Last updated: October 2, 2026
This Data Processing Agreement (“DPA”) is entered into by Thrifty AI (“Thrifty AI”) and the Thrifty AI customer identified in the Agreement (“Customer”) (each a “Party”; collectively the “Parties”) and is incorporated by reference into the applicable subscription agreement governing Customer’s use of Thrifty AI’s Platform, including Thrifty Studio, the Thrifty AI APIs and SDKs, Thrifty Agent, and any managed deployments (the “Agreement”) between the Parties and takes precedence over the Agreement to the extent of any conflict. All capitalized terms used in this DPA but not defined will have the meaning set forth in the Agreement or under Data Protection Laws. Any prior data protection agreement that may already exist between the Parties is superseded and replaced by this DPA on the date this DPA has been fully executed by the Parties.
1. Definitions.
- (a) “Data Protection Laws” means all applicable laws, regulations, and other legal or regulatory requirements in any jurisdiction relating to privacy, data protection, data security, biometric privacy, breach notification, or the Processing of personal data, including without limitation, to the extent applicable, the General Data Protection Regulation, Regulation (EU) 2016/679 (“GDPR”); the United Kingdom Data Protection Act of 2018; the Swiss Federal Act on Data Protection (“FADP”); the California Consumer Privacy Act, Cal. Civ. Code § 1798.100 et seq., as amended and including its regulations (“CCPA”); India’s Digital Personal Data Protection Act, 2023; and other applicable U.S. state and federal laws, including state biometric privacy laws. For the avoidance of doubt, if Thrifty AI’s Processing activities involving Personal Data are not within the scope of a Data Protection Law, such law is not applicable for purposes of this DPA.
- (b) “Biometric Data” means Personal Data resulting from specific technical processing relating to the physical, physiological, or behavioral characteristics of a natural person, such as facial imagery or voice characteristics, where such data allows or confirms the unique identification of that person, and includes “biometric identifiers” and “biometric information” and analogous terms as defined by applicable Data Protection Laws.
- (c) “Conversation Data” means Personal Data captured or generated during a conversation between an end user and an artificial human provided through the Platform, including voice audio, camera video frames and facial imagery, screen-share content, conversation transcripts, audio and video recordings, and interview, assessment, or roleplay scores and reports.
- (d) “Data Privacy Frameworks” means the EU-U.S Data Privacy Framework (“EU-U.S. DPF”), the Swiss-U.S. Data Privacy Framework (“Swiss-U.S. DPF”), and the UK Extension to the EU-U.S. DPF (“UK Extension”) as administered by the U.S. Department of Commerce.
- (e) “Data Subject” means an identified or identifiable natural person to whom Personal Data relates, and is deemed to also include a “consumer” and a “data principal” as defined under Data Protection Laws.
- (f) “EU SCCs” means the Standard Contractual Clauses issued pursuant to Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of Personal Data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council, available at http://data.europa.eu/eli/dec_impl/2021/914/oj and completed as set forth herein.
- (g) “Personal Data” includes “personal data,” “personal information,” “personally identifiable information,” and analogous terms, as defined by applicable Data Protection Laws, that Thrifty AI Processes to provide the Platform under the Agreement, including Conversation Data and Biometric Data.
- (h) “Process”, “Processing,” “Processed,” etc., mean any operation or set of operations performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, creating, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
- (i) “Security Incident” means any confirmed breach of security that results in the accidental or unlawful acquisition, destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data processed by Thrifty AI and/or its Subprocessors in connection with Thrifty AI’s provision of the Platform.
- (j) “Subprocessor” means any third party that Thrifty AI engages to Process Personal Data to provide the Platform.
- (k) “UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner’s Office, located at https://ico.org.uk/media2/migrated/4019539/international-data-transfer-addendum.pdf and completed as set forth herein.
- (l) The terms “Business,” “Controller,” “Processor,” and “Service Provider” are defined as in Data Protection Laws. “Controller” is deemed to also refer to “Business” and “Data Fiduciary,” and “Processor” is deemed to also refer to “Service Provider” and “Data Processor.”
2. Roles of the Parties; Scope and Purposes of Processing.
- (a) Roles of the Parties. To the extent that Customer is the Controller of Personal Data, Thrifty AI is its Processor. To the extent that Customer is a Processor of Personal Data, Thrifty AI is its Subprocessor.
