Legal
Data Processing Addendum
Transformation, Co. (formerly Altrix Technologies, Inc.) · Exhibit A to the Master Services & License Agreement
This Data Processing Addendum (“DPA”) forms part of the Master Services & License Agreement (the “Agreement”) between Transformation, Co., a Delaware corporation, operating as “Latent Variables” (“Provider”), and the Customer that is a party to the Agreement (“Customer”). Provider and Customer are each a “party” and together the “parties.” This DPA governs Provider’s Processing of Personal Data on Customer’s behalf in connection with the Services.
Capitalized terms used but not defined in this DPA have the meanings given to them in the Agreement.
1Definitions
1.1 “Agreement” means the Master Services & License Agreement between the parties, together with each Order Form executed under it.
1.2 “Applicable Data Protection Laws” means all laws and regulations applicable to Provider’s Processing of Personal Data under this DPA, including, as and where applicable, the California Consumer Privacy Act as amended by the California Privacy Rights Act and its implementing regulations (“CCPA”); the Colorado Privacy Act; other U.S. state privacy and consumer-protection laws; state laws governing automated decision-making and the use of artificial-intelligence inferences, including those of California, Colorado, and New York; the Health Insurance Portability and Accountability Act of 1996 and the Health Information Technology for Economic and Clinical Health Act, together with their implementing regulations (“HIPAA”); state biometric-privacy and recorded-communications laws, including the Illinois Biometric Information Privacy Act, the Texas Capture or Use of Biometric Identifier Act, and the Washington biometric statute; and, where the optional International-Transfers Module in Section 10 is engaged, the EU General Data Protection Regulation 2016/679 (“GDPR”) and the UK GDPR and Data Protection Act 2018 (“UK GDPR”).
1.3 “Controller” means the natural or legal person that, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. For Personal Data Processed under this DPA, Customer is the Controller (or, where Customer itself acts as a processor for a third party, the relevant Controller’s processor).
1.4 “Customer Data” has the meaning given in the Agreement and includes (a) data Customer provides (roster or directory export, operational context, and template kit); (b) the Interview content, recordings, and transcripts of Customer’s Participants; and (c) the behavioral model and memory derived from them. To the extent Customer Data contains information relating to an identified or identifiable natural person, it constitutes Personal Data under this DPA. Customer owns Customer Data.
1.5 “Data Subject” means the identified or identifiable natural person to whom Personal Data relates. Under this DPA, Data Subjects are primarily Customer’s Participants.
1.6 “Personal Data” means any information relating to an identified or identifiable natural person that is contained in Customer Data and Processed by Provider under the Agreement. “Personal Data” includes “personal information” and “personal data” as those terms are defined under Applicable Data Protection Laws.
1.7 “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored, or otherwise Processed by Provider or a Sub-processor. A Personal Data Breach does not include an unsuccessful attempt or activity that does not compromise the security of Personal Data, including pings, port scans, denial-of-service attacks, or other broadcast attacks on firewalls or networked systems.
1.8 “PHI” or “Protected Health Information” means individually identifiable health information, as defined at 45 C.F.R. § 160.103, that Provider creates, receives, maintains, or transmits on Customer’s behalf where Customer is a covered entity or business associate under HIPAA and PHI is within the scope of an engagement.
1.9 “Processing” (and “Process” and “Processed”) means any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure, transmission, dissemination, restriction, erasure, or destruction.
1.10 “Processor” means the natural or legal person that Processes Personal Data on behalf of the Controller. With respect to Personal Data Processed under this DPA, Provider is the Processor (and a “service provider” under the CCPA).
1.11 “Services” has the meaning given in the Agreement: the Platform together with the managed research and diagnostic services Provider performs under an Order Form, delivered in three parts (Stand-up, Continual Service, and Service on Demand), including Interviews conducted by Juniper.
1.12 “Sub-processor” means any third party engaged by Provider to Process Personal Data on Provider’s behalf in connection with the Services, as further described in Section 6 and listed in Annex B.
1.13 The terms “Interview,” “Participant,” “Wave,” “Campaign,” “Cohort,” “Platform,” “Juniper,” “Standing Read,” “Outputs,” and “Authorized Users” have the meanings given to them in the Agreement.
