Legal · nSpire AI, Inc.
Data Processing Addendum
The terms that apply when nSpire processes personal data on a Customer's behalf in providing the Services. This DPA forms part of your agreement with nSpire.
This Data Processing Addendum ("DPA") forms part of the agreement between nSpire AI, Inc., 95 Third Street, 2nd Floor, San Francisco, CA 94103 ("nSpire"), and the customer named in that agreement ("Customer") for nSpire's services (the "Services") (the "Agreement").
This DPA applies when nSpire processes Customer Personal Data on Customer's behalf in providing the Services. It takes effect on the date the Agreement takes effect, or the date Customer accepts this DPA if later. By signing or accepting the Agreement, Customer enters into this DPA on behalf of itself and its authorized affiliates.
1. Definitions
Capitalized terms not defined here have the meanings given in the Agreement.
- "Services"
- means the nSpire products and services described in the Agreement and, where the Agreement does not describe them, in Annex I item 6.
- "Data Protection Laws"
- means all laws that apply to the processing of Customer Personal Data under the Agreement, including, where applicable, the EU GDPR, the UK GDPR and UK Data Protection Act 2018, the Swiss Federal Act on Data Protection, and US State Privacy Laws.
- "EU GDPR" / "UK GDPR"
- "EU GDPR" means Regulation (EU) 2016/679. "UK GDPR" means the EU GDPR as it forms part of UK law.
- "US State Privacy Laws"
- means the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA") and comparable US state privacy laws.
- "Customer Personal Data"
- means personal data that nSpire processes on behalf of Customer in providing the Services, as described in Annex I.
- "Personal Data Breach"
- means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
- "Subprocessor"
- means any third party nSpire engages to process Customer Personal Data.
- "SCCs"
- means the standard contractual clauses approved by the European Commission in Implementing Decision (EU) 2021/914.
- "UK Addendum"
- means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner.
"Controller", "processor", "data subject", "personal data", "processing" and "supervisory authority" have the meanings given in the GDPR. "Business", "service provider", "sell" and "share" have the meanings given in the CCPA.
2. Roles and scope of processing
2.1 Roles. Customer is the controller of Customer Personal Data and nSpire is its processor. Where Customer acts as a processor for another controller, nSpire is Customer's subprocessor.
2.2 Scope. nSpire processes Customer Personal Data only to provide, secure, support and maintain the Services, as described in Annex I.
2.3 Customer responsibilities. Customer is responsible for the lawfulness of the Customer Personal Data it provides and of its instructions. Customer will provide any notices and obtain any consents Data Protection Laws require, including notices to its employees and learners about recorded practice sessions and AI-generated feedback.
2.4 Out of scope. This DPA does not apply where nSpire acts as an independent controller, such as for its own account administration, billing, website visitors and marketing. nSpire's Privacy Policy governs that processing.
2.5 AI-generated outputs. Scores, feedback, match results and other outputs of the Services are generated by AI and may be inaccurate or incomplete. Customer will not use them as the sole basis for any decision that produces legal or similarly significant effects on an individual, including decisions about hiring, promotion, compensation, discipline or termination. Where such outputs inform those decisions, Customer will ensure meaningful human review and give individuals a way to contest the outcome. Customer is responsible for any notices, impact assessments or other obligations that Data Protection Laws or laws regulating artificial intelligence impose on its use of the Services.
2.6 Minors. The Services are not directed to children. Under nSpire's Terms of Service, the Services may not be used by anyone under 13 years of age, and a person under 18 may use them only with the approval of a parent or guardian. Customer is responsible for ensuring that the users it enrolls meet this requirement and, where a user is under the age of digital consent in their jurisdiction, that any parental or guardian consent Data Protection Laws require has been obtained. Where Customer is a university or workforce program enrolling minors, the parties will agree specific terms in writing before enrollment.
