.png)
Research
Resources
This Data Processing Addendum ("DPA") forms part of the written or electronic agreement, order form, statement of work, terms of service, master services agreement, or other agreement between Deccan.ai, Inc. ("Deccan AI") and the customer or other entity receiving the Services ("Customer") (the "Agreement"). This DPA applies to Deccan AI’s Processing of Customer Personal Data in connection with the Services.
This DPA is intended to address Deccan AI’s obligations as a Processor, service provider, contractor, or equivalent role under Applicable Data Protection Laws, including where applicable the GDPR, UK GDPR, Swiss FADP, and U.S. state privacy laws. Except as modified by this DPA, the Agreement remains in full force and effect. If there is a conflict between this DPA and the Agreement regarding the Processing of Customer Personal Data, this DPA controls.
1. DEFINITIONS
"Affiliate" means any entity that directly or indirectly controls, is controlled by, or is under common control with a Party.
"Applicable Data Protection Laws" means all privacy, data protection, data security, cybersecurity, breach notification, electronic communications, and similar laws and regulations applicable to the Processing of Customer Personal Data under the Agreement, including, where applicable, the EU GDPR, UK GDPR, Swiss FADP, U.S. state privacy laws, and implementing regulations.
"Controller" has the meaning given under Applicable Data Protection Laws and includes, where applicable, a "business" under U.S. state privacy laws.
"Customer Personal Data" means Personal Data that Customer provides or makes available to Deccan AI, or that Deccan AI Processes on behalf of Customer, in connection with the Services.
"Data Subject" means the identified or identifiable natural person to whom Customer Personal Data relates and includes, where applicable, a "consumer" under U.S. state privacy laws.
"De-identified Data" means data that cannot reasonably be used to infer information about, or otherwise be linked to, an identified or identifiable individual, provided that Deccan AI implements reasonable measures to maintain and use the data only in de-identified form and does not attempt to re-identify the data except as permitted by law.
"GDPR" means Regulation (EU) 2016/679. "UK GDPR" means the GDPR as incorporated into UK law under the UK Data Protection Act 2018.
"Personal Data" has the meaning given under Applicable Data Protection Laws and includes "personal information" under U.S. state privacy laws.
"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
"Process" or "Processing" means any operation performed on Customer Personal Data, including collection, access, receipt, use, storage, disclosure, transmission, organization, structuring, adaptation, alteration, retrieval, consultation, annotation, labeling, analysis, deletion, or destruction.
"Processor" has the meaning given under Applicable Data Protection Laws and includes, where applicable, a "service provider," "contractor," or equivalent role under U.S. state privacy laws.
"Restricted Transfer" means a transfer of Customer Personal Data from the EEA, UK, or Switzerland to a country that does not provide an adequate level of protection under Applicable Data Protection Laws.
"SCCs" means the European Commission Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, as amended or replaced from time to time.
"Subprocessor" means any third party appointed by or on behalf of Deccan AI to Process Customer Personal Data in connection with the Services.
2. SCOPE AND ROLES
2.1 Scope. This DPA applies only to Deccan AI’s Processing of Customer Personal Data on behalf of Customer in connection with the Services.
2.2 Roles. As between the Parties, Customer is the Controller and Deccan AI is the Processor with respect to Customer Personal Data, unless the Agreement or applicable Order Form expressly states otherwise. For U.S. state privacy laws, Deccan AI acts as Customer’s service provider, contractor, processor, or equivalent role.
2.3 Customer Responsibility. Customer is responsible for determining the purposes and means of Processing, providing legally sufficient notices, obtaining required consents, establishing a valid legal basis for Processing, and ensuring that Customer is entitled to provide Customer Personal Data to Deccan AI for Processing under the Agreement.
2.4 Deccan AI Responsibility. Deccan AI shall Process Customer Personal Data only in accordance with this DPA, the Agreement, applicable Order Forms, documented instructions from Customer, and Applicable Data Protection Laws.
3. Processing Instructions and Purpose Limitation
3.1 Documented Instructions. Customer instructs Deccan AI to Process Customer Personal Data as necessary to provide, secure, support, maintain, improve, and perform the Services, as described in the Agreement, applicable Order Form, Annex A, and Customer’s documented instructions.
