This Data Processing Addendum (“DPA”) forms part of the agreement governing Customer’s use of the Sloancode AI Services (the “Agreement”) between Sloancode Technology Group LLC (“Sloancode,” “Processor,” “Service Provider,” “Contractor,” “we,” “us,” or “our”) and the customer identified in the Agreement (“Customer,” “Controller,” “Business,” “you,” or “your”).
This DPA applies to Processing of Customer Personal Data by Sloancode on behalf of Customer in connection with the Services. It is intended to establish the parties’ respective obligations under Applicable Data Protection Law and does not expand Sloancode’s role beyond Processing performed on Customer’s behalf.
For Processing in which Sloancode independently determines the purposes and means, Sloancode acts as an independent Controller or Business, as applicable, and that Processing is governed by the Sloancode AI Privacy Policy and Applicable Data Protection Law rather than the processor provisions of this DPA.
Capitalized terms not defined in this DPA have the meanings given in the Agreement.
1. Definitions
“Applicable Data Protection Law” means privacy, data protection, data security, breach-notification, and similar laws applicable to the Processing of Customer Personal Data under the Agreement, including where applicable the CCPA/CPRA, other U.S. comprehensive state privacy laws, GDPR, UK GDPR, and implementing legislation.
“CCPA” means the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act and implementing regulations.
“Customer Personal Data” means Personal Data contained in Customer Content that Sloancode Processes on behalf of Customer under the Agreement.
“Data Subject” or “Consumer” means an identified or identifiable individual or other person to whom rights attach under Applicable Data Protection Law.
“GDPR” means Regulation (EU) 2016/679. “UK GDPR” means the GDPR as incorporated into United Kingdom law.
“Personal Data,” “Personal Information,” “Process/Processing,” “Controller,” “Processor,” “Business,” “Service Provider,” “Contractor,” “Sell,” “Share,” and “Sensitive Personal Data/Information” have the meanings assigned by Applicable Data Protection Law.
“Security Incident” means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data processed by Sloancode, excluding unsuccessful attempts or events that do not compromise Customer Personal Data.
“Subprocessor” means a third party engaged by Sloancode to Process Customer Personal Data on Customer’s behalf in connection with the Services.
2. Scope; Roles; Fact-Based Determination
Customer appoints Sloancode to Process Customer Personal Data on Customer’s behalf solely to provide the Services and perform the documented instructions in the Agreement, this DPA, applicable Order Forms, Customer configurations, and lawful instructions consistent with the Services.
Customer is the Controller/Business and Sloancode is the Processor/Service Provider/Contractor for Customer Personal Data, except where Applicable Data Protection Law requires a different classification based on the facts of a particular Processing activity.
If Sloancode determines the purposes and means of a Processing activity beyond Customer’s documented instructions, Sloancode will be a Controller/Business for that Processing to the extent required by law and will assume the obligations applicable to that role.
Nothing in this DPA relieves either party of obligations independently imposed on it by Applicable Data Protection Law.
3. Customer Instructions
Sloancode will Process Customer Personal Data only on Customer’s documented instructions, including as necessary to provide, secure, support, maintain, troubleshoot, and administer the Services; perform Customer-authorized integrations and AI workflows; comply with the Agreement; and comply with law.
Customer’s instructions must be lawful, within the scope of the Services, and technically feasible. If Sloancode reasonably believes an instruction violates Applicable Data Protection Law, Sloancode will inform Customer unless prohibited by law and may suspend the affected Processing pending resolution.
Sloancode will not materially expand the purposes for which Customer Personal Data is Processed without Customer instruction or another lawful basis that independently applies to Sloancode.
4. Processing Details and Required Particulars
The subject matter, nature, purpose, duration, categories of Data Subjects, and categories of Customer Personal Data are set out in Annex I. Annex I forms part of this DPA and is intended to satisfy applicable contractual-detail requirements.
The parties may update Annex I through an Order Form or written amendment where a new Service materially changes the Processing.
5. Purpose Limitation; CCPA Service Provider / Contractor Restrictions
For Customer Personal Data subject to the CCPA, Sloancode will Process Personal Information only for the limited and specified business purposes described in Annex I and the Agreement, or as otherwise permitted by the CCPA and its regulations.
Sloancode will not Sell or Share Customer Personal Data collected pursuant to the Agreement.