3. nSpire's obligations
3.1 Instructions. nSpire will process Customer Personal Data only on Customer's documented instructions. The Agreement, this DPA and Customer's configuration and use of the Services are Customer's complete instructions. nSpire will tell Customer if it believes an instruction violates Data Protection Laws, unless the law prohibits that notice.
3.2 Legal requirements. If law requires nSpire to process Customer Personal Data other than on Customer's instructions, nSpire will inform Customer before processing, unless the law prohibits it.
3.3 Confidentiality. nSpire will ensure that personnel authorized to process Customer Personal Data are bound by confidentiality obligations and receive appropriate data protection training.
3.4 Security. nSpire will implement and maintain the technical and organizational measures in Annex II. nSpire may update these measures, provided the updates do not materially reduce the overall protection of Customer Personal Data.
3.5 Records. nSpire will maintain records of its processing activities as a processor as required by Article 30(2) GDPR.
3.6 No model training.
(a) nSpire does not use Customer Personal Data to train, fine-tune or otherwise develop machine learning models. Customer Personal Data submitted to AI models is processed solely to generate the output returned to the user, and is transmitted to the AI Subprocessors listed in Annex III for that purpose.
(b) nSpire requires by contract that each AI Subprocessor listed in Annex III does not use Customer Personal Data to train or improve its models.
3.7 Aggregated data. nSpire may create aggregated or de-identified data from its use of the Services, provided the data cannot reasonably be used to identify Customer or any individual.
4. Subprocessors
4.1 Authorization. Customer gives nSpire general authorization to engage Subprocessors. The Subprocessors listed in Annex III are approved as of the effective date.
4.2 Obligations. nSpire will enter into a written agreement with each Subprocessor that imposes data protection obligations no less protective than this DPA. nSpire remains responsible for each Subprocessor's performance.
4.3 Notice of changes. nSpire will notify Customer of any new or replacement Subprocessor at least 30 days before it processes Customer Personal Data, by email to Customer's designated contact.
4.4 Objection. Customer may object in writing on reasonable data protection grounds within 30 days of notice. The parties will discuss the objection in good faith. If they cannot resolve it, Customer may terminate the affected Services and receive a refund of prepaid fees for the unused term.
5. Data subject requests and assistance
5.1 Requests. If nSpire receives a request from a data subject about Customer Personal Data, nSpire will not respond directly except to redirect the data subject to Customer, unless Customer authorizes otherwise. nSpire will forward the request to Customer promptly.
5.2 Assistance. Taking into account the nature of the processing, nSpire will provide Customer with reasonable assistance, on request to nSpire support, so Customer can fulfil its obligations to respond to data subject requests under Data Protection Laws, including requests to access, correct, delete, restrict, object to, or port Customer Personal Data.
5.3 Impact assessments. nSpire will provide reasonable information and assistance for Customer's data protection impact assessments and prior consultations with supervisory authorities, to the extent Customer cannot obtain the information itself.
6. Personal Data Breach
6.1 Notice. nSpire will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.
6.2 Content. The notice will describe, to the extent known:
- the nature of the breach, including the categories and approximate number of data subjects and records affected;
- the likely consequences;
- the measures taken or proposed to address the breach and mitigate its effects;
- a contact point for more information.
Where information is not yet available, nSpire will provide it in phases as it becomes available.
6.3 Response. nSpire will take reasonable steps to contain, investigate and mitigate the breach, and will reasonably cooperate with Customer's own notification obligations.
6.4 No admission. nSpire's notice of a Personal Data Breach is not an acknowledgment of fault or liability.
7. Audits
7.1 Reports. On written request, and subject to confidentiality, nSpire will provide information reasonably necessary to demonstrate compliance with this DPA.
7.2 Audits. If that information does not reasonably satisfy Customer's obligations under Data Protection Laws, or a supervisory authority requires it, Customer may audit nSpire's compliance with this DPA. The audit:
- requires at least 30 days' written notice, and occurs no more than once in any 12-month period unless a Personal Data Breach has occurred;
- takes place during normal business hours, without unreasonable disruption to nSpire's operations;
- is conducted by Customer or an independent auditor bound by confidentiality who is not a competitor of nSpire;
- is at Customer's expense.
