Data Processing Agreement
Effective April 9, 2026
1. Definitions
Any capitalized terms used but not defined in this DPA have the meaning provided in the Agreement.
“Applicable Data Protection Law” means the laws applicable to the EEA and Switzerland (including the GDPR and the Swiss FADP), the UK Data Protection Act 2018 and the UK GDPR, California Privacy Law, and any other laws applicable to Processor’s Processing of Controller Data.
“California Privacy Law” means the CCPA as amended by the CPRA, and any implementing regulations.
“Controller” means Customer.
“Controller Data” means Personal Data Processed by Processor on behalf of Customer pursuant to the Agreement.
“Personal Data” means information relating to an identified or identifiable natural person.
“Processing” means any operation or set of operations performed upon Personal Data, whether or not by automatic means.
“Processor” means Sparky AI, Inc. d/b/a ArchetypeID and its Affiliates.
“Sub-processor” means any third-party data processor engaged by Processor who receives Personal Data from Processor for processing on behalf of Controller.
2. Purpose
Controller and Processor have entered into the Agreement, under which Controller is granted a right to access and use the Services. The Parties are entering into this DPA to ensure that the Processing of Controller Data is done in a manner compliant with Applicable Data Protection Law.
3. Authority and Roles
3.1 Roles of the Parties. Customer is the Controller and ArchetypeID is the Processor acting on behalf of Customer. For purposes of California Privacy Law, ArchetypeID acts as a Service Provider. ArchetypeID will only use Controller Data to provide the Services and will not sell, disclose, or otherwise process any Controller Data for any purpose other than providing the Services. Any Controller Data utilized for product development or AI model training must be strictly aggregated and de-identified so it cannot be linked to any individual Data Subject or the Customer. ArchetypeID shall not use Controller Data for third-party sales or marketing purposes.
3.2 Controller’s Instructions. Customer represents and warrants that it has complied with Applicable Data Protection Law in respect of its Processing of Controller Data and has obtained all consents necessary for Processor to process Controller Data for the purposes described in the Agreement. Customer shall have sole responsibility for the accuracy, quality, and legality of Controller Data.
4. Obligations of Processor
4.1 Confidentiality. Processor restricts access to Controller Data to personnel who need access to meet Processor’s obligations.
4.2 Disclosure to Third Parties. Processor will not disclose Controller Data to third parties except as permitted by this DPA or the Agreement, or as required by a competent governmental authority.
4.3 Retention. Processor will retain Controller Data only for as long as necessary for the Permitted Purpose or as required by law. Upon Customer’s written request or termination of the Agreement, Processor will destroy or return the Controller Data.
4.4 Data Subject Requests. Processor will promptly notify Controller in writing of any complaints, questions, or requests received from Data Subjects or Regulators, and provide commercially reasonable assistance to fulfill Data Subject rights requests.
4.5 Security. Processor will implement and maintain appropriate technical, physical, and administrative measures to protect Controller Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, utilizing state-of-the-art encryption and zero-trust architectures where applicable.
5. Data Breach
If Processor becomes aware of any Data Security Breach impacting Controller Data, Processor will notify Customer without undue delay, and in no event later than seventy-two (72) hours after confirmation. Processor will investigate the Data Breach, provide relevant information, and take reasonable steps to mitigate the effects.
6. Audits
Customer may audit Processor’s compliance with this DPA up to once per calendar year. The audit will be conducted by an independent third party reasonably acceptable to Processor. Customer must submit a detailed proposed audit plan at least thirty (30) business days in advance. Audits must be conducted during normal business hours, and Customer shall bear the costs unless a material breach is discovered.
7. Use of Sub-Processors
7.1 General Consent. Customer acknowledges that Processor may appoint Sub-processors, provided that such Sub-processors are bound by written agreements requiring them to protect Controller Data to a standard consistent with this DPA.
7.2 Sub-Processor List. The current roster of approved Sub-processors is available at https://archetypeid.ai/legal/sub.
7.3 Objection to New Sub-Processors. Processor will provide notice of any new Sub-processor via updates to the URL above. Customer may object to a new Sub-processor within ten (10) days based on reasonable data protection grounds. If the parties cannot resolve the objection within sixty (60) days, Customer may discontinue the use of the affected Services.
8. International Transfers
To the extent Customer’s use of the Services involves a Restricted Transfer of Controller Data originating from the EEA, Switzerland, or the UK to a country not recognized as providing an adequate level of protection, the applicable Standard Contractual Clauses (SCCs) approved by the European Commission, the Swiss FDPIC, and/or the UK ICO shall be incorporated by reference and apply to such transfers, with Customer as the “Data Exporter” and ArchetypeID as the “Data Importer.”
9. Limitation of Liability
Each Party’s liability arising out of or related to this DPA shall be subject to the exclusions and limitations of liability set forth in the Master Services Agreement (MSA).
10. Miscellaneous
This DPA shall be governed by and construed in accordance with the governing law and jurisdiction provisions in the Agreement. This DPA may be executed in counterparts. If any provision is deemed invalid or unenforceable, the remaining provisions shall remain in full force and effect.
Schedule 1 — Details of Processing
Categories of Data Subjects: Authorized Users of the Customer’s account; employees, contractors, or agents of the Customer; and individuals whose data is explicitly uploaded by the Customer into the platform to generate Virtual Twins or Synthetic Focus Groups.
Types of Personal Data Transferred: account registration data (name, business email, IP address, login credentials); demographic information, behavioral traits, survey responses, or other text/multimodal inputs determined by the Controller. The Acceptable Use Policy strictly prohibits Controller from uploading data to create unauthorized digital replicas of specific, identifiable living individuals.
Nature and Purpose of Processing: Processor will Process Controller Data solely to provide the behavioral simulation, analytics, and platform Services and to provide technical support and account management. Any utilization of data for proprietary AI model training or optimization will be strictly aggregated and de-identified.
Duration of the Processing: the Term of the Agreement, plus the period from the expiry of such Term until the secure deletion of all Controller Data by the Processor in accordance with this DPA.
Contact
Questions about this DPA can be directed to legal@archetypeid.ai, or by mail: Sparky AI, Inc. d/b/a ArchetypeID, 235 Mitchell St SW, Atlanta, GA 30303.