2Roles and Scope of Processing
2.1 Roles of the parties. As between the parties, Customer is the Controller and Provider is the Processor of Personal Data Processed under the Agreement. Where PHI is within the scope of an engagement, Provider acts as Customer’s Business Associate, and that PHI is governed by the separate Business Associate Agreement between the parties (the “BAA”). In the event of a conflict between this DPA and the BAA with respect to PHI, the BAA controls as to that PHI.
2.2 Customer instructions. Provider shall Process Personal Data only on Customer’s documented instructions, including with respect to international transfers, unless Provider is required to Process by a law to which it is subject, in which case Provider shall (where legally permitted) inform Customer of that requirement before Processing. Customer’s documented instructions are constituted by the Agreement, each Order Form, this DPA, and Customer’s use of and written configurations within the Platform. Customer may issue additional reasonable written instructions consistent with the Agreement.
2.3 Compliance of instructions. Customer is responsible for the lawfulness of Customer Data and of Customer’s instructions, including that Customer has provided all required notices and obtained all consents and legal bases necessary for Provider to Process Personal Data as contemplated by the Agreement. Provider shall promptly inform Customer if, in Provider’s reasonable opinion, an instruction infringes Applicable Data Protection Laws; in such case Provider may suspend performance of the affected instruction until it is confirmed, modified, or withdrawn, without liability for the suspension.
2.4 Scope. This DPA applies to Provider’s Processing of Personal Data for the duration of the Agreement and survives as set out in Section 13.
3Nature and Purpose of Processing
3.1 Nature and purpose. Provider Processes Personal Data to deliver the Services: to conduct AI-conducted, approximately ten-minute one-to-one Interviews with Participants by voice and web; to transcribe and analyze Interview content; to build and maintain the behavioral model and the Standing Read; and to generate the Outputs Customer receives, in each case solely to deliver the contracted engagement. Personal Data is used solely to deliver Customer’s engagement and is not used for Provider’s research, publication, benchmarking, marketing, or product development, and is not shared outside Provider except as expressly permitted by the Agreement and this DPA.
3.2 Details. The categories of Data Subjects and Personal Data, the subject matter, the duration, and the purpose of the Processing are described in Annex A (Details of Processing). The Sub-processors authorized under Section 6 are listed in Annex B (Sub-processor Schedule). The technical and organizational security measures are summarized in Annex C (Technical and Organizational Measures) and set out in full in the Security Exhibit to the Agreement (the “Security Exhibit”).
4Provider Obligations
4.1 Confidentiality of personnel. Provider shall ensure that personnel authorized to Process Personal Data are bound by appropriate obligations of confidentiality (whether contractual or statutory), are subject to background checks before being granted access to systems that hold Customer Data, and complete privacy and security training at onboarding and at least annually thereafter with documented acknowledgment. Access is limited to those personnel who require it to deliver the engagement, under role-based controls consistent with the minimum-necessary standard.
4.2 Security measures. Provider shall implement and maintain appropriate technical and organizational measures designed to protect Personal Data against a Personal Data Breach, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing, as well as the risk to Data Subjects. Those measures are summarized in Annex C and set out in full in the Security Exhibit, and include encryption of Personal Data at rest (AES-256) and in transit (TLS 1.2 or higher); single-tenant isolation with per-tenant encryption keys managed in a cloud key-management service; role-based access controls, multi-factor authentication, and logged and reviewed administrative access; and storage and Processing within the United States only. Provider may update its security measures from time to time, provided that the updates do not materially reduce the overall level of protection.
4.3 Assistance with Data-Subject requests. Taking into account the nature of the Processing, Provider shall provide Customer with reasonable assistance, by appropriate technical and organizational measures and insofar as possible, to enable Customer to respond to requests from Data Subjects to exercise their rights under Applicable Data Protection Laws, as further described in Section 7. If Provider receives such a request directly from a Data Subject, Provider shall, unless legally prohibited, promptly notify Customer and shall not respond to the request itself except on Customer’s documented instructions or as required by law.
