Data Processing Addendum

Effective date: October 6, 2026 · Version 1.0

This Data Processing Addendum (this "DPA") applies between Neev Technologies, Inc. ("NeevAI") and each customer that accepts it through an Order that references it ("Customer") (each a "Party" and together the "Parties"). It forms part of the agreement made up of that Order and the Customer Terms of Service (together, the "Agreement"), under which NeevAI provides the NeevAI Platform and related services (the "Services").

In providing the Services, NeevAI may Process Customer Personal Data on Customer's behalf. This DPA sets out the Parties' obligations for that Processing. Customer does not need to sign this DPA separately; accepting an Order that references it is enough. On request, NeevAI will countersign a copy of this DPA.

1. Definitions

Capitalized terms not defined in this DPA have the meanings given in the Customer Terms of Service. In this DPA:

  • "Affiliate" means an entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity, where "control" means direct or indirect ownership of more than 50% of the voting rights in the entity.
  • "Customer Personal Data" means Personal Data that NeevAI or its Subprocessors Process on behalf of Customer under the Agreement, as described in Annex I.
  • "Data Protection Assessment" means an assessment of the impact of Processing on the protection of Personal Data and the rights of Data Subjects, including a data protection impact assessment or risk assessment as defined by Data Protection Laws.
  • "Data Protection Laws" means all data protection and privacy laws that apply to the Processing of Customer Personal Data under the Agreement, which may include: (i) the EU General Data Protection Regulation 2016/679 ("GDPR") and laws of EU Member States implementing or supplementing it; (ii) the UK Data Protection Act 2018 and the GDPR as it forms part of UK law ("UK GDPR"); (iii) the Swiss Federal Act on Data Protection; (iv) the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020, and its regulations ("CCPA"); (v) the comprehensive consumer privacy laws of other U.S. states, such as Virginia, Colorado, Connecticut and Utah; and (vi) any other equivalent laws, in each case as amended or replaced from time to time.
  • "Data Subject" means an identified or identifiable natural person whose Personal Data is Processed, and includes a "consumer" as defined in Data Protection Laws.
  • "Deidentified Data" means information that cannot reasonably be used to infer information about, or otherwise be linked to, an identified or identifiable natural person.
  • "Order Term" has the meaning given in the Customer Terms of Service.
  • "Personal Data" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual or household, or that is otherwise "personal data" or "personal information" under Data Protection Laws.
  • "Personnel" means a Party's officers, directors, employees, contractors and agents.
  • "Regulatory Authority" means a public authority responsible for supervising compliance with Data Protection Laws, such as an EU Member State supervisory authority, the UK Information Commissioner's Office, the California Privacy Protection Agency, or a U.S. state attorney general.
  • "Security Breach" means a breach of security of NeevAI's or its Subprocessors' systems leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data. Unsuccessful attempts that do not compromise the security of Customer Personal Data, such as pings, port scans, blocked log-in attempts and denial of service attacks, are not Security Breaches.
  • "Subprocessor" means a third party that NeevAI engages to Process Customer Personal Data on Customer's behalf in providing the Services.
  • The terms "Business", "Business Purpose", "Controller", "Process", "Processor", "Sell", "Service Provider", "Share" and "Third Party" have the meanings given in Data Protection Laws, and related terms are interpreted accordingly.

2. Application and versions

2.1 Application. This DPA applies to Customer from the date Customer signs an Order that references it, and continues for as long as NeevAI Processes Customer Personal Data.

2.2 Versions. NeevAI may publish a new version of this DPA at neevai.io/legal/dpa with a new version number and effective date. The version in effect on the date an Order is signed applies to that Order for its current Order Term. A later version applies to that Order only from the start of its next renewal term that begins after the later version's effective date, unless Customer agrees in writing to apply it sooner or Section 15 applies. Updates to the list of Subprocessors in Annex III follow Section 6, not this Section 2.2.

3. Processing of Personal Data

3.1 Roles of the Parties. With respect to Customer Personal Data, Customer is the Controller or Business, and NeevAI is the Processor or Service Provider. NeevAI may engage Subprocessors in accordance with Section 6.

3.2 NeevAI's Processing. NeevAI will treat Customer Personal Data as confidential and will Process it only on Customer's documented instructions, which are: (a) to provide the Services in accordance with the Agreement, each Order and this DPA; (b) Processing initiated by Customer, its Authorized Users or its End Users in their use of the Services, including through the configuration Customer sets in the NeevAI portal; and (c) other reasonable written instructions from Customer that are consistent with the Agreement. NeevAI may also Process Customer Personal Data where required by applicable law, in which case it will inform Customer of that legal requirement before Processing unless the law prohibits it.

