Data Processing Agreement (DPA)
Effective date: September 18, 2026.
Last updated: October 8, 2026.
This Data Processing Agreement is part of the Terms of Service of AskRoby and regulates the processing of Personal Data that José Julio Córdova Jaramillo, a natural person with RUC 1707017693001, operating commercially under the brand AskRoby, hereinafter “AskRoby”, “Processor” or “we”, carries out on behalf of the Client when the Client acts as Data Controller.
For the purposes of this Data Processing Agreement, the “Client” or “Controller” may be a natural or legal person who uses the Services and determines the purposes and essential elements of the processing of Personal Data incorporated into AskRoby.
AskRoby can be used by individuals, professionals, companies and other organizations. This Data Processing Agreement applies only when AskRoby processes Personal Data on behalf of the Customer as Processor. A natural person who uses AskRoby solely to organize their own documents does not automatically become a Controller of third-party data merely by doing so.
If the Client is an organization, the person accepting this Data Processing Agreement on its behalf represents that it has sufficient authority to bind it. If the Client is a natural person acting on his own behalf as Controller, he accepts this Data Processing Agreement on his own behalf. Subsequently invited users do not individually enter into a new Data Processing Agreement simply by accessing an Account or workspace.
Electronic acceptance of this Data Processing Agreement will be recorded by AskRoby together with the version of the document, its content or archived reference, hash, language, Account and, where applicable, organization, date and time of acceptance and other evidence reasonably necessary to substantiate the conclusion and content of the agreement.
When AskRoby itself determines the purposes and means of processing, for example with respect to Account data, billing, security, analytics or business management, such processing will be governed by the Privacy Policy and applicable law.
1. Definitions
For the purposes of this DPA:
“Personal Data” means any information that identifies or allows the identification, directly or indirectly, of a natural person, in accordance with applicable legislation.
“Customer Personal Data” means Personal Data contained in documents, files, images, text or other content that Customer or its authorized users provide to AskRoby and that AskRoby processes on Customer's behalf.
“Processing” includes any operation performed on Personal Data, including receipt, storage, conversion, automated reading, extraction, indexing, generation of search representations, retrieval, consultation, transmission to authorized subprocessors and deletion.
“Data Protection Laws” means the Organic Law on the Protection of Personal Data of Ecuador, its Regulations and applicable regulations issued by the Superintendency of Personal Data Protection and, when applicable due to the Client, the interested parties or the treatment, other mandatory data protection regulations, including the GDPR or UK GDPR.
Other terms related to data protection will have the meaning established by the applicable Data Protection Laws.
2. Roles of the Parties
Regarding the Client's Personal Data processed to provide the Services:
- The Client acts as Data Controller.
- AskRoby acts as Data Processor.
- The Client determines what information it provides to AskRoby, the purposes for which it uses the Services and who is authorized to use them.
- AskRoby processes Customer's Personal Data solely to provide, maintain, protect and correct the Services (corrective maintenance and verification of the contracted service) in accordance with Customer's documented instructions and this DPA, without using that data as material for development, analysis or training.
AskRoby does not acquire ownership of the Client's Personal Data by processing it.
3. Client Instructions
The Client instructs AskRoby to process the Client's Personal Data to the extent necessary to:
- receive and process documents and files provided by the Client;
- convert documents into representations usable by the Services;
- generate and preserve optimized page images where appropriate;
- extract, digitize, organize and index text and other information;
- generate embeddings or other representations necessary for search and retrieval functions;
- answer queries and execute functions assisted by artificial intelligence;
- generate metadata and derived results necessary to provide the Services;
- perform integrity, recovery, security and operational continuity checks;
- provide support requested by the Client;
- delete information in accordance with the Client's instructions, this DPA and the life cycle of the Service.
AskRoby will not use the Client's Personal Data for purposes other than those stated in this DPA and the Terms of Service.
AskRoby does not use the Client's documents to train or fine-tune its own models.
AI requests that contain Customer information are configured to require that the routing provider not collect the data for its own purposes and use routes that support zero data retention requirements set for such requests.