4.4 Assistance with DPIAs and consultation. Taking into account the nature of Processing and the information available to Provider, Provider shall provide Customer with reasonable assistance with data protection impact assessments and, where required by Applicable Data Protection Laws, with prior consultation of a supervisory authority, in each case relating to Provider’s Processing under the Agreement.
4.5 Assistance with breach notification. Provider shall provide Customer with reasonable assistance in meeting Customer’s own obligations to notify Personal Data Breaches to supervisory authorities and to affected Data Subjects, as further described in Section 8.
4.6 No legal, clinical, or HR advice. The Services are decision-support and do not constitute legal, clinical, or human-resources advice. Provider does not guarantee any business outcome or any regulatory-compliance result; Customer remains responsible for its own compliance obligations as Controller.
5Individual-Confidentiality and Inference Governance
This Section is a material term of the Agreement and reflects the load-bearing confidentiality promises on which the Services rest.
5.1 Cohort-level reporting only. Leadership-facing views and Outputs delivered to Customer’s leadership are cohort-level only, with a minimum floor of eight (8) Participants per reported group. Provider shall not deliver to leadership any report, metric, or view that would reveal, or that is constructed from a group smaller than, eight Participants.
5.2 Sealed individual transcripts. Individual Interview transcripts and recordings are sealed and are not disclosed to Customer or to any of Customer’s personnel, except as expressly permitted under Section 5.4.
5.3 Identities withheld. Provider shall withhold from Customer (the employer) the identities of individual Participants and the attribution of any individual response, by contract and by technical access control. Identity is bound to Interview content only internally, under access control, for the limited purpose of operating the Services.
5.4 Quotation by per-quote consent. A free-text quotation from a Participant reaches leadership only with the per-quote consent of the person who said it. Absent that specific consent, no individual quotation is surfaced in any Output.
5.5 Inference governance. Inferences are drawn only from material the Participant produced voluntarily during an Interview. Customer shall not, and shall ensure that its personnel do not, use any inference, Output, or other product of the Services as a basis for any compensation, promotion, scheduling, or discipline decision concerning an individual, and Provider does not design or represent the Services for any such use. The Services are built to operate consistently with state laws governing automated decision-making and the use of artificial-intelligence inferences, including those of California, Colorado, and New York.
5.6 No voiceprints or biometric identifiers. Recordings and transcripts are used solely to produce the engagement’s analysis. Provider shall not use voice recordings to create voiceprints or other biometric identifiers, and the program operates consistently with applicable federal and state laws governing recorded communications and biometric data. Each Interview opens with a statement of purpose and a recorded consent, participation is voluntary, and explicit recorded-communications and biometric-style consent is obtained where required.
6Sub-processing
6.1 General authorization. Customer provides a general written authorization for Provider to engage the Sub-processors listed in Annex B to Process Personal Data in connection with the Services. The list in Annex B is maintained as a living schedule and is not closed.
6.2 Notice of new Sub-processors and right to object. Provider shall give Customer advance written notice (which may be by email or through the Platform) before authorizing any new Sub-processor that would have access to Personal Data. Customer may object to a new Sub-processor on reasonable data-protection grounds within fifteen (15) days of the notice by providing written notice describing the grounds. The parties shall work in good faith to resolve the objection. If the parties cannot resolve it within a reasonable period, Customer may, as its sole and exclusive remedy, terminate the affected portion of the Services by written notice, with a pro-rata refund of any prepaid fees for the terminated and unused portion.
6.3 Flow-down of obligations. Before a Sub-processor Processes Personal Data, Provider shall enter into a written agreement with the Sub-processor that imposes data-protection obligations that are, in substance, no less protective than those in this DPA and appropriate to the Sub-processor’s Processing, including a Business Associate Agreement or equivalent data-protection agreement with each Sub-processor that creates, receives, maintains, or transmits PHI on Provider’s behalf. Provider remains responsible to Customer for each Sub-processor’s performance of its data-protection obligations.
6.4 No model training on Customer Data. Customer Data, including Interview recordings, transcripts, and the memory graph, is not used to train or fine-tune any model, whether Provider’s or a Sub-processor’s. Model inference is performed through enterprise application programming interfaces, not consumer products, under terms that contractually exclude Customer Data from model training. PHI is never used for model development under any circumstance.
