Second Opinion for Sales · Pansophy AI Inc. · Last Updated: June 24, 2026
This Data Processing Agreement ("DPA") forms part of the agreement between Pansophy AI Inc. ("Pansophy AI," "Processor") and the customer that subscribes to or uses Second Opinion for Sales (the "Customer," "Controller") (together, the "Parties") for the provision of Second Opinion for Sales (the "Service"). It governs the processing of personal data that the Customer submits to the Service. It takes effect on the date the Customer accepts it or first uses the Service, whichever is earlier. Where it conflicts with the End User License Agreement or Terms of Service on the subject of personal data processing, this DPA controls.
1. Definitions
Terms not defined here have the meaning given in applicable Data Protection Law.
"Applicable Data Protection Law" means all data protection and privacy laws applicable to the processing of personal data under this DPA, which may include the EU General Data Protection Regulation (GDPR), the UK GDPR, and the California Consumer Privacy Act as amended (CCPA).
"Controller," "Processor," "Data Subject," "Personal Data," "Processing," and "Subprocessor" have the meanings given in Applicable Data Protection Law. Where the CCPA applies, "Controller" corresponds to "Business" and "Processor" corresponds to "Service Provider."
"Customer Personal Data" means personal data contained in content the Customer submits to the Service for analysis.
"Service" means Second Opinion for Sales as described in its documentation.
2. Roles of the Parties
For Customer Personal Data submitted to the Service for analysis, the Customer is the Controller and Pansophy AI is the Processor. Pansophy AI processes Customer Personal Data only on the Customer's documented instructions, which are constituted by this DPA, the Service documentation, and the Customer's use of the Service.
For account, identity, subscription, and billing data, Pansophy AI may act as a Controller in its own right for the purposes of operating, securing, and billing the Service, as described in its Privacy Policy.
3. Scope and Details of Processing
The subject matter, duration, nature and purpose of processing, types of personal data, and categories of data subjects are set out in Annex A.
4. Processor Obligations
Pansophy AI shall:
Process on instructions. Process Customer Personal Data only on the Customer's documented instructions, including with regard to transfers, unless required to act otherwise by law, in which case Pansophy AI shall inform the Customer of that legal requirement before processing, unless prohibited from doing so by law.
Confidentiality. Ensure that persons authorized to process Customer Personal Data are bound by appropriate obligations of confidentiality.
Security. Implement the technical and organizational measures set out in Annex C, appropriate to the risk, in accordance with Article 32 of the GDPR or its equivalent.
Subprocessors. Engage Subprocessors only in accordance with Section 5.
Data subject requests. Taking into account the nature of the processing, assist the Customer by appropriate technical and organizational measures, insofar as possible, in responding to requests from data subjects exercising their rights. Where a data subject contacts Pansophy AI directly regarding Customer Personal Data, Pansophy AI shall, where permitted, refer them to the Customer.
Assistance. Assist the Customer in ensuring compliance with its obligations regarding security of processing, notification of personal data breaches, data protection impact assessments, and prior consultation, taking into account the nature of processing and the information available to Pansophy AI.
Breach notification. Notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and provide the information reasonably available to it to assist the Customer in meeting its own notification obligations.
Deletion or return. At the Customer's choice, delete or return Customer Personal Data at the end of the provision of the Service, and delete existing copies unless retention is required by law. Because submitted content is discarded at session close and is not written to persistent storage, content submitted to the Service is not retained beyond the active session in the ordinary course.
Audits and information. Make available to the Customer information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, subject to reasonable notice, confidentiality, and frequency limits, and conducted so as not to disrupt the Service or compromise the security of other customers.
5. Subprocessors
The Customer authorizes Pansophy AI to engage the Subprocessors listed in Annex B. Pansophy AI shall impose on each Subprocessor data protection obligations no less protective than those in this DPA, and shall remain liable to the Customer for the performance of each Subprocessor's obligations.