7.3 SCC audits. Audits under the SCCs will be carried out in accordance with this Section 7.
8. International transfers
8.1 Location. nSpire stores Customer Personal Data in the United States. Application infrastructure, databases and compute run on Google Cloud (us-west2). User media — resumes, documents, and audio and video recordings — is stored on Amazon Web Services S3 (us-west-2). Certain AI Subprocessors process Customer Personal Data in regions set by the vendor and not pinned by nSpire; those Subprocessors are identified as such in the Subprocessor List (Annex III). Other Subprocessors may process Customer Personal Data in the locations listed there.
8.2 EEA transfers. Where Customer Personal Data is transferred from the EEA to nSpire and that transfer is not covered by an adequacy decision or another appropriate safeguard under Chapter V of the EU GDPR, the SCCs are incorporated into this DPA by reference, as follows:
- Module Two (controller to processor) applies where Customer is a controller; Module Three (processor to processor) applies where Customer is a processor.
- Clause 7 (docking clause) applies.
- Clause 9 option 2 (general authorization) applies, with the notice period in Section 4.3.
- Clause 11 optional language does not apply.
- Clause 17: Option 1 applies; the SCCs are governed by the law of Ireland.
- Clause 18(b): the courts of Ireland.
- Annexes I, II and III of this DPA complete the SCC Annexes.
8.3 UK transfers. For transfers from the UK, the UK Addendum applies. Its Table 1 is completed with the parties' details in Annex I, Tables 2 and 3 with the SCC selections in Section 8.2 and the Annexes of this DPA, and in Table 4 neither party may end the Addendum.
8.4 Swiss transfers. For transfers from Switzerland, the SCCs apply as set out in Section 8.2, with references to the GDPR read as references to the Swiss Federal Act on Data Protection and the competent supervisory authority being the Swiss Federal Data Protection and Information Commissioner.
8.5 Alternative mechanisms. If nSpire adopts another lawful transfer mechanism, such as certification under the EU-US Data Privacy Framework, that mechanism will apply instead to the extent it covers the transfer.
8.6 Precedence. If the SCCs or UK Addendum conflict with this DPA, they prevail.
8.7 Government access requests. If nSpire receives a legally binding request from a public authority for access to Customer Personal Data, nSpire will, unless the law prohibits it:
- promptly notify Customer and, where possible, redirect the authority to request the data directly from Customer;
- review the legality of the request and challenge it where there are reasonable grounds to consider it unlawful or overbroad;
- disclose only the minimum data necessary to comply;
- keep a record of the request and nSpire's response.
Where the law prohibits notice, nSpire will use reasonable efforts to obtain a waiver so it can inform Customer. As of the date of this DPA, nSpire has not received any such request for Customer Personal Data.
9. US State Privacy Laws
Customer is the business and nSpire is the service provider or processor with respect to Customer Personal Data. Where US State Privacy Laws apply, nSpire:
- certifies that it understands the restrictions in this Section 9 and will comply with them;
- will not sell or share Customer Personal Data;
- will not retain, use or disclose Customer Personal Data for any purpose other than the limited and specified business purposes described in Annex I items 4 and 6, or outside the direct business relationship with Customer;
- will not combine Customer Personal Data with personal data it receives from other sources, except as those laws permit;
- will comply with applicable obligations under those laws and provide the same level of protection they require;
- will notify Customer if it can no longer meet its obligations under those laws;
- grants Customer the right to take reasonable and appropriate steps to ensure that nSpire uses Customer Personal Data in a manner consistent with Customer's obligations under US State Privacy Laws;
- permits Customer to take reasonable steps to stop and remediate unauthorized use of Customer Personal Data.
