Data Processing Agreement
This Data Processing Agreement (this "DPA") governs Prestance Lab's processing of Personal Data carried out in the course of providing the Services under the Agreement. Capitalised terms not defined here have the meaning given to them in the General Terms and Conditions or, failing that, in the GDPR. It is incorporated by reference into the Agreement pursuant to GTC §14.3.
1. Roles and definitions
In order to provide the Services, Prestance Lab is required to process the Personal Data of Authorized Users. The Parties acknowledge that, with respect to the processing of such Personal Data carried out under the Agreement, the Customer acts as the data controller (the "Controller") and Prestance Lab acts as the data processor (the "Processor").
"Controller", "Data Subject", "Personal Data", "Process / Processing", "Processor", "Sub-processor", "Data Protection Impact Assessment", "Data Protection Officer" and "Personal Data Breach" have the same meaning as in the GDPR.
2. Applicable legislation
Each Party undertakes to comply with the provisions of any applicable legislation concerning the protection of Personal Data, in particular the French Data Protection Act No. 78-17 of 6 January 1978 in its latest version in force and Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data (the "GDPR"), together the "Applicable Data Protection Legislation".
3. Description of the processing
The Personal Data processing operations carried out by the Processor are described below.
- Concerned service(s)
- The Services as defined in the GTCs (Solution, Maintenance Services, and Professional Services where applicable).
- Nature of the processing operations
- Storage, consultation, organization, transmission, erasure, recording (voice), transcription (speech-to-text), automated analysis (LLM-as-judge), profiling within the meaning of Article 4(4) GDPR (skill mapping over time), and anonymization.
- Purpose(s) of processing
- Performance of the Agreement and provision of the Services, including: authentication of Authorized Users; delivery of voice-drill rehearsal sessions; generation of coaching letters; provision of the manager dashboard; technical support; and security monitoring.
- Categories of Data Subjects
- Authorized Users of the Customer (typically the Customer's employees acting in a sales-advisor, manager, or administrator role).
- Categories of Personal Data
- Identity data (first name, last name); professional contact data (professional email address); authentication metadata (hashed password, MFA token state, session identifiers); voice and session content (voice recordings of client-conversation simulations, advisor → persona transcripts, coaching letters and Solution-generated feedback, performance scores and skill ratings); drill metadata (drill identifiers, timestamps, scenarios); technical telemetry (IP address, browser user-agent, error logs).
- Special categories of Personal Data
- None processed by design. The Solution does not perform emotion recognition in the workplace within the meaning of Article 5(1)(f) of the EU AI Act.
- Duration of the processing
- Until deletion by the Authorized User or by the Customer administrator, and at the latest at the end of the Agreement followed by the deletion procedure described in Section 5 below and in the Security Policy (typically within 30 days; backups purged within 90 days).
4. Controller's undertakings
The Controller undertakes to:
- Ensure that the collection and transmission of Personal Data to the Processor comply with the Applicable Data Protection Legislation.
- Provide the Processor with any information necessary for the performance of this DPA.
- Document in writing all instructions concerning the processing carried out by the Processor.
- Ensure, beforehand and throughout the duration of the Agreement, that the Processor complies with the obligations of the Applicable Data Protection Legislation.
5. Processor's undertakings
The Processor undertakes to:
- Process Personal Data solely for the performance of the Agreement and, in general, only on the Controller's documented instructions. The Parties agree to negotiate in good faith if the Processor must use resources other than, or in addition to, those required to perform the Services, and thus incurs specific costs, owing to the Controller's instructions regarding the processing of Personal Data. The Processor will inform the Controller without undue delay if, in the Processor's opinion, an instruction given by the Controller constitutes an infringement of the Applicable Data Protection Legislation.
- Limit access to Personal Data to its staff members subject to an obligation of confidentiality.
- Implement appropriate technical and organisational measures, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of Data Subjects, to ensure a level of security appropriate to the risk. These measures are described in our Security Policy; the Controller acknowledges and agrees that such measures are sufficient to protect the Personal Data and to ensure compliance with the Applicable Data Protection Legislation.
- Notify Personal Data Breaches to the Controller in writing without undue delay after becoming aware of such Breach, together with any useful information that would enable the Controller, where legally required, to notify the competent supervisory authority and the Data Subjects. Where it is not possible to provide all relevant information at the same time, the initial notification will contain the information then available and further information will, as it becomes available, be provided without undue delay. The initial breach contact is security@sparred.ai.
- Maintain a list of Sub-processors involved in the processing of Personal Data (Section 7 below). The Sub-processors listed in Section 7 are presumed to be authorized by the Controller. The Processor will inform the Controller of any change to this list before such change is made, in order to give the Controller the opportunity to object within ten (10) calendar days following receipt of such notification, it being understood that such objection will only be valid if the Controller provides objective written justification explaining its position and relating to the capacity of the subsequent Sub-processor to comply with the obligations of the Applicable Data Protection Legislation. The Processor remains fully liable to the Controller for the performance of the Sub-processors' obligations relating to the processing of Personal Data.