Pansophy AI shall inform the Customer of any intended addition or replacement of a Subprocessor with reasonable advance notice, giving the Customer the opportunity to object on reasonable data protection grounds. If the Parties cannot resolve an objection, the Customer may terminate the Service for the affected processing.
6. International Transfers
Pansophy AI processes Customer Personal Data within Microsoft Azure in the United States. Two categories of processing on the direct plan involve providers outside that environment: payment processing by Stripe, and, where the Customer connects a third-party AI agent, the transit of submitted text through that agent provider. Where Applicable Data Protection Law requires a transfer mechanism for personal data leaving the European Economic Area, the United Kingdom, or Switzerland, the Parties shall give effect to the applicable Standard Contractual Clauses, which shall be incorporated by reference and shall prevail over this DPA in the event of conflict on transfer matters.
7. CCPA Terms
Where the CCPA applies, Pansophy AI acts as a Service Provider. Pansophy AI shall not sell or share Customer Personal Data, shall not retain, use, or disclose it for any purpose other than performing the Service or as otherwise permitted by the CCPA, and shall not combine it with personal data from other sources except as permitted by the CCPA. Pansophy AI certifies that it understands and will comply with these restrictions.
8. Liability and Term
This DPA is effective for as long as Pansophy AI processes Customer Personal Data on behalf of the Customer. The liability of each Party under this DPA is subject to the limitations and exclusions of liability set out in the agreement between the Parties. This DPA does not relieve either Party of obligations imposed directly on it by Applicable Data Protection Law.
Provision of the Service, namely behavioral analysis of submitted text.
Duration
For the term of the Customer's use of the Service. Submitted content is processed only during the active session and discarded at session close.
Nature and purpose
Detection and redaction of personally identifiable information, behavioral trait scoring, and generation of a written read, performed so that the Customer's AI agent or the Customer can use the read in a sales context.
Types of personal data
Personal data the Customer chooses to include in submitted content, which may include the names and statements of the individuals whose words are submitted, such as a prospect or a salesperson, and, incidentally and prior to redaction, contact details such as email addresses and phone numbers contained in that content. On the direct plan, account and billing data is processed as described in the Privacy Policy.
Special categories
The Service is not designed to process special categories of personal data. The Customer should not submit content for the purpose of processing special category data.
Categories of data subjects
The individuals whose words are contained in content the Customer submits, which may include the Customer's prospects, customers, counterparties, and personnel.
Annex B: Approved Subprocessors
Microsoft Corporation (United States): cloud infrastructure (Azure) and the Azure-hosted Anthropic Claude Sonnet 4.6 model used to generate the read.
GoGig Inc. (United States): behavioral scoring engine, running as a containerized service inside the Pansophy AI Azure tenant; receives PII-redacted text only; retains no data it processes.
Stripe, Inc. (United States, direct plan only): payment processing and subscription billing.
On the direct plan, the Customer also selects a third-party MCP-capable AI agent, such as Anthropic's Claude or Microsoft Copilot, through which submitted text passes. That provider acts under its own terms with the Customer and is selected and controlled by the Customer rather than engaged by Pansophy AI as a Subprocessor.
Annex C: Technical and Organizational Security Measures
Encryption of personal data in transit using TLS 1.2 or higher
Encryption of personal data at rest using AES-256
Server-side detection and redaction of personally identifiable information before content reaches the scoring engine or the language model
Discarding of submitted content, extracted text, and PII-redacted text at session close, with no persistence to durable storage
Retention of only an anonymized analytical record that contains no identity and no source text
Authentication of all access: Microsoft Entra ID on the Teams plan, and a unique connector credential stored only as a cryptographic hash on the direct plan
Access scoping by tenant or subscription identifier, with no architecturally possible cross-account access
Management of secrets and credentials through Microsoft Azure Key Vault
Restriction of the scoring step from public internet access during analysis processing