warmo, Warmo shall take reasonable steps to ensure that such individuals are subject to confidentiality obligations no less protective than those applicable to Warmo personnel.
8.6 Disclosure Required by Law
Nothing in this DPA shall prohibit Warmo from disclosing Customer Data where such disclosure is required by Applicable Data Protection Laws, court order, regulatory requirement, governmental authority, or other legal obligation. Where legally permitted, Warmo shall use reasonable efforts to notify the Customer of such requirement before disclosing Customer Data.
8.7 Continuing Obligations
The confidentiality obligations set forth in this Section shall continue for so long as Warmo Processes Customer Data on behalf of the Customer and shall survive termination of this DPA to the extent required by Applicable Data Protection Laws.
9. Security Measures
9.1 General Security Commitment
Warmo shall implement and maintain appropriate technical and organizational measures designed to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Data.
9.2 Security Safeguards
Without limiting the generality of Section 9.1, Warmo shall maintain reasonable safeguards designed to: (a) protect the confidentiality, integrity, availability, and resilience of the Services and Customer Data; (b) restrict access to Customer Data to authorized personnel; (c) authenticate and manage access to systems; (d) protect Customer Data during transmission, storage, and Processing; (e) monitor, detect, investigate, and respond to security-related events; (f) maintain the security and operational integrity of the Services; and (g) support the ongoing protection of Customer Data against unauthorized access, misuse, disclosure, alteration, destruction, or loss.
9.3 Organizational Measures
Warmo shall maintain reasonable administrative, organizational, and operational measures designed to support the security of Customer Data, including appropriate policies, procedures, and security-related safeguards.
9.4 Access Management
Warmo shall implement reasonable measures designed to ensure that access to Customer Data is limited to authorized personnel who require such access in connection with the provision, maintenance, support, security, or operation of the Services.
9.5 Evaluation and Improvement
Warmo may periodically review, update, modify, or otherwise improve its security measures to address evolving technologies, operational requirements, legal obligations, security threats, and industry practices.
9.6 Security Responsibilities of the Customer
The Customer remains responsible for: (a) maintaining the security of its accounts, credentials, devices, networks, and systems; (b) managing user access and permissions; (c) protecting authentication credentials and account information; (d) configuring the Services in accordance with the Customer's requirements; and (e) implementing appropriate safeguards within its own environment.
9.7 No Guarantee of Absolute Security
While Warmo maintains security measures designed to protect Customer Data, no method of transmission, storage, Processing, or security control can guarantee absolute security.
10. Subprocessors
10.1 Authorization to Engage Subprocessors
The Customer acknowledges and agrees that Warmo may engage Subprocessors to assist in the provision, operation, maintenance, support, security, and delivery of the Services. By entering into this DPA, the Customer provides general authorization for Warmo to engage and use Subprocessors.
10.2 Selection and Oversight of Subprocessors
Warmo shall exercise reasonable care in the selection and engagement of Subprocessors and shall take reasonable steps to ensure that Subprocessors are capable of providing appropriate safeguards for the protection of Customer Data.
10.3 Data Protection Obligations
Where a Subprocessor Processes Customer Data on behalf of Warmo, Warmo shall impose contractual obligations on the Subprocessor designed to provide a level of protection for Customer Data substantially similar to the obligations applicable to Warmo under this DPA.
10.4 Changes to Subprocessors
Warmo may add, replace, remove, or otherwise modify its use of Subprocessors from time to time as necessary to support the Services and its business operations. Warmo shall maintain information regarding its Subprocessors through a publicly available list, customer notice process, or other reasonable mechanism.
10.5 Customer Concerns Regarding Subprocessors
If the Customer has reasonable concerns regarding a newly engaged Subprocessor and such concerns relate to the protection of Customer Data or compliance with Applicable Data Protection Laws, the Customer may notify Warmo in writing. The parties shall discuss such concerns in good faith.
10.6 International Processing by Subprocessors
To the extent a Subprocessor Processes Customer Data in a jurisdiction different from the jurisdiction in which the Customer Data was originally collected or submitted, Warmo shall ensure that appropriate safeguards are implemented as required by Applicable Data Protection Laws.