6.5 Zero-retention where offered. Where the relevant model provider offers it, Provider uses zero-retention Processing, so that prompts and outputs are not persisted by that provider beyond the moment of inference. Where zero-retention is not offered, retention by the provider is limited to what is required to deliver the Services and is governed by the flow-down obligations in Section 6.3. Zero-retention is provided where available and is not an unconditional warranty.
7Data-Subject Rights
7.1 Assistance. Provider shall assist Customer, insofar as reasonably possible and taking into account the nature of the Processing, in fulfilling Customer’s obligation to respond to Data-Subject requests to exercise rights of access, correction, deletion, restriction, portability, objection, and, where applicable, rights relating to automated decision-making, under Applicable Data Protection Laws.
7.2 Deletion requests. Provider shall process Participant deletion requests, when directed by Customer or received and confirmed under the agreed process, within fifteen (15) days, subject to any retention required by law and to the constraints of de-identified or aggregated data from which the relevant individual can no longer be identified.
7.3 Routing of requests. Where Provider receives a Data-Subject request directly, Provider shall, unless prohibited by law, route it to Customer and shall not independently respond except on Customer’s documented instructions.
8Personal Data Breach
8.1 Notification. Provider shall notify Customer of a confirmed Personal Data Breach affecting Customer’s Personal Data without undue delay after becoming aware of it, and in any event within thirty (30) calendar days of discovery. A potential incident is triaged within twenty-four (24) hours of detection and a formal investigation begins to establish its nature, scope, and cause.
8.2 Contents of notice. The notice shall, to the extent then known and as information becomes available, describe the nature of the Personal Data Breach, including where possible the categories and approximate number of Data Subjects and records concerned; the likely consequences; the measures taken or proposed to address it and to mitigate its adverse effects; and a point of contact from whom further information may be obtained. Provider may provide information in phases as the investigation proceeds.
8.3 Cooperation and mitigation. Provider shall cooperate with Customer and take reasonable steps to investigate, contain, mitigate, and remediate the Personal Data Breach, including credential rotation, access revocation, and forensic analysis as appropriate, and shall document the investigation and the mitigation undertaken. Where PHI is in scope, breach notification is also governed by the BAA and Provider’s Breach Notification Policy consistent with 45 C.F.R. §§ 164.400–414 and the HITECH Act.
8.4 No admission. Provider’s notification of or response to a Personal Data Breach is not an acknowledgment of fault or liability.
9Deletion and Return of Personal Data
9.1 Deletion on termination. On termination or expiration of the Agreement, Provider shall securely delete Customer Data and Personal Data held by Provider within thirty (30) calendar days, unless a written alternative is agreed (including a port-over to Customer’s own environment) or unless retention is required by law.
9.2 Backups. Encrypted backups containing Personal Data are purged within ninety (90) calendar days of termination.
9.3 Certificate of destruction. Provider shall provide a certificate of destruction on Customer’s written request.
9.4 Export and portability. During the engagement and on its conclusion, Customer may export Customer Data and Outputs. Structured data is provided in open, non-proprietary formats (for example, CSV or Parquet) and analytical Outputs are provided as standard documents. No proprietary format is required to read or retain what Customer exports, and export does not depend on continuation of the engagement.
10International Transfers
10.1 United States only. In the standard deployment, Personal Data is stored and Processed exclusively in the United States, within United States AWS regions, and all Sub-processors Process Personal Data exclusively in United States regions. The parties do not contemplate the transfer of Personal Data outside the United States under the standard engagement.
10.2 Optional EU/UK Transfers Module — use only if EU or UK personal data is in scope. The following Section 10.3 applies only where Personal Data subject to the GDPR or UK GDPR is within the scope of an engagement. It does not assert that Provider conducts active operations in the European Union or the United Kingdom. If no EU or UK Personal Data is in scope, this Module does not apply.
