Version 0.9 (draft) · August 31, 2026
This Data Processing Agreement (this “DPA”, also referred to in the parties’ agreements and on the Platform as the “Data Processing Addendum”) is entered into between Audacity Advisory Corp, d/b/a AI Reserve, a Delaware C corporation (“Audacity”, “we”, “us” or “our”), and the customer identified in the signature block below or in the agreement into which this DPA is incorporated (the “Customer”).
This DPA forms part of, and is incorporated into, the agreement between Audacity and the Customer governing the Customer’s access to and use of the Platform and Services — the AI Rights Purchase Agreement and its Addenda, an Evaluation Term Agreement, or the Terms of Service, as applicable (the “Agreement”). Where the Agreement is the AI Rights Purchase Agreement, this DPA constitutes Addendum 2 to that instrument. This DPA governs Audacity’s Processing of Personal Data on the Customer’s behalf in connection with the Services and takes effect on the date last signed below or the effective date of the Agreement, whichever is earlier (the “Effective Date”).
1.1 Roles. As part of providing the Services, Audacity Processes Personal Data on the Customer’s behalf. Audacity acts as a Processor (and as an independent Controller of Service Data as described in Section 9); the Customer acts as a Controller (or, where the Customer causes Audacity to Process Personal Data on behalf of the Customer’s own customers, as a Processor). Capitalized terms not defined in this DPA have the meanings given in the Agreement.
1.2 GDPR Gating. The European Annex (Annex 2) and the standard contractual clauses referenced therein apply solely to Processing of Personal Data that is subject to the GDPR or FADP. For Customers not subject to the GDPR or FADP, Annex 2 does not apply and imposes no obligations on either party. This DPA is structured for U.S. customers; the State Privacy Laws Annex (Annex 3) governs Processing subject to applicable U.S. state privacy laws.
1.3 Definitions. “Personal Data” means information relating to an identified or identifiable natural person that Audacity Processes on the Customer’s behalf in connection with the Services. “Processing” (and its cognates) means any operation performed on Personal Data, whether or not by automated means. “Data Subject”, “Controller”, “Processor”, and “Supervisory Authority” have the meanings given in applicable Data Protection Laws. “Data Protection Laws” means the privacy and data-protection laws applicable to the Processing of Personal Data under this DPA, including as applicable the GDPR, the UK GDPR, the Swiss FADP, and applicable U.S. state privacy laws. “Customer Data” means data submitted to the Services by or on behalf of the Customer, including Inputs and Outputs as defined in the Agreement. “Stored Customer Content” means the Customer Data stored by the platform: account data, uploaded documents, and any opt-in stored content (such as prompt and response text stored for chat history where the Customer’s organization has content storage enabled). “Service Data” means data Audacity collects or generates in connection with providing and operating the Services: usage metadata (model, token counts, cost, latency, status, and user, key, and team attribution), billing and ledger records, administrative and access audit logs, and support and account records. Service Data contains no prompt or response content. “Subprocessor” means a third party engaged by Audacity that Processes Personal Data solely on Audacity’s behalf and on the Customer’s documented instructions. “Subprocessor List” means the current list of Subprocessors maintained on the Platform as set out in Annex 5. “Information Security Incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data Processed by Audacity under this DPA. “SCCs” means the standard contractual clauses approved by the European Commission (Implementing Decision (EU) 2021/914), as populated under Annex 2.
2.1 Documented Instructions. Audacity will Process Personal Data as a Processor only in accordance with the Customer’s documented instructions. The parties agree that this DPA, the Agreement, and the configuration choices the Customer makes within the Services (including model and provider selections, routing policies, and content-storage, retention, classification, and consent-gate settings) constitute the Customer’s documented instructions. Audacity will Process Personal Data in accordance with those instructions unless required to do otherwise by applicable law, in which case Audacity will inform the Customer of the requirement before Processing unless legally prohibited from doing so. The details of Processing are set out in Annex 1.