Sloancode will not retain, use, or disclose such Personal Information outside the direct business relationship between Sloancode and Customer or for a commercial purpose other than the specific business purposes stated in the Agreement, except as permitted by Applicable Data Protection Law.
Sloancode will not combine Customer Personal Data received from or on behalf of Customer with Personal Information received from or on behalf of another person or collected from Sloancode’s own interaction with a Consumer except as expressly permitted by the CCPA and its regulations.
Sloancode certifies that it understands and will comply with the restrictions applicable to a service provider or contractor under the CCPA to the extent applicable to the Processing.
6. No Generalized Cross-Customer Model Training by Default
Unless Customer affirmatively opts in, separately authorizes such use in writing, or enters into an agreement expressly permitting it, Sloancode will not use Customer Personal Data, including prompts, messages, documents, voice recordings, transcripts, or other Customer Content, to train generalized Sloancode AI models for use across unrelated Customers.
Sloancode may Process Customer Personal Data as necessary to provide Customer-specific AI functionality, including inference, retrieval, embeddings, Customer-authorized fine-tuning, evaluation, or configuration, where such Processing is part of the Services and consistent with Customer’s instructions.
Sloancode may use data that has been lawfully de-identified or aggregated so that it is no longer Personal Data for security, reliability, analytics, capacity planning, and service improvement, subject to applicable law and the Agreement.
Sloancode will contractually and technically seek to prevent a Subprocessor from using Customer Personal Data for generalized model training where the applicable provider terms or configuration support such restriction and the Processing is performed on Sloancode’s behalf.
7. Confidentiality of Processing Personnel
Sloancode will ensure that persons authorized to Process Customer Personal Data are subject to confidentiality obligations or an appropriate statutory duty of confidentiality and receive access only to the extent necessary for their functions.
Sloancode will maintain reasonable access-management practices designed to limit privileged access to authorized personnel.
8. Security Measures
Sloancode will implement and maintain appropriate administrative, technical, and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, taking into account the nature, scope, context, and purposes of Processing and the risks to individuals.
The baseline technical and organizational measures are described in Annex II. Sloancode may update measures over time provided the overall level of protection is not materially diminished during an applicable committed term.
Where required by Applicable Data Protection Law, Sloancode will assist Customer with information reasonably necessary for Customer to assess the security of Processing.
9. Data Minimization; Privacy by Design
Sloancode will design and operate the Services to support Processing that is proportionate to the documented purposes and will not intentionally require Customer to provide categories of Customer Personal Data unnecessary for the applicable Service.
Customer remains responsible for configuring the Services and Customer workflows to avoid unnecessary collection and for determining which Customer Personal Data is appropriate for its use case.
10. Sensitive and Regulated Data
Customer will not submit specially regulated data to a Service unless the applicable Order Form, Documentation, or written authorization confirms that the Service is approved for that data category.
Without such approval, Customer must not use the Services to Process protected health information subject to HIPAA, full payment-card credentials, biometric identifiers used for identification/authentication, genetic data, Social Security numbers, highly sensitive government identifiers, children’s data requiring specialized consent, consumer health data subject to specialized state statutes, or other specially regulated data requiring controls not included in the Service.
Where approved Sensitive Personal Data is Processed, the parties will comply with additional requirements in Applicable Data Protection Law and any applicable product supplement.
11. Subprocessors; General Authorization
Customer provides general written authorization for Sloancode to engage Subprocessors necessary to provide the Services, subject to this Section.
Sloancode will maintain a current list of material Subprocessors that Process Customer Personal Data, including the Subprocessor’s name, location where appropriate, and general processing function.
Sloancode will enter into a written agreement with each Subprocessor imposing data-protection obligations that are no less protective in material respects than those applicable to Sloancode for the relevant Processing, as required by Applicable Data Protection Law.
Sloancode remains responsible for its Subprocessors’ performance of their data-protection obligations to the extent required by Applicable Data Protection Law and the Agreement.
12. Subprocessor Changes and Objections
Where required by Applicable Data Protection Law or the Agreement, Sloancode will provide reasonable advance notice of a new material Subprocessor that will Process Customer Personal Data.
Customer may object in writing within [15] days after notice based on reasonable, documented data-protection grounds. The parties will work in good faith to resolve the objection, which may include using a commercially reasonable alternative where available.