- Assist the Controller, to the extent possible, in meeting its obligations to respond to requests from Data Subjects to exercise their rights, taking into account the nature of the processing and the information available to the Processor.
- At the Controller's choice, delete or return all Personal Data to the Controller at the end of the Agreement and delete existing copies, unless otherwise required or permitted by applicable law. Returned data is provided in a structured, commonly used, and machine-readable format (CSV or JSON, depending on the data category).
- Make available to the Controller (or to another auditor appointed by the Controller), at the Controller's expense and request, all information necessary to demonstrate compliance with the obligations set forth in this DPA, and submit its Personal Data processing facilities, data files, and documentation needed for processing the Controller's Personal Data to audits, subject to compliance by the Controller with (i) one month's prior written notice and (ii) a limit of one audit per year. The audit will be conducted during the Processor's normal business hours and will not unreasonably disrupt the Processor's performance of its obligations under the Agreement or the Processor's business in general. The Controller will provide the Processor with a copy of the audit report at no additional cost to the Processor, within a reasonable time following receipt of the audit report.
- Cooperate and assist the Controller, to the extent possible and at the Controller's request, in the performance of a Data Protection Impact Assessment ("DPIA") where such DPIA is legally required.
6. International transfers
The Controller gives general consent to transfers of Personal Data outside the European Economic Area ("EEA") by the Processor, provided that such transfers are subject to the appropriate safeguards set out in Chapter V of the GDPR (including, where applicable, the European Commission's Standard Contractual Clauses and the UK Addendum, as well as any Transfer Impact Assessment required). The Sub-processor list in Section 7 below indicates the relevant transfer mechanism for each Sub-processor.
7. List of Sub-processors
As of the last-updated date at the top of this page, the following Sub-processors are engaged by the Processor for the provision of the Services.
| Sub-processor | Entity / address | Activity | Country of processing | Transfer mechanism | DPA |
|---|---|---|---|---|---|
| OpenAI Ireland Limited | 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, D01 YC43, Ireland | Eval judge for internal test fixtures only — synthetic data, no Authorized User Personal Data | United States | SCCs | OpenAI DPA |
| Fireworks AI, Inc. | 539 Bryant Street, Suite 100, San Francisco, CA 94107, USA [to confirm] | Post-drill analysis | United States (EU dedicated deployment available on request) | SCCs | Fireworks Privacy & DPA |
| Google LLC | 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA [to confirm — EU customers may contract via Google Ireland Limited, Gordon House, Barrow Street, Dublin 4] | Live-drill voice-to-voice, coach, and intro-briefing voice synthesis (all languages) | United States (no EU data residency) | SCCs | Google Cloud DPA [to confirm exact instrument] |
| Supabase, Inc. | 970 Toa Payoh North #07-04, Singapore 318992 (operating via Supabase Pte. Ltd.); EU hosting on AWS Frankfurt [to confirm] | Authentication, PostgreSQL database, object storage | Germany (EU) | Intra-EEA hosting; SCCs for any extra-EEA support operations | Supabase DPA |
| LiveKit, Inc. | 1 Bluxome Street, Suite 410, San Francisco, CA 94107, USA [to confirm] | WebRTC media transport (SFU); session recording via Egress API to Prestance Lab-controlled storage |
Germany (EU, eu-central region); US transit for
observability
|
Intra-EEA media; SCCs for US-side observability data | LiveKit DPA |
| Fly.io, Inc. | 2261 Market Street #4990, San Francisco, CA 94114, USA [to confirm] | Application hosting (backend, voice-agent worker, manager dashboard) | France (Paris cdg region) |
Intra-EEA hosting; SCCs for any US-side operational data | Fly.io DPA |
| Langfuse GmbH | Charlottenstrasse 2, 10969 Berlin, Germany [to confirm] | LLM observability | Germany (EU) | Intra-EEA | Langfuse DPA |
| PostHog, Inc. | 2261 Market Street #4008, San Francisco, CA 94114, USA [to confirm] | Product analytics, logging, and error tracking | Germany (EU, eu.i.posthog.com) |
Intra-EEA hosting; SCCs for any US-side support operations | PostHog DPA |
8. Updates to this DPA
Pursuant to GTC §2.7, Prestance Lab may update this DPA. Material changes will be notified to active Customers at least thirty (30) days in advance, unless a shorter period is required by law or to address a security risk. Changes to the Sub-processor list follow the procedure set out in Section 5 above.
9. Contact
- Data Protection contact: privacy@sparred.ai
- Security incidents and Personal Data Breaches: security@sparred.ai