3.2 No Unauthorized Processing. Deccan AI shall not Process Customer Personal Data for any purpose other than providing the Services or as otherwise expressly permitted by Customer in writing, this DPA, or Applicable Data Protection Laws.
3.3 Unlawful Instructions. Deccan AI shall promptly inform Customer if, in Deccan AI’s reasonable opinion, an instruction infringes Applicable Data Protection Laws, unless prohibited by law.
3.4 AI-Specific Restrictions. Deccan AI shall not use Customer Personal Data for model training, model fine-tuning, foundation model development, benchmarking, product improvement, research, analytics unrelated to the Services, or creation of reusable datasets unless expressly authorized in the Agreement, Order Form, or Customer’s written instructions.
3.5 De-identified and Aggregated Data. Deccan AI may Process De-identified Data or aggregated data only to the extent permitted by the Agreement and Applicable Data Protection Laws. Deccan AI shall not attempt to re-identify De-identified Data except as permitted by law and Customer’s written instructions.
4. U.S. State Privacy Law Requirements
4.1 Service Provider / Contractor Commitments. To the extent U.S. state privacy laws apply, Deccan AI shall Process Customer Personal Data only for the limited and specified business purpose of providing the Services.
4.2 Prohibited Uses. Deccan AI shall not: (a) sell or share Customer Personal Data; (b) retain, use, or disclose Customer Personal Data outside the direct business relationship between Deccan AI and Customer; (c) retain, use, or disclose Customer Personal Data for any purpose other than performing the Services or as otherwise permitted by Applicable Data Protection Laws; (d) combine Customer Personal Data with Personal Data received from another source except as permitted by Applicable Data Protection Laws and Customer’s documented instructions; or (e) use Customer Personal Data for targeted advertising, profiling, or Deccan AI’s independent commercial purposes.
4.3 Same Level of Protection. Deccan AI shall provide at least the same level of privacy protection for Customer Personal Data as required of Customer under Applicable Data Protection Laws, to the extent applicable to Deccan AI’s role and Processing.
4.4 Compliance Monitoring. Customer may take reasonable and appropriate steps to ensure that Deccan AI’s Processing of Customer Personal Data is consistent with Customer’s obligations under Applicable Data Protection Laws, including through the audit and information rights in Section 12.
4.5 Inability to Comply. Deccan AI shall notify Customer if Deccan AI determines that it can no longer meet its obligations under this DPA or Applicable Data Protection Laws. Customer may take reasonable and appropriate steps to stop and remediate unauthorized Processing.
5. Confidentiality and Personnel Controls
5.1 Confidentiality. Deccan AI shall ensure that personnel authorized to Process Customer Personal Data are bound by written confidentiality obligations or are under an appropriate statutory duty of confidentiality.
5.2 Access Limitation. Deccan AI shall restrict access to Customer Personal Data to personnel, contractors, and approved Subprocessors who have a business need to access such data to provide the Services.
5.3 Training. Deccan AI shall provide appropriate privacy, confidentiality, security, and data handling training to personnel with access to Customer Personal Data.
5.4 Contractor and Freelancer Controls. Where contractors, freelancers, reviewers, annotators, or similar personnel support the Services, Deccan AI shall require confidentiality, data-use, security, no-unauthorized-AI-tool-use, and deletion obligations at least as protective as those required under this DPA.
6. Security Measures
6.1 Security Program. Deccan AI shall implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against unauthorized or unlawful Processing and against accidental loss, destruction, damage, alteration, or disclosure.
6.2 Minimum Measures. The measures shall include, as appropriate to the nature of the Services and Customer Personal Data, the technical and organizational measures described in Annex B.
6.3 Updates. Deccan AI may update its security measures from time to time, provided such updates do not materially reduce the overall level of protection for Customer Personal Data.
6.4 Customer Responsibilities. Customer is responsible for securely configuring the Services, managing Customer-controlled accounts and credentials, and using the Services in accordance with the Agreement and documentation.