If the parties cannot resolve a legitimate objection and the affected Service cannot reasonably be provided without the Subprocessor, Customer may terminate only the materially affected Service and receive a prorated refund of prepaid unused fees for that terminated portion, unless the Agreement provides another remedy.
An objection may not be used solely to avoid contractual commitments or fees.
13. Data Subject / Consumer Rights Assistance
Taking into account the nature of Processing and information available to Sloancode, Sloancode will provide reasonable assistance to Customer through appropriate technical and organizational measures for Customer to respond to requests to exercise rights under Applicable Data Protection Law.
If Sloancode receives a request directly from a Data Subject concerning Customer Personal Data for which Customer is the Controller/Business, Sloancode will, where legally permitted, direct the requester to Customer or notify Customer and will not independently respond substantively except on Customer’s documented instructions or as required by law.
Customer is responsible for verifying requests and determining whether a request must be fulfilled. Sloancode may charge reasonable fees for extraordinary assistance not included in the Services where permitted by law and agreed in advance.
14. Deletion, Correction, Restriction, and Portability
Sloancode will provide functionality or reasonable assistance, as applicable to the Service, to enable Customer to delete, correct, restrict, access, or export Customer Personal Data where required for Customer to fulfill applicable rights.
Deletion from active systems may not result in immediate deletion from backups. Backup data will remain protected and will be deleted or overwritten according to applicable backup lifecycle controls, unless earlier deletion is required and technically feasible under Applicable Data Protection Law.
If backup data is restored, Sloancode will reapply applicable deletion or restriction instructions where reasonably practicable.
15. Return or Deletion at End of Services
Upon termination or expiration of the applicable Services and at Customer’s choice, Sloancode will return or delete Customer Personal Data as provided by the Service and Agreement, unless Applicable Data Protection Law or another legal obligation requires retention.
Where Customer does not make a timely election or retrieve available data during the contractual retrieval period, Sloancode may delete Customer Personal Data according to its retention schedule.
Any legally required retained data will remain protected under this DPA and will be Processed only for the purpose requiring retention.
16. Security Incident Notification
Sloancode will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data. The parties may specify a more precise contractual notification target in an Order Form or security addendum.
Notification will include, to the extent known and reasonably available: the nature of the Security Incident; categories of affected data and Data Subjects; known or reasonably estimated scope; likely consequences where assessable; mitigation or remediation measures taken or proposed; and a contact for follow-up.
Sloancode may provide information in phases as the investigation progresses. Notification or response to a Security Incident is not an admission of fault or liability.
Sloancode will take reasonable steps to contain, investigate, mitigate, remediate, and document a Security Incident and will reasonably cooperate with Customer’s legally required notification or investigation obligations.
Customer is responsible for determining whether notification to regulators, Data Subjects, or other parties is legally required unless the law independently imposes that obligation on Sloancode.
17. Security Incident Exclusions
A Security Incident does not include unsuccessful attempts or activities that do not compromise Customer Personal Data, such as pings, port scans, blocked attacks, unsuccessful login attempts, denial-of-service attempts without data compromise, or events involving only Customer Systems not controlled by Sloancode.
This exclusion does not limit any obligation arising from an event that actually compromises Customer Personal Data.
18. Assistance with Security, DPIAs, Risk Assessments, and Regulatory Duties
Taking into account the nature of Processing and information available to Sloancode, Sloancode will provide reasonable assistance necessary for Customer to comply with applicable obligations concerning security of Processing, breach response, data protection impact assessments, privacy risk assessments, cybersecurity audits, and prior consultation with regulators.
For California-covered Processing, Sloancode will cooperate with Customer’s applicable CCPA cybersecurity audit and risk assessment obligations by making available relevant information in Sloancode’s possession, custody, or control as required by law.
For U.S. state laws requiring processor assistance with data protection assessments, Sloancode will provide information reasonably necessary to enable Customer to conduct and document such assessments.
Customer remains responsible for conducting assessments required of Customer as Controller/Business.
19. Audits and Demonstration of Compliance
Sloancode will make available information reasonably necessary to demonstrate compliance with this DPA and Applicable Data Protection Law within the scope of Sloancode’s processor obligations.
Where Sloancode maintains current independent audit, certification, penetration-test summary, or assessment reports relevant to the Services, Sloancode may satisfy reasonable audit requests by providing such materials under confidentiality restrictions.