- (b) Scope and Purposes of Processing. This DPA applies to all Personal Data that Thrifty AI Processes to provide the Platform to Customer. Thrifty AI will Process Personal Data (i) in compliance with Data Protection Laws; (ii) on Customer’s behalf and in accordance with Customer’s instructions as set forth in this DPA and the Agreement, and as otherwise provided by the Customer in writing; and (iii) to provide the Platform to Customer under the Agreement for the business purposes set forth in the Agreement and as set forth in this DPA, unless other Processing activities are required otherwise to comply with Data Protection Laws (in which case, Thrifty AI shall provide prior notice to Customer of such legal requirement, unless such law prohibits this disclosure). Customer’s configuration of its artificial humans and of the Platform, including whether conversations are recorded, how long recordings and transcripts are retained, whether memory across conversations is enabled, and which documents are uploaded to a knowledge base, constitutes part of Customer’s instructions.
- (c) Customer Rights. Customer retains the right to take reasonable and appropriate steps to (i) ensure that Thrifty AI Processes Personal Data in a manner consistent with Data Protection Laws, and (ii) upon notice, stop and remediate unauthorized Processing of Personal Data, including any use of Personal Data not expressly authorized in this DPA.
- (d) Customer Obligations. Where Customer is a Controller, Customer is responsible for providing any notices, obtaining any consents or authorizations, and otherwise satisfying its own compliance obligations with respect to the Processing of Personal Data under this DPA. Where Customer is a Processor, Customer represents to Thrifty AI that its provision of Personal Data to Thrifty AI is in compliance with Data Protection Laws and Customer’s contractual obligations. Customer will not instruct Thrifty AI to Process Personal Data in a violation of Data Protection Laws or any third party’s legal, contractual, or other rights. Customer in its sole discretion determines the categories and types of Personal Data that it provides to Thrifty AI through the Platform. Customer is responsible for secure and responsible use of the Platform and for determining that the Platform ensure a level of security appropriate to the risk in respect of Personal Data and agrees that the security and compliance measures set forth in the Agreement and this DPA are deemed sufficient.
- (e) End User Notices and Consents. Without limiting Section 2(d), Customer is responsible for (i) clearly disclosing to its end users that they are interacting with an artificial human and not a human being; (ii) notifying end users, and obtaining any consents required under Data Protection Laws, before their voice, camera video, facial imagery, or screen-share content is captured, and before any conversation is recorded or transcribed; (iii) where an artificial human joins a meeting on a third-party meeting platform such as Google Meet or Zoom, informing the meeting participants of its presence and of any recording; and (iv) where the Platform is used for interviews, assessments, or roleplays that produce scored reports, providing any notices and meaningful human review, and honoring any rights to object to or contest automated decisions, that Data Protection Laws require.
- (f) Biometric Data. Thrifty AI Processes Biometric Data, including facial imagery and voice characteristics contained in Conversation Data, only to the extent necessary to provide the Platform (for example, to enable an artificial human to hear, see, and respond to an end user in real time) and in accordance with Customer’s documented instructions. Thrifty AI will not use Biometric Data to identify or verify the identity of individuals unless Customer expressly configures the Platform to do so, will not sell, lease, trade, or otherwise profit from Biometric Data, and will retain and destroy Biometric Data in accordance with Customer’s instructions, Section 9, and applicable Data Protection Laws. Customer is responsible for any written policy, notice, written release, or consent that applicable biometric privacy laws require of it as the Controller.
3. Personal Data Processing Requirements.
- (a) Restrictions on Processing. Thrifty AI will:
- (i) not retain, use, or disclose Personal Data for any purpose other than the business purposes specified in the Agreement and this DPA, or outside of the direct business relationship between Thrifty AI and Customer, except as permitted by Data Protection Laws;
- (ii) not “sell” or “share” any Personal Data, or use Personal Data for purposes of “targeted advertising,” as such terms are defined in Data Protection Laws; and
- (iii) comply with any applicable restrictions under the CCPA on combining Personal Data with personal data that Thrifty AI receives from, or on behalf of, another person or persons, or that Thrifty AI collects from any interaction between it and any individual.
