Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of the master services agreement, order form, subscription terms, or other written agreement (the “Agreement”) between the customer (“Customer”, “Controller”, “you”) and NeuralVerge Inc. (“NeuralVerge”, “Processor”, “we”, “us”). It governs the Processing of Customer Personal Data by NeuralVerge in the course of providing the NeuralVerge platform, AI agents, and related services (the “Services”). Where this DPA conflicts with the Agreement in respect of the Processing of Personal Data, this DPA controls. Capitalised terms not defined here have the meaning given in the Agreement.
1. Definitions
“Applicable Data Protection Law” means all laws and regulations applicable to the Processing of Personal Data under the Agreement, including the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and Data Protection Act 2018 (“UK GDPR”), the Swiss Federal Act on Data Protection (“FADP”), and U.S. state privacy laws such as the California Consumer Privacy Act as amended (“CCPA/CPRA”). “Controller”, “Processor”, “Data Subject”, “Personal Data”, “Personal Data Breach”, “Processing”, and “Supervisory Authority” have the meanings given in the GDPR (or the equivalent concepts, including “business”, “service provider”, and “consumer”, under U.S. state laws). “Customer Personal Data” means Personal Data that NeuralVerge Processes on behalf of Customer under the Agreement, as described in Annex I. “Sub-processor” means any third party engaged by NeuralVerge to Process Customer Personal Data. “Standard Contractual Clauses” or “SCCs” means the clauses annexed to EU Commission Implementing Decision 2021/914, and, for the UK, the UK International Data Transfer Addendum (“UK Addendum”).
2. Roles of the parties and scope
As between the parties, Customer is the Controller (or a Processor acting on behalf of a third-party Controller) and NeuralVerge is the Processor of Customer Personal Data. NeuralVerge will Process Customer Personal Data only as a Processor, acting on Customer’s documented instructions, for the purposes described in Annex I and for no other purpose. The subject matter, duration, nature and purpose of the Processing, the types of Personal Data, and the categories of Data Subjects are set out in Annex I. This DPA does not apply to Personal Data that NeuralVerge Processes as an independent Controller (see Section 13).
3. Customer instructions and responsibilities
Customer’s instructions to NeuralVerge for the Processing of Customer Personal Data are set out in the Agreement, this DPA, and Customer’s configuration and use of the Services; additional instructions must be agreed in writing. Customer will comply with Applicable Data Protection Law in its own capacity, and warrants that: (a) it has a valid legal basis and, where required, all necessary notices, consents, and authorisations to provide Customer Personal Data to NeuralVerge and to have it Processed as described; (b) its instructions are lawful; and (c) it will not use the Services to Process Personal Data in a manner that would infringe Applicable Data Protection Law. NeuralVerge will inform Customer if, in its opinion, an instruction infringes Applicable Data Protection Law (without obligation to conduct a legal review of instructions).
4. NeuralVerge obligations
NeuralVerge will: (a) Process Customer Personal Data only on Customer’s documented instructions, including regarding international transfers, unless required to do otherwise by law (in which case it will inform Customer unless legally prohibited); (b) ensure that persons authorised to Process Customer Personal Data are bound by an appropriate duty of confidentiality; (c) implement and maintain the technical and organisational measures set out in Annex II; (d) respect the conditions in Section 7 for engaging Sub-processors; (e) taking into account the nature of the Processing, assist Customer with appropriate measures to respond to Data Subject requests (Section 9); (f) assist Customer with security, breach notification, data protection impact assessments, and prior consultations with Supervisory Authorities (Sections 6, 10); and (g) delete or return Customer Personal Data as described in Section 11. NeuralVerge will make available information reasonably necessary to demonstrate compliance with Article 28 GDPR.
5. Confidentiality
NeuralVerge will treat Customer Personal Data as Customer’s confidential information and will not disclose it except to its personnel, Sub-processors, and advisers who need it to provide the Services and who are bound by confidentiality obligations, or as required by law. If NeuralVerge receives a legally binding request from a public authority to disclose Customer Personal Data, it will, unless legally prohibited, notify Customer and challenge disclosure requests that are unlawful or overbroad.
6. Security
NeuralVerge will implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing, as described in Annex II. Customer is responsible for its own use and configuration of the Services, including access controls, credentials, and the security of systems Customer connects to the Services.
7. Sub-processors
Customer provides a general authorisation for NeuralVerge to engage Sub-processors to Process Customer Personal Data. A current list of Sub-processors is set out in Annex III (or made available at neuralverge.ai/subprocessors). NeuralVerge will impose on each Sub-processor data protection obligations no less protective than those in this DPA and remains responsible for its Sub-processors’ performance. NeuralVerge will give Customer at least 30 days prior notice of the addition or replacement of a Sub-processor (e.g., by updating the list and, where Customer has subscribed, by email). Customer may object on reasonable, data-protection-related grounds within that period; the parties will work in good faith to resolve the objection, and if they cannot, Customer may terminate the affected Services as its exclusive remedy.
8. International data transfers
NeuralVerge and its Sub-processors may Process Customer Personal Data in countries other than the country of origin, including the United States. Where such transfers are subject to the GDPR, UK GDPR, or FADP and are made to a country without an adequacy decision, the parties agree that the Standard Contractual Clauses (with the UK Addendum and Swiss amendments as applicable) are incorporated by reference and apply, with the modules, options, and annex information completed by reference to Annex I and Annex III. If the SCCs or an alternative valid transfer mechanism cease to be valid, the parties will cooperate in good faith to implement an alternative mechanism.