10.3 Where EU or UK Personal Data is transferred to Provider in a country that does not benefit from an adequacy decision, the parties agree that the transfer is governed by the appropriate transfer mechanism, which is hereby incorporated by reference and completed as follows:
- Standard Contractual Clauses (EU). For transfers subject to the GDPR, the Standard Contractual Clauses approved by Commission Implementing Decision (EU) 2021/914 (the “SCCs”) are incorporated by reference, with Module Two (Controller to Processor) applying (or Module Three, Processor to Processor, where Customer is itself a processor). For the purposes of the SCCs: Customer is the data exporter and Provider is the data importer; the optional docking clause applies; in Clause 9, Option 2 (general written authorization) applies with the change-notice period in Section 6.2; in Clause 11, the optional independent-dispute-resolution language does not apply; in Clause 17, the governing law is the law of the Republic of Ireland; in Clause 18, the forum is the courts of Ireland; and Annexes I, II, and III to the SCCs are populated by Annexes A, C, and B to this DPA, respectively.
- International Data Transfer Addendum (UK). For transfers subject to the UK GDPR, the UK International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner (“IDTA Addendum”) is incorporated by reference, with the SCCs above forming the approved addendum, Tables 1 to 3 populated by the corresponding Annexes to this DPA, and Table 4 indicating that neither party may end the IDTA Addendum as set out in its Section 19.
- Precedence and updates. Where there is a conflict between this DPA and the SCCs or IDTA Addendum with respect to in-scope EU or UK Personal Data, the SCCs or IDTA Addendum control. If the relevant transfer mechanism is invalidated or replaced, the parties shall work in good faith to implement an alternative lawful mechanism.
11CCPA Module (Optional — California)
This Section applies to Personal Data subject to the CCPA.
11.1 Service-provider status. With respect to Personal Data subject to the CCPA, Provider is a “service provider” and Customer is a “business,” as those terms are defined under the CCPA. Provider Processes such Personal Data solely to perform the Services and for the business purposes specified in the Agreement and this DPA.
11.2 No sale or sharing. Provider shall not sell or share (as those terms are defined under the CCPA) Personal Data, and shall not retain, use, or disclose Personal Data for any purpose other than the business purposes specified in the Agreement, or as otherwise permitted by the CCPA, including outside the direct business relationship between the parties.
11.3 No combining. Provider shall not combine Personal Data received from Customer with personal information Provider receives from or on behalf of another person, or collects from its own interaction with a consumer, except as permitted by the CCPA.
11.4 Certification and assistance. Provider certifies that it understands and will comply with the restrictions in this Section. Provider shall assist Customer in responding to verifiable consumer requests and shall, on notice, comply with deletion, correction, and opt-out instructions to the extent applicable to Provider’s Processing.
12Audits and Security Assurance
12.1 Audit and evidence. On Customer’s reasonable written request, no more than once per twelve-month period (except following a Personal Data Breach affecting Customer’s Personal Data or where required by a supervisory authority), and subject to a non-disclosure agreement, Provider shall make available to Customer the information reasonably necessary to demonstrate compliance with this DPA. Provider is undergoing independent examination toward SOC 2 Type II attestation; Provider shall, under NDA, make available its current SOC 2 examination status, interim evidence (including the control-environment description and, where applicable, a bridge letter), and the SOC 2 Type II report when issued.
12.2 On-site audit. Where the information described in Section 12.1, together with Provider’s then-current third-party reports, is insufficient to demonstrate compliance, Customer may conduct, or mandate an independent auditor bound by confidentiality to conduct, an audit of Provider’s relevant controls during normal business hours, on reasonable advance notice, in a manner that does not unreasonably disrupt Provider’s operations or compromise the confidentiality of other customers’ data. The parties shall agree in advance on scope, timing, and any reasonable cost allocation.
12.3 Security questionnaires. Provider shall provide reasonable support for Customer’s security review, including a completed security questionnaire (such as SIG Lite or CAIQ) on request, a security overview, the current Sub-processor list, and a certificate of cyber-liability insurance on request.
13Order of Precedence; Term; General
13.1 Order of precedence. This DPA forms part of and is subject to the Agreement. In the event of a conflict between this DPA and the body of the Agreement with respect to the Processing of Personal Data, this DPA controls. With respect to PHI, the BAA controls over this DPA. With respect to in-scope EU or UK Personal Data, the SCCs or IDTA Addendum control over this DPA as set out in Section 10. The Order Form controls over the Agreement on commercial specifics.
