DECCAN.AI, INC.
DATA PROCESSING ADDENDUM

Last Updated: May 18, 2026

This Data Processing Addendum ("DPA") forms part of the written or electronic agreement, order form, statement of work, terms of service, master services agreement, or other agreement between Deccan.ai, Inc. ("Deccan AI") and the customer or other entity receiving the Services ("Customer") (the "Agreement"). This DPA applies to Deccan AI’s Processing of Customer Personal Data in connection with the Services.

This DPA is intended to address Deccan AI’s obligations as a Processor, service provider, contractor, or equivalent role under Applicable Data Protection Laws, including where applicable the GDPR, UK GDPR, Swiss FADP, and U.S. state privacy laws. Except as modified by this DPA, the Agreement remains in full force and effect. If there is a conflict between this DPA and the Agreement regarding the Processing of Customer Personal Data, this DPA controls.

1. DEFINITIONS

"Affiliate" means any entity that directly or indirectly controls, is controlled by, or is under common control with a Party.

"Applicable Data Protection Laws" means all privacy, data protection, data security, cybersecurity, breach notification, electronic communications, and similar laws and regulations applicable to the Processing of Customer Personal Data under the Agreement, including, where applicable, the EU GDPR, UK GDPR, Swiss FADP, U.S. state privacy laws, and implementing regulations.

"Controller" has the meaning given under Applicable Data Protection Laws and includes, where applicable, a "business" under U.S. state privacy laws.

"Customer Personal Data" means Personal Data that Customer provides or makes available to Deccan AI, or that Deccan AI Processes on behalf of Customer, in connection with the Services.

"Data Subject" means the identified or identifiable natural person to whom Customer Personal Data relates and includes, where applicable, a "consumer" under U.S. state privacy laws.

"De-identified Data" means data that cannot reasonably be used to infer information about, or otherwise be linked to, an identified or identifiable individual, provided that Deccan AI implements reasonable measures to maintain and use the data only in de-identified form and does not attempt to re-identify the data except as permitted by law.

"GDPR" means Regulation (EU) 2016/679. "UK GDPR" means the GDPR as incorporated into UK law under the UK Data Protection Act 2018.

"Personal Data" has the meaning given under Applicable Data Protection Laws and includes "personal information" under U.S. state privacy laws.

"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.

"Process" or "Processing" means any operation performed on Customer Personal Data, including collection, access, receipt, use, storage, disclosure, transmission, organization, structuring, adaptation, alteration, retrieval, consultation, annotation, labeling, analysis, deletion, or destruction.

"Processor" has the meaning given under Applicable Data Protection Laws and includes, where applicable, a "service provider," "contractor," or equivalent role under U.S. state privacy laws.

"Restricted Transfer" means a transfer of Customer Personal Data from the EEA, UK, or Switzerland to a country that does not provide an adequate level of protection under Applicable Data Protection Laws.

"SCCs" means the European Commission Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, as amended or replaced from time to time.

"Subprocessor" means any third party appointed by or on behalf of Deccan AI to Process Customer Personal Data in connection with the Services.

2. SCOPE AND ROLES

2.1 Scope. This DPA applies only to Deccan AI’s Processing of Customer Personal Data on behalf of Customer in connection with the Services.

2.2 Roles. As between the Parties, Customer is the Controller and Deccan AI is the Processor with respect to Customer Personal Data, unless the Agreement or applicable Order Form expressly states otherwise. For U.S. state privacy laws, Deccan AI acts as Customer’s service provider, contractor, processor, or equivalent role.

2.3 Customer Responsibility. Customer is responsible for determining the purposes and means of Processing, providing legally sufficient notices, obtaining required consents, establishing a valid legal basis for Processing, and ensuring that Customer is entitled to provide Customer Personal Data to Deccan AI for Processing under the Agreement.

2.4 Deccan AI Responsibility. Deccan AI shall Process Customer Personal Data only in accordance with this DPA, the Agreement, applicable Order Forms, documented instructions from Customer, and Applicable Data Protection Laws.

3. Processing Instructions and Purpose Limitation

3.1 Documented Instructions. Customer instructs Deccan AI to Process Customer Personal Data as necessary to provide, secure, support, maintain, improve, and perform the Services, as described in the Agreement, applicable Order Form, Annex A, and Customer’s documented instructions.

3.2 No Unauthorized Processing. Deccan AI shall not Process Customer Personal Data for any purpose other than providing the Services or as otherwise expressly permitted by Customer in writing, this DPA, or Applicable Data Protection Laws.