4. Client Obligations
The Client declares and guarantees that:
- you have a valid legal basis to collect, use and provide AskRoby with the Personal Data that you incorporate into the Services;
- has provided the interested parties with the notices and other information required by applicable legislation;
- your instructions to AskRoby are lawful;
- you have the right to permit processing by AskRoby and authorized sub-processors under this DPA;
- is responsible for determining whether certain Personal Data, including sensitive data or special categories of data, can be lawfully incorporated into the Service;
- will not instruct AskRoby to carry out treatments that violate Data Protection Laws.
AskRoby will inform the Customer when it reasonably believes that an instruction violates applicable Data Protection Laws, unless a regulation prevents doing so.
5. Obligations of AskRoby
AskRoby:
-
process the Client's Personal Data only in accordance with the Client's documented instructions, this DPA and applicable Data Protection Laws;
-
not process the Client's Personal Data for purposes other than those stated in this DPA and the Terms of Service;
-
not disclose, assign or transfer the Client's Personal Data to other persons, not even for retention, except (i) to authorized subprocessors under Section 8 and only to the extent necessary to provide the Services, (ii) on the Client's instruction, or (iii) where a competent authority requires it, in which case it will inform the Client unless the law prevents it;
-
ensure that persons authorized to process Personal Data are subject to appropriate confidentiality obligations;
-
apply technical and organizational measures appropriate to the risk;
-
limit human access to the Client's Personal Data to authorized or necessary situations in accordance with the Client's instructions, the security of the Service or an applicable legal obligation;
-
will use subprocessors only in accordance with this DPA;
-
will reasonably assist the Client, taking into account the nature of the processing and the information available, in responding to requests for the rights of the interested parties, and cooperate with the Client within two (2) days of the Client's request;
-
reasonably assist the Client with its obligations related to security, security incidents, impact assessments and regulatory inquiries where applicable;
-
will notify the Client as soon as possible and at the latest within two (2) days from when it has knowledge of a Personal Data breach affecting Personal Data processed on behalf of the Client;
-
maintain information reasonably necessary to demonstrate compliance with its obligations as Processor, including a record of the processing activities it carries out on behalf of the Client;
-
will delete the Customer's Personal Data in accordance with Section 10 when the processing ends, unless there is an applicable legal retention obligation.
6. Security
AskRoby applies technical and organizational measures appropriate to the risk, including:
- encryption of data in transit using HTTPS/TLS;
- encryption at rest provided by your infrastructure providers;
- password storage using hashing mechanisms managed by your authentication provider;
- authentication and authorization controls;
- security and access control policies applied at the database level;
- mandatory multi-factor authentication in accordance with the rules of the Service;
- logical separation between accounts and organizations;
- restrictions on privileged access;
- operational and error logs;
- periodic automated checks aimed at checking isolation between accounts;
- separate recovery copies from main storage;
- periodic verifications of critical recovery and continuity processes.
AskRoby's ordinary support and administration tools are not designed to display the content of Customer documents.
However, people with privileged access to the infrastructure could technically access stored information when necessary. AskRoby does not use such access to read Customer documents during the ordinary operation of the Service.
When the Client requests in writing a technical intervention that requires access to the content, such access may be made only for the authorized purpose and for the time reasonably necessary.
AskRoby may modify its technical and organizational measures to adapt them to technological, operational or regulatory changes, provided that it does not substantially decrease the general level of protection of the Customer's Personal Data.
7. Artificial Intelligence
Certain features of AskRoby require automated processing using artificial intelligence providers.
Depending on the function used, they can be sent to authorized providers:
-
page images;
-
fragments or blocks of text;
-
document text necessary for structured extraction;
-
user queries;
-
retrieved fragments relevant to answering a query;
-
text intended for the generation of embeddings.
AskRoby configures requests containing Customer content to apply collection and retention restrictions consistent with the privacy architecture implemented for those requests.
AskRoby does not sell Customer Personal Data and does not use the content of Customer documents to train its own models.
8. Subprocessors
Customer grants AskRoby a general authorization to use subprocessors where reasonably necessary to provide the Services.
AskRoby will disclose the Client's Personal Data to a subprocessor only to the extent necessary for that subprocessor to perform the function entrusted to it. The subprocessors listed in Section 8.1 when this DPA is accepted are authorized in writing by the Client.