If those materials are insufficient for a legally required assessment, Customer may request an additional audit no more than once annually, unless a Security Incident, regulator request, or reasonable evidence of material noncompliance justifies additional review.
Audits must be conducted during normal business hours, with reasonable advance notice, in a manner that avoids unreasonable disruption and does not expose other customers’ data, confidential information, security-sensitive details, or privileged materials.
Customer will bear its audit costs and reimburse Sloancode for extraordinary internal costs unless the audit identifies Sloancode’s material breach of this DPA, in which case reasonable allocation will be determined under the Agreement.
Sloancode may require an auditor to be independent, appropriately qualified, non-competitive, and bound by confidentiality.
20. Government and Law-Enforcement Requests
If Sloancode receives a legally binding request from a public authority for Customer Personal Data, Sloancode will, where legally permitted, notify Customer before disclosure so Customer may seek protective relief.
Sloancode will disclose only the Customer Personal Data it is legally required to disclose and may seek clarification, narrowing, or challenge of a request where Sloancode reasonably determines there are lawful grounds to do so.
Nothing in this DPA requires Sloancode to violate applicable law or obstruct lawful process.
21. International Data Transfers
Customer authorizes Sloancode to Process Customer Personal Data in the United States and other locations identified through the applicable Subprocessor List or Order Form, subject to Applicable Data Protection Law.
Where a transfer of Personal Data from the EEA, United Kingdom, or Switzerland to a country lacking an applicable adequacy mechanism requires contractual safeguards, the transfer mechanism in Annex III will apply.
The parties will cooperate in good faith to implement supplementary measures reasonably required by Applicable Data Protection Law for an international transfer.
22. EU Standard Contractual Clauses
Where required for a Restricted Transfer from the EEA, the European Commission Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 (“EU SCCs”) are incorporated by reference as described in Annex III.
For Customer acting as Controller and Sloancode as Processor, Module Two applies. Where Customer is a Processor and Sloancode is a Subprocessor, Module Three applies. Other modules apply only if the factual roles require them.
The parties will not modify the EU SCCs in a manner that conflicts with their mandatory text. Annex III supplies the elections and annex information necessary to operationalize the applicable module.
23. United Kingdom Restricted Transfers
Where UK data protection law requires a transfer mechanism, the parties will use the then-valid UK International Data Transfer Addendum to the EU SCCs or another lawful transfer mechanism, incorporated as specified in Annex III.
If the UK Information Commissioner issues a mandatory replacement or update, the parties will apply the replacement as required by law.
24. Swiss Transfers
For transfers subject to the Swiss Federal Act on Data Protection, the EU SCCs will apply with modifications necessary to recognize Switzerland, Swiss law, and the competent Swiss authority where legally appropriate, as further described in Annex III.
25. Transfer Impact Assessments and Supplementary Measures
Where required, the parties will reasonably cooperate in assessing laws and practices of destination jurisdictions relevant to a Restricted Transfer.
Sloancode will provide information reasonably available regarding its transfer practices, technical and organizational measures, Subprocessors, and government-access posture, subject to confidentiality, privilege, security, and legal restrictions.
Where necessary, Sloancode may implement supplementary contractual, technical, or organizational measures designed to protect transferred Customer Personal Data.
26. Data Location and Residency
Unless an Order Form expressly commits to a specific data-residency region, Customer acknowledges that Customer Personal Data may be Processed in locations used by Sloancode and authorized Subprocessors consistent with this DPA.
A contractual data-residency commitment applies only to the data categories and systems expressly identified in the applicable Order Form and does not automatically extend to support metadata, security logs, communications routing, or third-party integrations unless expressly stated.
27. AI Providers and AI Subprocessing
Where an AI, speech, transcription, or model provider Processes Customer Personal Data on Sloancode’s behalf, that provider will be treated as a Subprocessor where required by Applicable Data Protection Law.
Sloancode will use enterprise/API arrangements and available data controls appropriate to the relevant Service and will not knowingly route Customer Personal Data through a consumer AI account when enterprise/API processing is required by the applicable architecture.
Customer acknowledges that Customer-selected models, connectors, or external AI providers may be independent Third-Party Services rather than Sloancode Subprocessors where Customer contracts directly with or independently controls them.