3.3 Unlawful Instructions. Deccan AI shall promptly inform Customer if, in Deccan AI’s reasonable opinion, an instruction infringes Applicable Data Protection Laws, unless prohibited by law.

3.4 AI-Specific Restrictions. Deccan AI shall not use Customer Personal Data for model training, model fine-tuning, foundation model development, benchmarking, product improvement, research, analytics unrelated to the Services, or creation of reusable datasets unless expressly authorized in the Agreement, Order Form, or Customer’s written instructions.

3.5 De-identified and Aggregated Data. Deccan AI may Process De-identified Data or aggregated data only to the extent permitted by the Agreement and Applicable Data Protection Laws. Deccan AI shall not attempt to re-identify De-identified Data except as permitted by law and Customer’s written instructions.

4. U.S. State Privacy Law Requirements

4.1 Service Provider / Contractor Commitments. To the extent U.S. state privacy laws apply, Deccan AI shall Process Customer Personal Data only for the limited and specified business purpose of providing the Services.

4.2 Prohibited Uses. Deccan AI shall not: (a) sell or share Customer Personal Data; (b) retain, use, or disclose Customer Personal Data outside the direct business relationship between Deccan AI and Customer; (c) retain, use, or disclose Customer Personal Data for any purpose other than performing the Services or as otherwise permitted by Applicable Data Protection Laws; (d) combine Customer Personal Data with Personal Data received from another source except as permitted by Applicable Data Protection Laws and Customer’s documented instructions; or (e) use Customer Personal Data for targeted advertising, profiling, or Deccan AI’s independent commercial purposes.

4.3 Same Level of Protection. Deccan AI shall provide at least the same level of privacy protection for Customer Personal Data as required of Customer under Applicable Data Protection Laws, to the extent applicable to Deccan AI’s role and Processing.

4.4 Compliance Monitoring. Customer may take reasonable and appropriate steps to ensure that Deccan AI’s Processing of Customer Personal Data is consistent with Customer’s obligations under Applicable Data Protection Laws, including through the audit and information rights in Section 12.

4.5 Inability to Comply. Deccan AI shall notify Customer if Deccan AI determines that it can no longer meet its obligations under this DPA or Applicable Data Protection Laws. Customer may take reasonable and appropriate steps to stop and remediate unauthorized Processing.

5. Confidentiality and Personnel Controls

5.1 Confidentiality. Deccan AI shall ensure that personnel authorized to Process Customer Personal Data are bound by written confidentiality obligations or are under an appropriate statutory duty of confidentiality.

5.2 Access Limitation. Deccan AI shall restrict access to Customer Personal Data to personnel, contractors, and approved Subprocessors who have a business need to access such data to provide the Services.

5.3 Training. Deccan AI shall provide appropriate privacy, confidentiality, security, and data handling training to personnel with access to Customer Personal Data.

5.4 Contractor and Freelancer Controls. Where contractors, freelancers, reviewers, annotators, or similar personnel support the Services, Deccan AI shall require confidentiality, data-use, security, no-unauthorized-AI-tool-use, and deletion obligations at least as protective as those required under this DPA.

6. Security Measures

6.1 Security Program. Deccan AI shall implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against unauthorized or unlawful Processing and against accidental loss, destruction, damage, alteration, or disclosure.

6.2 Minimum Measures. The measures shall include, as appropriate to the nature of the Services and Customer Personal Data, the technical and organizational measures described in Annex B.

6.3 Updates. Deccan AI may update its security measures from time to time, provided such updates do not materially reduce the overall level of protection for Customer Personal Data.

6.4 Customer Responsibilities. Customer is responsible for securely configuring the Services, managing Customer-controlled accounts and credentials, and using the Services in accordance with the Agreement and documentation.

7. Subprocessors

7.1 Authorization. Customer provides general authorization for Deccan AI to engage Subprocessors to Process Customer Personal Data in connection with the Services, subject to this Section 7.

7.2 Subprocessor List. Deccan AI shall maintain a current list of Subprocessors in Annex C or at a publicly available URL or customer portal identified by Deccan AI. The list shall include the Subprocessor name, location, and nature of Processing.

7.3 Notice of Changes. Deccan AI shall provide notice of new or replacement Subprocessors at least thirty (30) days before authorizing such Subprocessor to Process Customer Personal Data, unless a shorter period is required due to emergency, security, legal, or service continuity reasons.

