This Data Processing Agreement ("DPA") forms part of the agreement between Pansophy AI Inc. ("Pansophy AI," "Processor") and the customer that subscribes to or uses Second Opinion for Sales (the "Customer," "Controller") (together, the "Parties") for the provision of Second Opinion for Sales (the "Service"). It governs the processing of personal data that the Customer submits to the Service. It takes effect on the date the Customer accepts it or first uses the Service, whichever is earlier. Where it conflicts with the End User License Agreement or Terms of Service on the subject of personal data processing, this DPA controls.

1. Definitions

Terms not defined here have the meaning given in applicable Data Protection Law.

2. Roles of the Parties

For Customer Personal Data submitted to the Service for analysis, the Customer is the Controller and Pansophy AI is the Processor. Pansophy AI processes Customer Personal Data only on the Customer's documented instructions, which are constituted by this DPA, the Service documentation, and the Customer's use of the Service.

For account, identity, subscription, and billing data, Pansophy AI may act as a Controller in its own right for the purposes of operating, securing, and billing the Service, as described in its Privacy Policy.

3. Scope and Details of Processing

The subject matter, duration, nature and purpose of processing, types of personal data, and categories of data subjects are set out in Annex A.

4. Processor Obligations

Pansophy AI shall:

  1. Process on instructions. Process Customer Personal Data only on the Customer's documented instructions, including with regard to transfers, unless required to act otherwise by law, in which case Pansophy AI shall inform the Customer of that legal requirement before processing, unless prohibited from doing so by law.
  2. Confidentiality. Ensure that persons authorized to process Customer Personal Data are bound by appropriate obligations of confidentiality.
  3. Security. Implement the technical and organizational measures set out in Annex C, appropriate to the risk, in accordance with Article 32 of the GDPR or its equivalent.
  4. Subprocessors. Engage Subprocessors only in accordance with Section 5.
  5. Data subject requests. Taking into account the nature of the processing, assist the Customer by appropriate technical and organizational measures, insofar as possible, in responding to requests from data subjects exercising their rights. Where a data subject contacts Pansophy AI directly regarding Customer Personal Data, Pansophy AI shall, where permitted, refer them to the Customer.
  6. Assistance. Assist the Customer in ensuring compliance with its obligations regarding security of processing, notification of personal data breaches, data protection impact assessments, and prior consultation, taking into account the nature of processing and the information available to Pansophy AI.
  7. Breach notification. Notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and provide the information reasonably available to it to assist the Customer in meeting its own notification obligations.
  8. Deletion or return. At the Customer's choice, delete or return Customer Personal Data at the end of the provision of the Service, and delete existing copies unless retention is required by law. Because submitted content is discarded at session close and is not written to persistent storage, content submitted to the Service is not retained beyond the active session in the ordinary course.
  9. Audits and information. Make available to the Customer information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, subject to reasonable notice, confidentiality, and frequency limits, and conducted so as not to disrupt the Service or compromise the security of other customers.

5. Subprocessors

The Customer authorizes Pansophy AI to engage the Subprocessors listed in Annex B. Pansophy AI shall impose on each Subprocessor data protection obligations no less protective than those in this DPA, and shall remain liable to the Customer for the performance of each Subprocessor's obligations.

Pansophy AI shall inform the Customer of any intended addition or replacement of a Subprocessor with reasonable advance notice, giving the Customer the opportunity to object on reasonable data protection grounds. If the Parties cannot resolve an objection, the Customer may terminate the Service for the affected processing.

6. International Transfers

Pansophy AI processes Customer Personal Data within Microsoft Azure in the United States. Two categories of processing on the direct plan involve providers outside that environment: payment processing by Stripe, and, where the Customer connects a third-party AI agent, the transit of submitted text through that agent provider. Where Applicable Data Protection Law requires a transfer mechanism for personal data leaving the European Economic Area, the United Kingdom, or Switzerland, the Parties shall give effect to the applicable Standard Contractual Clauses, which shall be incorporated by reference and shall prevail over this DPA in the event of conflict on transfer matters.

7. CCPA Terms

Where the CCPA applies, Pansophy AI acts as a Service Provider. Pansophy AI shall not sell or share Customer Personal Data, shall not retain, use, or disclose it for any purpose other than performing the Service or as otherwise permitted by the CCPA, and shall not combine it with personal data from other sources except as permitted by the CCPA. Pansophy AI certifies that it understands and will comply with these restrictions.

8. Liability and Term

This DPA is effective for as long as Pansophy AI processes Customer Personal Data on behalf of the Customer. The liability of each Party under this DPA is subject to the limitations and exclusions of liability set out in the agreement between the Parties. This DPA does not relieve either Party of obligations imposed directly on it by Applicable Data Protection Law.

9. Contact

Data protection inquiries under this DPA:

Pansophy AI Inc., Privacy

privacy@pansophyai.com

pansophyai.com

Annex A: Details of Processing

Subject matter

Provision of the Service, namely behavioral analysis of submitted text.

Duration

For the term of the Customer's use of the Service. Submitted content is processed only during the active session and discarded at session close.

Nature and purpose

Detection and redaction of personally identifiable information, behavioral trait scoring, and generation of a written read, performed so that the Customer's AI agent or the Customer can use the read in a sales context.

Types of personal data

Personal data the Customer chooses to include in submitted content, which may include the names and statements of the individuals whose words are submitted, such as a prospect or a salesperson, and, incidentally and prior to redaction, contact details such as email addresses and phone numbers contained in that content. On the direct plan, account and billing data is processed as described in the Privacy Policy.

Special categories

The Service is not designed to process special categories of personal data. The Customer should not submit content for the purpose of processing special category data.

Categories of data subjects

The individuals whose words are contained in content the Customer submits, which may include the Customer's prospects, customers, counterparties, and personnel.

Annex B: Approved Subprocessors

On the direct plan, the Customer also selects a third-party MCP-capable AI agent, such as Anthropic's Claude or Microsoft Copilot, through which submitted text passes. That provider acts under its own terms with the Customer and is selected and controlled by the Customer rather than engaged by Pansophy AI as a Subprocessor.

Annex C: Technical and Organizational Security Measures