Data Processing Addendum
Last updated · 2026-09-11
This Data Processing Addendum (“DPA”) forms part of the Terms & Conditions(the “Terms”) between Noli LLC, a Wyoming limited liability company with its principal office at 30 N Gould St, Ste 100, Sheridan, WY 82801 (“Noli”), and the business customer that accepts the Terms (“Customer”). It applies whenever Noli processes personal data on Customer's behalf in providing the Noli AI products and services, including the Chief of Staff, CRM, Marketing (AMS), Knowledge Base, Project Manager, GTM Engineer, and Receptionist, and the AI tools offered through The Launch Pad, a program of Noli LLC (together, the “Service”).
This DPA is incorporated into the Terms by reference. Words defined in the Terms or in the Privacy Policy have the same meaning here. If this DPA conflicts with the Terms on the processing of personal data, this DPA controls. If it conflicts with the Standard Contractual Clauses described in Section 9, the Clauses control.
1. Acceptance without signature
No signature is needed. Customer accepts this DPA by using the Service, and it takes effect on the later of September 11, 2026 and the date Customer first uses the Service. Noli accepts it by publishing it here. A Customer that needs a countersigned copy for its records can email legal@noliai.com and we will return a signed PDF of this same text. Nothing in a countersigned copy changes these terms unless both parties agree in writing.
2. Definitions
- “Data Protection Law” means every law that applies to the processing of personal data under this DPA, including the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended (“CCPA”), and other U.S. state privacy laws.
- “Customer Personal Data” means personal data that Customer, its users, or its connected accounts put into the Service, or that Noli collects for Customer at its instruction, and that Noli processes on Customer's behalf. It includes Workspace Content and Prospect Data as described in the Privacy Policy.
- “Personal data,” “controller,” “processor,” “data subject,” “processing,” and “personal data breach” have the meanings given in the GDPR. Under the CCPA, “controller” means “business” and “processor” means “service provider.”
- “Sub-processor” means a third party Noli engages to process Customer Personal Data on Noli's behalf.
- “Standard Contractual Clauses” or “SCCs” means the clauses approved by European Commission Decision (EU) 2021/914, and “UK Addendum” means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.
3. Roles
For Customer Personal Data, Customer is the controller (or a processor acting for its own customer, in which case Noli is a sub-processor) and Noli is the processor. Customer decides what data goes into the Service, what the Service does with it, and who it is sent to. Noli acts on Customer's instructions.
Noli is an independent controller only for the limited data it holds about Customer's own account, billing, support, and usage, as described in the Privacy Policy. This DPA does not apply to that data.
Where Customer acts for its own clients, Customer represents that it has the authority to instruct Noli and that its own agreements with those clients allow the processing this DPA describes.
4. Details of the processing
4.1 Subject matter and duration
The subject matter is the personal data Customer places in, connects to, or asks Noli to collect for, the Service. The processing lasts for the term of Customer's subscription plus the deletion period in Section 11.
4.2 Nature and purpose
Storing, organizing, retrieving, analyzing, and generating content from Customer Personal Data so that Noli's AI agents can do the work Customer asks for: keeping records, drafting and sending approved communications, scheduling, answering and placing calls and texts, publishing approved content, sourcing business prospects, and reporting. Noli processes Customer Personal Data only to provide, secure, support, and improve the Service as described in the Terms and Privacy Policy, and never to train an AI model.
4.3 Categories of data
- Identity and contact details: names, email addresses, phone numbers, job titles, employers, postal addresses, social and public profile URLs.
- Business records: customer and prospect records, deals, notes, tasks, projects, calendar events, documents, transcripts, and files.
- Communications: emails, text messages, call recordings where Customer enables them, voicemails, chat messages, and their metadata.
- Marketing data: audience lists, campaign content, engagement metrics, and website leads.
- Financial and property data where Customer connects it: invoices, transactions, property addresses and records.