AskRoby contracts Subprocessors that offer privacy, confidentiality, and security obligations under their terms of service, and will remain responsible for its own obligations under this DPA to the extent required by applicable law.
AskRoby may replace or incorporate sub-processors. When a change is material to the processing of Customer Personal Data, AskRoby will inform Customer by email, notice within the Service or other reasonable means.
The Client may raise a reasoned objection specifically related to the protection of Personal Data. The parties will try to resolve it in good faith. If resolution is not reasonably possible, Customer may stop using the affected portion of the Services or terminate the Services in accordance with the Terms of Service.
8.1 Current Subprocessors
The subprocessor directory provides each provider's function, processing locations and verification status.
| Supplier | Function related to treatment | Data you can process |
|---|---|---|
| Supabase | Authentication, Database and Primary Storage | Account data, metadata, document content, page images, extracted text and operational data |
| Vercel | Hosting, server functions, application delivery and execution of document conversion environments | Account data, application requests and, where necessary, content processed temporarily by functions or Vercel Sandbox |
| Cloudflare R2 | Separate storage for recovery and continuity | File copies and representations stored by AskRoby |
| OpenRouter | Artificial Intelligence Request Gateway and Routing | Images, text, queries and snippets required for AI functions |
| Underlying provider of AI models for certain reading, extraction and processing functions | Images and/or text necessary for the requested operation | |
| OpenAI | Embedding generation and other AI functions used by AskRoby where applicable | Text fragments required for the operation |
| Microsoft (Azure) | Underlying AI infrastructure serving embeddings through OpenRouter | Text fragments required for the operation |
| Resend | Transactional email | Email addresses, information needed for notifications, and certain metadata displayed in transactional messages |
| Evolution API (WhatsApp) | Operational and security notices sent to the phone number of the person responsible for AskRoby | Metadata of the notice: what happened, amounts, deadlines and internal links. The name, email or telephone number of a Client are not sent by this means, they travel only by email |
| GitHub Actions | Technical automations and backup processes | Content temporarily processed by jobs necessary to generate or verify recovery copies |
Supabase
Function related to treatmentAuthentication, Database and Primary Storage
Data you can processAccount data, metadata, document content, page images, extracted text and operational data
Vercel
Function related to treatmentHosting, server functions, application delivery and execution of document conversion environments
Data you can processAccount data, application requests and, where necessary, content processed temporarily by functions or Vercel Sandbox
Cloudflare R2
Function related to treatmentSeparate storage for recovery and continuity
Data you can processFile copies and representations stored by AskRoby
OpenRouter
Function related to treatmentArtificial Intelligence Request Gateway and Routing
Data you can processImages, text, queries and snippets required for AI functions
Function related to treatmentUnderlying provider of AI models for certain reading, extraction and processing functions
Data you can processImages and/or text necessary for the requested operation
OpenAI
Function related to treatmentEmbedding generation and other AI functions used by AskRoby where applicable
Data you can processText fragments required for the operation
Microsoft (Azure)
Function related to treatmentUnderlying AI infrastructure serving embeddings through OpenRouter
Data you can processText fragments required for the operation
Resend
Function related to treatmentTransactional email
Data you can processEmail addresses, information needed for notifications, and certain metadata displayed in transactional messages
Evolution API (WhatsApp)
Function related to treatmentOperational and security notices sent to the phone number of the person responsible for AskRoby
Data you can processMetadata of the notice: what happened, amounts, deadlines and internal links. The name, email or telephone number of a Client are not sent by this means, they travel only by email
GitHub Actions
Function related to treatmentTechnical automations and backup processes
Data you can processContent temporarily processed by jobs necessary to generate or verify recovery copies
| Push notification services from Apple, Google and/or Mozilla | Notification delivery to registered devices or browsers | Notification identifiers or endpoints and technical content necessary to deliver the notification |
The notices sent by WhatsApp to the person responsible for AskRoby are written so that they do not contain identifying data of the Client: they indicate what happened and where to consult it, and the details are sent by email.
Treatment locations depend on each provider's infrastructure and may include the United States and other jurisdictions in which such providers or their subprocessors legally operate.
8.2 Providers that do not necessarily act as subprocessors of content
AskRoby uses Polar Software, Inc. as Merchant of Record for certain merchant transactions.
