Data Processing Agreement
This Data Processing Agreement (“DPA”) forms part of the agreement for services (the “Agreement”) between Cultural Relevance, LLC, a Delaware limited liability company (“Processor” or “CR”), and the customer identified in the applicable Order Form (“Controller” or “Customer”), and reflects the parties’ agreement regarding the Processing of Personal Data.
1. Definitions
“Personal Data,” “Processing,” “Controller,” “Processor,” “Data Subject,” and “Supervisory Authority” have the meanings given in Applicable Data Protection Law. “Applicable Data Protection Law” means all laws applicable to the Processing of Personal Data under the Agreement, including U.S. state privacy laws (e.g., CCPA/CPRA, and the comprehensive laws of Colorado, Connecticut, Delaware, Texas, Virginia and other states), and where applicable the GDPR and UK GDPR. “Customer Data” means Personal Data that CR Processes on Customer’s behalf under the Agreement, including inputs to the AURA AI platform.
2. Scope, Roles, and Instructions
Customer is the Controller (or a Processor acting on behalf of a third-party Controller) and CR is the Processor of Customer Data. CR will Process Customer Data only (a) to provide and secure the services described in the Agreement, and (b) in accordance with Customer’s documented instructions, unless required otherwise by law (in which case CR will inform Customer unless legally prohibited). CR will promptly inform Customer if, in its opinion, an instruction infringes Applicable Data Protection Law.
Service Provider terms (U.S. state laws): CR will not sell or share Customer Data, will not retain, use, or disclose it outside the direct business relationship or for any purpose other than performing the services, will comply with applicable obligations under U.S. state privacy laws, and will notify Customer if it can no longer meet them. Customer may take reasonable steps to stop and remediate unauthorized use.
3. No AI Training Without Consent
CR will not use Customer Data to train, fine-tune, or improve any artificial intelligence or machine learning model, except (a) with Customer’s express prior written consent, or (b) using data that has been irreversibly de-identified and aggregated such that it no longer constitutes Personal Data, where permitted by the Agreement. CR will maintain de-identified data in de-identified form and will not attempt re-identification.
4. Confidentiality
CR ensures that personnel authorized to Process Customer Data are bound by written confidentiality obligations and receive appropriate privacy and security training.
5. Security
CR will implement and maintain appropriate technical and organizational measures designed to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, as described in Annex II. CR maintains (or is pursuing) a SOC 2 examination covering the services; upon request and under NDA, CR will provide its most recent SOC 2 report or equivalent third-party assessment.
6. Subprocessors
Customer provides general authorization for CR to engage the subprocessors listed in Annex III. CR will (a) impose data protection obligations on subprocessors no less protective than this DPA, (b) remain liable for their performance, and (c) provide at least 30 days’ prior notice of new subprocessors, during which Customer may object on reasonable data-protection grounds; if the parties cannot resolve the objection, Customer may terminate the affected services and receive a pro-rata refund of prepaid fees.
7. Data Subject Requests
Taking into account the nature of the Processing, CR will assist Customer through appropriate technical and organizational measures in fulfilling Customer’s obligation to respond to Data Subject requests (access, correction, deletion, portability, opt-out). If a Data Subject request is made directly to CR, CR will promptly forward it to Customer and will not respond except to direct the Data Subject to Customer, unless legally required.
8. Personal Data Breach
CR will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Data. The notice will describe, to the extent known, the nature of the breach, categories and approximate volumes of affected data and Data Subjects, likely consequences, and measures taken or proposed. CR will provide reasonable cooperation with Customer’s notification and remediation obligations. CR’s notice is not an admission of fault.
9. Assistance; DPIAs
CR will provide reasonable assistance with data protection impact assessments and prior consultations with Supervisory Authorities, to the extent required of Customer by Applicable Data Protection Law and taking into account the information available to CR.
10. Audits
CR will make available information reasonably necessary to demonstrate compliance with this DPA. Customer’s audit rights are satisfied, to the extent permitted by law, by CR’s then-current SOC 2 report, security questionnaire responses, and certifications. Where Applicable Data Protection Law requires more, Customer (or an independent auditor bound by confidentiality) may audit CR’s relevant controls no more than once per 12 months, on at least 30 days’ notice, during business hours, without disrupting operations, and subject to CR’s security policies. Each party bears its own audit costs.
11. International Transfers
Where Processing involves a transfer of Personal Data from the EEA, UK, or Switzerland to a jurisdiction without an adequacy decision, the parties incorporate the European Commission’s Standard Contractual Clauses (Module 2: Controller-to-Processor, or Module 3 as applicable) and the UK International Data Transfer Addendum, completed with the details in Annex I. If CR certifies to the EU–U.S. Data Privacy Framework, transfers may instead rely on that certification while valid.
12. Return and Deletion
Upon termination or expiration of the Agreement, CR will, at Customer’s election, return Customer Data in a commonly used format or delete it, and will delete existing copies within 90 days, unless retention is required by law (in which case CR will isolate and protect the data from further Processing). Deletion from backups occurs in the ordinary course of backup rotation.
13. Liability; Order of Precedence; Term
Each party’s liability under this DPA is subject to the limitations of liability in the Agreement, except where prohibited by Applicable Data Protection Law. In case of conflict: (1) the Standard Contractual Clauses, (2) this DPA, (3) the Agreement. This DPA is effective as long as CR Processes Customer Data.
Annex I — Details of Processing
| Item | Description |
| Subject matter | Provision of the Cultural Relevance platform and services, including AURA AI, assessments, certifications, and related support. |
| Duration | The term of the Agreement plus the deletion period in Section 12. |
| Nature and purpose | Hosting, storage, analysis, generation of assessment outputs and cultural-intelligence insights, support, and service improvement as permitted by the Agreement. |
| Categories of Data Subjects | Customer’s employees, contractors, and other end users authorized to use the services; survey/assessment respondents. |
| Categories of Personal Data | Name, business contact details, credentials, role information, usage data, assessment responses, and content submitted to the services. |
| Sensitive data | Only if and to the extent Customer configures assessments to collect it (e.g., voluntary self-identified demographic information), subject to heightened safeguards and applicable consent requirements. |
| Frequency | Continuous, for the duration of the Agreement. |
Annex II — Technical and Organizational Measures
- Encryption of Personal Data in transit (TLS 1.2+) and at rest (AES-256).
- Role-based access controls, least privilege, and multi-factor authentication for all systems Processing Customer Data.
- Logical separation of customer environments and data.
- Centralized logging, monitoring, and alerting; documented incident response plan tested at least annually.
- Secure software development lifecycle: code review, dependency scanning, vulnerability management, and at least annual third-party penetration testing.
- Personnel security: background checks where permitted by law, confidentiality agreements, and annual security and privacy training.
- Vendor risk management program covering all subprocessors.
- Business continuity and disaster recovery with defined RTO/RPO and periodic testing; encrypted backups.
- Data minimization, retention schedules, and secure deletion procedures.
- Governance aligned to SOC 2 Trust Services Criteria (Security, Availability, Confidentiality).
Annex III — Approved Subprocessors
| Subprocessor | Function | Location |
| AWS / GCP | Cloud hosting | United States |
| Antrophic | LLM inference (no-training tier) | United States |
| Google Analytics | Product analytics | United States |