Data Processing Addendum
Last updated:
This Data Processing Addendum ("DPA") sets out the terms on which Calven processes personal data on Customer's behalf under the Calven Terms of Use (or any other written agreement governing Customer's use of the Platform), in satisfaction of Article 28 of the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the UK GDPR where applicable, and the California Consumer Privacy Act as amended ("CCPA"). It is incorporated by reference into that agreement; no separate signature is required.
This DPA refers to three related documents: the Calven Terms of Use (the "Agreement"), of which this DPA forms part by reference, in particular the clauses titled "Your content" and "Privacy"; the Calven Security and Data Handling Overview (the "Security Overview"), the source of the technical and organizational measures in Annex II; and the Mutual Non-Disclosure Agreement (the "NDA"), which governs the confidentiality obligations of Calven personnel referenced in this DPA. The authorized sub-processors are not listed in this DPA; they are published on the Calven trust center at trust.calven.ai (the "Sub-processor List"), which forms part of this DPA by reference (Section 8).
Parties and incorporation
This DPA is between Calven AI, LLC, a Delaware limited liability company with a business address at 6 Liberty Square, PMB #596, Boston, MA 02109, United States ("Calven"), acting as processor, and the customer that has entered into the Agreement with Calven ("Customer"), acting as controller (each a "Party", together the "Parties").
This DPA forms part of the Agreement between Customer and Calven that references or otherwise incorporates it: the Calven Terms of Use, or any other written agreement governing Customer's use of the Platform. It takes effect automatically on the effective date of that Agreement; no separate signature is required. By entering into the Agreement or using the Platform, Customer agrees to this DPA. If Customer's internal processes require an executed copy, Calven will countersign this DPA on request; execution does not change its terms.
1. Definitions and roles
1.1 Defined terms. "Controller", "Processor", "Data Subject", "Personal Data", "Processing", "Personal Data Breach", "Supervisory Authority", and "Special Categories of Personal Data" have the meanings given in the GDPR. Capitalized terms not defined here have the meaning given in the Agreement. "Customer Personal Data" means Personal Data that Calven processes on Customer's behalf under the Agreement, as described in Annex I. "Data Protection Law" means the GDPR, the UK GDPR, the CCPA, and any other data protection or privacy law applicable to a Party's processing under the Agreement. "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries approved by European Commission Implementing Decision (EU) 2021/914. "Data Privacy Framework" or "DPF" means the EU-US Data Privacy Framework (and the UK Extension and Swiss-US framework where relevant) administered by the US Department of Commerce.
1.2 Roles. For Customer Personal Data, Customer is the controller (or, where Customer itself acts as a processor for a third-party controller, the processor) and Calven is the processor (or sub-processor, correspondingly). Each Party will comply with the obligations that apply to it in that role under Data Protection Law.
1.3 Relationship to the Agreement. This DPA supplements the Agreement. The Agreement's provisions on Customer content and its ownership (the clause titled "Your content") continue to apply; where they address Personal Data specifically, this DPA prevails to the extent of any conflict (see Section 11).
2. Scope and details of processing (Annex I)
2.1 The subject matter, duration, nature and purpose of the processing, the categories of Data Subjects, and the categories of Customer Personal Data are set out in Annex I. Calven processes Customer Personal Data only for as long as the Agreement remains in effect and for any wind-down period described in Section 9 of this DPA and in the Agreement's clause titled "Termination".
2.2 Calven does not require Customer to provide Special Categories of Personal Data and the Platform is not designed to process them. Customer will not upload or connect data sources whose primary purpose is Special Categories of Personal Data. Incidental special-category content that appears within business records (for example, within a free-text call transcript) is processed under the general measures in this DPA.
3. Processor obligations (Article 28(3))
3.1 Processing on documented instructions. Calven will process Customer Personal Data only on Customer's documented instructions, including as to international transfers, unless required to process by EU or Member State (or other applicable) law to which Calven is subject; in that case Calven will inform Customer of that legal requirement before processing, unless the law prohibits it on important grounds of public interest. The Agreement, the Security Overview, this DPA, and Customer's documented use of the Platform (including the integrations Customer connects and the workspace members it authorizes) constitute Customer's complete and final instructions. If Calven believes an instruction infringes Data Protection Law, it will inform Customer without undue delay.
3.2 Confidentiality of personnel. Calven will ensure that persons authorized to process Customer Personal Data, being authorized Calven personnel bound by confidentiality obligations under the NDA, have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and access Customer Personal Data strictly on a need-to-know basis, limited to those delivering the Platform and the setup, onboarding, and support services Customer asks Calven to perform. This mirrors Section 7 of the Security Overview (access control).