- (b) Confidentiality. Thrifty AI will ensure that the persons Processing the Personal Data are bound by obligations of confidentiality no less protective than those set forth in the Agreement or are under an appropriate statutory obligation of confidentiality.
- (c) Assistance. Thrifty AI will provide Customer with reasonable assistance:
- (i) by appropriate technical and organizational measures, insofar as possible, in fulfilling Customer’s obligation to respond to requests from Data Subjects to exercise their rights under Data Protection Laws, including requests to access or delete conversation recordings, transcripts, and assessment results; and
- (ii) in performing any required data protection impact assessment of Processing or proposed Processing of Personal Data, and in consulting with regulatory authorities in relation to the Processing or proposed Processing of Personal Data, including any applicable obligation upon Thrifty AI to consult with a regulatory authority in relation to Thrifty AI’s Processing or proposed Processing of Personal Data.
- (d) Notice Regarding Compliance and Instructions. Thrifty AI will promptly notify Customer if Thrifty AI determines that it can no longer meet its obligations under Data Protection Laws or if it believes that Customer’s instructions violate Data Protection Laws, and Thrifty AI is not deemed to be in breach of this DPA if it declines to Process Personal Data in a way that Thrifty AI reasonably and in good faith believes would cause Thrifty AI to violate Data Protection Laws.
- (e) Model Training. Thrifty AI will not use Conversation Data or Biometric Data to train or fine-tune machine learning models made available to other customers, except as expressly authorized by Customer in writing.
4. Data Security.
Thrifty AI will use appropriate administrative, technical, physical, and organizational measures to protect Personal Data as set forth in Exhibit B. Thrifty AI will provide the level of protection for Personal Data that is required under Data Protection Laws. Such measures will take into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing, including the sensitivity of audio, video, facial imagery, and Biometric Data, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, so as to ensure a level of security appropriate to the risk.
5. Security Incident.
- (a) Notice. Thrifty AI will notify Customer of any Security Incident without undue delay or within the time period required under Data Protection Laws. To the extent available, this notification will include Thrifty AI’s then-current assessment of the following: (i) the nature of the Security Incident, including, where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of Personal Data records concerned; (ii) the likely consequences of the Security Incident; and (iii) measures taken or proposed to be taken by Thrifty AI to address the Security Incident, including, where applicable, measures to mitigate its possible adverse effects. Thrifty AI will provide timely and periodic updates to Customer as additional information regarding the Security Incident becomes available. Customer acknowledges that any updates may be based on incomplete information.
- (b) Responsibilities of the Parties. Thrifty AI will comply with the Security Incident-related obligations applicable to it under Data Protection Laws and will assist Customer in Customer’s compliance with its Security Incident-related obligations. Thrifty AI will not assess the contents of Customer Data for the purpose of determining if such data is subject to any requirements under Data Protection Laws. Nothing in this DPA or in the EU SCCs will be construed to require Thrifty AI to violate, or delay compliance with, any legal obligation it may have with respect to a Security Incident or other security incidents generally.
6. Subprocessors.
- (a) Authorization to Engage Subprocessors. Customer agrees that Thrifty AI may engage Subprocessors to Process the Personal Data on Thrifty AI’s behalf to provide the Platform. A list of Thrifty AI’s Subprocessors is available at thriftyai.com/legal/subprocessors. Thrifty AI will impose contractual obligations on any Subprocessor it appoints requiring it to protect Personal Data to standards that are no less protective than those set forth under this DPA. Thrifty AI shall remain fully liable to Customer for the performance of the Subprocessor’s data protection obligations. The subprocessor agreements to be provided under Clause 9 of the EU SCCs may have all commercial information, or provisions unrelated to the Standard Contractual Clauses, redacted prior to sharing with Customer, and Customer agrees that such copies will be provided only upon Customer’s written request, no more than once annually.