28. Voice, Audio, Communications, and Consent Data
Where the Services Process voice, audio, telephone calls, transcripts, SMS, email, chat, or messaging data on Customer’s behalf, such data constitutes Customer Personal Data to the extent it is Personal Data.
Customer is responsible for establishing the lawful basis, providing legally required notices, and obtaining legally required consent for recording, transcription, monitoring, messaging, telemarketing, or other communications Processing.
Sloancode will Process consent and preference records supplied through the Services according to Customer’s instructions and applicable product functionality.
Sloancode will not intentionally create biometric voiceprints for identification or authentication from Customer audio unless the applicable Service expressly supports that use and the parties have agreed to required additional terms.
29. Children’s Data
Customer may not intentionally use general-purpose Sloancode AI Services to collect or Process Personal Data of children where specialized parental consent or age-specific compliance is required unless Sloancode has expressly approved the use and the parties have implemented appropriate supplemental terms and controls.
Customer is responsible for determining applicable age thresholds and obtaining required parental or guardian authorization.
30. De-Identified and Aggregated Data
Where Sloancode creates data that qualifies as de-identified under Applicable Data Protection Law, Sloancode will maintain it in de-identified form and will not attempt to re-identify it except where permitted by law to test de-identification controls.
Where required, Sloancode will contractually require recipients of de-identified data to maintain applicable restrictions.
31. Retention and Legal Holds
Customer controls retention to the extent the Services provide configurable retention. Sloancode may maintain default retention schedules for data categories not configured by Customer.
Sloancode may preserve Customer Personal Data beyond ordinary retention where required by law, valid legal process, litigation hold, fraud/security investigation, or to establish or defend legal claims.
Data retained under a legal hold will remain subject to this DPA and will not be used for unrelated purposes.
32. Business Continuity and Backups
Sloancode will maintain backup and recovery measures appropriate to the applicable Services. Backup frequency, recovery objectives, and disaster-recovery commitments are governed by applicable security documentation, SLA, or Order Form where expressly stated.
This DPA does not create a specific recovery-time or recovery-point commitment unless separately agreed.
33. Customer Obligations as Controller / Business
Customer represents and warrants that its instructions and Processing of Customer Personal Data comply with Applicable Data Protection Law and that it has all rights, notices, lawful bases, consents, and authorizations necessary for Sloancode to Process Customer Personal Data under the Agreement.
Customer is responsible for data accuracy, data minimization decisions, privacy notices, consent collection, rights-request verification, Customer user access, Customer-side security, Customer Systems, and the legality of Customer’s use cases.
Customer will not instruct Sloancode to Process Customer Personal Data in violation of law or for a purpose outside the contracted Services.
34. Customer as Processor; Sloancode as Subprocessor
If Customer Processes Personal Data on behalf of another Controller and appoints Sloancode as a Subprocessor, Customer represents that it has authority to appoint Sloancode and issue instructions consistent with the upstream Controller’s requirements.
Sloancode will provide Customer with the processor obligations in this DPA so that Customer can satisfy applicable obligations to its Controller, but Sloancode is not bound by upstream terms that Sloancode has not expressly accepted.
Customer remains responsible for ensuring that its agreement with the upstream Controller permits the Processing and Subprocessors used.
35. Independent Controller Processing
This DPA does not govern Personal Data that Sloancode Processes as an independent Controller/Business for its own purposes, such as certain business contact data, billing records, legal compliance records, security information, or account administration data, except where Applicable Data Protection Law classifies that Processing differently.
Such Processing is governed by the Sloancode AI Privacy Policy and Applicable Data Protection Law.
36. Records of Processing and Regulatory Cooperation
Sloancode will maintain records of Processing activities to the extent required by Applicable Data Protection Law for its role.
Sloancode will reasonably cooperate with competent supervisory authorities or regulators where legally required, subject to applicable procedural rights and confidentiality obligations.
Customer is responsible for its own regulatory registrations, records, assessments, and filings unless expressly assumed by Sloancode.
37. Notification of Inability to Comply
If Sloancode determines that it can no longer meet an applicable obligation under this DPA or Applicable Data Protection Law for Customer Personal Data, Sloancode will notify Customer without undue delay unless prohibited by law.
Customer may take reasonable and appropriate steps to stop and remediate unauthorized Processing, including requiring corrective action or suspending affected data transfers, consistent with Applicable Data Protection Law and the Agreement.