- Credentials Customer connects: OAuth tokens, app passwords, and API keys, stored encrypted.
- AI interaction data: prompts, retrieved context, outputs, and usage metadata.
Customer must not put special-category data (health, biometric, genetic, racial or ethnic origin, political, religious, union, sex life, or sexual orientation data), criminal-record data, data about children under 13, payment card numbers, or government identifiers into the Service unless a feature is expressly designed for it. The Acceptable Use Policy prohibits targeting on such criteria.
4.4 Categories of data subjects
- Customer's employees, contractors, and team members who use the Service.
- Customer's customers, clients, leads, prospects, subscribers, and callers.
- Customer's suppliers, partners, and other business contacts.
- Individuals whose public or licensed business information Customer instructs Noli to source through the GTM Engineer.
- Anyone else whose personal data appears in the content Customer uploads or connects.
5. Noli's obligations as processor
5.1 Instructions
Noli will process Customer Personal Data only on Customer's documented instructions, which are: the Terms, this DPA, the settings Customer chooses in the Service, and the actions Customer or its users request or approve in the Service. Noli will tell Customer if it believes an instruction breaks Data Protection Law, and may pause that instruction until it is resolved. Noli will process Customer Personal Data outside these instructions only where a law of the United States or a member state of the EU requires it, in which case Noli will tell Customer first unless that law forbids it.
5.2 Confidentiality
Noli limits access to Customer Personal Data to personnel and contractors who need it to provide the Service, and makes sure each of them is bound by a written confidentiality obligation.
5.3 Security
Noli will keep the technical and organizational measures described in Annex 2 in place and will not reduce the overall level of protection during the term. Noli will keep these measures under review and update them as threats and the Service change.
5.4 Sub-processors
Customer gives Noli general authorization to engage Sub-processors. The current list, what each one does, and where it processes data is published at noliai.com/legal/sub-processors and is incorporated into this DPA by reference. Noli will:
- bind each Sub-processor by a written contract with data protection obligations at least as protective as this DPA;
- remain responsible to Customer for each Sub-processor's performance;
- email the account owner at least thirty (30) days before a new Sub-processor starts processing Customer Personal Data, and update the page at the same time;
- allow Customer to object on reasonable data-protection grounds by emailing privacy@noliai.com within that period. If Noli cannot offer a reasonable alternative within thirty (30) days of the objection, Customer may cancel the affected subscription and Noli will refund any prepaid fees for the period after cancellation.
A Sub-processor that Customer chooses and connects itself (for example its own mailbox provider, calendar, social network, or a model provider under a Bring Your Own API Key) is Customer's own processor or an independent controller, not a Noli Sub-processor.
5.5 Assistance
Taking into account the nature of the processing, Noli will help Customer meet its obligations under Data Protection Law by:
- providing export, correction, and deletion tools in the Service, and forwarding to Customer within five (5) business days any request Noli receives directly from a data subject that relates to Customer Personal Data, without answering it except to say it has been forwarded, unless the law requires Noli to act;
- giving Customer the information it reasonably needs to carry out a data protection impact assessment or to consult a supervisory authority, where Customer cannot get that information itself;
- helping Customer meet its own breach-notification duties under Section 8.
Noli may charge a reasonable fee for assistance that goes beyond what the Service already provides or that is unusually burdensome.
5.6 Records and cooperation with authorities
Noli keeps a record of the categories of processing it carries out for Customer and will cooperate with a competent supervisory authority as the law requires.
6. Customer's obligations
Customer will:
- make sure it has a lawful basis, and has given any notice and obtained any consent Data Protection Law requires, for every item of Customer Personal Data it places in or collects through the Service, including consent for call recording and for outreach;
- give Noli only instructions that comply with Data Protection Law;
- keep its own account credentials secure, manage its users' access, and configure the Service's settings appropriately for its data;
- answer data subject requests, and respond to authorities, for its own processing;
- comply with the Acceptable Use Policy.
