Version 2026-09-23 · Effective 2026-09-23
Prior versions
This Data Processing Agreement (“DPA”) forms part of and supplements the existing customer agreement (“Agreement”) between Oasive, Inc. (“Oasive”), and the counterparty to the Agreement (“Customer”). If any conflict arises between this DPA and the Agreement with respect to the Processing of Personal Data, the terms of this DPA prevail; in all other respects, the Agreement controls. Capitalized terms used in this DPA that are not otherwise defined will have the meanings given to them under the Agreement or, if not defined in the Agreement, under applicable Data Protection Laws.
Customer and Oasive agree as follows:
1. Definitions
For purposes of this DPA:
1.1 “Affiliate” means any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity. “Control,” for purposes of this definition, means direct or indirect ownership or control of more than 50% of the voting interests of the subject entity.
1.2 “Data Protection Laws” means all applicable laws, regulations, and other legal or self-regulatory requirements in any jurisdiction relating to privacy, data protection, data security, breach notification, or the Processing of Personal Data, including without limitation, to the extent applicable, the following: the General Data Protection Regulation, Regulation (EU) 2016/679 (“EU GDPR”), the EU Directive 2002/58/EC (the “ePrivacy Directive”), and the national laws of each European Economic Area member state made under, pursuant to, or that implement the EU GDPR or the ePrivacy Directive; the EU GDPR as it forms part of United Kingdom law by virtue of section 3 of the European Union (Withdrawal) Act 2018 (the “UK GDPR”), the United Kingdom Data Protection Act 2018, and the Privacy and Electronic Communications (EC Directive) Regulations 2003; the Swiss Federal Act on Data Protection (“FADP”); and the following (collectively, the “U.S. Privacy Laws”): the California Consumer Privacy Act, Cal. Civ. Code § 1798.100 et seq. (“CCPA”), including its regulations and the amendments made by the California Privacy Rights Act of 2020 (“CPRA”), the Virginia Consumer Data Protection Act, the Colorado Privacy Act and related regulations (“CPA”), the Utah Consumer Privacy Act, and the Connecticut Act Concerning Personal Data Privacy and Online Monitoring. Each of the laws referred to in this definition applies as amended or superseded from time to time. If a party’s activities involving Personal Data are not within the scope of a given Data Protection Law, that law is not applicable for purposes of this DPA.
1.3 “Personal Data” includes “personal data,” “personal information,” “personally identifiable information,” and analogous terms, as defined by Data Protection Laws, that Oasive Processes in relation to the provision of the Services under the Agreement, as further described in Annex I.
1.4 “Process” and its cognates “Processing,” “Processed,” etc. mean any operation or set of operations performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, creating, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
1.5 “SCCs” means, where the EU GDPR or the FADP applies, the standard contractual clauses set out in the European Commission Implementing Decision (EU) 2021/914 on standard contractual clauses for the transfer of personal data to third countries according to the EU GDPR, being: (i) where Customer is a Controller, Module Two (Transfer: Controller to Processor); and (ii) where Customer is a Processor, Module Three (Transfer: Processor to Processor).
1.6 “Security Breach” means any confirmed unlawful acquisition, destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.
1.7 “Services” means the services that Oasive performs on behalf of Customer pursuant to the Agreement.
1.8 “Sub-processor” means any third party or Oasive Affiliate that Oasive engages to Process Personal Data.
1.9 “UK Addendum” means, where the UK GDPR applies, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the United Kingdom Information Commissioner under section 119A(1) of the United Kingdom Data Protection Act 2018.
1.10 The terms “Business,” “Consumer,” “Controller,” “Data Subject,” “Processor,” and “Service Provider” are defined as in Data Protection Laws. “Controller” is deemed to also refer to “Business,” and “Processor” is deemed to also refer to “Service Provider.” “Data Subject” is deemed to include “Consumer.”
2. Roles of the Parties; Scope and Purposes of Processing
2.1 Unless otherwise specified, this DPA applies to all Personal Data that Oasive Processes in relation to the Agreement.
2.2 To the extent that Customer is the Controller of Personal Data, Oasive is its Processor. To the extent that Customer is a Processor of Personal Data, Oasive is its sub-processor (within the meaning of Data Protection Laws).