38. Costs of Assistance
Routine assistance reasonably necessary for Sloancode’s compliance with its statutory processor obligations is included in the Services.
Where Customer requests extraordinary, repetitive, bespoke, or technically burdensome assistance beyond legal requirements or standard product functionality, Sloancode may charge reasonable fees at agreed rates after providing advance notice, except where charging would be prohibited by Applicable Data Protection Law.
39. Liability; Relationship to Agreement
Each party’s liability arising from this DPA is subject to the exclusions and limitations of liability in the Agreement, except to the extent Applicable Data Protection Law prohibits application of a contractual limitation to a particular obligation or liability.
Nothing in this DPA limits Data Subject rights or regulatory authority where such rights or authority cannot lawfully be limited by contract.
If the EU SCCs or another mandatory transfer mechanism applies and conflicts with the Agreement’s liability terms, the mandatory transfer mechanism controls to the extent of the conflict.
40. Order of Precedence
For matters concerning Processing of Customer Personal Data, this DPA prevails over conflicting provisions of the Agreement unless a signed amendment expressly identifies and modifies a provision of this DPA.
For Restricted Transfers, the applicable EU SCCs, UK transfer addendum, or other mandatory transfer instrument prevails over conflicting terms to the extent required by law.
An Order Form may supplement Processing details but will not reduce mandatory statutory processor obligations unless Applicable Data Protection Law permits the modification.
41. Term and Survival
This DPA begins when Sloancode Processes Customer Personal Data under the Agreement and continues for as long as Sloancode Processes Customer Personal Data on Customer’s behalf.
Obligations concerning confidentiality, security, deletion/return, Restricted Transfers, audits, and other provisions that by their nature must continue will survive termination for so long as Sloancode retains Customer Personal Data.
42. Changes in Law
If Applicable Data Protection Law changes in a manner that materially affects this DPA, the parties will cooperate in good faith to amend the DPA as reasonably necessary to maintain compliance.
Sloancode may implement legally required updates to standard processor terms or transfer mechanisms upon notice, provided such updates do not materially reduce Customer’s legally required protections.
43. Execution; Incorporation; Electronic Acceptance
This DPA may be executed in counterparts, by electronic signature, or incorporated by reference into an Order Form or Agreement through a legally effective acceptance process.
Where incorporated electronically, Sloancode should maintain version and acceptance records sufficient to identify the DPA accepted by Customer.
44. Contact for Data Protection Matters
Sloancode Technology Group LLC
Attn: Sloancode AI Privacy / Data Protection
99 Wall Street
Suite 3772
New York, NY 10005
United States
ANNEX I. Details of Processing
This Annex describes the Processing authorized under the DPA. The applicable Order Form and Customer configuration may narrow these details.
| Subject Matter | Provision, operation, security, support, administration, and Customer-authorized configuration of Sloancode AI Services, including horizontal AI capabilities and applicable Industry Clouds. |
|---|---|
| Duration | For the term of the applicable Services plus the limited period during which Customer Personal Data remains in active systems, backups, legal holds, or other lawful retention. |
| Nature of Processing | Collection/receipt, organization, storage, hosting, retrieval, consultation, analysis, inference, generation, transcription, transformation, embedding, transmission, disclosure to authorized Subprocessors/integrations, workflow execution, deletion, and other operations necessary to provide the Services. |
| Purposes | Provide and secure the Services; authenticate users; process Customer-authorized AI interactions; execute authorized workflows; provide voice/conversational AI; communications; integrations; analytics requested by Customer; support; troubleshooting; security; abuse prevention; compliance with Customer instructions and law. |
| Frequency | Continuous, recurring, or event-driven depending on Customer use and configuration. |
Categories of Data Subjects
- Customer employees, administrators, contractors, and Authorized Users;
- Customer’s customers, prospective customers, callers, website visitors, and other End Users;
- restaurant patrons and ordering/reservation contacts where Restaurant AI is used;
- field-service customers, technicians, dispatchers, and service contacts where Field Services AI is used;
- facilities personnel, occupants, vendors, contractors, and service contacts where Facilities AI is used;
- construction personnel, contractors, vendors, project stakeholders, and contacts where Construction AI is used;
- property owners, residents, tenants, applicants, vendors, contractors, and service contacts where Property Management AI is used, subject to approved use cases;
- business contacts and other individuals whose Personal Data Customer lawfully submits to the Services.
