Data Processing Addendum
Last updated 6 October 2026 · Questions: [email protected]
This Data Processing Addendum ("DPA") forms part of the Sparring Terms of Service between Carnegie Intelligent Technology Limited ("Processor") and the Customer ("Controller") and applies to the extent Processor processes Personal Data on Controller's behalf in providing the Service. Capitalised terms not defined here have the meaning in the GDPR (Regulation (EU) 2016/679) and, where applicable, the UK GDPR and the Hong Kong PDPO.
1. Details of processing
| Subject matter | Provision of simulated-conversation practice, AI-agent evaluation and scenario drafting services. |
|---|---|
| Duration | The term of the Agreement plus the deletion period in Section 8. |
| Nature & purpose | Hosting, storage, transmission to model providers for inference, generation of feedback, analytics for Controller, delivery by email/webhook, billing. |
| Categories of data subjects | Controller's employees, contractors and other authorised users; individuals mentioned in content Controller submits (e.g. anonymised call notes). |
| Categories of Personal Data | Identity and contact data; role; content of practice conversations and debriefs; Arena transcripts; Studio material; usage and audit data. Special-category data is not intended; incidental disclosures in conversations are processed as part of the transcript only. |
2. Processor obligations
Processor will: (a) process Personal Data only on Controller's documented instructions, including these Terms and Controller's use of the Service's settings, unless required by law (in which case Processor informs Controller unless prohibited); (b) ensure persons authorised to process are bound by confidentiality; (c) implement the technical and organisational measures in Annex 1; (d) assist Controller, taking into account the nature of processing, with data-subject requests and with Articles 32–36 GDPR; (e) delete or return Personal Data at the end of the Service per Section 8; (f) make available information necessary to demonstrate compliance and allow audits per Section 7.
3. Sub-processors
Controller provides general authorisation for the sub-processors listed at sparringhq.com/legal/subprocessors. Processor will give at least 30 days' notice of additions or replacements by updating that page and emailing Controller's administrators. Controller may object on reasonable data-protection grounds within that period; if unresolved, Controller may terminate the affected Service for a pro-rata refund. Processor remains liable for its sub-processors' performance.
4. International transfers
Where Personal Data protected by the GDPR/UK GDPR is transferred to a country without an adequacy decision, the parties enter into the EU Standard Contractual Clauses (Commission Decision 2021/914, Module Two, with Clause 7 optional docking and Clause 9 Option 2), and for UK data the ICO International Data Transfer Addendum, each incorporated by reference, with Annexes completed by this DPA. Controller may select GCP-resident or AWS-resident model routing to constrain the location of inference.
5. Security
Processor maintains the measures in Annex 1 and will not materially decrease the overall security of the Service during the term.
6. Personal data breach
Processor will notify Controller without undue delay and in any event within 48 hours after becoming aware of a Personal Data Breach affecting Controller's data, providing information reasonably available to help Controller meet its obligations, and will cooperate in remediation.
7. Audit
Processor will provide, on request and no more than annually (or following a breach), its most recent third-party reports or completed security questionnaire. Where these are insufficient to demonstrate compliance, Controller may conduct an audit on 30 days' notice, during business hours, subject to confidentiality and at Controller's cost, without disrupting the Service.
8. Deletion and return
Controller may export its data at any time through the Service. Within 30 days of termination Processor will, at Controller's choice, return or delete all Personal Data and delete existing copies within a further 60 days, unless retention is required by law, in which case Processor will isolate and protect the data.
9. Liability
Each party's liability under this DPA is subject to the limitations in the Agreement, except where such limitation is prohibited by applicable data-protection law.
Annex 1 — Technical and organisational measures
- Encryption in transit (TLS 1.2+) and at rest (AES-256); customer-managed keys on Enterprise.
- Logical tenant isolation enforced in application and database layers; row-level organisation scoping on every query.
- Identity: enterprise SSO (OIDC), verified email, signed HttpOnly session cookies, scoped and hashed API keys, role-based access control.
- Secrets in Google Secret Manager; least-privilege service accounts; no production credentials on developer machines.
- Audit logging of administrative and security-relevant actions; centralised, tamper-evident logs retained 2 years.
- Change management via version control, automated tests, dependency and container scanning, reproducible builds; production deploys from CI only.
- Backups encrypted, tested quarterly; recovery objectives RPO 24 h / RTO 8 h (Enterprise: RPO 1 h / RTO 4 h).
- Model providers contractually bound to no-training and limited retention; inference routed per Controller's residency setting.
- Personnel: confidentiality undertakings; access reviewed quarterly; security awareness training.
- Incident response plan with 48-hour customer notification; vulnerability disclosure channel at [email protected].
Annex 2 — Sub-processors
See the current list.
To countersign this DPA for your organization or request the SCC schedule as a signed PDF, email [email protected].