Data Processing Agreement

Last updated: July 5, 2026

Version: 2026-07-05

This Data Processing Agreement ("DPA") forms part of the agreement between Agile OCM Corp.("LaunchMap," the "Processor") and the customer identified in the applicable order or subscription ("Customer," the "Controller") for the use of the LaunchMap platform (the "Service"). It reflects the parties' agreement on the processing of personal data under the GDPR, the UK GDPR, and other applicable data protection laws. It applies from the date the Customer first accepts the Terms of Service or accesses the Service, whichever is earlier, and continues for as long as LaunchMap processes personal data on Customer's behalf. Where a signed enterprise DPA is required, contact privacy@launchmap.ai.

1. Roles of the Parties

With respect to personal data contained in Customer's plans, stakeholder assessments, uploaded documents, and user accounts ("Customer Personal Data"), the Customer is the Controller and LaunchMap is the Processor. LaunchMap processes Customer Personal Data only on documented instructions from the Customer, including as set out in these Terms, the Privacy Policy, and Customer's use of the Service's features.

LaunchMap acts as an independent Controller for limited data it processes for its own purposes, such as account administration, billing, security, and improving the Service; that processing is described in our Privacy Policy.

2. Subject Matter and Details of Processing

  • Subject matter: provision of the LaunchMap change management platform and its AI features.
  • Duration: the term of the subscription, plus the retention and deletion periods described in the Privacy Policy.
  • Nature and purpose: hosting, storage, and processing of Customer content to deliver the Service, including AI-assisted plan generation, recommendations, and chat.
  • Categories of data subjects: Customer's authorized users and the individuals referenced in Customer's plans and stakeholder data.
  • Categories of personal data: names, email addresses, roles, organization details, and any personal data Customer chooses to include in plans, comments, uploaded documents, or AI prompts.
  • Special categories: not intended. Customer should not upload special-category data unless strictly necessary and lawful.

3. LaunchMap's Obligations

  • Process Customer Personal Data only on the Customer's documented instructions.
  • Ensure personnel authorized to process the data are bound by confidentiality.
  • Implement appropriate technical and organizational security measures (Section 6).
  • Assist the Customer, taking into account the nature of processing, in responding to data subject requests and in meeting its security, breach-notification, and data protection impact assessment obligations.
  • At the Customer's choice, delete or return Customer Personal Data at the end of the engagement, except where retention is required by law.
  • Make available information necessary to demonstrate compliance and allow for reasonable audits, subject to confidentiality and security constraints.
  • Not use Customer content, including AI prompts and uploaded documents, to train LaunchMap's or any third party's AI models.

4. Sub-processors

The Customer authorizes LaunchMap to engage the sub-processors below to process Customer Personal Data. Each sub-processor is bound by a written agreement imposing data protection obligations no less protective than those in this DPA. LaunchMap remains responsible for its sub-processors' performance.

Sub-processorPurposeRegion
ClerkAuthentication and identity managementUnited States
ConvexApplication database and real-time syncUnited States
StripeSubscription billing and paymentsUnited States
AnthropicAI model inference (Claude)United States
OpenAIAI model inference (GPT), alternative providerUnited States
OpenRouter (incl. DeepSeek)AI model routing and inferenceUnited States and downstream model providers
LangFuseAI observability and tracingUnited States
PostHogProduct analytics (consent-gated)United States
GlitchTipError and performance monitoringUnited States
ResendTransactional and notification emailUnited States
VercelApplication hosting and content deliveryUnited States and global edge network

LaunchMap will give the Customer notice of any intended addition or replacement of a sub-processor and a reasonable opportunity to object on legitimate data protection grounds.

5. International Transfers

Where LaunchMap transfers Customer Personal Data from the EEA, the UK, or Switzerland to a country that has not received an adequacy decision, the transfer is governed by the European Commission's Standard Contractual Clauses and, where applicable, the UK International Data Transfer Addendum, which are incorporated into this DPA by reference. The applicable module is Module Two (Controller to Processor). For the SCC annexes: the data exporter is the Customer (as Controller) and the data importer is Agile OCM Corp., 90 Stadium Road, Unit 103, Toronto, Ontario M5V 3W5, Canada (as Processor); the description of processing is set out in Section 2 of this DPA, and the technical and organizational measures in Section 6.

6. Security Measures

LaunchMap maintains appropriate technical and organizational measures designed to protect Customer Personal Data, including:

  • Encryption of data in transit (TLS) and at rest
  • Delegated authentication and session management through a dedicated identity provider
  • Role-based access controls and organization-level data isolation
  • Plan-level collaborator permissions and least-privilege internal access
  • Audit logging of security-relevant actions
  • Automated redaction and minimization of data sent to AI sub-processors
  • Ongoing security review of systems and dependencies, and secure software development practices

7. Personal Data Breach

LaunchMap will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to help the Customer meet its own notification obligations. LaunchMap will take reasonable steps to mitigate the effects of and to minimize any damage resulting from the breach.

8. Assistance and Data Subject Requests

Taking into account the nature of the processing, LaunchMap will assist the Customer by appropriate technical and organizational measures, insofar as possible, to respond to requests from data subjects exercising their rights, and to fulfil the Customer's obligations relating to security, breach notification, data protection impact assessments, and prior consultation. If LaunchMap receives a request directly from a data subject relating to Customer Personal Data, it will refer the request to the Customer.

9. Return and Deletion

On termination of the Service, and at the Customer's choice, LaunchMap will return or delete Customer Personal Data in accordance with the retention and deletion timelines described in the Privacy Policy, except to the extent retention is required by applicable law.

10. Contact

For DPA requests, sub-processor notifications, or data protection questions, contact us at privacy@launchmap.ai or dpo@launchmap.ai.