Data Processing Agreement
Last updated: 23 June 2026 · Dogma Group Limited (trading as goatelevate.com)
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Dogma Group Limited (company number 12096627, registered office 483 Green Lanes, London, N13 4BS), trading as goatelevate.com ("Processor", "GOAT Elevate", "we"), and the customer ("Controller", "you"). It governs GOAT Elevate's processing of personal data contained in the content and data sources you make available to the Service, and is designed to meet Article 28 of the UK GDPR and the EU GDPR. Where this DPA conflicts with the Terms, this DPA prevails for data-protection matters.
1. Definitions
"Personal Data", "Processing", "Controller", "Processor", "Sub-processor", "Data Subject", and "Personal Data Breach" have the meanings given in the UK/EU GDPR. "Customer Personal Data" means personal data contained in the content and data sources you make available to the Service and that GOAT Elevate processes on your behalf. "Data Protection Legislation" means the UK GDPR, the EU GDPR, the Data Protection Act 2018, and associated ICO guidance.
2. Roles
You are the Controller (or a processor acting for your own clients, for example where you are an agency using the white-label portal) and determine the purposes and means of processing. GOAT Elevate is the Processor (or Sub-processor) and processes Customer Personal Data only to provide the Service.
3. GOAT Elevate's obligations
GOAT Elevate will:
- Process Customer Personal Data only on your documented instructions (including the Terms, this DPA, and your configuration of the Service — in particular what you connect, upload and approve for publication), except where required by law. The Service ingests, analyses, optimises, publishes and monitors the content you make available; it does not use Customer Personal Data to train AI models, and our AI sub-processors are engaged under terms that prohibit training on customer inputs and outputs.
- Ensure persons authorised to process the data are bound by confidentiality.
- Implement the technical and organisational measures in Schedule 3, providing a level of security appropriate to the risk, including logical isolation between customers and, for agencies, between their clients.
- Assist you, taking into account the nature of processing, in responding to Data Subject requests and in meeting your obligations on security, breach notification, and data protection impact assessments (Articles 32 to 36 UK GDPR).
- Notify you without undue delay and within 24 hours of becoming aware of a Personal Data Breach affecting Customer Personal Data.
- At your choice, delete or return Customer Personal Data at the end of the Service, and delete existing copies unless legally required to retain them. Content already published to public surfaces will be unpublished on request, subject to caching by third parties and AI engines outside our control.
- Make available information necessary to demonstrate compliance and allow for and contribute to audits, on reasonable notice and subject to confidentiality.
- Inform you if, in its opinion, an instruction infringes the Data Protection Legislation.
4. Sub-processors
You provide general authorisation for GOAT Elevate to engage the Sub-processors listed in Schedule 2. GOAT Elevate will impose data-protection terms on each Sub-processor equivalent to those in this DPA, and remains fully liable for their performance. GOAT Elevate will give you not less than 14 days' notice of any new Sub-processor; you may object on reasonable data-protection grounds, in which case the parties will work in good faith to resolve it, failing which the Sub-processor will not be appointed.
5. International transfers
5.1 Hosting and storage. The Service runs within Microsoft Azure UK-region infrastructure; Customer Personal Data at rest remains within the United Kingdom. Approved content published to public surfaces may be delivered globally through a content-delivery network so that it can be served to human visitors and AI engines worldwide.
5.2 AI inference. To analyse and optimise content for answer engines, the Service transmits relevant content to its AI sub-processors. Where an AI sub-processor processes data outside the UK or EEA (for example, a US-based large language model provider), this is a Restricted Transfer.
5.3 Transfer mechanism. Any such transfer is covered by the UK International Data Transfer Addendum and/or the EU Standard Contractual Clauses incorporated into the relevant sub-processor's data processing terms, which GOAT Elevate has entered into on a back-to-back basis. Where required, we carry out a transfer risk assessment and apply supplementary technical and organisational measures; copies of the relevant safeguards are available on request, subject to confidentiality and commercial restrictions.
5.4 In-region alternative. Where you require AI inference to remain within the UK/EU, the Service can be configured to route inference through a UK/EU-region provider, which eliminates the transfer outside the UK/EEA.