7.4 Objection. Customer may object to a new Subprocessor on reasonable data protection grounds by notifying Deccan AI within fifteen (15) days after notice. The Parties shall work in good faith to resolve the objection. If the objection is not resolved, Customer may terminate the affected Services to the extent the Services cannot be provided without the objected-to Subprocessor.

7.5 Subprocessor Obligations. Deccan AI shall enter into a written agreement with each Subprocessor imposing data protection obligations no less protective than those required under this DPA, to the extent applicable to the Subprocessor’s Processing.

7.6 Liability. Deccan AI remains responsible for the performance of its Subprocessors’ obligations with respect to Customer Personal Data.

8. Data Subject Requests

8.1 Assistance. Taking into account the nature of the Processing, Deccan AI shall provide reasonable assistance to Customer to respond to Data Subject requests to exercise rights under Applicable Data Protection Laws.

8.2 Direct Requests. If Deccan AI receives a Data Subject request relating to Customer Personal Data, Deccan AI shall, to the extent legally permitted, either direct the Data Subject to Customer or notify Customer. Deccan AI shall not respond substantively unless authorized by Customer or required by law.

8.3 Self-Service Tools. Where the Services provide functionality for Customer to retrieve, correct, delete, or restrict Customer Personal Data, Customer shall use such functionality before requesting manual assistance.

9. Assistance with Compliance

9.1 DPIAs and Assessments. Taking into account the nature of Processing and information available to Deccan AI, Deccan AI shall provide reasonable assistance with data protection impact assessments, risk assessments, transfer assessments, and consultations with supervisory authorities or regulators where required by Applicable Data Protection Laws.

9.2 Security and Breach Support. Deccan AI shall provide reasonable assistance to Customer in meeting security and breach notification obligations related to Customer Personal Data.

9.3 Cooperation. Assistance under this Section shall be at Customer’s reasonable expense unless the assistance is required because of Deccan AI’s breach of this DPA.

10. Personal Data Breach

10.1 Notice. Deccan AI shall notify Customer without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.

10.2 Contents of Notice. The notice shall include, to the extent known at the time: (a) nature of the incident; (b) categories and approximate volume of affected data and Data Subjects; (c) systems involved; (d) likely consequences; (e) mitigation and remediation steps; and (f) a contact point for follow-up.

10.3 Cooperation. Deccan AI shall take reasonable steps to contain, investigate, mitigate, and remediate the Personal Data Breach and shall provide reasonable cooperation to Customer.

10.4 No Admission. Deccan AI’s notification or response to a Personal Data Breach shall not be construed as an admission of fault or liability.

11. Return and Deletion

11.1 Return or Deletion. Upon termination or expiration of the Services, or upon Customer’s written request, Deccan AI shall return or delete Customer Personal Data in accordance with the Agreement, applicable Order Form, and Customer’s documented instructions, unless retention is required by law.

11.2 Backup Systems. Customer Personal Data stored in backups shall be deleted or overwritten in accordance with Deccan AI’s standard backup retention cycle, provided that such data remains protected under this DPA and is not actively Processed except for disaster recovery, security, legal, or compliance purposes.

11.3 Certification. Upon Customer’s reasonable request, Deccan AI shall certify completion of deletion or return, subject to any legal retention or backup limitations.

11.4 Legally Required Retention. If Deccan AI is legally required to retain Customer Personal Data, Deccan AI shall protect such data in accordance with this DPA and Process it only as required by law.

12. Audits and Information Rights

12.1 Information Rights. Deccan AI shall make available information reasonably necessary to demonstrate compliance with this DPA, including summaries of relevant third-party certifications, audit reports, security documentation, or questionnaire responses, subject to confidentiality obligations.

12.2 Audit. If the information provided is insufficient to demonstrate compliance, Customer may request an audit no more than once annually, unless a Personal Data Breach or material non-compliance reasonably requires an additional audit.

12.3 Audit Conditions. Audits must be conducted during normal business hours, on at least thirty (30) days’ prior written notice, without unreasonable disruption, and subject to confidentiality, security, and safety requirements. Customer shall bear its audit costs unless the audit reveals material non-compliance by Deccan AI.

12.4 Third-Party Reports. Where Deccan AI provides SOC 2, ISO, penetration test summary, or similar third-party report, Customer shall rely on such report where reasonably sufficient, before requesting an onsite audit.