13.2 Term and survival. This DPA takes effect on the effective date of the Agreement and remains in effect for as long as Provider Processes Personal Data under the Agreement. Provisions that by their nature should survive termination (including Sections 5, 9, and 13) survive.
13.3 Liability. Each party’s liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement.
13.4 Changes in law. If a change in Applicable Data Protection Laws requires amendment of this DPA, the parties shall negotiate in good faith to make the necessary amendments.
13.5 Governing law. This DPA is governed by the law of the State of Delaware, without regard to its conflicts-of-law rules, except where Applicable Data Protection Laws or an incorporated transfer mechanism require otherwise.
13.6 Severability and counterparts. If any provision of this DPA is held invalid or unenforceable, the remainder remains in full force and effect. This DPA may be executed in counterparts, including by electronic signature.
13.7 Notices. Data-protection notices to Provider may be sent to legal@latentvariables.com; notices to Customer may be sent to the contact stated in the Agreement or the Order Form.
Annex A — Details of Processing
A.1 Subject matter of the Processing. Provider’s delivery of the Services under the Agreement, namely the conduct, transcription, and analysis of AI-conducted Interviews and the generation of Outputs for Customer.
A.2 Duration of the Processing. For the term of the Agreement and until deletion of Customer Data in accordance with Section 9.
A.3 Nature and purpose of the Processing. To conduct Interviews by voice and web; to transcribe and analyze Interview content; to build and maintain the behavioral model and the Standing Read; and to generate cohort-level Outputs, in each case solely to deliver Customer’s engagement.
A.4 Categories of Data Subjects. Customer’s workforce, namely the Participants invited to or completing Interviews (and, in a white-label engagement, the Partner’s customer’s workforce). May also include Customer’s named lead and Authorized Users.
A.5 Categories of Personal Data.
- Identity and contact information from the roster or directory export (for example, name, work email, role, department, location), linked to Interview content only internally and under access control;
- Voice recordings of Interviews;
- Interview transcripts;
- The derived behavioral model and memory graph;
- Operational context Customer supplies to ground the work;
- Access and audit metadata (for example, identifiers, timestamps, and actions of Authorized Users).
A.6 Special categories of Personal Data. None are required for the Services. Special categories of Personal Data (including, where PHI is in scope, health information) are Processed only where applicable to a specific engagement and, in the case of PHI, only under the BAA. Participants may voluntarily disclose sensitive information during an Interview; such information is Processed under the confidentiality and inference-governance terms of Section 5.
A.7 Frequency of the Processing. On a continuous basis for the term, across Waves within each Campaign.
A.8 Recipients. Provider’s authorized personnel under role-based access control, and the Sub-processors listed in Annex B.
A.9 Retention. Default transcript retention is twelve (12) months. Customer Data is deleted within thirty (30) days of termination, with backups purged within ninety (90) days, as set out in Section 9. Participant deletion requests are processed within fifteen (15) days.
Annex B — Sub-processor Schedule
Provider engages the Sub-processors below to Process Personal Data in connection with the Services. This Schedule is maintained as a living list and is not closed. New Sub-processors are subject to the advance change-notice and right-to-object process in Section 6.2. All listed Sub-processors Process Personal Data exclusively in United States regions, and Provider maintains a Business Associate Agreement or equivalent data-protection terms with every Sub-processor that touches Customer Data or other personal information.