10.7 Categories of Subprocessors
Subprocessors may include service providers supporting areas such as: (a) infrastructure and hosting; (b) data storage and processing; (c) communications and messaging; (d) customer support and service operations; (e) security, monitoring, and fraud prevention; (f) analytics and operational services; (g) integrations and platform functionality; and (h) other services reasonably necessary to provide, maintain, secure, improve, and support the Services.
10.8 No Obligation to Disclose Operational Details
Nothing in this DPA shall require Warmo to disclose proprietary operational information, internal security measures, confidential vendor arrangements, or other information that could reasonably compromise the security, integrity, or operation of the Services.
11. International Data Transfers
11.1 International Processing
The Customer acknowledges and agrees that, in connection with the provision of the Services, Customer Data may be Processed in jurisdictions other than the jurisdiction in which the Customer Data was originally collected, submitted, stored, or accessed. Such Processing may be performed by Warmo or its authorized Subprocessors.
11.2 Transfer Safeguards
Where the Processing of Customer Data involves a transfer of Personal Data that is subject to restrictions under Applicable Data Protection Laws, Warmo shall implement and maintain appropriate safeguards. Such safeguards may include, where applicable: (a) adequacy decisions issued by a competent authority; (b) Standard Contractual Clauses approved or recognized by applicable regulatory authorities; (c) the United Kingdom International Data Transfer Addendum or other approved transfer mechanisms; (d) binding corporate rules, where applicable; or (e) any other lawful transfer mechanism recognized under Applicable Data Protection Laws.
11.3 Future Transfer Mechanisms
Where a transfer mechanism described in this Section is amended, replaced, superseded, or invalidated, Warmo may rely upon any successor, replacement, or alternative lawful transfer mechanism recognized under Applicable Data Protection Laws.
11.4 Transfers by Subprocessors
Warmo shall take reasonable steps to ensure that authorized Subprocessors engaged in the Processing of Customer Data implement appropriate safeguards for international transfers where required by Applicable Data Protection Laws.
11.5 Customer Instructions Regarding Transfers
The Customer acknowledges that the use of the Services may require the transfer, storage, access, transmission, or Processing of Customer Data across multiple jurisdictions. To the extent such activities are necessary to provide, maintain, secure, support, or improve the Services, the Customer instructs Warmo to perform such transfers in accordance with this DPA and Applicable Data Protection Laws.
11.6 Compliance with Applicable Data Protection Laws
Warmo shall implement international data transfer safeguards to the extent required by Applicable Data Protection Laws and shall make reasonable efforts to maintain compliance with applicable legal requirements governing international transfers of Personal Data.
11.7 No Obligation to Disclose Operational Infrastructure
Nothing in this DPA shall require Warmo to disclose specific infrastructure locations, data center locations, hosting arrangements, network architecture, or other security-sensitive or confidential commercial arrangements.
12. Assistance with Data Subject Rights
12.1 Customer Responsibility
The Customer remains solely responsible for responding to requests, inquiries, complaints, and other communications received from Data Subjects relating to the Processing of Personal Data, including requests made under Applicable Data Protection Laws.
12.2 Reasonable Assistance
Taking into account the nature of the Processing and the information available to Warmo, Warmo shall provide reasonable assistance to the Customer, where technically feasible and commercially reasonable, to enable the Customer to fulfill its obligations under Applicable Data Protection Laws with respect to Data Subject rights.
12.3 Categories of Assistance
Such assistance may include support relating to requests concerning: (a) access to Personal Data; (b) correction or rectification of Personal Data; (c) deletion or erasure of Personal Data; (d) restriction of Processing; (e) data portability; (f) objections to Processing; and (g) other rights available to Data Subjects under Applicable Data Protection Laws.
12.4 Direct Requests Received by Warmo
If Warmo receives a request directly from a Data Subject relating to Customer Data Processed on behalf of the Customer, Warmo may: (a) refer the Data Subject to the Customer; (b) notify the Customer of the request, where appropriate and legally permitted; or (c) take such other action as may be required by Applicable Data Protection Laws.
12.5 Technical and Operational Limitations
Warmo's obligation to provide assistance under this Section is limited to assistance that is technically feasible, operationally reasonable, and consistent with the functionality of the Services. Nothing in this DPA shall require Warmo to develop new features, perform custom engineering work, undertake disproportionate efforts, or take actions that would compromise the security or integrity of the Services.
12.6 Information Available to Warmo
Warmo shall provide assistance based upon the information available to Warmo in its capacity as a Processor and shall not be responsible for information, records, or Processing activities outside of Warmo's control.