Polar processes billing, payment, tax, fraud and transaction information under its own terms and legal obligations. Polar does not receive document content from Customer to provide AskRoby's document functions and is not listed above as a subprocessor of document content under this DPA.
Treatment related to payments is further described in the Privacy Policy and Terms of Service.
9. International Transfers
The Customer acknowledges that the provision of the Services may involve processing of Personal Data in the United States and other jurisdictions in which AskRoby or its authorized subprocessors operate.
Where an international transfer of Personal Data is subject to specific requirements of applicable Data Protection Laws, AskRoby will use the legal mechanisms required by those laws.
For transfers to the United States, AskRoby relies on the data processing agreements of Supabase, OpenRouter, Resend, and Cloudflare, which form part of their terms of service and incorporate the European Commission’s standard contractual clauses, and on that of GitHub, which relies on its EU-US Data Privacy Framework certification and, as the case may be, on those clauses. For other providers, their own terms and privacy policies apply.
For treatments subject to Ecuadorian legislation, AskRoby will carry out international transfers or communications in accordance with the LOPDP, its Regulations and the current regulations issued by the Superintendency of Personal Data Protection.
When the GDPR or UK GDPR is applicable, the parties will use, when legally necessary, adequacy decisions, standard contractual clauses, addendums or other mechanisms recognized by the corresponding legislation.
Nothing in this Section should be construed as a statement that any specific mechanism is applicable to any transfer or to any Client regardless of jurisdiction.
10. Retention, Deletion and Data Life Cycle
10.1 Original file
The original file that the Client uploads to AskRoby is temporarily retained to allow processing and, where necessary, automatic recovery of pages that could not be processed correctly.
AskRoby tries to delete said original file within a maximum period of approximately two days once it is incorporated into the processing system.
Once the original file is deleted, AskRoby continues to provide the Service using the necessary in-memory representations, which may include optimized page images, extracted text, embeddings, indexes, metadata and derived results.
10.2 Active memories
As long as a memory remains active, AskRoby will retain data and representations reasonably necessary to provide the query, search, retrieval, display and processing functions associated with that memory.
AskRoby is not offered as a permanent archiving service or as a substitute for the Client's original documents.
The Client is responsible for retaining its own originals and any copies it needs to retain for business, legal, regulatory, accounting or archival reasons.
10.3 Deleting a memory
When the Client deletes a memory, it immediately enters the AskRoby delete cycle.
During the recovery period displayed by the Service, currently up to approximately two days, memory may be restored using the functions that AskRoby makes available to the Customer.
Once this period has ended and the permanent deletion has been executed, the memory is no longer available in the Service and cannot be recovered through the normal functions of AskRoby.
AskRoby-controlled copies in separate recovery storage are typically deleted by the daily purge process, which waits one day after first detecting the deletion; this usually means within three days after the active system is permanently deleted.
Recovery copies exist exclusively for operational continuity, failover, and infrastructure security. They do not constitute an archive, an extended trash bin or an individual recovery service for deleted documents.
Once the hard delete is performed, AskRoby has no obligation to search, rebuild or restore deleted memory for Customer using infrastructure recovery copies.
Certain infrastructure providers may maintain residual copies during technical, regulatory or recovery periods controlled by such providers. Such copies will remain subject to applicable security, confidentiality and deletion obligations.
10.4 Termination of Services
Upon completion of the provision of the Services, the Client instructs AskRoby to delete the Personal Data processed on its own behalf, unless:
- an applicable legal obligation requires its conservation; or
- before termination the parties expressly agree in writing to a different instruction permitted by applicable law.
AskRoby will destroy all copies of the Client's Personal Data existing under its control, except those that a legal obligation requires it to retain, and will execute the deletion within the time required by applicable Data Protection Laws and will retain reasonable evidence of its execution where appropriate.
Before terminating the Service, the Client is responsible for downloading any information they wish to retain. The bulk download in Settings provides a ZIP of retained page images as PDF files and readable text, without original uploads, for the personal space and workspaces the Client owns. The download page offers individual PDFs and ZIP packages of up to 25 MB each, including ZIP overhead. Packages are grouped by size, prepared only on request, and downloaded one at a time. Larger Memories are divided into PDF parts by page range; no retained pages are silently removed or reduced in quality. A single page that cannot fit within the limit is identified explicitly.