2.2 Provider Selection Is an Instruction. The data-handling characteristics of each AI model provider available through the Services — including, as applicable, whether the provider trains or fine-tunes on inputs, its data retention, its processing region, and its role under this DPA — are disclosed on the Platform’s Provider Data Handling page and may be updated from time to time as provider policies change. The Customer’s (or its authorized users’) selection of an AI model or provider constitutes the Customer’s instruction to route the associated request content to that provider on the disclosed terms. Sending prompts and responses to the model providers the Customer’s organization has selected is the service operating, not secondary sharing.
2.3 No Sale; Limits on Disclosure. Customer Data is never sold. The only Customer Data that leaves the platform is: (a) prompts and responses, sent to the model providers the Customer’s organization has selected — this is the service operating, not secondary sharing (Section 2.2); (b) account email addresses, sent to Audacity’s transactional email Subprocessor for account-related notifications; and (c) hosting data processed by Audacity’s disclosed infrastructure Subprocessors as part of running the platform. Nothing is shared for advertising, analytics, or any other purpose. Disclosure may occur where required by law (Section 8.4). For organizations that adopt an optional collaboration surface operated by a disclosed Subprocessor (for example, a Slack Connect shared channel, including its optional mention agent), the messages participants choose to post in that surface and the completions returned there are processed by that Subprocessor as disclosed on the Subprocessor List; where the mention agent is invoked in a message thread, or responds to a follow-up in a thread in which it is already participating, the messages in that thread — including messages posted by participants who did not invoke the agent — are included as context in the request sent to the selected model provider, on the same terms as other prompt content under clause (a); content sent through the API directly does not transit that surface.
2.4 Notices to Customer. Audacity will promptly inform the Customer in writing if, in Audacity’s opinion, a Customer instruction infringes applicable Data Protection Laws. Audacity will, to the extent legally permitted, inform the Customer if Audacity receives a legally binding request for disclosure of Customer Data by a law enforcement authority.
3.1 Security Measures. Audacity will implement and maintain the technical, administrative, physical, and organizational measures described in Annex 4 (the “Security Measures”), and may update them from time to time so long as the protection they provide is not materially decreased.
3.2 Personnel. Audacity requires personnel authorized to access Personal Data to be subject to appropriate confidentiality obligations, and limits access to the specific data a task requires on a least-privilege basis, with access events audit-logged.
3.3 Incident Notification. Audacity will notify the Customer without undue delay after becoming aware of an Information Security Incident affecting Customer Personal Data, with then-available details and recommended mitigations, and will keep the Customer reasonably informed as material information becomes available. The Customer is solely responsible for its own notification obligations under applicable law.
3.4 Customer Responsibilities for Security. The Customer is responsible for securing its credentials, systems, and devices and for backing up its Personal Data, and has determined that the Services and the Security Measures are adequate for its needs.
Taking into account the nature of the Processing, Audacity will provide the Customer with reasonably necessary and technically feasible assistance to respond to Data Subject requests to exercise rights under applicable Data Protection Laws, at Audacity’s then-current professional services rates. If Audacity receives such a request directly, it will notify the Customer and advise the Data Subject to submit the request to the Customer, who is solely responsible for responding. Self-service controls also satisfy many requests directly: users can delete their own chats, documents, or entire account from their profile (Section 8.6).
The Customer is solely responsible for providing all required notices to, and obtaining all required consents from, Data Subjects, and represents and warrants that there is and will be a valid legal basis for Audacity’s Processing of Personal Data under this DPA throughout the term of the Agreement.
6.1 General Authorization. The Customer generally authorizes Audacity to engage third parties as Subprocessors to Process Personal Data in connection with the Services. A current list of Subprocessors, including their functions and jurisdictions, is maintained on the Platform at the location set out in Annex 5 (the “Subprocessor List”). The Customer’s execution of this DPA constitutes the Customer’s authorization of the Subprocessors identified on the Subprocessor List as of the Effective Date and of Subprocessors added thereafter in accordance with Section 6.3.