7. CCPA and U.S. state privacy laws
Where the CCPA or a similar U.S. state law applies, Noli acts as a service provider or processor. Noli will not sell or share Customer Personal Data, will not retain, use, or disclose it for any purpose other than the business purposes in this DPA and the Terms, will not use it outside the direct business relationship with Customer, and will not combine it with personal data from other sources except as the law allows a service provider to do. Noli will tell Customer if it can no longer meet these obligations, and Customer may take reasonable steps to stop and remediate unauthorized use.
8. Personal data breach
If Noli becomes aware of a personal data breach affecting Customer Personal Data, Noli will notify the account owner by email without undue delay and in any case within seventy-two (72) hoursof becoming aware. The notice will describe, as far as then known, the nature of the breach, the categories and approximate numbers of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Noli may provide the information in phases as it becomes available. Noli's notice is not an admission of fault. Customer is responsible for notifying its own customers, data subjects, and regulators where the law requires it, and Noli will give the reasonable help Customer needs to do so. Report suspected breaches to security@noliai.com.
9. International transfers
The Service is offered from the United States. Noli stores and processes Customer Personal Data in the United States and, for some Services, in Germany and other countries where its Sub-processors operate, as shown on the sub-processor page. Noli has not appointed a representative in the European Union or the United Kingdom under Article 27 of the GDPR or the UK GDPR. Customer should take this into account when deciding whether to use the Service for data subjects in those regions.
Where Customer transfers personal data that is subject to the GDPR to Noli, the parties agree that the SCCs, Module Two (controller to processor)are incorporated into this DPA by reference and apply to that transfer, completed as follows: Clause 7 (docking) applies; under Clause 9 Option 2 (general authorization) applies with the notice period in Section 5.4; the optional wording in Clause 11 does not apply; under Clauses 17 and 18 the law and courts of Ireland govern; Annex I is completed by Sections 3 and 4 of this DPA and the parties' account details; Annex II is Annex 2 of this DPA; and Annex III is the sub-processor page. Where Customer acts as a processor for its own clients, Module Three applies on the same basis.
Where Customer transfers personal data that is subject to the UK GDPR to Noli, the UK Addendum is incorporated by reference and applies to the SCCs as completed above, with the tables in Part 1 of the Addendum completed by the information in this DPA and Part 2 set so that either party may end the Addendum as set out in Section 19 of it. For transfers subject to Swiss law, the SCCs apply with the changes the Swiss Federal Data Protection and Information Commissioner requires, and references to a member state or the EU include Switzerland.
Noli will tell Customer if it is asked by a public authority to disclose Customer Personal Data, where the law allows, and will challenge requests it considers unlawful. Customer may request a copy of the completed clauses by emailing privacy@noliai.com.
10. Audits
Noli will make available the information reasonably necessary to show that it complies with this DPA. In the first instance that means this DPA, the Privacy Policy, the sub-processor page, Annex 2, and written answers to Customer's reasonable security questionnaire, which Noli will return within thirty (30) days.
If that documentation is not enough to meet a requirement of Data Protection Law, Customer (or an independent auditor bound by confidentiality and reasonably acceptable to Noli) may audit Noli's compliance once in any twelve (12) month period, on at least thirty (30) days' written notice, during business hours, in a way that does not disrupt the Service or expose other customers' data, and at Customer's cost. The limit of once a year does not apply to an audit a supervisory authority requires or one that follows a personal data breach affecting Customer Personal Data. The parties will agree the scope and timing in advance, and Customer will share its findings with Noli.
11. Deletion and return
During the term, Customer can export Customer Personal Data at any time from the Plan page in its account, and can delete individual records in the Service. After the subscription ends, Customer Personal Data stays available for export for thirty (30) days, consistent with the Terms and Privacy Policy. Noli emails the account owner seven (7) days before the deletion date. At the end of that period Noli deletes Customer Personal Data from its active systems and instructs its Sub-processors to do the same, unless a law requires Noli to keep it, in which case Noli will keep it only for as long as that law requires and only for that purpose. Copies held in backups are deleted as those backups expire in the ordinary course. Customer may ask for a written confirmation of deletion by emailing privacy@noliai.com.