5.5 Monitoring. To monitor how AI engines describe your brand, the Service sends topic and brand prompts to third-party AI engines and reads their public responses. These prompts are constructed from non-personal topic and brand terms and are not intended to contain Customer Personal Data.
6. Liability and term
Each party's liability under this DPA is subject to the limitations in the Terms. This DPA continues for as long as GOAT Elevate processes Customer Personal Data. It is governed by the laws of England and Wales.
Schedule 1 — Details of processing
- Subject matter: ingesting, analysing, optimising, publishing and monitoring the content and data sources you make available to the Service for answer-engine visibility.
- Duration: the term of the subscription and for so long as Customer Personal Data is processed in connection with the Service.
- Nature of processing: reading and ingesting content from connected CMS and uploaded files; binding live data tokens from connected systems (such as CRM, billing or inventory) into content blocks; AI analysis and rewriting for AEO and GEO; human-in-the-loop review; publishing approved content to a curated site and a structured knowledge layer; and monitoring AI-engine outputs.
- Purpose: to provide the Service to you.
- Types of personal data: may include names; business and personal contact details; job titles; the identities, quotes and images of individuals featured in case studies, testimonials, customer interviews and similar content; and any personal data contained in connected data sources that you bind into content via live data tokens. Special Category Data is processed only where your content or sources contain it.
- Categories of data subjects: your employees, customers, prospects, partners, interviewees and any other individuals whose personal data appears in the content or data sources you make available.
- Authorised persons (Controller): your designated workspace administrator(s) and approvers.
Schedule 2 — Authorised Sub-processors
Sub-processor | Purpose | Location & safeguards |
|---|---|---|
Microsoft Corporation (Azure) | Platform and hosting | UK data centres; data at rest remains in the UK |
Content-delivery / edge provider | Global delivery of published public content | Available on request |
AI sub-processors for content generation (OpenAI, Anthropic, Google) | AI analysis and optimisation (AEO / GEO) | UK IDTA / EU SCCs via the provider's DPA; no model training |
AI engines monitored (OpenAI, Anthropic, Perplexity, Google) | Citation and visibility monitoring (reading public outputs) | Public outputs read; non-personal prompts only |
Dogma International Pvt. Ltd | Technical delivery and support | Nepal; access via UK-based VDI only — no data leaves the UK |
Schedule 3 — Technical and organisational security measures
Control area | Measures in place |
|---|---|
Identity & access | Zero Trust architecture; mandatory multi-factor authentication; role-based access control; access reviewed and revoked promptly on role change or departure |
Tenant isolation | Each customer workspace logically isolated; agency clients separated within the white-label portal so no client can access another's data |
Publication control | No content published without approval through the human-in-the-loop Review stage; full audit trail of changes and approvals; ability to unpublish on request |
Encryption | AES-256 at rest; TLS 1.2 or higher in transit |
Device management | All access devices enrolled in Microsoft Intune: full-disk encryption, compliance policies, remote wipe, conditional access |
Data loss prevention | Microsoft Purview DLP policies; alerts on anomalous data transfer |
Threat detection | Microsoft Defender for Endpoint; continuous security monitoring; automated incident alerts |
Overseas personnel | Any overseas support personnel access only via UK-based Azure Virtual Desktop Infrastructure; only screen rendering reaches the endpoint; no data stored outside the UK |
Personnel & training | Confidentiality agreements before commencing; data protection training on induction and annually; background checks per local law |
Audits & testing | Internal security reviews quarterly; external penetration testing at least annually |
Backup & continuity | Regular backups within UK Azure infrastructure; recovery procedures tested periodically |
Incident response | Documented procedure; suspected breaches escalated within two hours; Controller notified within 24 hours |
GOAT Elevate will maintain measures of at least equivalent effectiveness throughout the term, and may update them provided the overall level of protection is not reduced.
Contact: enquiries@goatelevate.com · Dogma Group Limited (trading as goatelevate.com), 483 Green Lanes, London, N13 4BS