2.3 Oasive will Process Personal Data solely: (1) to fulfill its obligations to, and documented instructions from, Customer under the Agreement, including this DPA; (2) on Customer’s behalf; and (3) in compliance with Data Protection Laws. Oasive will:
2.3.1 not retain, use, or disclose Personal Data outside of the direct business relationship between Customer and Oasive, except to the extent strictly required by applicable law or expressly permitted by the Agreement;
2.3.2 not “sell” any Personal Data, as such term is defined in U.S. Privacy Laws (regardless of whether any such laws apply);
2.3.3 not “share” any Personal Data, as such term is defined in the CCPA (regardless of whether the CCPA applies);
2.3.4 comply with any applicable restrictions under Data Protection Laws on combining Personal Data with personal data that Oasive receives from, or on behalf of, another person or persons, or that Oasive collects from any interaction between it and any individual;
2.3.5 not attempt to re-identify any pseudonymized or otherwise de-identified Personal Data received from Customer without Customer’s express written permission;
2.3.6 not otherwise engage in any Processing of Personal Data that is prohibited or not permitted by Processors or Service Providers under Data Protection Laws;
2.3.7 use commercially reasonable efforts to provide the level of protection for the Personal Data subject to the CPRA as is required under the CPRA; and
2.3.8 promptly inform Customer if, in Oasive’s opinion, an instruction from Customer infringes Data Protection Laws.
2.4 Where Customer acts as a Processor, Customer represents and warrants that it has obtained the relevant Controller’s authorization to engage Oasive as a sub-processor, that Customer’s instructions to Oasive are consistent with the Controller’s instructions to Customer, and that Customer is authorized to enter into this DPA (including the SCCs and the UK Addendum, as applicable) on the Controller’s behalf. Customer will relay to Oasive any Controller instructions applicable to Oasive’s Processing, and Oasive may treat Customer as its sole point of contact for all matters arising under this DPA.
3. Personal Data Processing Requirements
Oasive will:
3.1 Ensure that the persons it authorizes to Process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
3.2 Assist Customer in the fulfillment of Customer’s obligations to respond to verifiable requests by Data Subjects (or their lawful representatives) for exercising their rights under Data Protection Laws (such as rights to access or delete Personal Data).
3.3 Promptly notify Customer of any Data Subject requests to exercise their rights under Data Protection Laws with regard to the Personal Data or any government request for access to or information about Customer’s Processing of Personal Data on Customer’s behalf (collectively, “Personal Data Request”), unless prohibited by applicable law from making such notification. Unless otherwise required by applicable law, if Oasive receives a Personal Data Request, after notifying Customer of such request, Oasive will await written instructions from Customer on how, if at all, to assist in responding. Oasive will provide Customer with reasonable and timely cooperation and assistance in relation to any Personal Data Request.
3.4 Solely to the extent that such Processing activities are within Oasive’s control and directly relate to the Services, Oasive will provide reasonable assistance to and cooperation with Customer for Customer’s (i) performance of a data protection impact assessment of Processing or proposed Processing of Personal Data, when required by Data Protection Laws; and/or (ii) consultation with regulatory authorities in relation to the Processing or proposed Processing of Personal Data, including complying with any applicable obligation upon Oasive to consult with a regulatory authority in relation to Oasive’s Processing or proposed Processing of Personal Data.
4. Data Security
4.1 Oasive will implement appropriate administrative, technical, physical, and organizational measures to protect Personal Data, as set forth in Annex II. In the event of any conflict between the body of this DPA and the Annexes, the body of this DPA will prevail.
5. Security Breach
5.1 Oasive will notify Customer of any Security Breach promptly, and in any event within 72 hours after becoming aware of such Security Breach. Oasive will comply with the Security Breach-related obligations directly applicable to it under Data Protection Laws. Oasive will also assist Customer in Customer’s compliance with its Security Breach-related obligations, including by:
5.1.1 Taking steps to mitigate the effects of the Security Breach and reduce the risk to Data Subjects whose Personal Data was involved, at Oasive’s own expense to the extent the Security Breach arose within Oasive’s systems or security infrastructure, and otherwise at Customer’s reasonable expense to the extent the Security Breach was caused by Customer’s acts or omissions; and
5.1.2 Providing Customer with the following information, to the extent known:
(a) The nature of the Security Breach, including, where possible, how the Security Breach occurred, the categories and approximate number of Data Subjects concerned, and the categories and approximate number of Personal Data records concerned;
(b) The likely consequences of the Security Breach; and
(c) Measures taken or proposed to be taken by Oasive to address the Security Breach, including, where appropriate, measures to mitigate its possible adverse effects.