- (b) Subprocessor Notice and Objections. If Customer subscribes to receive updates available on Thrifty AI’s Subprocessor page, Customer will be automatically notified of new Subprocessors before Thrifty AI authorizes such Subprocessor to process Customer Personal Data (or in the case of an emergency, as soon as reasonably practicable). Customer has fourteen (14) calendar days from such notice to make an objection on reasonable grounds relating to the protection of the Personal Data by notifying Thrifty AI at privacy@thriftyai.com. In the event Customer objects to a new Subprocessor, Thrifty AI will use commercially reasonable efforts to make available to Customer a change in the Platform or Customer’s configuration or use of the Platform to avoid processing of Customer Personal Data by the objected-to new Subprocessor. If Thrifty AI is unable to make available such change within a reasonable period of time, which will not exceed thirty (30) days, either Party may upon written notice terminate without penalty the applicable Order Form(s) or the Agreement.
7. Data Transfers.
- (a) Authorization to Transfer Personal Data. Customer authorizes Thrifty AI and its Subprocessors to make international transfers of Personal Data in accordance with this DPA and Data Protection Laws.
- (b) Order of Precedence. The Parties acknowledge that Data Protection Laws may require the Parties to implement certain safeguards (a “Transfer Mechanism”) for Customer to transfer Personal Data to Thrifty AI. In the event a transfer of Personal Data is covered by more than one Transfer Mechanism, the transfer will be subject to a single Transfer Mechanism, in accordance with the following order of precedence: (i) the Data Privacy Frameworks; (ii) to the extent that the Data Privacy Frameworks do not apply to a given transfer or are invalidated, the EU SCCs and/or UK Addendum as set forth in Sections 7(d)-(f), as applicable; and (iii) if neither of the preceding is applicable, the Parties will cooperate in good faith to enter into an alternative Transfer Mechanism to the extent required by Data Protection Laws.
- (c) Data Privacy Frameworks. To the extent Thrifty AI processes Personal Data originating from the EEA, United Kingdom, or Switzerland and Thrifty AI is self-certified under the Data Privacy Frameworks, Thrifty AI will adhere to the Data Privacy Principles with respect to Personal Data transferred to Thrifty AI, as applicable.
- (d) EU SCCs. To the extent legally required, by entering into this DPA, Customer and Thrifty AI are deemed to have signed the EU SCCs, which form part of this DPA and (except as described in Sections 7(e) and (f) below) are deemed completed as follows:
- (i) Module Two (Controller to Processor) will apply where Customer is a Controller, and Module Three (Processor to Processor) will apply where Customer is a Processor;
- (ii) Clause 7 (the optional docking clause) is not included;
- (iii) Clause 9 (Use of sub-processors): Option 2 (General written authorization) will apply and the time period for prior notice of Subprocessor changes is set forth in Section 6 of this DPA;
- (iv) Clause 11 (Redress): The optional language will not apply;
- (v) Clause 17 (Governing law): The Parties choose Option 1 (the law of an EU Member State that allows for third-Party beneficiary rights) and select the law of Ireland;
- (vi) Clause 18 (Choice of forum and jurisdiction): The Parties select the courts of Ireland;
- (vii) Annexes I (List of Parties) and II (Technical and organizational measures) are completed as set forth in Exhibits A and B of this DPA, respectively; and
- (viii) Annex III (List of subprocessors) is not applicable because the Parties have chosen General Authorization under Clause 9.
- (e) UK Addendum. To the extent legally required, by entering into this DPA, the Parties are deemed to be signing the UK Addendum, which forms part of this DPA and takes precedence over the rest of this DPA as set forth in the UK Addendum. The Tables within the UK Addendum are deemed completed as follows:
- (i) Table 1: The Parties’ details and key contacts are set forth in Exhibit A of this DPA;
- (ii) Table 2: The Approved EU SCCs referenced in Table 2 shall be the EU SCCs as executed by the Parties and completed in Section 7(d) of this DPA;
- (iii) Table 3: Annexes I and II are set forth in Exhibits A and B below, respectively. Annex III is inapplicable; and
- (iv) Table 4: Either Party may end this DPA as set out in Section 19 of the UK Addendum.