13. International Transfers

13.1 Restricted Transfers. To the extent Deccan AI Processes Customer Personal Data subject to the GDPR, UK GDPR, or Swiss FADP in a country that does not provide an adequate level of protection, the Parties shall rely on the SCCs and, where applicable, the UK Addendum or other lawful transfer mechanism.

13.2 SCC Module. For Customer-to-Deccan AI Restricted Transfers where Customer is a Controller and Deccan AI is a Processor, Module Two of the SCCs applies. If the Parties’ roles differ, the applicable SCC module shall apply based on the actual roles.

13.3 Annexes. Annex A, Annex B, and Annex C of this DPA shall be deemed to populate the relevant annexes of the SCCs.

13.4 Transfer Assessments. Deccan AI shall provide reasonable information necessary for Customer to conduct transfer impact assessments where required by Applicable Data Protection Laws.

13.5 Onward Transfers. Deccan AI shall ensure onward transfers by Subprocessors are subject to appropriate transfer safeguards required by Applicable Data Protection Laws.

14. Government and Legal Requests

14.1 Notice. If Deccan AI receives a subpoena, court order, regulator request, law enforcement request, or other legal demand for Customer Personal Data, Deccan AI shall, to the extent legally permitted, promptly notify Customer before disclosure.

14.2 Cooperation. Deccan AI shall cooperate with Customer’s reasonable efforts to limit disclosure, obtain confidential treatment, or challenge the request, at Customer’s expense unless the request arises from Deccan AI’s breach.

15. Order of Precedence

In the event of conflict regarding the Processing of Customer Personal Data, the order of precedence shall be: (a) SCCs or applicable transfer mechanism; (b) this DPA; (c) the Agreement; and (d) any other document incorporated by reference, unless expressly stated otherwise in a signed writing.

16. Survival

This DPA shall survive termination or expiration of the Agreement for so long as Deccan AI Processes Customer Personal Data.

ANNEX A – DETAILS OF PROCESSING

This Annex describes the Processing of Customer Personal Data by Deccan AI in connection with the Services. The applicable Order Form, SOW, or Agreement may supplement or modify these details.

Field Description
Subject matter Provision of enterprise AI, automation, data operations, annotation, model evaluation, RLHF, research environment, data processing, and related services described in the Agreement and applicable Order Forms.
Duration For the term of the Agreement or applicable Order Form, plus any period required for deletion, transition, backup retention, legal compliance, dispute resolution, audit, or customer-requested retention.
Nature of Processing Collection, access, receipt, storage, hosting, organization, structuring, annotation, labeling, transformation, analysis, evaluation, review, quality assurance, transmission, deletion, and other Processing necessary to provide the Services.
Purpose To provide, secure, support, maintain, troubleshoot, improve as authorized, and perform the Services for Customer and Customer-authorized users.
Categories of Data Subjects Customer’s authorized users, employees, contractors, representatives, customers, end users, research participants, or other individuals whose Personal Data is submitted to or Processed through the Services.
Categories of Personal Data May include name, email, phone number, user ID, username, address, account information, device identifiers, IP address, usage data, logs, images, audio, video, text, prompts, outputs, annotations, metadata, professional information, demographic information where provided, and other data submitted by Customer or its users.
Sensitive Data Sensitive data is not intended to be submitted unless expressly authorized in the Agreement, Order Form, project documentation, or Customer instructions. If submitted, it may include government IDs, precise geolocation, financial information, health-related information, biometric-related information, racial/ethnic information, children’s data, or similar sensitive data, subject to stricter access, security, minimization, and purpose limitations.
Frequency Continuous or as otherwise required for the Services.
Processing Locations United States, India, and other locations where Deccan AI, its Affiliates, and approved Subprocessors operate, subject to the Agreement, Customer instructions, and Applicable Data Protection Laws.
Retention As specified in the Agreement, Order Form, Customer instructions, or Deccan AI’s retention practices, subject to legal, security, backup, audit, and compliance requirements.

ANNEX B – TECHNICAL AND ORGANIZATIONAL MEASURES

1. Governance and Security Program

  • Designated security and privacy owners responsible for maintaining the information security and privacy program.
  • Written security, privacy, access control, incident response, and vendor management policies.
  • Periodic risk assessments and risk-based remediation tracking.
  • Annual review of security policies and material controls.

2. Personnel Security

  • Confidentiality obligations for personnel and contractors with access to Customer Personal Data.
  • Background checks where lawful and appropriate for personnel with access to sensitive systems or Customer Personal Data.
  • Privacy and security training during onboarding and periodically thereafter.
  • Role-based access approval and removal procedures.