3.3 Security. Calven will implement and maintain the technical and organizational measures required by Article 32 GDPR, as described in Annex II, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to Data Subjects. Calven may update the measures in Annex II from time to time provided the level of protection is not materially reduced.
3.4 Sub-processing.
(a) General authorization. Customer gives Calven general written authorization to engage the sub-processors on the Sub-processor List to process Customer Personal Data. Calven will impose on each sub-processor, by written contract, data protection obligations no less protective than those in this DPA, in particular sufficient guarantees to implement appropriate technical and organizational measures. Calven remains fully liable to Customer for its sub-processors' performance of their data protection obligations.
(b) Changes and right to object. Calven will give Customer advance notice (by email to Customer's notice contact, or in-Platform, at least 14 days before the change) of any intended addition or replacement of a sub-processor that processes Customer Personal Data, and will update the Sub-processor List accordingly. Customer may object on reasonable data-protection grounds within that notice period. If Customer objects, the Parties will discuss in good faith; if the concern cannot be resolved, Customer may stop using the Platform and terminate the Agreement at any time and without penalty, as provided in the Agreement's clause titled "Termination", with Customer Personal Data handled per Section 9 of this DPA. (Consistent with Section 4 of the Security Overview: Calven notifies customers before adding a sub-processor that processes customer data.)
3.5 Assistance with Data Subject rights (Articles 12 to 23). Taking into account the nature of the processing, Calven will assist Customer by appropriate technical and organizational measures, insofar as possible, to fulfil Customer's obligation to respond to requests to exercise Data Subject rights (access, rectification, erasure, restriction, portability, objection, and rights relating to automated decision-making). Because Customer administers its own workspace and can export and delete data directly, much of this is available to Customer as Platform functionality. If Calven receives a Data Subject request relating to Customer Personal Data, it will not respond directly (except to acknowledge and direct the requester to Customer where appropriate) and will forward the request to Customer without undue delay.
3.6 Assistance with Articles 32 to 36. Taking into account the nature of processing and the information available to Calven, Calven will assist Customer in ensuring compliance with its obligations under Articles 32 to 36 GDPR, namely: security of processing (Article 32); Personal Data Breach notification to the Supervisory Authority and communication to Data Subjects (Articles 33 and 34); data protection impact assessments (Article 35); and prior consultation with the Supervisory Authority (Article 36). This assistance includes providing the information reasonably available to Calven that Customer needs for a DPIA of Customer's use of the Platform.
3.7 Deletion or return at end of services. Section 9 of this DPA governs the return and deletion of Customer Personal Data at the end of the Agreement.
3.8 Information and audit rights.
(a) Calven will make available to Customer the information reasonably necessary to demonstrate compliance with this DPA and Article 28 GDPR, including by completing reasonable security and data-protection questionnaires and providing the Security Overview and other relevant documentation (for example, sub-processor contracts' data-protection terms in summary, and, when available, third-party audit reports or certifications).
(b) Where documentation is insufficient to demonstrate compliance, Customer (or an independent auditor Customer mandates, who is bound by confidentiality) may audit Calven's processing of Customer Personal Data. Audits are limited to once per twelve (12) months, on at least 30 days' prior written notice, during business hours, in a manner that does not unreasonably disrupt Calven's operations, and at Customer's expense. This frequency limit does not apply where an audit is required by a Supervisory Authority or is triggered by a confirmed Personal Data Breach affecting Customer Personal Data, in which case a reasonable additional audit may occur on reasonable notice. Audits will not extend to the systems, premises, or data of other Calven customers or to Calven's sub-processors' own infrastructure (for those, Calven will use reasonable efforts to obtain the relevant information from the sub-processor).
4. Personal Data Breach notification
4.1 Calven will notify Customer without undue delay, and in any case within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.
4.2 The notification will describe, to the extent known and as it becomes available: (a) the nature of the breach, including where possible the categories and approximate number of Data Subjects and records concerned; (b) the likely consequences; (c) the measures taken or proposed to address it and mitigate its effects; and (d) a contact point for more information. Where Calven cannot provide all information at once, it may provide it in phases without undue further delay.
4.3 Calven will take reasonable steps to contain and remediate the breach and will cooperate with Customer and provide reasonable assistance for Customer to meet its own notification obligations to Supervisory Authorities and Data Subjects under Articles 33 and 34 GDPR. Calven's notification is not an acknowledgment of fault or liability.
5. International transfers
5.1 EU hosting is primary. Calven stores Customer Personal Data in the European Union on Microsoft Azure, as described in the Security Overview (Section 2). Microsoft Azure is Calven's cloud provider; to the extent any processing (for example, AI model inference on models not offered in the EU region) is carried out by Microsoft outside the EU, it is covered by Microsoft's own EU-US Data Privacy Framework certification and Standard Contractual Clauses.