- (f) Transfers of Swiss Personal Data. For transfers of Personal Data that are subject to the FADP, the EU SCCs form part of this DPA as set forth in Section 7(d) of this DPA, but with the following differences to the extent required by the FADP: (i) references to the GDPR in the EU SCCs are to be understood as references to the FADP insofar as the data transfers are subject exclusively to the FADP and not to the GDPR; (ii) the term “member state” in EU SCCs shall not be interpreted in such a way as to exclude data subjects in Switzerland from the possibility of suing for their rights in their place of habitual residence (Switzerland) in accordance with Clause 18(c) of the EU SCCs; and (iii) the relevant supervisory authority is the Swiss Federal Data Protection and Information Commissioner (for transfers subject to the FADP and not the GDPR), or both such Commissioner and the supervisory authority identified in the EU SCCs (where the FADP and GDPR apply, respectively).
8. Audits.
- (a) Standard Audit Process. Thrifty AI will make available to Customer documentation, data, reports, and records (“Records”) relating to Thrifty AI’s Processing of Personal Data to demonstrate compliance with this DPA (an “Audit”) provided the Agreement remains in effect and such audit is at Customer’s sole expense. Customer may request an Audit upon fourteen (14) days’ prior written notice to Thrifty AI, no more than once annually, except, in the event of a Security Incident occurring on Thrifty AI’s systems, in which case Customer may request an Audit within a reasonable period of time following such Security Incident.
- (b) Written Requests and Inspections. If Customer has a reasonable objection that the Records provided are not sufficient to demonstrate Thrifty AI’s compliance with this DPA, Customer may, as necessary: (i) request additional information from Thrifty AI in writing, and Thrifty AI will respond to such written requests within a reasonable period of time (“Written Requests”); and (ii) only where Thrifty AI’s responses to such Written Requests do not provide the necessary level of information required by Customer, request access to Thrifty AI’s premises, systems and staff, upon twenty one (21) days prior written notice to Thrifty AI (an “Inspection”) subject to the parties having mutually agreed upon (a) the scope, timing, and duration of the Inspection, (b) the use of an auditor to conduct the Inspection, (c) the Inspection being carried out only during Thrifty AI’s regular business hours, with minimal disruption to Thrifty AI’s business operations, and (d) all costs associated with the Inspection being borne by Customer (including Thrifty AI’s time in connection with facilitating the Inspection, charged at Thrifty AI’s then-current rates). Inspections will be permitted no more than once annually, except in the event of a Security Incident.
9. Return or Destruction of Personal Data.
Except to the extent required otherwise by Data Protection Laws, Thrifty AI will, at the choice of Customer and upon Customer’s written request return to Customer and/or delete all Personal Data, including conversation recordings, transcripts, and assessment reports, unless Data Protection Laws require Thrifty AI to retain Personal Data. Customer may also delete individual recordings, transcripts, and conversation memory through the Platform during the term of the Agreement. Biometric Data will be permanently destroyed when the initial purpose for collecting it has been satisfied, upon termination of the Agreement, or within any shorter period required by Data Protection Laws, whichever occurs first.
10. Survival; Amendments.
The provisions of this DPA survive the termination or expiration of the Agreement for so long as Thrifty AI or its Subprocessors Process Personal Data. Thrifty AI may amend this DPA in order to comply with Data Protection Laws and will notify Customer of such changes. By continuing to use the Platform after the DPA has been updated, Customer is deemed to have agreed to the updated DPA.
Exhibit A
ANNEX I to the EU SCCs
A. List of parties
Data exporter(s):
- Name: Customer, as identified in the Agreement.
- Address: As provided in the Agreement.
- Contact person’s name, position, and contact details: As provided in the Agreement.
- Activities relevant to the data transferred under these Clauses: The data exporter receives access to the data importer’s Platform pursuant to their underlying Agreement.
- Signature and date: The Parties agree that execution of the Agreement shall constitute execution of these EU SCCs by both parties.
- Role: Controller or Processor, as applicable.
Data importer(s):
- Name: Thrifty AI, as identified in the Agreement.
- Address: [Registered address], or as provided in the Agreement.
- Contact person’s name, position, and contact details: As provided in the Agreement, or privacy@thriftyai.com.
- Activities relevant to the data transferred under these Clauses: The data importer provides the Platform, including real-time, face-to-face conversations between end users and artificial humans, to the data exporter pursuant to their underlying Agreement.
- Signature and date: The Parties agree that execution of the Agreement shall constitute execution of these EU SCCs by both parties.
- Role: Processor or Subprocessor, as applicable.