6. Sub-Processors
6.1 Customer acknowledges and agrees that Oasive may use Sub-processors to Process Personal Data in accordance with the provisions within this DPA and Data Protection Laws. Where Oasive sub-contracts any of its rights or obligations concerning Personal Data under this DPA to a Sub-processor, Oasive will: (i) take steps to select and retain Sub-processors that are capable of maintaining appropriate privacy and security measures to protect Personal Data consistent with Data Protection Laws; (ii) enter into a written agreement with each Sub-processor requiring it to comply with obligations that are, in all material respects, no less protective of Personal Data than those imposed on Oasive under this DPA; and (iii) remain liable to Customer for any breach of this DPA caused by an act or omission of a Sub-processor to the same extent Oasive would be liable under this DPA had Oasive itself committed such act or omission.
6.2 Oasive will maintain an up-to-date list of its Sub-processors. The initial list is provided in Annex III of this DPA, and Customer authorizes Oasive’s use of the Sub-processors on this list. To the extent required by applicable Data Protection Laws, Oasive will provide Customer notice of any new Sub-processor in writing, which may include by email or through a subscription mechanism Oasive makes available on its website. Oasive will allow Customer thirty (30) days from the day Oasive gives such notice to object to the appointment. If Customer has legitimate objections to the appointment of a new Sub-processor, Oasive will work with Customer in good faith to resolve the grounds for the objection.
7. Data Transfers
7.1 Oasive’s primary application storage is hosted in the United States. Sub-processors may Process Personal Data in other locations, subject to this DPA and applicable Data Protection Laws. In the event that Oasive Processes Personal Data transferred from the European Union, the European Economic Area and/or its member states (collectively, “EEA”) and/or the United Kingdom where the transfer is either prohibited by applicable Data Protection Laws or permitted to proceed only if certain additional requirements specified by applicable Data Protection Laws are fulfilled (a “Restricted Transfer”), the provisions set forth in this Data Transfers section will apply.
7.2 The SCCs apply to a Restricted Transfer of Personal Data under this DPA from the EEA between Customer and Oasive. Customer agrees the SCCs are completed and supplemented as follows:
7.2.1 Module Two applies where Customer is a Controller, and Module Three applies where Customer is a Processor;
7.2.2 Customer is the data exporter and Oasive is the data importer;
7.2.3 The optional docking clause under Clause 7 of the SCCs will not apply;
7.2.4 option 2 under Clause 9 of the SCCs applies and Customer generally authorizes Oasive to engage Sub-processors according to, and the time period for prior notice of Sub-processor changes will be as set out in, the Sub-processors section of this DPA;
7.2.5 the optional redress language under Clause 11(a) of the SCCs will not apply;
7.2.6 the governing law under Clause 17 of the SCCs will be the laws of Ireland;
7.2.7 the choice of forum and jurisdiction under Clause 18 of the SCCs will be the courts of Ireland;
7.2.8 Annexes I, II and III of the SCCs are deemed to be populated with the information set out in Annexes I, II and III of this DPA; and
7.2.9 Annex IV of this DPA supplements the SCCs with additional clauses as described in it.
7.3 The UK Addendum applies to a Restricted Transfer of Personal Data under this DPA from the United Kingdom between Customer and Oasive. Customer agrees the UK Addendum is completed and supplemented as follows:
7.3.1 Customer is the data exporter and Oasive is the data importer;
7.3.2 Table 1 of the UK Addendum is deemed to be populated with the information set out in Annex I of this DPA;
7.3.3 for the purposes of Table 2 of the UK Addendum, the version of the Approved EU SCCs (including the appendix information, modules and selected clauses) appended to the UK Addendum is the SCCs;
7.3.4 the optional docking clause under Clause 7 of the SCCs will not apply;
7.3.5 option 2 under Clause 9 of the SCCs applies and Customer generally authorizes Oasive to engage Sub-processors according to, and the time period for prior notice of Sub-processor changes will be as set out in, the Sub-processors section of this DPA;
7.3.6 the optional redress language under Clause 11(a) of the SCCs will not apply;
7.3.7 Annex IV of this DPA supplements the SCCs with additional clauses as described in it;
7.3.8 Table 3 of the UK Addendum is deemed to be populated with the information set out in Annexes I, II and III of this DPA;
7.3.9 The “importer” and “exporter” option applies for the purposes of Table 4 of the UK Addendum;
7.3.10 under Part 2, the mandatory clauses of the UK Addendum will apply; and
7.3.11 by using the Services to transfer Personal Data to Oasive, Customer will be deemed to have signed the UK Addendum.
7.4 The terms applicable to the transfer of Personal Data under this DPA from any other country or region are listed in Annex IV of this DPA and are incorporated into this DPA.
7.5 In the event of any conflict between the SCCs or the UK Addendum and the terms of this DPA, the terms of the SCCs or the UK Addendum, as applicable, will prevail.