3. Access Controls

  • Least-privilege and need-to-know access controls.
  • Unique user IDs and strong authentication.
  • Multi-factor authentication for administrative and sensitive systems where available.
  • Periodic access reviews and prompt access revocation upon role change or offboarding.
  • Logging of access to systems containing Customer Personal Data where technically feasible.

4. Network, Infrastructure, and Cloud Security

  • Use of reputable cloud infrastructure providers, including AWS or equivalent providers.
  • Network segmentation and firewall/security group controls.
  • Secure configuration standards for production systems.
  • Vulnerability scanning and risk-based patch management.
  • Backup and restoration procedures designed to preserve availability and resilience.

5. Encryption and Transmission Security

  • Encryption in transit using HTTPS/TLS or comparable safeguards.
  • Encryption at rest where supported and appropriate to the Services.
  • Secure credential and secret management practices.

6. Data Segregation and Customer Isolation

  • Logical separation of customer data in multi-tenant environments.
  • Access controls designed to prevent unauthorized cross-customer access.
  • Customer-specific project/workspace controls where applicable.

7. AI and Project Data Controls

  • Restrictions on unauthorized model training, fine-tuning, benchmarking, or reuse of Customer Personal Data.
  • Controls prohibiting upload of Customer Personal Data into unapproved AI tools.
  • Access logging and project-level authorization for personnel, freelancers, and contractors where applicable.
  • Deletion/return certification for freelancers or contractors where applicable to high-risk projects.

8. Incident Response

  • Maintained incident response procedures and escalation paths.
  • Prompt investigation, containment, mitigation, and remediation of security incidents.
  • Preservation of relevant logs and evidence.
  • Customer notification procedures aligned with contractual and legal requirements.

9. Vendor and Subprocessor Management

  • Due diligence of Subprocessors based on the nature of Processing and risk.
  • Written agreements imposing confidentiality, security, breach notice, and data protection obligations.
  • Periodic review of material Subprocessors.

10. Deletion and Disposal

  • Secure deletion or return of Customer Personal Data upon request or termination, subject to legal and backup retention.
  • Secure disposal processes for media and systems containing Customer Personal Data.
  • Deletion verification where reasonably available.

ANNEX C – SUBPROCESSORS

Customer authorizes Deccan AI to use Subprocessors necessary to provide the Services. Deccan AI should maintain a current Subprocessor list at [insert URL/customer portal] or in the table below. This list should be completed before publication or customer execution.

Subprocessor Location Nature of Processing Safeguards / Notes
[AWS / hosting provider] [●] Cloud hosting, storage, networking, infrastructure DPA/security terms in place
[Analytics/security/payment/communication vendors] [●] As applicable to the Services Add only if Processing Customer Personal Data
[Freelancer/annotation/review platforms, if applicable] [●] Annotation, review, quality assurance, project support Use only where customer-authorized

ANNEX D – INTERNATIONAL TRANSFER MECHANISMS

Where the SCCs apply, the following selections shall apply unless the Agreement or Order Form states otherwise:

  • Module Two applies for Controller-to-Processor transfers.
  • Clause 7 (Docking Clause): optional docking clause applies if agreed by the Parties.
  • Clause 9 (Subprocessors): general written authorization applies, with prior notice and objection rights as described in Section 7 of this DPA.
  • Clause 11 (Redress): optional language does not apply unless expressly agreed.
  • Clause 17 (Governing Law): the law of an EU Member State that allows third-party beneficiary rights shall apply, as specified in the Agreement or Order Form; if not specified, Ireland shall apply.
  • Clause 18 (Forum): courts of the governing-law Member State shall apply, unless otherwise required by the SCCs.
  • Annex I: populated by Annex A of this DPA.
  • Annex II: populated by Annex B of this DPA.
  • Annex III: populated by Annex C of this DPA.
  • For UK transfers, the UK Addendum to the SCCs shall apply as required under UK data protection law.
  • For Swiss transfers, references to the GDPR shall be interpreted to include the Swiss FADP as required, and the Swiss Federal Data Protection and Information Commissioner shall be the competent supervisory authority where applicable.

ANNEX E – OPTIONAL CUSTOMER-SPECIFIC TERMS

The Parties may use this Annex to document customer-specific restrictions, including prohibited data categories, approved processing locations, approved Subprocessors, customer-specific security requirements, retention periods, or AI-use restrictions.

This doesn’t have to end here

Accuracy is Intelligence