12.7 Costs of Extraordinary Assistance
To the extent permitted by Applicable Data Protection Laws, Warmo may charge reasonable fees for assistance requests that are excessive, repetitive, extraordinary, resource-intensive, or beyond the scope of standard support provided under the Services.
12.8 Limitation of Assistance Obligations
Warmo's obligations under this Section apply solely to Customer Data Processed by Warmo on behalf of the Customer in connection with the Services.
13. Security Incidents
13.1 Notification of Security Incidents
In the event that Warmo becomes aware of a Security Incident affecting Customer Data Processed on behalf of the Customer, Warmo shall notify the Customer without undue delay.
13.2 Information Regarding Security Incidents
To the extent reasonably available and legally permissible, Warmo shall provide the Customer with information regarding the Security Incident, which may include: (a) the nature of the Security Incident; (b) the categories of Customer Data affected; (c) the known or reasonably suspected consequences; (d) measures taken or proposed to address the Security Incident; and (e) other information reasonably necessary to assist the Customer in meeting its obligations under Applicable Data Protection Laws.
13.3 Ongoing Updates
The Customer acknowledges that information relating to a Security Incident may not be available immediately following discovery. Accordingly, Warmo may provide information in phases and supplement or update previously provided information as additional facts become available.
13.4 Cooperation and Assistance
Taking into account the nature of the Processing, Warmo shall provide reasonable cooperation and assistance to the Customer in connection with a Security Incident affecting Customer Data.
13.5 Customer Responsibilities
The Customer remains solely responsible for: (a) determining whether a Security Incident triggers notification obligations under Applicable Data Protection Laws; (b) notifying Supervisory Authorities, regulators, affected individuals, or other third parties where required by law; (c) assessing legal obligations arising from the Security Incident; and (d) making decisions regarding communications, disclosures, or remediation actions.
13.6 No Admission of Liability
Any notification, communication, investigation, cooperation, assistance, or other action taken by Warmo in connection with a Security Incident shall not constitute an admission of fault, liability, wrongdoing, negligence, breach of contract, or violation of Applicable Data Protection Laws.
13.7 Confidentiality of Security Incident Information
Information relating to a Security Incident, including investigations, findings, remediation efforts, communications, and reports, shall be treated as confidential information and used solely for purposes reasonably related to addressing the Security Incident.
13.8 Protection of Security Information
Nothing in this DPA shall require Warmo to disclose internal security procedures, security architecture, vulnerability information, forensic methodologies, or other information that could reasonably compromise the security, confidentiality, integrity, or operation of the Services.
13.9 Scope of Security Incident Obligations
The obligations set forth in this Section apply solely to Security Incidents affecting Customer Data Processed by Warmo on behalf of the Customer and do not apply to incidents arising from the Customer's own systems, actions or omissions of the Customer or its users, or circumstances outside the scope of Warmo's Processing activities.
14. Audits and Information Requests
14.1 Compliance Information
Upon reasonable written request, Warmo shall make available information reasonably necessary to demonstrate its compliance with the obligations set forth in this DPA, to the extent required by Applicable Data Protection Laws. Warmo may satisfy such requests by providing documentation, policies, summaries, reports, certifications, attestations, or other appropriate materials.
14.2 Alternative Means of Verification
The Customer acknowledges that Warmo may satisfy audit and verification requirements through reasonable alternative means, including: (a) compliance documentation; (b) security and privacy materials; (c) responses to reasonable information requests; (d) independent assessments; (e) certifications or attestations obtained by Warmo; and (f) other information reasonably designed to demonstrate compliance with this DPA.
14.3 Audit Requests
Where Applicable Data Protection Laws require an audit right that cannot reasonably be satisfied through alternative means, the Customer may request an audit relating solely to Warmo's Processing of Customer Data. Any such audit shall: (a) be reasonable in scope; (b) be limited to matters directly relevant to the Processing of Customer Data; (c) avoid unreasonable disruption to Warmo's business operations; and (d) be conducted in a manner that protects the security, confidentiality, and integrity of the Services.
14.4 Frequency and Notice
Except where required by Applicable Data Protection Laws or following a Security Incident materially affecting Customer Data, the Customer may not conduct or request more than one audit during any twelve (12) month period. The Customer shall provide at least thirty (30) days' prior written notice of any audit request.