8. Audits
8.1 Oasive will provide Customer with the information reasonably necessary to demonstrate Oasive’s compliance with this DPA, through the process described in this section. Customer may conduct an audit to confirm Oasive’s compliance with this DPA by submitting a data protection questionnaire of reasonable length not more than once annually. Oasive will promptly complete and return such questionnaire to Customer. To the extent Customer is able to demonstrate that Oasive’s questionnaire responses do not provide sufficient information to demonstrate compliance with this DPA, Customer may conduct follow-up interviews with Oasive’s personnel at times mutually agreed by the parties, subject to the confidentiality obligations in the Agreement, and at Customer’s reasonable expense.
9. Return or Destruction of Personal Data
9.1 Except to the extent required otherwise by applicable law or the Agreement, Oasive will, at the choice of Customer, return to Customer and/or securely destroy all Personal Data upon (a) written request of Customer or (b) termination of the Agreement. Except to the extent prohibited by applicable law, Oasive will inform Customer if it is not able to return or delete Personal Data.
10. Survival
10.1 The provisions of this DPA survive the termination or expiration of the Agreement for so long as Oasive or its Sub-processors Process Personal Data.
This DPA is incorporated into the Agreement. For online subscriptions, Customer accepts this DPA through the online acceptance process; Customer’s identity and acceptance date are recorded with its account. A separately executed agreement may also incorporate this DPA.
Contact: Oasive, Inc., hello@oasive.ai.
Annex I
Approved Data Transfer Mechanism: Description of Processing and Transfer
A. LIST OF PARTIES
MODULE TWO: Transfer Controller to Processor / MODULE THREE: Transfer Processor to Processor
Data exporter(s):
• Name: Customer, as identified in the Agreement.
• Address: As provided in the Agreement.
• Contact person’s name, position, and contact details: As provided in the Agreement.
• Activities relevant to the data transferred under these Clauses: The data exporter receives the data importer’s Services pursuant to their underlying Agreement.
• Signature and date: The parties agree that execution of the Agreement constitutes execution of these SCCs by both parties.
• Role: Controller and/or Processor
Data importer(s):
• Name: Oasive, as identified in the Agreement.
• Address: As provided in the Agreement.
• Contact person’s name, position, and contact details: As provided in the Agreement.
• Activities relevant to the data transferred under these Clauses: The data importer provides Services to the data exporter pursuant to their underlying Agreement.
• Signature and date: The parties agree that execution of the Agreement constitutes execution of these SCCs by both parties.
• Role: Processor
B. DESCRIPTION OF TRANSFER
MODULE TWO: Transfer Controller to Processor / MODULE THREE: Transfer Processor to Processor
• Categories of data subjects whose personal data is transferred: Customer’s employees and contractors who are authorized to use the Services, and any other individuals whose Personal Data Customer submits to the Services.
• Categories of personal data transferred: Name, business contact details, employer and job title, login credentials, records of use of the Services, and any Personal Data contained in content Customer submits to the Services.
• Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialised training), keeping a record of access to the data, restrictions for onward transfers or additional security measures: N/A
• The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis): Continuous for the duration of the Agreement.
• Nature of the processing: Hosting, storage, transmission to Sub-processors, and the other Processing necessary to provide the Services under the Agreement.
• Purpose(s) of the data transfer and further processing: The purpose of the transfer to and further Processing of Personal Data by Oasive is for Oasive to provide the Services to Customer.
• The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period: Personal Data will be retained for the period of time necessary for Oasive to provide the Services to Customer under the Agreement and/or in accordance with applicable legal requirements.
• For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing: Same as above to the extent that Personal Data is provided to Sub-processors for purposes of providing the Services.
C. COMPETENT SUPERVISORY AUTHORITY
MODULE TWO: Transfer Controller to Processor / MODULE THREE: Transfer Processor to Processor
To the extent legally permitted, the competent supervisory authority is the supervisory authority of the EEA member state in which the data exporter is established.
Annex II
Technical and Organisational Measures to Ensure the Security of the Data
1. Scope
1.1 Security Program. This Annex II sets out Oasive’s information security program (the “Security Program”), which Oasive will maintain and comply with in all material respects. The Security Program applies to Oasive’s performance under the Agreement and all access, collection, use, storage, transmission, disclosure, destruction or deletion of, and security incidents regarding all Personal Data. The Security Program does not limit other obligations of Oasive, including under the Agreement or any laws that apply to Oasive, Oasive’s performance under the Agreement, the Personal Data or the Permitted Purpose.
