Experiential
8.9k
DPA

Data processing addendum

1 Parties scope and definitions

This Data processing addendum (DPA) forms part of the Terms between Resolute Labs AI, Inc., operating as Experiential Labs (Experiential), and the Customer identified by the account or applicable agreement, where Experiential processes personal data on Customer's behalf and applicable law requires a processor or service-provider agreement. It applies regardless of subscription tier. A separately signed DPA prevails to the extent it governs the same processing and conflicts with this DPA.

Experiential's address is 989 Market Street, 2nd Floor, San Francisco, CA 94103, United States and its contact is founders@experientiallabs.ai. Customer's identity and contact details are those supplied for the account or applicable agreement.

Customer Personal Data means personal data processed by Experiential on Customer's behalf to provide the Services. Applicable Data Protection Law means privacy and data-protection laws applicable to that processing, including the EU GDPR, UK GDPR, Swiss data-protection law and applicable US state privacy laws. Controller, processor, business, service provider and related terms have their statutory meanings. A Security Incident is a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of or access to Customer Personal Data.

Customer acts as controller, or as a processor authorized by its controller to appoint Experiential. Experiential acts as processor or subprocessor accordingly. Processing of account and business-contact information for Experiential's own purposes is described in the Privacy policy and is outside this DPA only to the extent that Experiential lawfully determines those purposes.

2 Instructions and purpose limits

Experiential will process Customer Personal Data only on Customer's documented instructions, including instructions concerning transfers, unless applicable law requires otherwise. It will inform Customer of such a legal requirement before processing unless prohibited by law. The Terms, this DPA, enabled service settings and authorized requests constitute the instructions. Additional instructions must be documented and within the agreed service scope.

Experiential will promptly inform Customer if it considers an instruction to infringe applicable data-protection law and will suspend the affected instruction while the parties resolve it. Customer is responsible for the lawfulness of its collection and instructions, including required notices, rights and permissions. These responsibilities do not remove Experiential's own obligations.

Experiential will not sell Customer Personal Data or share it for cross-context behavioral advertising, as defined by applicable law. It will not use covered data or datasets derived from it for unrelated advertising, dataset sales or training shared models or models for other customers. Customer-specific evaluation and training require a documented instruction and lawful content and provider permissions. Completion of a training job does not make its data or artifacts anonymous.

3 Confidentiality and security

Experiential will ensure that people authorized to process Customer Personal Data are bound by confidentiality duties and receive access only as needed for their responsibilities. It will implement technical and organizational measures appropriate to the risk, taking account of the state of the art, implementation costs, the nature and purposes of processing, and risks to individuals.

Those measures will address access control, separation of customer data, protection of credentials, secure transmission and storage, incident response, recovery and deletion as appropriate to the processing. Experiential will provide information about applicable measures on request and will not materially reduce an agreed level of protection during the service term. This DPA does not represent that Experiential holds an independent security certification.

4 Subprocessors and provider relationships

Customer grants general written authorization for Experiential to use subprocessors identified in the subprocessor list supplied to Customer before covered processing begins, for their stated functions. The list forms part of this DPA, and the current version is available on request at founders@experientiallabs.ai. A route not identified in that list is not authorized to receive Customer Personal Data under this DPA. Experiential will impose written obligations providing the protection required by applicable law and this DPA, and remains responsible for its subprocessors' performance as required by law.

Experiential will inform Customer of intended additions or replacements before they take effect and provide a reasonable opportunity to object on data-protection grounds. The parties will work to resolve an objection through a permitted alternative or another appropriate measure. If no compliant arrangement is available, the affected processing will not proceed; termination and any required remedies follow the Terms and applicable law. Mandatory transfer terms or a signed agreement may require a more specific notice period or procedure.

The actual hosting and contractual route determine whether a model publisher is a subprocessor or another recipient. Customer's use of its own provider credentials does not by itself determine the parties' legal roles. A provider must meet the applicable instructions and safeguards before receiving Customer Personal Data under this DPA.