5.2 Sub-processors outside the EU. Some sub-processors are established in the United States or in other third countries and process limited Customer Personal Data, as described in the Sub-processor List. Transfers of Customer Personal Data to these sub-processors are subject to an appropriate transfer mechanism under Chapter V GDPR, as follows:
(a) Adequacy decision. Where the sub-processor is established in a country covered by a European Commission adequacy decision, that decision is the transfer mechanism.
(b) Data Privacy Framework. Where the sub-processor is certified under the EU-US Data Privacy Framework (and the UK Extension and Swiss-US framework as applicable) for the relevant categories of data, that certification is the transfer mechanism.
(c) Standard Contractual Clauses (fallback). Where neither applies, the transfer is made under the Standard Contractual Clauses (Decision (EU) 2021/914), Module Three (processor-to-processor), as incorporated into the sub-processor's own data processing agreement with Calven, together with any supplementary measures identified as necessary by a transfer risk assessment.
(d) Per-vendor mechanism. The specific mechanism relied on for each sub-processor established outside the EU is recorded in the Sub-processor List.
5.3 Customer as data exporter. To the extent the SCCs apply and are entered into directly between the Parties for a transfer for which Customer is the exporter, the Parties agree that the SCCs (Module Two controller-to-processor, or Module Three where Customer is itself a processor) are incorporated into this DPA by reference and completed by the information in Annexes I and II and the Sub-processor List; the audit and sub-processor terms of this DPA apply to the extent the SCCs allow the Parties to specify them.
6. CCPA service provider terms
6.1 To the extent Calven processes Personal Information (as defined in the CCPA) on Customer's behalf, Calven acts as a service provider and Customer as a business.
6.2 Calven will not: (a) sell or share Customer's Personal Information (as those terms are defined in the CCPA, including for cross-context behavioral advertising); (b) retain, use, or disclose Customer's Personal Information for any purpose other than the specific business purpose of performing the services under the Agreement, or as otherwise permitted by the CCPA; (c) retain, use, or disclose it outside the direct business relationship between the Parties; or (d) combine it with Personal Information obtained from other sources, except as permitted by the CCPA for a service provider.
6.3 Calven certifies that it understands and will comply with these restrictions. Calven will assist Customer in responding to verifiable consumer requests under the CCPA on the same basis as Section 3.5. These commitments are consistent with the Agreement, under which Customer retains all rights to its content, Calven's license is limited to hosting and processing that content solely to provide and support the Platform, and Customer content is not used to train foundation AI models (the clause titled "Your content").
7. Customer obligations
7.1 Customer warrants that it has a lawful basis for the processing it instructs, has provided any notices and obtained any consents required under Data Protection Law, and that its instructions comply with Data Protection Law. Customer is responsible for the accuracy, quality, and legality of the Customer Personal Data it (or its connected systems) makes available to the Platform, and for the workspace members it authorizes to access the Platform.
8. Sub-processor list
8.1 The authorized sub-processors, their processing purposes, the Customer Personal Data they process, their location, and the applicable transfer mechanism are published on the Calven trust center at trust.calven.ai (the "Sub-processor List"). The Sub-processor List forms part of this DPA by reference and is the single authoritative record of Calven's sub-processors; this DPA deliberately does not restate it. Calven keeps the Sub-processor List current and gives notice of changes under Section 3.4(b).
9. Return and deletion of Customer Personal Data
9.1 Consistent with Section 8 of the Security Overview and the Agreement's clause titled "Termination": Customer may export its Customer Personal Data at any time. On the end of the Agreement, and at Customer's choice, Calven will either return or delete Customer Personal Data. Unless Customer's workspace continues in use (in which case the data stays in place), Calven will delete Customer Personal Data from its production systems within 30 days of Customer's written request, and in any event within 90 days after the Agreement ends, except where retention is required by law. A workspace kept read-only under the Termination section of the Agreement remains under the Agreement until it is deleted.
9.2 Backup copies containing Customer Personal Data age out on the normal automated backup rotation and are not restored except for disaster recovery; while they persist they remain protected by the measures in Annex II and are not used for any other purpose.
10. Liability
10.1 Each Party's liability under this DPA is subject to the exclusions and limitation of liability in the Agreement (the clause titled "Limitation of liability"). Nothing in this DPA limits any liability that cannot be limited under Data Protection Law, including liability to Data Subjects under Article 82 GDPR.
11. Order of precedence and general
11.1 Precedence. For matters of data protection concerning Customer Personal Data, this DPA prevails over the body of the Agreement and the Security Overview in the event of conflict. Where SCCs are incorporated under Section 5, the SCCs prevail over this DPA to the extent of any conflict, as required by Data Protection Law. In all other respects the Agreement continues in full force.