3.3 Customer's Processing. Customer will comply with Data Protection Laws in its use of the Services and in its instructions to NeevAI. Customer is responsible for having a lawful basis for the Processing, for giving Data Subjects any notices required by Data Protection Laws (including that they are interacting with an AI agent), and for obtaining any consents required.

3.4 Unlawful instructions. NeevAI will promptly inform Customer if, in its opinion, an instruction from Customer breaches Data Protection Laws. NeevAI is not required to follow such an instruction.

3.5 CCPA and U.S. state privacy laws. To the extent the CCPA or a similar U.S. state law applies to Customer Personal Data, NeevAI will not: (a) Sell or Share Customer Personal Data; (b) retain, use or disclose Customer Personal Data for any purpose other than the Business Purposes specified in the Agreement, or as otherwise permitted by Data Protection Laws; (c) retain, use or disclose Customer Personal Data outside the direct business relationship between NeevAI and Customer; or (d) combine Customer Personal Data with Personal Data it receives from or on behalf of another person, or collects from its own interactions with Data Subjects, except as permitted by Data Protection Laws. NeevAI will provide the same level of privacy protection as Data Protection Laws require, will notify Customer if it determines that it can no longer meet its obligations under them, and grants Customer the right, on reasonable notice, to take reasonable and appropriate steps to stop and remediate any unauthorized use of Customer Personal Data. NeevAI certifies that it understands and will comply with these restrictions.

3.6 Details of the Processing. The subject matter, duration, nature and purpose of the Processing, and the types of Customer Personal Data and categories of Data Subjects, are described in Annex I.

3.7 Data Protection Assessments. Taking into account the nature of the Processing and the information available to it, NeevAI will provide Customer with reasonable information and assistance that Customer needs to carry out a Data Protection Assessment, or to consult a Regulatory Authority, about the Processing under this DPA.

4. Rights of Data Subjects

4.1 Notification. If NeevAI receives a request from a Data Subject to exercise their rights under Data Protection Laws with respect to Customer Personal Data, such as a request for access, correction, deletion, restriction, portability, or to opt out (a "Data Subject Request"), NeevAI will, to the extent legally permitted, notify Customer promptly and in any event within five (5) business days of receipt. NeevAI will not respond to the Data Subject Request itself, except to direct the Data Subject to Customer, unless Customer authorizes it or the law requires it.

4.2 Assistance. Taking into account the nature of the Processing, NeevAI will provide reasonable assistance to help Customer respond to Data Subject Requests, including by locating, exporting, correcting or deleting the relevant Customer Personal Data on Customer's request where Customer cannot do so itself through the Services. Where a Data Subject Request concerns deletion and Data Protection Laws require it, NeevAI will instruct its Subprocessors to delete the relevant Customer Personal Data.

5. NeevAI Personnel

5.1 Confidentiality. NeevAI will ensure that its Personnel who Process Customer Personal Data are informed of its confidential nature, are bound by written confidentiality obligations, and have received appropriate guidance on handling it.

5.2 Reliability. NeevAI will take reasonable steps to ensure the reliability of its Personnel who Process Customer Personal Data.

5.3 Limitation of access. NeevAI will limit access to Customer Personal Data to those Personnel who need it to provide, support or secure the Services.

6. Subprocessors

6.1 Authorization. Customer generally authorizes NeevAI to engage Subprocessors, and specifically authorizes the Subprocessors listed in Annex III as of the date of its Order.

6.2 Subprocessor obligations. NeevAI will enter into a written agreement with each Subprocessor that imposes data protection obligations no less protective of Customer Personal Data than those in this DPA, to the extent appropriate to the service the Subprocessor provides. NeevAI remains responsible to Customer for the performance of each Subprocessor's obligations.

6.3 New Subprocessors. NeevAI will notify Customer by email to the notice contact in the Order at least thirty (30) days before a new Subprocessor begins Processing Customer Personal Data, stating the Subprocessor's name, the service it provides and its location, and will update Annex III. Where a new Subprocessor is urgently needed to keep the Services running or secure, NeevAI may engage it on shorter notice and will notify Customer as soon as reasonably practicable, and Customer's objection rights in Section 6.4 still apply.