12. Liability, term, and changes
Each party's liability under this DPA is subject to the exclusions and the cap in Section 19.0 of the Terms, and the parties agree that the total liability of the Noli Parties under the Terms and this DPA together will not exceed that cap. Nothing in this DPA limits a data subject's rights under the SCCs. This DPA lasts as long as Noli processes Customer Personal Data. Noli may update this DPA to reflect changes in the Service or the law; material changes will be emailed to the account owner thirty (30) days before they take effect, and continued use after that date is acceptance. A change that reduces the protection this DPA gives will not apply to a Customer that objects in writing within that period until its current subscription term ends.
13. Contact
Data protection questions and objections: privacy@noliai.com. Contract questions and signed copies: legal@noliai.com. Security incidents: security@noliai.com.
Annex 1: Summary of the processing
| Data exporter | Customer, as identified in its Noli account. Role: controller (or processor for its own clients). |
| Data importer | Noli LLC, 30 N Gould St, Ste 100, Sheridan, WY 82801, United States. privacy@noliai.com. Role: processor. |
| Data subjects | See Section 4.4. |
| Categories of data | See Section 4.3. |
| Sensitive data | Not intended; see the restriction in Section 4.3. |
| Frequency | Continuous, for as long as Customer uses the Service. |
| Nature and purpose | See Section 4.2. |
| Retention | Term of the subscription plus the 30-day export period in Section 11, subject to the retention rules in the Privacy Policy. |
| Sub-processors | noliai.com/legal/sub-processors |
| Competent supervisory authority | The authority of the EU member state where the data exporter is established or, if it is not established in the EU, where its EU representative is established, or otherwise the Irish Data Protection Commission. |
Annex 2: Technical and organizational measures
- Encryption in transit. All connections to the Service, and between the Service and its Sub-processors, use TLS.
- Encryption at rest. Stored data is encrypted at the storage layer by Noli's hosting and database providers. Connected credentials, access tokens, and API keys are encrypted a second time at the application layer before they are stored.
- Access control. Every request to the Service is authenticated through Noli's identity provider. Access is scoped to the workspace and organization the user belongs to, and enforced by the database as well as the application. Noli staff access to production data is limited to named individuals and used only for support, security, and operations.
- Secrets management. Platform secrets are held in managed secret storage, not in code, and are rotated when a holder changes or a compromise is suspected. Customer AI agents never hold Noli's platform model keys.
- Agent guardrails. AI agents act only within the connections Customer has made and the scope Customer granted, and file outbound actions for Customer's approval unless Customer turns on an autopilot for that action.
- Tenant isolation. Each customer's workspace is logically separated. The Chief of Staff runs in a per-customer container.
- Logging and monitoring. Application and access logs are kept, error and security alerts are monitored, and browser security headers (including a content security policy) are applied.
- Backups and recovery. Databases are backed up on a schedule, backups are encrypted and stored separately from production, and restores are tested periodically.
- Vendor review. Sub-processors are reviewed before use and listed publicly; each is bound by a data processing agreement.
- Secure development. Changes go through code review and automated tests before deployment; dependencies are updated and reviewed for known vulnerabilities.
- Incident response. A documented process for detecting, containing, and notifying personal data breaches, with the timeline in Section 8.
- Personnel. Everyone with access to Customer Personal Data is bound by confidentiality and receives security guidance.
- Data minimization and retention. Prospect Data has automatic retention deadlines; call recording is off by default; data is deleted on the schedule in the Privacy Policy.
© 2026 Noli LLC. All rights reserved. Noli AI is a product offered by Noli LLC.