11.2 Term. This DPA takes effect on the effective date of the Agreement and continues for as long as Calven processes Customer Personal Data. Sections that by their nature should survive (including Sections 9, 10, and 11) survive termination.
11.3 General. The Agreement's general terms (including governing law and the process for changes to the Agreement) apply to this DPA. This DPA is incorporated into the Agreement by reference (see "Parties and incorporation" above) and requires no separate execution.
Annex I. Details of processing
Controller: Customer (as defined above).
Processor: Calven AI, LLC.
Subject matter. Calven's provision of the Calven Platform (Intelligence Core: market and competitive research, target audience intelligence, and positioning and messaging modules) and the setup, onboarding, and support services Customer asks Calven to perform, under the Agreement.
Duration. For as long as the Agreement remains in effect, plus the wind-down and deletion period described in Section 9 of this DPA.
Nature of the processing. Collection, storage, organization, analysis, retrieval, generation of derived outputs, and (at the end of the Agreement) return or deletion. Processing includes AI and machine analysis of connected and uploaded data to produce research, audience, and messaging outputs, and, for participants who join a scheduled AI-conducted win/loss interview, real-time voice interaction and transcription.
Purpose of the processing. To provide the Platform and services under the Agreement, and only for that purpose. Calven does not sell Customer Personal Data, share it with other customers, or use it to train machine-learning models (Section 6.2 of this DPA).
Categories of Data Subjects:
- Customer's team members who use the Platform (authorized users).
- Customer's business contacts within its connected systems, for example contacts, leads, and stakeholders in the CRM, and speakers and participants named in sales-call transcripts.
- Individuals referenced in documents Customer uploads or in connected communication channels.
- Participants in AI-conducted win/loss interviews (for example Customer's customers or prospects who agree to be interviewed).
- Customer's billing contact.
Categories of Customer Personal Data:
- B2B business contact data: names, work email addresses, job titles, employer or company, and business phone numbers.
- CRM records: account and company records, contact records, deal and pipeline data, and associated notes referencing individuals.
- Call transcripts: sales-call transcripts and call metadata, which may name and quote individuals.
- Uploaded documents: briefs, persona documents, and other files Customer provides that may reference individuals.
- User account data: authorized users' names, work emails, and sign-in and authentication metadata.
- Interview audio and transcripts: interview audio (processed in real time, not recorded) and transcripts from AI-conducted win/loss interviews.
- Billing data: billing contact name and work email, company name, billing address, tax ID, and payment history (card numbers are entered on Stripe's hosted pages and never reach Calven).
Special Categories of Personal Data: None required or intended (see Section 2.2). Any special-category content is incidental within business free-text.
Frequency of processing: Continuous for the duration of the Agreement.
Annex II. Technical and organizational measures (Article 32)
These measures are lifted from Sections 2, 6, 7, and 8 of the Security Overview and are current as of the date of this DPA; Calven may update them provided the level of protection is not materially reduced.
Data location.
- Customer Personal Data is stored in the EU on Microsoft Azure. No self-hosted infrastructure and no secondary cloud provider. (International transfers are addressed in Section 5.)
Tenant isolation.
- Every customer is a separate tenant, and application access is constrained to the customer's own tenant. Calven never uses one customer's data to produce outputs for another.
Encryption.
- Data at rest is encrypted using Azure's platform-managed encryption (database and file storage), and data in transit is encrypted with TLS. Integration credentials are additionally encrypted at the application layer.
Access and least privilege.
- Access to production data is limited to narrowly scoped, authorized identities, with no standing human access paths and no shared human logins. The single bootstrap-only administrative credential is held in the secrets vault. Credentials and keys are held in a managed secrets vault with role-based access.
- Where Customer asks Calven to assist with setup, onboarding, or support, workspace access is limited to authorized Calven personnel bound by the NDA, on a need-to-know basis, to the Customer's Calven workspace only, never to Customer's own systems. Customer may decline or revoke that access at any time.
Backups and resilience.
- The managed database and file storage are backed up automatically and restored only for disaster recovery.
Monitoring and logging.
- Infrastructure logs and metrics stay within Azure; product analytics and error monitoring run on PostHog (see the Sub-processor List). Infrastructure is managed as code with peer-reviewed changes.
Personnel confidentiality.
- Authorized Calven personnel are bound by confidentiality obligations under the NDA and access Customer Personal Data strictly on a need-to-know basis.
Assisting Customer.
- Customer administers its own workspace access (its workspace administrators manage members and their access) and can export and delete its data on request, supporting fulfilment of Data Subject rights.