6.2 Subprocessor Characteristics; Independent Controllers. The Subprocessor List states, for each entry, its relevant data-handling characteristics, including as applicable whether it trains or fine-tunes on data, its data retention, and its processing region (with per-provider detail on the Provider Data Handling page). A third party that Processes Personal Data solely on Audacity’s behalf and on the Customer’s instructions is a Subprocessor. A provider that processes data for its own purposes, including to train or fine-tune its models, acts as an independent controller with respect to such processing and not as Audacity’s Subprocessor; such providers are identified as such on the Subprocessor List, and the Customer’s selection of any such provider constitutes the Customer’s authorization of, and instruction to effect, the associated disclosure. Models served by providers that soften a platform data guarantee (training-permitted terms, retention that cannot be turned off or verified, or PRC-hosted processing) are additionally locked for every organization until the Customer’s own administrator enables the corresponding consent in the AI Reserve console; absent that consent such models are excluded from routing for the Customer and requests to them are refused.
6.3 Changes; Notice; Objection. Audacity will update the Subprocessor List before any new Subprocessor Processes Customer Personal Data. Notice of a change is given by updating the Subprocessor List and, for Customers that have subscribed to change notifications by emailing product@aireserve.com, by email. The Customer may object to a new Subprocessor on reasonable data-protection grounds by written notice within fifteen (15) days of notice. On objection, the parties will cooperate in good faith to resolve the objection: where the new Subprocessor is a model provider, the Customer’s own routing controls (model selection and provider allowlist pinning, enforced at the gateway) prevent the Customer’s traffic from reaching it, and Audacity will pin the Customer’s account accordingly on request — a new model provider receives Customer content only when the Customer’s organization’s routing sends traffic to it (Section 2.2). Where the objection cannot reasonably be resolved by such controls or other measures, the Customer may terminate the affected Services in accordance with the Agreement.
6.4 Requirements for Engagement. When engaging any Subprocessor, Audacity will enter into a written contract imposing data protection obligations no less protective than those in this DPA to the extent applicable to the services provided. Audacity remains liable for the acts and omissions of its Subprocessors to the same extent as if it had performed the Processing itself.
The Customer may audit Audacity’s compliance with this DPA up to once per year (and as required by applicable law), with at least two weeks’ advance written notice and a proposed audit plan, subject to a mutually acceptable non-disclosure agreement. Given the nature of the Services, on-site audits are not necessary. Audacity will complete reasonable written security questionnaires up to once per year in support of such audits. Once Audacity’s SOC 2 Type II examination (in progress as of the version date of this DPA) results in an issued report, a current SOC 2 Type II, ISO, NIST, or similar report issued within the prior twelve months, where controls are unchanged, will be accepted in lieu of an audit of the covered controls. Audits are at the Customer’s sole expense, and the Customer shall reimburse Audacity for time expended at its then-current professional services rates.
8.1 Deletion on Verified Request. At any time during the term of the Agreement, on a verified request, the Customer Data stored — account data, uploaded documents, and any opt-in stored content (together, the Stored Customer Content) — is deleted within a fourteen (14)-day window of the verified request, to the extent technically possible, subject to the legal-retention carve-outs in Section 8.4; billing and audit records are retained as set out in Section 8.3. For API-only organizations this deletion commitment applies chiefly to account data — prompt and response content sent through API keys passes through the gateway in memory only and is never stored to begin with. A “verified request” is a written deletion request from the Customer’s Admin User or other authorized representative whose identity and authority Audacity has verified. Deletion requests may be directed to the Customer’s AI Reserve point of contact or to product@aireserve.com.
8.2 Return and Deletion at End of Services. Upon cessation of the Services involving Processing of Personal Data (the “Cessation Date”), Audacity will cease Processing except for storage or as otherwise permitted under this DPA. On the Customer’s written request made within fourteen (14) days after the Cessation Date, Audacity will, within fourteen (14) days and to the extent technically possible, either (i) return a complete copy of structured Personal Data in a commonly used, machine-readable format and then delete or anonymize remaining copies, or (ii) delete or anonymize all structured Personal Data. Absent instruction, Audacity will delete or anonymize such data after the storage period. Full data deletion is available on account offboarding.