6.4 Objection. Customer may object to a new Subprocessor on reasonable grounds relating to data protection by written notice to NeevAI within the notice period in Section 6.3. The Parties will discuss Customer's concerns in good faith, and NeevAI may offer a reasonable alternative, such as not using the Subprocessor for Customer. If the Parties cannot resolve the objection within thirty (30) days of Customer's notice, Customer may terminate the affected Services by written notice, and NeevAI will refund to Customer a pro-rata portion of prepaid fees for those Services covering the period after termination.

6.5 Customer-connected systems. Third-party systems that Customer chooses to connect to its AI agents through connectors, such as Customer's own CRM, help desk or calendar, are Customer's own service providers and not NeevAI's Subprocessors. NeevAI transmits Customer Personal Data to those systems only as Customer configures and instructs.

7. Security

7.1 Security measures. Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the Processing, NeevAI will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against Security Breaches, as described in Annex II. NeevAI may update these measures from time to time, provided the updates do not materially reduce the overall protection of Customer Personal Data.

7.2 Customer's responsibilities. Customer is responsible for the security of its own systems, its account credentials, the configuration of its AI agents and connectors, and for using the security features the Services make available.

7.3 Security Breach notification. NeevAI will notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a confirmed Security Breach affecting Customer Personal Data. NeevAI will promptly investigate the Security Breach, take reasonable steps to contain and remediate it and mitigate its effects, and provide information that Customer reasonably requests about it.

7.4 Content of notice. The notice will include, to the extent reasonably known at the time: (a) a description of the nature of the Security Breach, including, where possible, the categories and approximate number of Data Subjects and records concerned; (b) the name and contact details of a NeevAI contact who can provide more information; (c) a description of the likely consequences of the Security Breach; and (d) a description of the measures taken or proposed to address it, including measures to mitigate its possible adverse effects. Where it is not possible to provide all of this information at the same time, NeevAI may provide it in phases without undue further delay.

7.5 Notice address. NeevAI will send Security Breach notices to the security contact named in the Order or, if none is named, to Customer's notice contact in the Order, or to another contact Customer designates in writing.

7.6 Notifications to third parties. Customer decides whether to notify Data Subjects and Regulatory Authorities of a Security Breach affecting Customer Personal Data. NeevAI will not notify them about such a Security Breach without Customer's prior written consent, unless the law requires it, and will provide reasonable assistance with Customer's notifications. NeevAI's notification of or response to a Security Breach is not an acknowledgement of fault or liability.

8. Information, cooperation and audits

8.1 Information. On Customer's reasonable request, NeevAI will make available information necessary to demonstrate its compliance with this DPA and Data Protection Laws, and will complete Customer's reasonable security questionnaire once in any twelve (12) month period.

8.2 Audits. Where Data Protection Laws require it, or following a Security Breach affecting Customer Personal Data, Customer may carry out an audit of NeevAI's compliance with this DPA, either itself or through an independent auditor that is not a competitor of NeevAI and is bound by confidentiality obligations, subject to the following: (a) Customer gives at least thirty (30) days' written notice and the Parties agree the scope, timing and duration in advance; (b) the audit takes place during business hours and is conducted so as to minimize disruption to NeevAI's business; (c) the audit does not give access to other customers' data or to information subject to legal privilege or third-party confidentiality; (d) Customer bears its own costs and the auditor's costs; and (e) audits take place no more than once in any twelve (12) month period, unless a Regulatory Authority requires otherwise.

8.3 Confidentiality. All information provided or obtained under this Section 8, including any audit report, is NeevAI's Confidential Information.

9. Return and deletion of Customer Personal Data

9.1 During the term. Customer may export Customer Personal Data held in the Services at any time during the Order Term, using the export features of the NeevAI portal or with NeevAI's reasonable assistance.

9.2 After the term. NeevAI will delete Customer Personal Data from its systems within thirty (30) days after the end of the Order Term, unless the Order states a different period or applicable law requires NeevAI to retain it. Until deletion, NeevAI will make Customer Personal Data available for export on Customer's request as described in the Customer Terms of Service. Customer Personal Data held in backups is deleted when those backups expire in the ordinary course. On Customer's written request, NeevAI will confirm the deletion in writing.

9.3 Retained data. Any Customer Personal Data that NeevAI retains after the Order Term as required by law remains subject to this DPA, and NeevAI will Process it only for the purposes that require its retention.