B. Description of transfer
Categories of data subjects whose personal data is transferred: The categories of data subjects whose Personal Data is transferred are determined solely by the data exporter. In the normal course of the data importer’s provision of the Platform, the categories of data subjects might include (but are not limited to):
- end users who converse with the data exporter’s artificial humans by voice, video, or text, such as the data exporter’s customers, prospective customers, patients, students, learners, and members of the public;
- candidates, employees, and trainees who take part in AI interviews, assessments, or roleplays;
- participants in Google Meet, Zoom, or other meetings that an artificial human joins at the data exporter’s direction;
- individuals whose likeness or voice the data exporter authorizes for use in creating an artificial human;
- individuals referenced in documents the data exporter uploads to a knowledge base; and
- the data exporter’s personnel, authorized users, service providers, business partners, affiliates, and other end users.
Categories of personal data transferred: The categories of Personal Data transferred are determined solely by the data exporter. In the normal course of the data importer’s provision of the Platform, the categories of Personal Data transferred might include (but are not limited to):
- voice audio captured from an end user’s microphone during a conversation;
- camera video frames and facial imagery captured from an end user’s camera, used to enable the artificial human to see and respond to the end user;
- screen-share content an end user chooses to share;
- conversation transcripts and audio and video recordings of conversations, where recording is enabled by the data exporter;
- interview, assessment, and roleplay responses, scores, and reports;
- conversation memory retained across sessions, where enabled by the data exporter;
- contact and identification details an end user provides during a conversation, such as name, email address, phone number, or account or reference numbers;
- content of documents uploaded to a knowledge base;
- images, video, and voice samples of individuals whose likeness or voice is used to create an artificial human, where provided by the data exporter;
- account, authentication, and usage data of the data exporter’s authorized users, and technical data such as IP address, device and browser information, and session metadata; and
- any other Personal Data submitted by Customer’s data subjects in connection with their use of the Platform, which may include information collected through Customer’s use of Third-Party Services available through the Platform, such as meeting platform integrations.
Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialised training), keeping a record of access to the data, restrictions for onward transfers or additional security measures: At its sole discretion, the data exporter determines all categories and types of Personal Data it may submit and transfer to the data importer as part of its provision of the Platform. Facial imagery and voice audio Processed through the Platform may constitute Biometric Data under certain Data Protection Laws. The data importer Processes such data only as necessary to provide the Platform and in accordance with the data exporter’s instructions, subject to the restrictions in Section 2(f) of this DPA, encryption in transit and at rest, role-based access restricted to personnel who require access to deliver the Platform, and retention and deletion in accordance with the data exporter’s configuration and Section 9 of this DPA. Depending on the data exporter’s use case (for example, healthcare patient intake or financial services), conversations may also contain health, financial, or other special category data. If the data exporter chooses to transmit sensitive data through the Platform or permits its end users to, the data exporter is responsible for ensuring that suitable safeguards are in place prior to transmitting or processing, or prior to permitting the data exporter’s end users to transmit or process, any sensitive data through the Platform (including through information collected through Customer’s use of Third-Party Services available through the Platform).
The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis): Continuous for the duration of the Agreement.
Nature of the processing: The data importer’s Processing activities shall be limited to those discussed in the Agreement and the DPA, and may include: real-time capture and streaming of audio and video; speech recognition and transcription; generation of the artificial human’s responses using large language models, grounded in the data exporter’s knowledge base; speech and voice synthesis; rendering of the artificial human’s face and expressions; analysis of camera frames to enable the artificial human to respond to what it sees; recording and storage of conversations; generation of interview, assessment, and roleplay scores and reports; and hosting, storage, and support.
Purpose(s) of the data transfer and further processing: The purpose of the transfer to and further Processing of Personal Data by the data importer is for the data importer to provide the Platform to the data exporter as set forth in the Agreement, including enabling the data exporter’s artificial humans to hold real-time voice and video conversations with end users.
The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period: Personal Data will be retained for the period of time necessary for the data importer to provide the Platform to the data exporter under the Agreement, in accordance with the retention settings configured by the data exporter, and/or in accordance with applicable legal requirements. Live audio and video streams that are not recorded are Processed transiently to generate the artificial human’s responses and are not retained after the conversation ends, except as needed to produce transcripts or other outputs the data exporter has enabled.