5 Assistance with individual rights

Taking account of the nature of processing, Experiential will assist Customer through appropriate measures with requests to exercise rights under applicable law. It will promptly notify Customer of requests relating to Customer Personal Data received directly, unless prohibited by law, and respond only on Customer's instructions or as legally required.

Customer may send instructions and requests for assistance to founders@experientiallabs.ai. Assistance must allow Customer to meet applicable deadlines. Any agreed charge for additional work must not condition mandatory assistance or correction of Experiential's own breach on payment.

6 Security incidents

Experiential will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data. Notice will go to Customer's designated contact or account contact and include, as available, the nature of the incident, affected data and individuals, likely consequences, remedial steps and a contact for follow-up.

Experiential may provide information in phases as it becomes available and will reasonably assist Customer with investigation, legally required notifications and mitigation. It will document the incident and corrective action. Notification is not an admission of fault. The parties will coordinate notifications where permitted, while retaining their own legal obligations.

7 Assessments and compliance information

Experiential will provide information needed to demonstrate compliance with this DPA and assist Customer with applicable security obligations, impact assessments and prior consultation with authorities, taking account of the processing and information available to Experiential.

Customer or its mandated independent auditor may audit or inspect relevant processing on reasonable notice and under proportionate confidentiality and security arrangements. Available reports may satisfy a request where they address the relevant obligations. These arrangements will not prevent an audit or authority's access required by law. Audits must protect other customers' information and avoid unnecessary disruption.

8 Return and deletion

At Customer's choice, Experiential will return or delete Customer Personal Data after the end of the relevant Services and delete existing copies unless applicable law requires retention. Customer may send instructions to founders@experientiallabs.ai. Ordinary retention settings continue during the Services; return obligations apply to information still held.

Information that must be retained remains protected and restricted to the purpose requiring retention. Protected backup copies will remain isolated from ordinary use until removed under the applicable deletion cycle. Experiential will reapply deletion instructions when a backup is restored. On request, it will confirm deletion and identify any lawful retention exception. Personal data within derived datasets or model artifacts remains subject to the applicable requirements.

9 International transfers

Experiential will not make a transfer of Customer Personal Data that is restricted under applicable data-protection law without a valid mechanism and any required supplementary measures. Customer's use of the Services does not waive this requirement.

Where standard contractual clauses or other transfer terms are required, the applicable approved instrument, parties, roles, annexes and elections must be incorporated into the agreement before the affected transfer. UK or Swiss requirements apply where relevant. Mandatory transfer terms prevail over inconsistent provisions of this DPA or the Terms.

Experiential will notify Customer if it can no longer comply with applicable safeguards and will suspend or remediate the affected transfer as required by law and the applicable instrument. It will handle government access requests consistently with those obligations.

10 US state service provider terms

Where applicable US privacy law requires service-provider or contractor terms, the limited purposes are the processing described in Schedule A and account administration on Customer's behalf.

Experiential will not sell or share the covered personal information; retain, use or disclose it outside the specified purposes or the direct business relationship except as legally permitted; or combine it with information from other sources except as permitted by applicable law. Experiential certifies that it understands and will comply with these restrictions where that certification is required.

Experiential will provide the required level of protection, notify Customer if it can no longer meet its obligations, and permit reasonable steps to assess compliance and stop or remedy unauthorized use. It will assist with consumer requests and impose applicable restrictions on authorized subprocessors.

11 Liability term and precedence

This DPA applies while Experiential processes Customer Personal Data for Customer. The liability provisions in the Terms apply between the parties except to the extent applicable law, mandatory transfer terms or a signed agreement requires otherwise. Nothing here limits nonwaivable rights of individuals or authorities.

This DPA prevails on its personal-data subject matter, subject to the precedence of mandatory transfer terms and separately signed agreements. A later Privacy policy or acceptable-use update does not silently amend this DPA.

Schedule A Processing details