AskRoby is not obligated to maintain a permanent export or archive service after termination.
Where an applicable Data Protection Law compulsorily grants the Customer the right to choose between return and deletion, AskRoby will comply with such obligation to the extent and manner required by such legislation.
10.6 Non-payment of a Subscription
When a renewal charge cannot be completed, the Client's Personal Data contained in its memories is kept for up to forty-five days from the first failed charge. From the seventh day onwards, access is suspended, without this implying elimination. Once the payment is regularized within that period, the treatment continues without loss of information. After the period without regularization, AskRoby carries out the deletion in accordance with this Section.
11. Requests from Interested Parties
Taking into account the nature of the processing, AskRoby will provide reasonable assistance to the Client in responding to requests regarding the exercise of data subjects' rights when the corresponding Personal Data is processed by AskRoby on behalf of the Client, and will do so within two (2) days of the Client's request.
If AskRoby receives directly from an interested party a request clearly related to Personal Data controlled by the Customer, AskRoby may refer the interested party to the Customer or transfer the request to the Customer, unless otherwise required by applicable law.
The Client will remain responsible for determining whether to comply with the request and for providing the corresponding instructions.
12. Incidents and Personal Data Breaches
AskRoby will maintain reasonable procedures to identify, investigate and respond to incidents that may affect the confidentiality, integrity or availability of Customer Personal Data.
When AskRoby has knowledge of a Personal Data breach that affects information processed on behalf of the Client, it will notify the Client as soon as possible and at the latest within two (2) days from when it has knowledge of the breach.
To the extent information is available, AskRoby will endeavor to provide details reasonably necessary to enable Customer to evaluate and comply with its own notification obligations.
Reporting an incident does not in itself constitute acknowledgment of liability on the part of AskRoby.
13. Audits and Evidence of Compliance
AskRoby will make available to the Client information reasonably necessary to demonstrate compliance with its obligations as Processor.
The Client may, at any time, review AskRoby's records and processing procedures relating to its Personal Data, itself or through an auditor, including an auditor accredited by the data protection authority, subject to the conditions of this Section.
Audit requests must:
- be reasonably related to the processing carried out by AskRoby;
- be carried out with reasonable notice, except for serious incidents or legal obligation;
- respect the confidentiality, security and rights of other Clients;
- avoid disproportionate interference with the operation of the Services.
When the documentary information available is sufficient to demonstrate compliance, AskRoby may use it as the first way to address the request.
In-person or technically intrusive audits will be limited to cases in which they are reasonably necessary or required by competent authority.
The Client will bear the reasonable costs of extraordinary audits requested exclusively by the Client, except when the audit reveals a material non-compliance of AskRoby or otherwise provided by law.
Nothing in this Section limits audits, inspections or requests of the data protection authority or of an auditor accredited by it: AskRoby will allow and cooperate with them without requiring advance notice or conditions that prevent them, and their cost will not be passed on to the Client.
14. Confidentiality and Human Access
AskRoby does not access the content of Customer documents as part of the ordinary human operation of the Service.
AskRoby's automated systems necessarily process such content to provide the contracted functions.
Technically privileged human access will be limited to authorized persons and may be used when necessary to:
- comply with express instructions of the Client;
- investigate security incidents;
- resolve technical problems that cannot reasonably be addressed in any other way;
- fulfill a valid legal obligation.
Where there is a separate agreement with a Customer that expressly authorizes additional human access for testing, implementation, support or diagnosis, such agreement shall prevail over that specific authorization.
15. Sensitive Data or Special Categories
AskRoby does not require Customer to upload special or sensitive categories of Personal Data to use the Service.
If the Client decides to incorporate information of this nature, it will be responsible for previously determining that it has a valid legal basis and that the processing through AskRoby is appropriate and lawful.
AskRoby will apply the general security measures described in this DPA, without the unilateral upload of particularly sensitive information by the Client implying the acceptance of additional obligations not expressly agreed.
16. Responsibility
The liability of the parties arising from this DPA is subject to the limitation of liability regime established in the Terms of Service.