8.3 Billing and Audit Records. Billing and audit records — Service Data such as usage metadata (model, token counts, cost, latency, status, and user, key, and team attribution), invoices and ledger entries, and administrative and access audit logs — are retained for the life of the account, and thereafter as reasonably needed, for billing integrity, audit, and compliance (Section 9). These records contain no prompt or response content. Deletion under Sections 8.1 and 8.2 removes Stored Customer Content; billing and audit records are retained as set out in this Section 8.3.
8.4 Legal Retention. Audacity may retain Personal Data where and for so long as required or expressly permitted by applicable law, protected under this DPA and Processed only as necessary for the purpose that required its retention. These are the legal-retention carve-outs referred to in this DPA and in Audacity’s customer-facing privacy documentation.
8.5 Backups. Deleted content is removed from production systems promptly and from backups on their rotation schedule (database backups currently roll off after seven (7) days).
8.6 Self-Service Controls. Independently of this Section 8: users can delete all their chats and documents while keeping their account, or delete their account entirely, from their profile; and enterprise administrators can permanently delete all previously stored content for their organization on demand (including classification text snapshots), disable content storage for their organization entirely, and set an automatic retention window that deletes stored content older than a chosen number of days. Deleting a user account deletes that user’s stored content; deleting an organization deletes all of its stored content. Billing and audit records are retained in each case as set out in Section 8.3.
The Customer acknowledges that Audacity may collect, use, and disclose Service Data for its own business purposes, including accounting, billing, audit, and compliance; to provide, improve, and maintain the Services; to investigate fraud or misuse; to de-identify data for lawful business purposes; and as otherwise permitted by law. In respect of such Processing, Audacity acts as an independent Controller, complies with applicable Data Protection Laws, and applies safeguards no less protective than the Security Measures where possible. Service Data contains no prompt or response content (Section 1.3).
Audacity may use aggregated, de-identified usage data, metadata, and derived data generated through use of the Services to develop, train, improve, and optimize its and, where applicable, third-party AI models and to enhance the performance, functionality, and security of the Services. Identifiable Customer Data is never used by Audacity to train models; any product-improvement use is limited to de-identified, aggregated data as set out in this Section 10. Audacity shall not use Customer Data in a manner that identifies the Customer or any individual, or that would reasonably be expected to permit re-identification of such data, when used for AI model training or product improvement, and will not re-identify de-identified Personal Data.
11.1 Liability. Audacity’s aggregate liability arising out of or relating to this DPA is subject to the limitations, exclusions, and caps on liability set out in the Agreement (for the Terms of Service, its Limitation of Liability section).
11.2 Order of Precedence. Except as modified by this DPA, the Agreement remains in full force. In any conflict between this DPA and the other documents comprising the Agreement, the order of precedence set out in the Agreement controls, provided that this DPA prevails over the other documents solely with respect to the Processing of Personal Data.
11.3 Updates. Audacity may update the Subprocessor List and the Security Measures as set out in Sections 6 and 3. Material changes to this DPA itself are made in accordance with the Agreement’s modification provisions.
11.4 Governing Law; Severability. This DPA is governed by the law governing the Agreement. If any portion of this DPA is held invalid or unenforceable, the remainder remains in full force and effect.
This DPA may be executed in counterparts, including by electronic signature, each of which is deemed an original. Where this DPA is incorporated by reference into an Agreement executed by both parties, execution of that Agreement constitutes execution of this DPA and no separate signature is required.
