Sparred ← Legal documents

Data Processing Agreement

Version 1.1 · Last updated 2026-07-27 · legal@sparred.ai

This Data Processing Agreement (this "DPA") governs Prestance Lab's processing of Personal Data carried out in the course of providing the Services under the Agreement. Capitalised terms not defined here have the meaning given to them in the General Terms and Conditions or, failing that, in the GDPR. It is incorporated by reference into the Agreement pursuant to GTC §14.3.

1. Roles and definitions

In order to provide the Services, Prestance Lab is required to process the Personal Data of Authorized Users. The Parties acknowledge that, with respect to the processing of such Personal Data carried out under the Agreement, the Customer acts as the data controller (the "Controller") and Prestance Lab acts as the data processor (the "Processor").

"Controller", "Data Subject", "Personal Data", "Process / Processing", "Processor", "Sub-processor", "Data Protection Impact Assessment", "Data Protection Officer" and "Personal Data Breach" have the same meaning as in the GDPR.

2. Applicable legislation

Each Party undertakes to comply with the provisions of any applicable legislation concerning the protection of Personal Data, in particular the French Data Protection Act No. 78-17 of 6 January 1978 in its latest version in force and Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data (the "GDPR"), together the "Applicable Data Protection Legislation".

3. Description of the processing

The Personal Data processing operations carried out by the Processor are described below.

Concerned service(s)
The Services as defined in the GTCs (Solution, Maintenance Services, and Professional Services where applicable).
Nature of the processing operations
Storage, consultation, organization, transmission, erasure, recording (voice), transcription (speech-to-text), automated analysis (LLM-as-judge), profiling within the meaning of Article 4(4) GDPR (skill mapping over time), and anonymization.
Purpose(s) of processing
Performance of the Agreement and provision of the Services, including: authentication of Authorized Users; delivery of voice-drill rehearsal sessions; generation of coaching letters; provision of the manager dashboard; technical support; and security monitoring.
Categories of Data Subjects
Authorized Users of the Customer (typically the Customer's employees acting in a sales-advisor, manager, or administrator role).
Categories of Personal Data
Identity data (first name, last name); professional contact data (professional email address); authentication metadata (hashed password, MFA token state, session identifiers); voice and session content (voice recordings of client-conversation simulations, advisor → persona transcripts, coaching letters and Solution-generated feedback, performance scores and skill ratings); drill metadata (drill identifiers, timestamps, scenarios); technical telemetry (IP address, browser user-agent, error logs).
Special categories of Personal Data
None processed by design. The Solution does not perform emotion recognition in the workplace within the meaning of Article 5(1)(f) of the EU AI Act.
Duration of the processing
Until deletion by the Authorized User or by the Customer administrator, and at the latest at the end of the Agreement followed by the deletion procedure described in Section 5 below and in the Security Policy (typically within 30 days; backups purged within 90 days).

4. Controller's undertakings

The Controller undertakes to:

5. Processor's undertakings

The Processor undertakes to:

6. International transfers

The Controller gives general consent to transfers of Personal Data outside the European Economic Area ("EEA") by the Processor, provided that such transfers are subject to the appropriate safeguards set out in Chapter V of the GDPR (including, where applicable, the European Commission's Standard Contractual Clauses and the UK Addendum, as well as any Transfer Impact Assessment required). The Sub-processor list in Section 7 below indicates the relevant transfer mechanism for each Sub-processor.

7. List of Sub-processors

As of the last-updated date at the top of this page, the following Sub-processors are engaged by the Processor for the provision of the Services.

Sub-processor Entity / address Activity Country of processing Transfer mechanism DPA
OpenAI Ireland Limited 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland Eval judge for internal test fixtures only — synthetic data, no Authorized User Personal Data United States SCCs OpenAI DPA
Fireworks AI, Inc. 539 Bryant Street, Suite 100, San Francisco, CA 94107, USA [to confirm] Post-drill analysis United States (EU dedicated deployment available on request) SCCs Fireworks Privacy & DPA
Google LLC 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA [to confirm — EU customers may contract via Google Ireland Limited, Gordon House, Barrow Street, Dublin 4] Live-drill voice-to-voice, coach, and intro-briefing voice synthesis (all languages) United States (no EU data residency) SCCs Google Cloud DPA [to confirm exact instrument]
Supabase, Inc. 970 Toa Payoh North #07-04, Singapore 318992 (operating via Supabase Pte. Ltd.); EU hosting on AWS Frankfurt [to confirm] Authentication, PostgreSQL database, object storage Germany (EU) Intra-EEA hosting; SCCs for any extra-EEA support operations Supabase DPA
LiveKit, Inc. 1 Bluxome Street, Suite 410, San Francisco, CA 94107, USA [to confirm] WebRTC media transport (SFU); session recording via Egress API to Prestance Lab-controlled storage Germany (EU, eu-central region); US transit for observability Intra-EEA media; SCCs for US-side observability data LiveKit DPA
Fly.io, Inc. 2261 Market Street #4990, San Francisco, CA 94114, USA [to confirm] Application hosting (backend, voice-agent worker, manager dashboard) France (Paris cdg region) Intra-EEA hosting; SCCs for any US-side operational data Fly.io DPA
Langfuse GmbH Charlottenstrasse 2, 10969 Berlin, Germany [to confirm] LLM observability Germany (EU) Intra-EEA Langfuse DPA
PostHog, Inc. 2261 Market Street #4008, San Francisco, CA 94114, USA [to confirm] Product analytics, logging, and error tracking Germany (EU, eu.i.posthog.com) Intra-EEA hosting; SCCs for any US-side support operations PostHog DPA

8. Updates to this DPA

Pursuant to GTC §2.7, Prestance Lab may update this DPA. Material changes will be notified to active Customers at least thirty (30) days in advance, unless a shorter period is required by law or to address a security risk. Changes to the Sub-processor list follow the procedure set out in Section 5 above.

9. Contact