For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing: Same as above to the extent that Personal Data is provided to Subprocessors for purposes of providing the Platform.
C. Competent supervisory authority
To the extent legally permitted, the competent supervisory authority is the Irish Data Protection Commission.
Exhibit B
Data security measures
Thrifty AI has implemented and will continue to maintain administrative, technical, physical, and organizational security measures to protect the security, confidentiality, and integrity of Customer Materials, including any Personal Data therein (collectively “Customer Data”), as set out below. Thrifty AI may update these measures from time to time, provided that any such update does not diminish the overall security of the Platform.
- Information Security Program & Risk Management. Thrifty AI maintains a risk-based information security and AI-governance program that includes policies and procedures defining security, privacy, and AI governance responsibilities, a risk management process to identify, assess, and remediate risk, and a review of risk and control effectiveness on at least an annual basis. Thrifty AI assigns personnel responsible for implementing, monitoring, and enforcing this program.
- Security Assessments. Thrifty AI periodically assesses its information security program and controls, including through internal reviews and, where appropriate, independent third-party security testing. Information about Thrifty AI’s security practices and the documentation it makes available is provided at thriftyai.com/trust and on request to security@thriftyai.com.
- Security Incident Monitoring and Response. Thrifty AI maintains a documented security incident response plan that enables Thrifty AI to respond to, investigate, contain, mitigate, and provide notification of Security Incidents consistent with its obligations under Data Protection Laws and this DPA. Thrifty AI tests and reviews its security incident response plan on an annual basis.
- Access Control and Identity Security. Access to Customer Data is restricted to authorized Thrifty AI personnel who are required to access such data to perform functions as part of the delivery of the Platform. Authentication and authorization are designed to enforce least-privilege principles and traceability. Thrifty AI has implemented and maintains logical segregation of Customer Data, role-based access controls, mandatory multi-factor authentication required for authenticating to Thrifty AI’s identity provider, provisioning, modification, and de-provisioning in line with Thrifty AI’s lifecycle procedures, and reviews access entitlements on a recurring basis. Access by Thrifty AI personnel to conversation recordings, camera video, and facial imagery is limited to what is necessary to provide support requested by Customer, investigate abuse or Security Incidents, or comply with law, and is logged.
- Encryption. Thrifty AI encrypts Customer Data while in transit and at rest consistent with industry-standard encryption practices (e.g. TLS 1.2 and AES 256), including encryption of real-time audio and video streams in transit. Encryption keys are generated, stored, rotated, and retired under documented key-management procedures and restricted access controls.
- Audio, Video, and Biometric Data Handling. Thrifty AI Processes live audio and camera video only for the duration of a conversation and only to the extent necessary to provide the Platform. Recordings, transcripts, and assessment reports are stored only where Customer has enabled them and are retained and deleted in accordance with Customer’s configured retention settings. Biometric Data is not used to identify individuals unless Customer expressly configures the Platform to do so.
- Network, System, and Application Security. Network, infrastructure, and applications are protected through layered security controls designed to detect and protect against unauthorized access, data loss, or service disruption, including network segmentation, firewall protection, and intrusion-detection mechanisms to help safeguard production environments, measures to enforce secure configuration baselines and change management, vulnerability scanning and patching occur on a defined cadence based on risk severity, and a secure development lifecycle with code review and dependency scanning.
- Business Continuity and Disaster Recovery. Thrifty AI implements disaster recovery and business resumption plans that are kept up to date and revised on a regular basis. Thrifty AI also adjusts its information security program in light of new laws and circumstances, including as Thrifty AI’s business and Processing change.
- Security Training and Awareness; Personnel Security. Thrifty AI has implemented and maintains a security awareness program to train employees about their security obligations and requires that employees follow established security policies and procedures. Employees are required to complete security training upon being hired and on an annual basis thereafter. As part of its hiring process, Thrifty AI conducts background checks on all prospective full-time and part-time employees to the extent legally permitted in accordance with applicable laws.
- Third-Party Risk Management. Thrifty AI maintains a third-party risk management program that includes the performance of risk-based assessments on its third-party vendors both prior to that vendor being on-boarded and during the engagement on an as needed basis as determined by Thrifty AI’s security personnel.