10. Cross-border data transfers

10.1 Transfers. NeevAI and its Subprocessors may Process Customer Personal Data in the United States and in the other locations listed in Annex III. Where the Processing involves a transfer of Customer Personal Data from the European Economic Area ("EEA"), Switzerland or the United Kingdom to a country that has not been recognized as providing an adequate level of protection, and Data Protection Laws require a transfer mechanism, the Parties will rely on the mechanisms in this Section 10 or another mechanism permitted by Data Protection Laws.

10.2 EU Standard Contractual Clauses. For transfers of Customer Personal Data from the EEA, the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914 (the "EU SCCs") are incorporated into this DPA as follows: (a) Module 2 (controller to processor) applies where Customer is a Controller; and (b) Module 3 (processor to processor) applies where Customer is itself a Processor acting for a third-party Controller. Customer is the data exporter and NeevAI is the data importer.

10.3 EU SCCs options. Where the EU SCCs offer options: (a) the optional docking clause in Clause 7 does not apply; (b) in Clause 9(a), Option 2 (general written authorization) applies, with the notice period and objection process in Section 6; (c) the optional language in Clause 11(a) does not apply; (d) in Clause 17, Option 1 applies and the EU SCCs are governed by the law of Ireland; (e) in Clause 18(b), disputes are resolved before the courts of Ireland; and (f) Annexes I, II and III of the EU SCCs are completed with the information in Annexes I, II and III of this DPA.

10.4 UK transfers. For transfers of Customer Personal Data from the United Kingdom, the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner under section 119A(1) of the Data Protection Act 2018 (the "UK Addendum") applies. Tables 1 to 3 of the UK Addendum are completed with the information in Section 10.2 and the Annexes to this DPA, and for Table 4 either Party may end the UK Addendum as set out in its Section 19.

10.5 Swiss transfers. For transfers of Customer Personal Data from Switzerland, the EU SCCs apply as amended to meet the requirements of the Swiss Federal Act on Data Protection, references to the GDPR are read as references to that Act, and the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner.

10.6 Onward transfers. Where a Subprocessor Processes Customer Personal Data outside the EEA, Switzerland or the United Kingdom, NeevAI will ensure that an appropriate transfer mechanism is in place with that Subprocessor where Data Protection Laws require one.

11. Deidentified Data

To the extent NeevAI receives Deidentified Data from Customer, or Processes Customer Personal Data so that it becomes Deidentified Data, NeevAI will: (a) take reasonable measures to ensure the data cannot be associated with an individual or household; (b) publicly commit to maintain and use it only in de-identified form and not attempt to re-identify it, except as permitted by Data Protection Laws; and (c) contractually require any recipient of it to comply with the same requirements. This Section 11 is that public commitment.

12. Marketing

NeevAI will not use Customer Personal Data to market its own or any third party's products or services.

13. Liability

Each Party's liability arising out of or relating to this DPA, including under the EU SCCs and UK Addendum to the extent permitted by Data Protection Laws, is subject to the exclusions and limitations of liability in the Customer Terms of Service. Nothing in this DPA limits either Party's liability to Data Subjects under the EU SCCs where that liability cannot lawfully be limited.

14. Breach of this DPA

A material breach of this DPA is a material breach of the Agreement, and the termination rights and remedies in the Customer Terms of Service apply.

15. Changes in Data Protection Laws

If a change in Data Protection Laws requires a change to this DPA, either Party may give the other written notice proposing amendments, and the Parties will negotiate in good faith to agree amendments that address the requirement. If the Parties cannot agree within sixty (60) days of the notice, either Party may terminate the affected Services by thirty (30) days' written notice, and NeevAI will refund to Customer a pro-rata portion of prepaid fees for those Services covering the period after termination.

16. Governing law

Except where the EU SCCs or UK Addendum require otherwise, this DPA is governed by the law, and disputes under it are subject to the jurisdiction, stated in the Customer Terms of Service.

17. Order of precedence

If there is a conflict between this DPA and the rest of the Agreement concerning the Processing of Customer Personal Data, this DPA controls, except where this DPA defers to the Order. If there is a conflict between this DPA and the EU SCCs or UK Addendum, the EU SCCs or UK Addendum control.

18. Severability

If any provision of this DPA is held invalid or unenforceable, it will be modified to the minimum extent necessary to make it enforceable, and the remaining provisions continue in full effect.

19. Survival

This DPA continues in effect for as long as NeevAI Processes Customer Personal Data, even after the Agreement ends.