| Sub-processor | Service provided | Location | Safeguards |
|---|---|---|---|
| Amazon Web Services, Inc. | Primary cloud infrastructure (compute, storage, networking); single-tenant per-Customer account and VPC with per-tenant encryption keys | United States | SOC 2 Type II; ISO 27001; HIPAA; FedRAMP. BAA / data-protection terms in place. |
| Google LLC (Google Cloud) | Cloud infrastructure and platform services supporting the Platform | United States | SOC 2 Type II; ISO 27001; HIPAA. BAA / data-protection terms in place. |
| OpenAI, L.L.C. | Voice interview layer and language-model inference (memory graph and Output generation) via enterprise API | United States | Enterprise terms that contractually exclude Customer Data from model training; no training on Customer Data; zero-retention where offered; SOC 2 Type II; HIPAA BAA in place. |
| Langfuse, Inc. | LLM observability, tracing, and quality monitoring of model inputs and outputs, which may include Interview-derived content | United States | BAA / data-protection terms in place. |
| Twilio Inc. | Telephony and messaging: placing Interview calls and sending invitations and reminders (processes call connectivity, audio in transit, and phone numbers) | United States | SOC 2 Type II; BAA / data-protection terms in place. |
| Twilio SendGrid | Transactional email (Interview invitations and notices); processes names and email addresses | United States | BAA / data-protection terms in place. |
| Postmark (ActiveCampaign, LLC) | Transactional email (Interview invitations and notices); processes names and email addresses | United States | BAA / data-protection terms in place. |
| PostHog, Inc. | Product analytics and usage monitoring of the Platform; processes usage events and identifiers | United States | BAA / data-protection terms in place. |
The current Sub-processor list is available to Customer on request and is maintained as a living schedule with advance change-notice and a right to object under Section 6.2.
Annex C — Technical and Organizational Measures
This Annex summarizes the technical and organizational measures Provider maintains. The full measures are set out in the Security Exhibit to the Agreement, which is incorporated by reference and controls in the event of any inconsistency in level of detail.
C.1 Encryption. Personal Data is encrypted at rest using AES-256 and in transit using TLS 1.2 or higher. No unencrypted Customer Data is stored or transmitted. Encryption keys are managed in AWS Key Management Service, isolated per tenant, access-controlled, and rotated on a defined schedule; workforce members cannot export key material.
C.2 Tenant isolation. Each Customer is provisioned in a dedicated, single-tenant environment bounded by a dedicated account and virtual private cloud with its own data stores. Customer Data is not commingled with that of any other customer, and each tenant is encrypted under its own keys.
C.3 Access controls. Role-based access controls limit every account to the minimum data and functions required, consistent with the minimum-necessary standard. Multi-factor authentication is enforced for all administrative and production access and for Authorized-User access to the web interface; single sign-on via SAML 2.0 is available. Sessions re-authenticate after a defined period of inactivity. Administrative privileges are granted sparingly, logged, and reviewed; there are no shared administrator accounts.
C.4 Audit logging. Access to electronic data is logged with user identity, timestamp, action, and the records touched, with a retained audit trail. Where PHI is in scope, logs are retained for at least six years per 45 C.F.R. § 164.316(b)(2).
C.5 Network and perimeter security. Production sits behind firewalls, a web application firewall, and network segmentation, with no Customer-data store exposed to the public internet. Only required services are exposed and all ingress is over TLS with certificate pinning at API endpoints. Production is separated from development and test environments; Customer Data is never used in non-production environments.
C.6 Personnel and administrative controls. A designated Privacy Officer and Security Officer oversee the program. Background checks precede access to systems holding Customer Data. Privacy and security training is completed at onboarding and at least annually. A documented risk analysis is conducted at least annually, and a written sanctions policy governs non-compliance.
C.7 Resilience and recovery. Provider maintains multi-zone redundancy with automatic failover, an uptime target of 99.9% with monitoring and alerting, disaster-recovery objectives designed for a recovery-time objective under four hours and a recovery-point objective under one hour, and encrypted backups with periodic restore testing. (Resilience and recovery objectives are design targets and commercially reasonable measures, not absolute guarantees.)
C.8 Vulnerability and threat management. Provider conducts vulnerability scanning and penetration testing, operates intrusion detection and prevention, deploys endpoint detection and response, and maintains an Incident Response Plan aligned with NIST SP 800-61.
C.9 Secure deletion. Customer Data is securely deleted on contract termination per Section 9, with backups purged within ninety (90) days and a certificate of destruction available on request.
C.10 Model-inference controls. Model inference is performed through enterprise APIs under terms that exclude Customer Data from model training; zero-retention Processing is used where the provider offers it; inference is performed in the United States; and Customer Data is never used to train or fine-tune any model.
© Transformation, Co. All rights reserved.