Categories of Customer Personal Data
- identity and contact data, including name, email, telephone number, address, business affiliation, role, and account identifiers;
- account, authentication, authorization, and user-role information;
- communications content and metadata, including SMS, chat, email, messaging, and support interactions;
- voice/audio data, call metadata, and transcripts where enabled;
- AI prompts, instructions, conversation context, Outputs associated with identifiable persons, and AI interaction records;
- orders, reservations, appointments, service requests, work orders, scheduling, dispatch, project, property, facility, asset, vendor, and operational records;
- documents, attachments, forms, knowledge-base content, and Customer-provided records;
- transaction metadata and payment-related status information, excluding full card credentials unless expressly supported;
- consent, preference, opt-in, opt-out, and communication-choice records;
- technical identifiers, IP addresses, device/browser information, logs, timestamps, and security events;
- other Personal Data submitted by Customer within the documented functionality of an approved Service.
Sensitive Data
Sensitive Personal Data is not required for general use of the Services. Processing of specially regulated or sensitive categories is permitted only where supported by the applicable Service, Customer has a lawful basis and required consent, and any required supplemental terms or controls are in place.
Processing Instructions
The Agreement, this DPA, applicable Order Forms, Customer configurations, API calls, administrator settings, workflow configurations, support requests, and other lawful written instructions consistent with the Services constitute Customer’s documented instructions.
ANNEX II. Technical and Organizational Measures
The following describes the baseline categories of safeguards Sloancode intends to maintain. Final publication/execution must be reconciled against verified production controls; no unverified certification or technical specification should be added.
Governance and Security Management
- documented security responsibilities and access governance;
- security policies and procedures appropriate to the Services;
- risk-based review of material security changes;
- security awareness appropriate to personnel responsibilities.
Identity and Access Management
- unique user identities where appropriate;
- role-based and least-privilege access;
- administrative access controls;
- credential and secret-management practices;
- periodic access review appropriate to privileged roles;
- multi-factor authentication where supported/required by the verified production architecture.
Data Protection
- encryption in transit using industry-standard protocols where supported by the relevant system;
- encryption at rest for production data stores where verified and applicable;
- separation of development/test and production environments;
- controls designed to prevent public access to private production data;
- data minimization and retention controls appropriate to the Service.
Tenant and Application Security
- logical tenant isolation controls appropriate to the multi-tenant architecture;
- authorization checks at relevant application/service boundaries;
- secure session and authentication controls;
- input validation and defensive application-security practices;
- protection against common web/application vulnerabilities.
Infrastructure and Network Security
- cloud/infrastructure access restrictions;
- network segmentation or equivalent logical controls where appropriate;
- security configuration management;
- restricted administrative interfaces;
- monitoring for material security events.
Software Development and Change Management
- source-control and change-management practices;
- code review/testing appropriate to material changes;
- dependency and vulnerability management;
- separation of duties or compensating controls where appropriate;
- controlled production deployment practices.
Logging, Monitoring, and Auditability
- logging of material authentication, administrative, security, and operational events where appropriate;
- restricted access to logs;
- monitoring and alerting appropriate to the risk of the Service;
- retention of logs according to security and operational requirements.
Vulnerability and Security Testing
- vulnerability identification and remediation processes;
- security testing appropriate to material releases and infrastructure;
- penetration testing or independent assessment where commercially appropriate and actually implemented;
- prioritization of remediation based on severity and exploitability.
Incident Response
- documented incident identification, escalation, containment, investigation, remediation, and post-incident processes;
- defined internal responsibilities;
- preservation of relevant evidence where appropriate;
- Customer notification procedures consistent with this DPA.
Business Continuity and Recovery
- backup controls appropriate to applicable production data;
- recovery procedures appropriate to critical services;
- protection of backups against unauthorized access;
- periodic testing appropriate to business-critical recovery processes.
Subprocessor and Vendor Management
- risk-based review of material providers;
- contractual privacy/security obligations where required;
- limitation of Subprocessor access to required purposes;
- maintenance of a Subprocessor inventory/list.
Personnel Security
- confidentiality obligations;
- role-appropriate security training;
- access termination/change procedures;
- background screening only where lawful, appropriate, and actually implemented for relevant roles.