10. Retention, return and deletion
10.1 During the term. nSpire retains Customer Personal Data for as long as appropriate to fulfil the purposes for which it was collected, including satisfying legal, accounting or reporting requirements, establishing or defending legal claims, and fraud prevention. In determining the appropriate retention period nSpire considers the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure, the purposes of processing and whether those purposes can be achieved by other means, and applicable legal requirements. Fixed retention periods apply to the categories listed in Annex I item 8.
Customer may ask nSpire to delete an individual user's data at any time.
Safety-record exception. nSpire retains, for the period stated in Annex I item 8, a restricted-access record of safety-flagged disclosures, including where the associated account has been deleted, where retention is necessary for the establishment, exercise or defence of legal claims or to protect the vital interests of a data subject.
10.2 On termination. nSpire will delete Customer Personal Data, including stored media, within 30 days of termination, except where law requires it to be kept or where the safety-record exception in 10.1 applies. Data in backups is deleted in the ordinary course of nSpire's backup rotation cycle and remains protected by the measures in Annex II until then.
10.3 Confirmation. On request, nSpire will confirm deletion in writing, subject to the exceptions in Section 10.1.
11. General terms
11.1 Liability. Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, except where Data Protection Laws or the SCCs do not permit this.
11.2 Order of precedence. If there is a conflict, the order of precedence is: the SCCs or UK Addendum, then this DPA, then the Agreement.
11.3 Term. This DPA lasts as long as nSpire processes Customer Personal Data.
11.4 Governing law. This DPA is governed by the law that governs the Agreement, except where the SCCs or Data Protection Laws require otherwise.
11.5 Changes. nSpire may update this DPA to reflect changes in Data Protection Laws or its Services, provided the changes do not materially reduce protection for Customer Personal Data.
11.6 Contact. Privacy questions and notices under this DPA: support@nspire.ai.
Annex I
Description of processing
A. Parties. Data exporter: Customer, as identified in the Agreement; role: controller (or processor). Data importer: nSpire AI, Inc., 95 Third Street, 2nd Floor, San Francisco, CA 94103; role: processor; contact: support@nspire.ai.
B. Description of processing
| Item | Description |
|---|---|
| 1. Data subjects | Customer's authorized users: employees, managers, administrators and learners, and where Customer is a university or workforce program, its students, alumni and program participants, subject to Section 2.6 |
| 2. Categories of personal data | Identity and account data (name, email, phone, location, LinkedIn URL, profile picture, login credentials); career content (resumes, portfolio documents, work history, education, skills, salary expectations); audio and video recordings of practice and interview sessions, including users' voices and facial images, and still-frame thumbnails; AI-derived data (transcripts, feedback, competency scorecards, manager coaching notes, match scores, embeddings, and safety-classifier records described in item 3); usage and device data (activity events, error logs, IP address and IP-derived location) |
| 3. Special category data | Not solicited, but reasonably foreseeable. The Services include conversational features in which a user may voluntarily disclose sensitive information, including health-related circumstances. nSpire operates automated safety classifiers over certain conversational features. Records flagged as involving a minor are quarantined and deleted after 7 days. Records flagged as crisis-related are held in a restricted-access store and retained for 12 months for safety and legal-claims purposes, including where the associated account has been deleted. Customer should assume special category data may be processed and address it in its own lawful-basis analysis. |
| 4. Nature of processing | Collection, storage, transcription, AI analysis and scoring, voice synthesis, display, and deletion, as needed to provide the Services |
| 5. Video and audio analysis | Where a user enables camera mode, the recording is analyzed by an automated multimodal model to produce coaching feedback on delivery — eye contact, facial expressiveness, vocal intonation, confidence and related measures — and an audio/video source-consistency check. The analysis evaluates behaviour. nSpire does not enrol, derive or store any biometric template, and performs no identification or 1:1 or 1:N matching of a data subject against any reference, and therefore does not process biometric data for the purpose of uniquely identifying a natural person within the meaning of Article 9(1). Customer acknowledges that the recordings themselves contain facial images and voice, are capable of biometric use, and are retained under Section 10. |