Annex I: Description of the Processing

A. List of parties

Data exporter
NameThe Customer named in the Order
AddressAs stated in the Order
Contact personThe notice contact named in the Order
Activities relevant to the transferUse of the NeevAI Platform to deploy AI agents to visitors of Customer's websites and other channels, and to manage those agents through the NeevAI portal
RoleController (or Processor, where Module 3 applies)
Signature and dateSignature of the Order that references this DPA
Data importer
NameNeev Technologies, Inc.
Address262 Chapman Rd, Ste 240, Newark, Delaware 19702, United States
Contact personVikhyat Puri, Chief Executive Officer, [email protected]
Activities relevant to the transferProvision of the NeevAI Platform and related services under the Agreement
RoleProcessor
Signature and dateSignature of the Order that references this DPA

B. Description of the transfer

ItemDescription
Categories of Data SubjectsVisitors and other End Users who use Customer's AI agents. Customer's Authorized Users of the NeevAI portal.
Categories of Personal DataChat messages, and any information visitors choose to type into a conversation. Optional pre-chat form fields that Customer enables, such as name and email address. Technical data needed to deliver the service, such as IP address and browser information. Names and email addresses of Authorized Users.
Sensitive dataNot intended. Customer instructs its AI agents and forms not to collect special categories of personal data or other sensitive information. Any such data that a visitor volunteers is protected by the measures in Annex II.
Frequency of the transferContinuous, for the duration of the Agreement.
Nature of the ProcessingHosting and storage; generation of AI agent responses using AI models; knowledge base search; conversation analysis for Customer's analytics (such as intent, sentiment and quality scoring); sending escalation emails to Customer's team where Customer enables them; transmitting data to third-party systems that Customer connects through connectors, on Customer's instruction; and support.
Purpose of the ProcessingTo provide, support and secure the Services for Customer under the Agreement.
RetentionFor the Order Term plus up to thirty (30) days, or the period stated in the Order, as described in Section 9, unless Customer deletes data earlier or the law requires longer retention.
Transfers to SubprocessorsAs described in Annex III, for the duration of the Agreement, for the service each Subprocessor provides.

C. Competent supervisory authority

For transfers under the EU SCCs: the Data Protection Commission of Ireland.

Annex II: Technical and Organizational Security Measures

NeevAI maintains the following measures for the Platform.

  • Encryption in transit: the NeevAI portal, NeevAI chat and the Platform's public endpoints are served over HTTPS using TLS.
  • Hosting: the Platform is hosted on Amazon Web Services in the United States (us-west-2), with its database on Amazon RDS for PostgreSQL in us-west-2, and relies on Amazon Web Services' physical and environmental controls for its data centers.
  • Connector credentials: API keys and access tokens that Customer provides for connectors are encrypted with AES-GCM before they are stored.
  • Tenant separation: each customer's data is logically separated from other customers' data by a tenant identifier.
  • Portal authentication: Authorized Users sign in to the NeevAI portal through Google Firebase Authentication.
  • Personnel access: access to production systems and Customer Personal Data is restricted to authorized NeevAI Personnel who need it to provide, support or secure the Services.
  • Personnel confidentiality: NeevAI Personnel with access to Customer Personal Data are bound by written confidentiality obligations, as required by Section 5.1.
  • AI model providers: AI model providers receive only the content needed to perform the relevant function. Customer content is not used to train models by NeevAI or by the model provider.
  • Incident response: NeevAI maintains an incident response process to identify, contain, investigate and remediate security incidents, and to notify Customer as described in Section 7.3.

Annex III: Authorized Subprocessors

Customer authorizes the following Subprocessors as of the date of its Order. Changes to this list follow Section 6.

NameServiceCustomer Personal DataLocation
Amazon Web Services, Inc.Hosting, compute and managed database (Amazon RDS for PostgreSQL)All Customer Personal DataUnited States (us-west-2)
Microsoft Corporation (Azure OpenAI Service)AI response generation and conversation analysis using OpenAI modelsConversation content and retrieved knowledge base passagesUnited States
Google LLC (Firebase Authentication)Sign-in to the NeevAI portalIdentity data (email address, user identifier)United States
Cloudflare, Inc.DNS, content delivery and the chat widget loaderVisitor technical data (such as IP address and browser information)Global network
Twilio Inc. (SendGrid)Escalation emails, when Customer enables themVisitor name, email address and questionUnited States

Related: Customer Terms of Service · Privacy Policy · All legal pages