AUDACITY ADVISORY CORP (d/b/a AI Reserve)
Signature:
Name:
Title:
Date:
CUSTOMER
Signature:
Name:
Title:
Date:
Data Importer (Processor): Audacity Advisory Corp (d/b/a AI Reserve), a U.S. corporation, 860 Broadway, New York, NY 10003, United States. Data protection contact: product@aireserve.com. Role: Processor (and independent Controller of Service Data, Section 9).
Data Exporter (Controller): The Customer / counterparty to the Agreement. Address and contact as in the signature block or the Agreement. Role: Controller (or Processor on behalf of its own customers, Section 1.1).
Categories of Data Subjects: Authorized users, employees, customers, and prospective customers of the Customer, in each case as the Customer causes Audacity to Process in providing the Services. Where the optional voice-cloning capability is enabled for the Customer’s organization, also the individuals whose voice recordings the Customer causes to be Processed (see Sensitive Data below).
Categories of Personal Data: Personal details; authentication details; technological details (IP addresses, identifiers, device data); user-service details (support content, logs); demographic and profile data; transactional and payment data; communications content and metadata; employment and education information — in each case only as the Customer causes Audacity to Process. Where the optional voice-cloning capability is enabled for the Customer’s organization, also voice recordings and derived voice models (see Sensitive Data below).
Sensitive Data: None, except: voice recordings and derived voice models (biometric-class data) are Processed only where the optional voice-cloning capability has been expressly enabled for the Customer’s organization at the Customer’s request; uploads require the uploader’s recorded consent attestation for the voice being cloned; such recordings and derived voice models are Processed by xAI (a Subprocessor, Annex 5), and the derived voice model is retained until the Customer deletes the voice, otherwise subject to Section 8. Audacity itself stores no voice audio — only the ownership and consent-attestation record, retained as an audit record (Section 8.3). No Sensitive Data is Processed for Customers for whom this capability has not been enabled.
Nature and Purpose of Processing: Processing operations required to provide the Services as initiated and configured by the Customer: routing AI requests to the model providers the Customer selects; operating chat history, search, document, and analytics features where enabled; metering, billing, and spend governance; security, authentication, and abuse prevention; and customer support.
Duration / Retention: As determined under the Agreement and Section 8 of this DPA.
Application. This Annex 2 applies solely to Processing of Personal Data subject to the GDPR or FADP. For Customers not subject to the GDPR or FADP, this Annex imposes no obligations on either party.
1. Processing. Where Audacity receives an instruction from the Customer that, in its reasonable opinion, infringes the GDPR, Audacity shall inform the Customer. The Customer acknowledges that its instructions shall comply with the GDPR and all other applicable laws.
2. Impact Assessments and Prior Consultation. Taking into account the nature of the Processing and the information available to it, Audacity shall provide reasonable assistance to the Customer, at the Customer’s cost (at Audacity’s then-current professional services rates), with data protection impact assessments and prior consultations with Supervisory Authorities that the Customer reasonably considers required under Articles 35 or 36 of the GDPR, solely in relation to Processing of Personal Data by Audacity.
3. Restricted Transfers. To the extent any Processing under this DPA involves an EU restricted transfer from the Customer to Audacity, the parties shall comply with the SCCs, which are deemed entered into by the parties and incorporated by reference into this DPA, populated as follows: Module Two (controller to processor) applies where the Customer is a Controller and Module Three (processor to processor) where the Customer acts as a Processor; the optional docking clause (Clause 7) is not used; in Clause 9, Option 2 (general written authorization) applies with the notice mechanics set out in Section 6.3 of this DPA; in Clause 11, the optional language is not used; in Clause 17, Option 1 applies and the SCCs are governed by the law of Ireland; for Clause 18, disputes shall be resolved by the courts of Ireland. Annex I to the Appendix of the SCCs is populated with the information in Annex 1 (Data Processing Details), with the Customer as data exporter and Audacity as data importer; Annex II is populated by reference to Section 3 (Security) and Annex 4 (Security Measures); Annex III is populated by reference to Annex 5 (Subprocessors). The competent Supervisory Authority is determined by the Customer’s place of establishment or EU representative as set out in the SCCs.