For paid Services, the general contractual limit agreed in the Terms is calculated by reference to the amounts actually paid or payable by the Customer for the Services during the twelve months immediately preceding the event giving rise to the claim, including unrefunded amounts corresponding to subscriptions, recharges or other Services, and excluding taxes and refunded amounts.
Where the Services have been provided entirely free of charge, including a free trial or pilot, the general contractual limit will be USD 10.
Nothing in this DPA shall limit any liability to the extent that such liability cannot be legally limited or excluded.
Nothing in this Section limits the rights that Data Protection Laws directly grant to data subjects or the powers of data protection authorities.
17. Validity
This DPA comes into force when it is validly accepted by a person authorized to act on behalf of the Client and will remain in force for as long as AskRoby processes Personal Data on behalf of the Client.
Obligations that by their nature should survive termination, including confidentiality, deletion, protection of Personal Data and liability, will remain in effect for the relevant period.
18. Relationship with other Documents
This DPA is part of the AskRoby Terms of Service.
In the event of a conflict between this DPA and the Terms of Service regarding the processing of Personal Data on behalf of the Client, this DPA shall prevail to the extent of the conflict.
The Privacy Policy regulates the treatments in which AskRoby acts as Controller and provides additional information about the general privacy practices of the Service.
Where AskRoby and a Customer have entered into a separate and signed agreement setting forth specific terms for such Customer, that agreement shall prevail only with respect to the specific provisions it expressly modifies.
19. Applicable Law and Jurisdiction
This DPA is governed by the laws of the Republic of Ecuador.
Except when a mandatory norm provides otherwise, the parties submit to the competent judges of the Metropolitan District of Quito, province of Pichincha, Ecuador.
Nothing in this clause limits the application of mandatory data protection rules that are applicable to the Client, the interested parties or the processing.
20. Contact
For questions related to this DPA, data protection, privacy, security or legal matters related to the Service:
José Julio Córdova Jaramillo.
RUC: 1707017693001.
Operating commercially under the brand name: AskRoby.
Email: support@askroby.io.
Address: La Primavera 2, Cumbayá, Metropolitan District of Quito, Pichincha, Ecuador.
Telephone: +593 99 061 2230.
AskRoby has not currently appointed a Personal Data Protection Officer. Queries related to data protection can be directed to the email address indicated above.
Annex A — Processing Details
A.1 Purpose
Provision of AskRoby Services, including receipt, processing, digitization, storage, organization, search, retrieval, consultation and artificial intelligence-assisted analysis of documents and other content provided by the Client.
A.2 Nature of Processing
Processing may include:
- reception and temporary storage of the original file;
- conversion of documents to formats usable by the Service;
- generation of page images;
- OCR and text extraction;
- automated structuring and classification;
- generation of embeddings and indexes;
- storage and retrieval;
- response to queries;
- processing using artificial intelligence models;
- infrastructure backup, verification and recovery;
- elimination.
A.3 Purpose
Allow the Client to create document memories, consult information contained in their documents, find relevant sources and pages, extract structured information and use the other functions available in AskRoby.
A.4 Duration
During the period in which the Client uses the Services and, thereafter, for the time technically necessary to execute the deletion processes established in this DPA and comply with applicable legal obligations.
A.5 Categories of Personal Data
Personal Data depends on the content that the Client chooses to provide and may include:
- names and other identifiers;
- contact information;
- contractual data;
- employment or professional data;
- commercial information;
- financial data contained in documents;
- tax identifiers;
- signatures;
- information contained in photographs, scanned documents or digital files;
- any other category of Personal Data incorporated by the Client.
Customer controls the content it provides to AskRoby.
A.6 Categories of Interested Parties
They may include:
- authorized users of the Client;
- employees;
- workers;
- contractors;
- customers;
- suppliers;
- lessors or tenants;
- representatives;
- partners or shareholders;
- persons mentioned in contracts, communications or documents;
- other third parties whose Personal Data appears in the content provided by the Client.
A.7 Frequency
The treatment is carried out continuously or according to the instructions and use of the Service by the Client.
A.8 Disposal Instruction
Unless otherwise validly agreed upon written instructions or an applicable legal obligation, the Customer instructs AskRoby to delete the Personal Data upon completion of processing in accordance with Section 10 of this DPA.