7. Subprocessors
7.1 Authorization. Customer provides general authorization for Deccan AI to engage Subprocessors to Process Customer Personal Data in connection with the Services, subject to this Section 7.
7.2 Subprocessor List. Deccan AI shall maintain a current list of Subprocessors in Annex C or at a publicly available URL or customer portal identified by Deccan AI. The list shall include the Subprocessor name, location, and nature of Processing.
7.3 Notice of Changes. Deccan AI shall provide notice of new or replacement Subprocessors at least thirty (30) days before authorizing such Subprocessor to Process Customer Personal Data, unless a shorter period is required due to emergency, security, legal, or service continuity reasons.
7.4 Objection. Customer may object to a new Subprocessor on reasonable data protection grounds by notifying Deccan AI within fifteen (15) days after notice. The Parties shall work in good faith to resolve the objection. If the objection is not resolved, Customer may terminate the affected Services to the extent the Services cannot be provided without the objected-to Subprocessor.
7.5 Subprocessor Obligations. Deccan AI shall enter into a written agreement with each Subprocessor imposing data protection obligations no less protective than those required under this DPA, to the extent applicable to the Subprocessor’s Processing.
7.6 Liability. Deccan AI remains responsible for the performance of its Subprocessors’ obligations with respect to Customer Personal Data.
8. Data Subject Requests
8.1 Assistance. Taking into account the nature of the Processing, Deccan AI shall provide reasonable assistance to Customer to respond to Data Subject requests to exercise rights under Applicable Data Protection Laws.
8.2 Direct Requests. If Deccan AI receives a Data Subject request relating to Customer Personal Data, Deccan AI shall, to the extent legally permitted, either direct the Data Subject to Customer or notify Customer. Deccan AI shall not respond substantively unless authorized by Customer or required by law.
8.3 Self-Service Tools. Where the Services provide functionality for Customer to retrieve, correct, delete, or restrict Customer Personal Data, Customer shall use such functionality before requesting manual assistance.
9. Assistance with Compliance
9.1 DPIAs and Assessments. Taking into account the nature of Processing and information available to Deccan AI, Deccan AI shall provide reasonable assistance with data protection impact assessments, risk assessments, transfer assessments, and consultations with supervisory authorities or regulators where required by Applicable Data Protection Laws.
9.2 Security and Breach Support. Deccan AI shall provide reasonable assistance to Customer in meeting security and breach notification obligations related to Customer Personal Data.
9.3 Cooperation. Assistance under this Section shall be at Customer’s reasonable expense unless the assistance is required because of Deccan AI’s breach of this DPA.
10. Personal Data Breach
10.1 Notice. Deccan AI shall notify Customer without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.
10.2 Contents of Notice. The notice shall include, to the extent known at the time: (a) nature of the incident; (b) categories and approximate volume of affected data and Data Subjects; (c) systems involved; (d) likely consequences; (e) mitigation and remediation steps; and (f) a contact point for follow-up.
10.3 Cooperation. Deccan AI shall take reasonable steps to contain, investigate, mitigate, and remediate the Personal Data Breach and shall provide reasonable cooperation to Customer.
10.4 No Admission. Deccan AI’s notification or response to a Personal Data Breach shall not be construed as an admission of fault or liability.
11. Return and Deletion
11.1 Return or Deletion. Upon termination or expiration of the Services, or upon Customer’s written request, Deccan AI shall return or delete Customer Personal Data in accordance with the Agreement, applicable Order Form, and Customer’s documented instructions, unless retention is required by law.
11.2 Backup Systems. Customer Personal Data stored in backups shall be deleted or overwritten in accordance with Deccan AI’s standard backup retention cycle, provided that such data remains protected under this DPA and is not actively Processed except for disaster recovery, security, legal, or compliance purposes.
11.3 Certification. Upon Customer’s reasonable request, Deccan AI shall certify completion of deletion or return, subject to any legal retention or backup limitations.
11.4 Legally Required Retention. If Deccan AI is legally required to retain Customer Personal Data, Deccan AI shall protect such data in accordance with this DPA and Process it only as required by law.