1.2 Permitted Purpose. Oasive may collect, use, store and retain only the Personal Data that is authorized under the Agreement, and then may only collect, use, store and retain that Personal Data solely as necessary for Oasive to perform the Services in accordance with the Agreement (“Permitted Purpose”).
2. Requirements
2.1 Security Practices. Oasive will maintain documented information security practices, proportionate to the size of its business and the sensitivity of the Personal Data, that apply to every person and supplier with access to Personal Data and that support the requirements of this Security Program.
2.2 Safeguards. Oasive will maintain administrative, technical and physical safeguards designed to protect the security and confidentiality of Personal Data accessed, collected, used, stored or transmitted by Oasive, and to protect that Personal Data from reasonably anticipated threats to its security and integrity, accidental loss, alteration, disclosure and other unlawful forms of processing. Without limiting the preceding sentence, Oasive will comply with the following requirements:
2.2.1 Hosting. Oasive will host the Services with an established cloud infrastructure provider that maintains independent third-party security certifications for its data centers and network, and will rely on that provider’s physical security, network firewalling and environmental controls for the production environment.
2.2.2 Updates. Oasive will use commercially reasonable efforts to keep its systems and software current with the security updates, bug fixes and new versions reasonably necessary to maintain the security of Personal Data.
2.2.3 Malware Protection. Oasive will use industry-standard malware protection on the endpoints used to administer the Services and will keep it updated.
2.3 Access Controls. Oasive will restrict access to Personal Data to those people who need it for a Permitted Purpose, will require unique credentials and multi-factor authentication for administrative access to the production environment, and will revoke access promptly when it is no longer needed.
2.4 Encryption. Oasive will encrypt Personal Data in transit over public networks and at rest, including on portable media and portable devices, using industry standard algorithms and methods.
2.5 Data Retention and Destruction.
2.5.1 Retention. Oasive will retain Personal Data only for the purpose of, and as long as is necessary for, the Permitted Purpose.
2.5.2 Return or Deletion. Except to the extent required otherwise by applicable law or the Agreement, Oasive will, within sixty (60) days after Customer’s written request, return to Customer and permanently and securely delete all Personal Data in accordance with Customer’s notice requiring return and/or deletion. Oasive will also permanently and securely delete all live (online or network accessible) instances of the Personal Data within sixty (60) days after the earlier of completion of the Permitted Purpose or termination or expiration of the Agreement. Personal Data held in routine backups will be deleted in the ordinary course of Oasive’s backup rotation.
2.6 Backups and Recovery. Oasive will maintain regular backups of Personal Data held in the production environment, stored separately from the live systems, and will use commercially reasonable efforts to restore the Services from those backups when needed.
2.7 Security Incidents. Oasive will inform Customer of any Security Breach within the period, and in the manner, set forth in the Security Breach section of this DPA. Oasive will remedy each Security Breach in a timely manner and provide Customer written details regarding Oasive’s internal investigation regarding each Security Breach.
Annex III
List of Sub-Processors
| Entity Name | Subprocessing Activities |
|---|---|
| Google LLC | Cloud hosting, storage, backups, logging, and Gemini/Vertex AI processing |
| Vercel Inc. | Website and application hosting, request processing and platform logs |
| Clerk, Inc. | Authentication and account management |
| Anthropic, PBC | AI responses and research, including web-search processing |
| OpenAI OpCo, LLC | AI processing for report review where used |
| Plus Five Five, Inc. (Resend) | Delivery of account and research emails |
| LangChain, Inc. (LangSmith) | Operational debugging traces, including prompts, tool inputs and results, responses, and portfolio/holdings content |
| Functional Software, Inc. (Sentry) | Error monitoring and diagnostics |
| PostHog, Inc. | Product analytics where enabled and retention of existing analytics records |
Annex IV
Supplemental Clauses
SWITZERLAND
The SCCs as adapted and supplemented as set forth in this section will only apply to a Restricted Transfer of Personal Data Processed under this DPA from Switzerland. Customer agrees that:
1. Any reference to “Member State” will not be interpreted in such a way as to exclude data subjects in Switzerland from the possibility of suing for their rights in their place of habitual residence (Switzerland);
2. Any references to “personal data” extend to personal data of legal entities if and to the extent such personal data pertaining to legal entities is within the scope of the FADP; and
3. To the extent the transfer of Personal Data is governed by the FADP, the Swiss Federal Data Protection and Information Commissioner will act as the competent supervisory authority. To the extent the transfer of Personal Data is governed by the EU GDPR, the supervisory authority determined in Annex I(C) will act as the competent supervisory authority. Any references to the “competent supervisory authority” will be interpreted accordingly.