14.5 Independent Auditors
Any audit permitted under this DPA shall be conducted by an independent third party auditor reasonably acceptable to Warmo. Such auditor shall be bound by written confidentiality obligations no less protective than those contained in this DPA and shall not be a competitor of Warmo.
14.6 Protection of Confidential Information
Nothing in this DPA shall require Warmo to disclose or make available: (a) trade secrets; (b) proprietary information; (c) confidential commercial information; (d) internal security procedures or architecture; (e) source code; (f) vulnerability information; (g) information relating to other customers; or (h) information subject to legal privilege.
14.7 Costs and Expenses
The Customer shall bear its own costs and expenses associated with any audit, inspection, assessment, or review conducted under this Section. Warmo may charge reasonable fees for requests requiring substantial additional resources or extraordinary effort.
14.8 Future Certifications and Assessments
Warmo may rely upon certifications, attestations, independent assessments, audit reports, or compliance frameworks obtained in the future to demonstrate compliance with this DPA.
14.9 No Access to Systems or Infrastructure
Nothing in this DPA grants the Customer, its auditors, or any third party any right to access production environments, systems, networks, infrastructure, or facilities; conduct penetration testing; perform vulnerability assessments; inspect source code; or otherwise interfere with the operation of the Services.
14.10 Good Faith Cooperation
The parties shall cooperate in good faith to address reasonable requests relating to compliance with Applicable Data Protection Laws while balancing the Customer's legitimate compliance requirements with Warmo's obligations to protect security, confidentiality, proprietary information, and the interests of its customers.
15. Data Retention and Deletion
15.1 Retention During the Services
Warmo shall retain Customer Data for so long as necessary to provide the Services, fulfill its obligations under the Terms of Service and this DPA, support Customer accounts, maintain the security and operation of the Services, and comply with Applicable Data Protection Laws.
15.2 Customer Access and Retrieval
During the term of the Services and for a reasonable period following termination or expiration of the Customer's account, the Customer may access, retrieve, export, or otherwise obtain Customer Data through the functionality made available by Warmo. The Customer is responsible for retrieving any Customer Data it wishes to retain before deletion occurs.
15.3 Post-Termination Retention Period
Following termination or expiration of the Services, Warmo may retain Customer Data for up to thirty (30) days, or such other reasonable period determined by Warmo, to facilitate account closure, customer requests, service administration, dispute resolution, operational continuity, and security purposes.
15.4 Deletion of Customer Data
Following the expiration of any applicable retention period, Warmo shall take reasonable steps to delete, erase, anonymize, de-identify, or otherwise remove Customer Data from its active systems, except where retention is permitted or required under this DPA or Applicable Data Protection Laws.
15.5 Backup and Archival Systems
Customer Data may remain in backup systems, archival systems, disaster recovery systems, security systems, logs, or other protected storage environments for a limited period following deletion from active systems. Such retained Customer Data shall remain subject to appropriate safeguards.
15.6 Retention Required by Law
Warmo may retain Customer Data to the extent required to: (a) comply with Applicable Data Protection Laws or other legal obligations; (b) comply with regulatory, tax, accounting, audit, or recordkeeping requirements; (c) establish, exercise, or defend legal claims; (d) investigate fraud, security incidents, misuse, or unlawful activity; (e) enforce contractual rights; or (f) satisfy other lawful business or compliance obligations.
15.7 De-Identified and Aggregated Information
Nothing in this DPA shall require Warmo to delete information that has been anonymized, aggregated, de-identified, or otherwise processed such that it no longer constitutes Personal Data under Applicable Data Protection Laws.
15.8 Subprocessor Deletion Obligations
To the extent Customer Data has been provided to authorized Subprocessors, Warmo shall take reasonable steps to ensure that applicable deletion or retention obligations are communicated to such Subprocessors.
15.9 No Obligation for Custom Retrieval Services
Warmo shall not be required to provide custom migration services, custom export formats, manual extraction projects, engineering services, or other extraordinary efforts in connection with the return, retrieval, export, or deletion of Customer Data, except where otherwise required by Applicable Data Protection Laws or agreed separately in writing.
15.10 Completion of Deletion Obligations
Warmo's obligations under this Section shall be deemed satisfied when Customer Data has been deleted, anonymized, de-identified, overwritten, retained pursuant to a lawful exception, or otherwise processed in accordance with this DPA and Applicable Data Protection Laws.