12. Audits and Information Rights
12.1 Information Rights. Deccan AI shall make available information reasonably necessary to demonstrate compliance with this DPA, including summaries of relevant third-party certifications, audit reports, security documentation, or questionnaire responses, subject to confidentiality obligations.
12.2 Audit. If the information provided is insufficient to demonstrate compliance, Customer may request an audit no more than once annually, unless a Personal Data Breach or material non-compliance reasonably requires an additional audit.
12.3 Audit Conditions. Audits must be conducted during normal business hours, on at least thirty (30) days’ prior written notice, without unreasonable disruption, and subject to confidentiality, security, and safety requirements. Customer shall bear its audit costs unless the audit reveals material non-compliance by Deccan AI.
12.4 Third-Party Reports. Where Deccan AI provides SOC 2, ISO, penetration test summary, or similar third-party report, Customer shall rely on such report where reasonably sufficient, before requesting an onsite audit.
13. International Transfers
13.1 Restricted Transfers. To the extent Deccan AI Processes Customer Personal Data subject to the GDPR, UK GDPR, or Swiss FADP in a country that does not provide an adequate level of protection, the Parties shall rely on the SCCs and, where applicable, the UK Addendum or other lawful transfer mechanism.
13.2 SCC Module. For Customer-to-Deccan AI Restricted Transfers where Customer is a Controller and Deccan AI is a Processor, Module Two of the SCCs applies. If the Parties’ roles differ, the applicable SCC module shall apply based on the actual roles.
13.3 Annexes. Annex A, Annex B, and Annex C of this DPA shall be deemed to populate the relevant annexes of the SCCs.
13.4 Transfer Assessments. Deccan AI shall provide reasonable information necessary for Customer to conduct transfer impact assessments where required by Applicable Data Protection Laws.
13.5 Onward Transfers. Deccan AI shall ensure onward transfers by Subprocessors are subject to appropriate transfer safeguards required by Applicable Data Protection Laws.
14. Government and Legal Requests
14.1 Notice. If Deccan AI receives a subpoena, court order, regulator request, law enforcement request, or other legal demand for Customer Personal Data, Deccan AI shall, to the extent legally permitted, promptly notify Customer before disclosure.
14.2 Cooperation. Deccan AI shall cooperate with Customer’s reasonable efforts to limit disclosure, obtain confidential treatment, or challenge the request, at Customer’s expense unless the request arises from Deccan AI’s breach.
15. Order of Precedence
In the event of conflict regarding the Processing of Customer Personal Data, the order of precedence shall be: (a) SCCs or applicable transfer mechanism; (b) this DPA; (c) the Agreement; and (d) any other document incorporated by reference, unless expressly stated otherwise in a signed writing.
16. Survival
This DPA shall survive termination or expiration of the Agreement for so long as Deccan AI Processes Customer Personal Data.
ANNEX A – DETAILS OF PROCESSING
This Annex describes the Processing of Customer Personal Data by Deccan AI in connection with the Services. The applicable Order Form, SOW, or Agreement may supplement or modify these details.
ANNEX B – TECHNICAL AND ORGANIZATIONAL MEASURES
1. Governance and Security Program
2. Personnel Security
3. Access Controls
4. Network, Infrastructure, and Cloud Security
5. Encryption and Transmission Security
6. Data Segregation and Customer Isolation
7. AI and Project Data Controls
8. Incident Response
9. Vendor and Subprocessor Management
10. Deletion and Disposal
ANNEX C – SUBPROCESSORS
Customer authorizes Deccan AI to use Subprocessors necessary to provide the Services. Deccan AI should maintain a current Subprocessor list at [insert URL/customer portal] or in the table below. This list should be completed before publication or customer execution.
ANNEX D – INTERNATIONAL TRANSFER MECHANISMS
Where the SCCs apply, the following selections shall apply unless the Agreement or Order Form states otherwise:
ANNEX E – OPTIONAL CUSTOMER-SPECIFIC TERMS
The Parties may use this Annex to document customer-specific restrictions, including prohibited data categories, approved processing locations, approved Subprocessors, customer-specific security requirements, retention periods, or AI-use restrictions.