| 6. Purpose | Providing AI-based practice, coaching and assessment Services under the Agreement, including support and security |
| 7. Frequency | Continuous, for the term of the Agreement |
| 8. Retention | Fixed periods, enforced by scheduled deletion: career-exploration transcripts 90 days; inactive confirmed career facts 24 months; crisis-flagged safety records 12 months; minor-flagged quarantine records 7 days. Other Customer Personal Data is retained on the criteria in Section 10.1, and deleted after termination under Section 10.2. |
| 9. Subprocessor transfers | As listed in Annex III, for the same purposes and duration. Session content, transcripts and model outputs are transmitted to the AI Subprocessors listed there, and diagnostic data to the observability Subprocessors listed there. |
C. Competent supervisory authority. Determined under Clause 13(a) of the SCCs: where Customer is established in an EU Member State, the supervisory authority of that Member State; where Customer is not established in the EU but falls within Article 3(2) EU GDPR and has appointed a representative under Article 27, the supervisory authority of the Member State in which that representative is established; otherwise, the supervisory authority of the Member State in which the data subjects whose personal data is transferred are located.
Annex II
Technical and organizational measures
nSpire implements and maintains the following technical and organizational measures. nSpire may update these measures as its Services evolve, provided the updates do not materially reduce the overall protection of Customer Personal Data.
| Area | Measures |
|---|---|
| Hosting | Application, database and compute infrastructure on Google Cloud (us-west2); user media storage on Amazon Web Services S3 (us-west-2). Physical and environmental security is managed by those providers. |
| Encryption in transit | TLS 1.2 or higher for all external connections; database connections require TLS. Internal message-queue traffic is encrypted and reachable only from the private network. |
| Encryption at rest | Production databases are encrypted at rest with customer-managed encryption keys (CMEK) managed in a cloud key management service. |
| Network controls | Private VPC with private database addressing, controlled egress, a web application firewall in front of the load balancer, and IP-allowlisted administrative interfaces. |
| Access control | Role-based access with dedicated per-service identities and permissions scoped per service. |
| Tenant separation | Customer data is logically separated by workspace and enforced through application-layer authorization on every request. |
| Secrets management | Application credentials are managed centrally and injected into services at runtime. |
| Logging and monitoring | Application error monitoring with alerting; cloud audit logging of data read and write operations across production services. |
| Resilience | Automated database backups with point-in-time recovery, retained transaction logs, and a regional high-availability configuration with a read replica. |
| Secure development | Code review before merge; automated dependency vulnerability scanning, static security analysis and container image scanning in the build pipeline. |
| Personnel | Confidentiality agreements; security and privacy training at onboarding. |
| Vendor management | Written data protection terms with each Subprocessor listed in Annex III. |
| Incident response | Security incidents affecting Customer Personal Data are handled and notified to Customer as described in Section 6. |
| Government requests | Requests for Customer Personal Data are handled under the process described in Section 8.7. |
| Data subject rights | Deletion of an individual user's data on request through nSpire support. |
| Termination deletion | Deletion of Customer Personal Data on termination under Section 10.2. |
Annex III
Authorized Subprocessors
nSpire maintains a current list of its authorized Subprocessors — including each Subprocessor's purpose, the categories of Customer Personal Data it processes, and its processing location — as the Subprocessor List. The Subprocessor List forms part of this DPA as Annex III.
Request the Subprocessor List
The Subprocessor List is available to Customers and prospective Customers on request, and is provided with every executed copy of this DPA. Customers receive notice of changes as described in Section 4.3.
Marketing and sales tools and billing providers process nSpire's own data with nSpire acting as controller and are covered by nSpire's Privacy Policy, not this DPA. Social sign-in providers are used only at the user's choice.