16. Liability
16.1 Application of the Terms of Service
The liability of each party arising out of or relating to this DPA shall be subject to the exclusions, limitations, disclaimers, and liability provisions set forth in the Terms of Service, which are incorporated into this DPA by reference.
16.2 No Expansion of Liability
Except as expressly required by Applicable Data Protection Laws, nothing in this DPA shall be construed to increase, expand, modify, or create additional liability for either party beyond the liability framework established in the Terms of Service.
16.3 Single Recovery
A party shall not be entitled to recover the same loss, damage, cost, expense, or liability more than once, regardless of whether such claim arises under this DPA, the Terms of Service, or any related agreement between the parties.
16.4 Mandatory Legal Rights
Nothing in this DPA shall limit or exclude liability to the extent such limitation or exclusion is prohibited by Applicable Data Protection Laws or other applicable laws. To the extent any provision of this Section conflicts with mandatory requirements of Applicable Data Protection Laws, such mandatory requirements shall prevail solely to the extent required by law.
16.5 Enterprise and Custom Agreements
Where the parties have entered into a separate written enterprise agreement containing liability provisions applicable to the Processing of Customer Data, those liability provisions shall govern to the extent of any conflict with this Section.
16.6 Interpretation
The parties acknowledge that this DPA is intended to supplement the Terms of Service and not to create a separate or independent liability regime. The provisions of this DPA shall be interpreted consistently with the liability allocation and limitations of liability established in the Terms of Service.
17. Term and Termination
17.1 Effective Date
This DPA becomes effective on the date the Customer first accepts the Terms of Service, accesses, uses, or otherwise receives the Services.
17.2 Duration of the DPA
This DPA shall remain in effect for so long as Warmo Processes Customer Data on behalf of the Customer in connection with the Services.
17.3 Termination of the DPA
Subject to the survival provisions of this Section, this DPA shall automatically terminate when: (a) the Customer's use of the Services has terminated or expired; (b) Warmo no longer Processes Customer Data on behalf of the Customer; and (c) any applicable obligations relating to the retention, deletion, anonymization, or lawful preservation of Customer Data have been satisfied.
17.4 Survival of Certain Obligations
Termination or expiration of this DPA shall not affect any rights, obligations, or provisions that by their nature are intended to survive termination, including: (a) confidentiality obligations; (b) security obligations; (c) data retention, deletion, and preservation obligations; (d) obligations relating to Security Incidents; (e) liability and limitation of liability provisions; (f) dispute resolution and enforcement rights; (g) legal compliance obligations; and (h) any other provision intended to survive termination.
17.5 Retained Customer Data
To the extent Customer Data is retained following termination pursuant to this DPA, Applicable Data Protection Laws, legal obligations, security requirements, or other lawful exceptions, such Customer Data shall remain subject to the confidentiality, security, and data protection obligations set forth in this DPA.
17.6 Enterprise and Custom Agreements
Where the parties have entered into a separate enterprise agreement or written agreement containing data processing provisions, such agreement may establish different term, termination, survival, or post-termination obligations.
17.7 Effect of Termination
Termination of this DPA shall not relieve either party of obligations accrued prior to termination, nor shall termination affect any rights, remedies, protections, limitations, or obligations that survive under this DPA, the Terms of Service, Applicable Data Protection Laws, or any applicable agreement between the parties.
18. Contact Information
18.1 Privacy and Data Protection Inquiries
Questions, requests, notices, or communications relating to privacy, data protection, Personal Data, Data Subject rights, or this DPA may be directed to: privacy@warmo.ai
18.2 Legal Notices
Questions, requests, notices, legal communications, or other matters relating to this DPA, the Terms of Service, or legal compliance may be directed to: legal@warmo.ai
18.3 Postal Correspondence
Written correspondence may also be sent to: Kokorick Ltd, 86-90 Paul Street, London EC2A 4NE, United Kingdom
18.4 Method of Communication
The parties agree that notices, requests, inquiries, and communications relating to this DPA may be provided electronically through the contact information designated by the parties, unless Applicable Data Protection Laws require another method of communication.
18.5 Updates to Contact Information
Warmo may update its contact information from time to time by posting updated contact details through the Services, on its website, or through other reasonable means of communication.