9. Assistance with Data Subject requests
Taking into account the nature of the Processing, NeuralVerge will provide reasonable assistance, including appropriate technical and organisational measures and Service functionality, to enable Customer to respond to requests from Data Subjects to exercise their rights (access, rectification, erasure, restriction, portability, objection) under Applicable Data Protection Law. If NeuralVerge receives such a request directly from a Data Subject relating to Customer Personal Data, it will, unless legally required to respond, direct the Data Subject to Customer.
10. Personal Data Breaches
NeuralVerge will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will provide information reasonably available to it to assist Customer in meeting its own breach-notification obligations. Such notification is not an acknowledgement of fault or liability.
11. Deletion or return of Personal Data
Upon termination or expiry of the Agreement, NeuralVerge will, at Customer’s choice, delete or return Customer Personal Data and delete existing copies, unless retention is required by law. NeuralVerge may retain Customer Personal Data in routine backups for a limited period consistent with its retention schedule, during which it remains subject to this DPA.
12. Audits and information
NeuralVerge will make available to Customer information reasonably necessary to demonstrate compliance with this DPA and Article 28 GDPR, and will allow for and contribute to audits, including inspections, conducted by Customer or an auditor it mandates. To minimise disruption, NeuralVerge may satisfy audit requests by providing then-current third-party certifications, audit reports (e.g., SOC 2 / ISO 27001, where available), or completed security questionnaires; on-site audits are limited to once per twelve (12) months (absent a Supervisory Authority requirement or a Personal Data Breach), on reasonable prior notice, during business hours, subject to confidentiality, and at Customer’s cost.
13. Independently-sourced intelligence data
The Services may involve NeuralVerge collecting and Processing Personal Data from third-party and publicly available sources to build and maintain its intelligence datasets and models. To the extent NeuralVerge determines the purposes and means of that Processing independently of any individual customer’s instructions, NeuralVerge acts as an independent Controller for that Processing, and that Processing is governed by NeuralVerge’s Privacy Policy at neuralverge.ai/privacy-policy and Applicable Data Protection Law, not by this DPA. This DPA governs only Customer Personal Data that NeuralVerge Processes on Customer’s behalf as a Processor.
14. Liability
Each party’s liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement, and any reference in the Agreement to a party’s liability means the aggregate liability of that party under the Agreement and this DPA together.
15. Term, precedence, and governing law
This DPA takes effect on the effective date of the Agreement and remains in force for as long as NeuralVerge Processes Customer Personal Data. It is governed by the law and subject to the jurisdiction set out in the Agreement, or, absent such terms, the laws of the State of Delaware, USA and the state and federal courts located in Delaware — except that, where the SCCs apply, the governing law and forum specified in the SCCs control for matters arising under them. In the event of a conflict, the order of precedence is: (1) the SCCs, (2) this DPA, (3) the Agreement.
Privacy contact: denis@neuralverge.ai.
Annex I — Details of the Processing
A. List of parties
Data exporter (Controller): Customer, as identified in the Agreement. Contact: as stated in the Agreement / order form.
Data importer (Processor): NeuralVerge Inc., 228 Park Ave S, PMB 85451, New York, NY 10003, USA. Contact: denis@neuralverge.ai. Activities: provision of the NeuralVerge Services.
B. Description of the Processing
| Item | Description |
|---|---|
| Categories of Data Subjects | Customer’s authorised users; and the individuals and business contacts that Customer researches, enriches, or monitors using the Services (e.g., prospects, counterparties, company representatives) |
| Categories of Personal Data | Account/user data (name, work email, credentials, role); query and input data submitted by Customer; and intelligence outputs about researched individuals (e.g., name, professional profile, employer, role, public business information, and other data Customer chooses to process) |
| Special category data | Not intended to be Processed. Customer must not submit special category data unless expressly agreed in writing and subject to additional safeguards |
| Frequency of Processing | Continuous, for the duration of the Agreement |
| Nature and purpose | Hosting, storage, retrieval, enrichment, analysis, and delivery of intelligence outputs, and provision and support of the Services |
| Duration | For the term of the Agreement plus the retention/deletion period in Section 11 |
C. Competent Supervisory Authority
Not applicable while NeuralVerge offers the Services to U.S.-based customers. If NeuralVerge later carries out Processing subject to EEA/UK data protection law, the competent Supervisory Authority will be determined at that time.
Annex II — Technical and organisational security measures
NeuralVerge maintains security measures appropriate to the risk, including: encryption of Personal Data in transit and at rest; access controls with multi-factor authentication for administrative access; logging and monitoring; regular encrypted backups; personnel confidentiality obligations; and a documented incident response process. NeuralVerge does not currently hold SOC 2 or ISO 27001 certification and is targeting SOC 2 by July 2027.
Annex III — Approved Sub-processors
The current list of approved Sub-processors, with the purpose and location of each, is published at Sub-processors and forms part of this DPA. It is maintained there rather than reproduced here so that it stays current; changes are notified as described in Section 7. Where a Sub-processor is located outside the United States, transfers are made on the basis set out in Section 8.
Every NeuralVerge policy in one place.
Privacy center →