Deletion and Media Handling
- secure logical deletion from active systems according to retention controls;
- backup expiration/overwrite according to lifecycle schedules;
- secure handling of storage media by relevant infrastructure providers;
- procedures designed to prevent ordinary reuse of deleted Customer Personal Data.
AI and Model Processing Controls
- use of authorized enterprise/API AI processing pathways where required by architecture;
- restriction of generalized cross-customer model training by default as stated in this DPA;
- tool/agent authorization boundaries appropriate to configured workflows;
- logging/auditability of material AI workflow actions where supported;
- human-approval gates for designated higher-risk actions where configured.
ANNEX III. International Transfer Mechanisms
This Annex applies only where Applicable Data Protection Law requires a transfer mechanism for a Restricted Transfer.
A. EU SCC Elections
- Applicable modules: Module Two (Controller to Processor) where Customer is Controller and Sloancode is Processor; Module Three (Processor to Processor) where Customer is Processor and Sloancode is Subprocessor.
- Docking clause: applies where permitted and agreed.
- Subprocessor authorization: general written authorization, subject to the notice/objection process in this DPA.
- Redress / optional language: mandatory SCC text controls; optional selections should be finalized with EU counsel before execution.
- Supervisory authority and governing law: determined based on the Data Exporter’s establishment and the mandatory SCC rules; complete in the applicable Order Form/DPA execution record.
- Annex I.A parties: Customer/Data Exporter as identified in the Agreement; Sloancode Technology Group LLC/Data Importer, 99 Wall Street, Suite 3772, New York, NY 10005, United States.
- Annex I.B transfer description: the Processing described in Annex I of this DPA.
- Annex II security measures: Annex II of this DPA, as verified and updated from time to time without materially reducing protection.
B. UK Transfers
For a UK Restricted Transfer, the then-current UK International Data Transfer Addendum to the EU SCCs (or successor mechanism) will be incorporated. Required tables/elections must be completed for the relevant Customer before relying on the mechanism.
C. Switzerland
For Swiss Restricted Transfers, references in the EU SCCs will be interpreted as necessary to cover the Swiss Federal Act on Data Protection, Swiss Data Subjects, and the competent Swiss supervisory authority, to the extent legally permitted.
D. Alternative Transfer Mechanisms
If an adequacy decision, certification, binding corporate rules, data privacy framework, or another lawful mechanism applies and is valid for the transfer, Sloancode may rely on that mechanism instead of or in addition to the SCCs where legally permitted.
E. Mandatory SCC Integrity
Nothing in the Agreement or this DPA modifies the EU SCCs in a manner that contradicts or restricts their mandatory provisions. If a conflict exists, the SCCs control for the Restricted Transfer.
ANNEX IV. U.S. State Privacy Law Processor Terms
This Annex supplements the DPA for Customer Personal Data subject to applicable U.S. comprehensive state privacy laws.
| Jurisdiction | Supplemental Processor Commitment |
|---|---|
| California | Sloancode will act as a service provider/contractor to the extent applicable; will not Sell or Share Customer Personal Data; will use it only for limited and specified business purposes or as otherwise permitted by law; will comply with applicable combination, retention/use/disclosure, subprocessor, assistance, audit/risk-assessment, and notification-of-inability-to-comply requirements. |
| Colorado | Sloancode will Process under Customer’s instructions, ensure confidentiality, assist with Consumer rights and security obligations, use written Subprocessor terms, provide information necessary to demonstrate compliance, and cooperate with reasonable assessments as required by applicable law. |
| Texas | Sloancode will adhere to Customer instructions; assist with Consumer rights, security/breach obligations, and data protection assessments; ensure confidentiality; delete or return data at Customer direction after services except where law requires retention; provide compliance information; and impose applicable obligations on Subprocessors. |
| Connecticut and Similar State Frameworks | Sloancode will provide the processor obligations required by applicable law, including documented instructions, confidentiality, deletion/return, compliance information, Subprocessor flow-down, and reasonable assessment cooperation where required. |
If another U.S. state privacy law applies and requires additional processor terms, this DPA will be interpreted to include the mandatory processor obligations to the extent legally permitted, and the parties will execute a conforming amendment if reasonably necessary.
Contact:
Legal: legal@sloancode.com
Support: support@sloancode.com
- Privacy: privacy@sloancode.com