4. UK and Swiss Transfers. To the extent any Processing involves a UK restricted transfer, the SCCs apply as varied by the UK International Data Transfer Addendum, with Tables 1–3 populated with the details in Annex 1 and this Annex and Table 4 completed with the “Data Importer” box ticked; the parties agree to be bound by the Mandatory Clauses of the UK Addendum. To the extent any Processing involves a Swiss restricted transfer, the SCCs apply with the following substitutions: “ GDPR” means the FADP; “European Union”, “ Union”, and “Member State(s)” mean Switzerland; and “supervisory authority” means the Swiss Federal Data Protection and Information Commissioner. Nothing in the applicable SCCs limits Data Subjects’ rights under Clause 18(c) to bring proceedings in Switzerland where Switzerland is their place of habitual residence.
5. New Transfer Mechanisms. Audacity may, on notice, vary this DPA and replace the relevant SCCs with any new or replacement form of the SCCs prepared and populated accordingly, or with another transfer mechanism that enables the lawful transfer of Personal Data in compliance with Chapter V of the GDPR. On specific written request of a Supervisory Authority, a Data Subject, or a further Controller (with suitable supporting evidence), Audacity shall provide the Customer an executed version of the relevant SCCs for countersignature and onward provision.
6. Operational Clarifications. When complying with transparency obligations under Clause 8.3 of the SCCs, the Customer shall protect Audacity’s and its licensors’ trade secrets, confidential information, and commercially sensitive information. The Subprocessor terms of Section 6 of this DPA apply to Audacity’s use of Subprocessors under the SCCs, and the Customer’s authorization under Section 6 constitutes documented instruction to effect disclosures under Clause 8.8. Audit rights under Clauses 8.9(c)–(d) are subject to Section 7 of this DPA. Certification of deletion under Clauses 8.5 and 16(d) shall be provided on the Customer’s written request.
For purposes of this Annex, “business”, “commercial purpose”, “sell”, “share”, “ targeted advertising”, and “service provider” have the meanings given in the applicable U.S. state privacy laws (the “State Privacy Laws”), and “ personal information” means Personal Data governed by those laws.
It is the parties’ intent that Audacity is a service provider with respect to personal information. Audacity: (a) acknowledges that personal information is disclosed only for the limited and specified purposes described in the Agreement; (b) will comply with applicable obligations under the State Privacy Laws and provide the same level of privacy protection they require; (c) agrees the Customer may take reasonable steps to ensure Audacity’s use of personal information is consistent with the Customer’s obligations; (d) will notify the Customer if it determines it can no longer meet its obligations; and (e) agrees the Customer may take reasonable steps to stop and remediate unauthorized use.
Audacity shall not (a) sell or share personal information or use it for targeted advertising; (b) retain, use, or disclose personal information for any purpose other than providing the Services; (c) retain, use, or disclose personal information outside the direct business relationship; or (d) combine personal information with data from other sources, except in each case as necessary to provide the Services or as otherwise permitted for a service provider under the State Privacy Laws. Audacity certifies that it understands and will comply with these obligations. Audacity’s engagement of Subprocessors is authorized by the Customer’s general authorization in Section 6 and satisfies any obligation to identify subcontractors under the State Privacy Laws.
Audacity maintains the following technical, administrative, physical, and organizational measures, which reflect how the platform actually operates:
A current list of Subprocessors engaged by Audacity to Process Personal Data, including their functions and jurisdictions, together with the identification of providers acting as independent controllers, is maintained and available on the Platform at aireserve.com/developers/subprocessors — the authoritative Subprocessor List for purposes of this DPA. Per-provider training, retention, and processing-region detail is documented at aireserve.com/developers/data-handling. The Customer’s execution of this DPA constitutes the Customer’s authorization of the Subprocessors identified on the Subprocessor List as of the Effective Date and of Subprocessors added thereafter in accordance with Section 6, including its notice and objection mechanics (Section 6.3).