Effective: [EFFECTIVE DATE] · Version: 1.0
This DPA forms part of the Terms of Service / Master Subscription Agreement (the "Agreement") between [COMPANY LEGAL NAME] ("Provider") and Customer. Capitalized terms not defined here have the meaning given in the Agreement. In the event of conflict, this DPA controls as to Personal Data.
"Applicable Data Protection Law" — all privacy and data protection laws applicable to the processing, including the California Consumer Privacy Act as amended by the CPRA ("CCPA"), and the comprehensive privacy statutes of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and any other US state law applicable to Customer.
"Controller" / "Business", "Processor" / "Service Provider", "Data Subject" / "Consumer", "Personal Data" / "Personal Information", "Process", and "Sell" and "Share" have the meanings given under Applicable Data Protection Law.
"Security Incident" — a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Personal Data processed by Provider. Unsuccessful attempts and routine events (pings, port scans, failed logins) are not Security Incidents.
"Subprocessor" — a third party engaged by Provider to process Personal Data.
2.1 Customer is the Controller / Business. Provider is the Processor / Service Provider acting on Customer's documented instructions.
2.2 Employee data. Customer is the employer of its Authorized Users and is the Controller of their Personal Data. Provider does not determine the purposes for which salesperson performance data is used by Customer.
2.3 Retail customer data — not ingested. Provider configures every feed, and every feed in service is a per-salesperson aggregate report: one row per salesperson, columns being counts and totals (leads, appointments, demos, write-ups, units, gross, calls/emails/texts sent). No retail customer Personal Data — no names, contact details, addresses, or VINs — is ingested, parsed, or stored.
Should Customer and Provider ever agree to enable a lead-level or deal-level feed containing retail customer Personal Data, Customer is the Controller of that data, warrants it has a lawful basis for its disclosure, and the 30-day raw-file retention in §9 and Annex I applies to it.
2.4 Provider does not act as a Controller of Customer Personal Data, except with respect to limited account, billing, and service-operations data described in the Privacy Policy.
3.1 Provider will process Personal Data only (a) on Customer's documented instructions, including as set out in the Agreement, this DPA, and Customer's configuration of the Service; (b) as necessary to provide, secure, and support the Service; and (c) as required by law, in which case Provider will notify Customer unless legally prohibited.
3.2 The Agreement and Customer's use of the Service constitute Customer's complete documented instructions. Additional instructions require written agreement and may incur fees.
3.3 Provider will inform Customer if, in its reasonable opinion, an instruction violates Applicable Data Protection Law.
Provider is a Service Provider under the CCPA. Provider will not:
(a) Sell or Share Personal Information; (b) retain, use, or disclose Personal Information for any purpose other than performing the services specified in the Agreement, or as otherwise permitted by the CCPA; (c) retain, use, or disclose Personal Information outside the direct business relationship with Customer; or (d) combine Personal Information received from Customer with Personal Information received from any other source, except as permitted by the CCPA to perform a business purpose.
Provider certifies that it understands and will comply with these restrictions. Customer may take reasonable and appropriate steps to stop and remediate unauthorized use.
No training. Provider will not use Customer Personal Data to train, fine-tune, or otherwise improve any machine-learning model, whether Provider's own or a third party's, except that Provider may use aggregated, de-identified data strictly within the limits of Agreement §5.4, which expressly excludes salesperson commission, earnings, and budget data at every level of aggregation.
Provider will ensure that persons authorized to process Personal Data are bound by confidentiality obligations, receive appropriate training, and are granted access on a least-privilege, need-to-know basis.
Provider will implement and maintain the technical and organizational measures described in Annex II, appropriate to the risk. Provider may update these measures provided security is not materially degraded.
Provider will notify Customer of a Security Incident affecting Customer Personal Data without undue delay and in any event within seventy-two (72) hours of becoming aware of it. The notice will describe, to the extent known: the nature of the incident, categories and approximate volume of data and individuals affected, likely consequences, and measures taken or proposed. Provider will provide reasonable cooperation and information to assist Customer's own notification obligations. Provider's notification is not an acknowledgment of fault or liability.
8.1 Data subject requests. Taking into account the nature of the processing, Provider will assist Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling Customer's obligation to respond to requests to access, correct, delete, port, restrict, or object to processing of Personal Data. If Provider receives such a request directly, it will not respond substantively other than to direct the individual to Customer, and will notify Customer without undue delay.
8.2 Assessments. Provider will provide reasonable assistance with data protection impact assessments, risk assessments, and consultations with supervisory authorities, at Customer's cost where the effort is more than trivial.
8.3 Algorithmic transparency. On request, Provider will provide the documentation described in the AI Disclosure to support Customer's obligations under any law governing automated decision-making, profiling, or automated employment decision tools.
On termination or expiry of the Agreement, Provider will, at Customer's election made within thirty (30) days, delete or return Customer Personal Data, and delete existing copies except to the extent retention is required by law. Provider will delete Personal Data within ninety (90) days following that period. Backups are overwritten on Provider's ordinary backup cycle and remain subject to this DPA until deleted.
10.1 Authorization. Customer provides general authorization for Provider to engage the Subprocessors listed in Annex III.
10.2 New Subprocessors. Provider will give Customer at least thirty (30) days' notice before engaging a new Subprocessor. Customer may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection, Customer may terminate the affected Service without penalty and receive a pro-rata refund of prepaid unused fees.
10.3 Flow-down. Provider will impose data protection obligations on each Subprocessor no less protective than those in this DPA and remains fully liable for each Subprocessor's performance.
11.1 Provider will make available information reasonably necessary to demonstrate compliance with this DPA.
11.2 No more than once per twelve (12) months, and on at least thirty (30) days' notice, Customer may request a remote audit limited to Provider's processing of Customer Personal Data, conducted during business hours, without unreasonably disrupting operations, subject to confidentiality, and at Customer's expense. Where Provider holds a current third-party audit report or certification, providing it satisfies this Section. Audits following a confirmed Security Incident are not subject to the annual frequency limit.
Provider processes Customer Personal Data in the United States. Provider will not transfer Customer Personal Data outside the United States without notice to Customer and an appropriate transfer mechanism.
Each party's liability under this DPA is subject to the limitations and exclusions in the Agreement.
Subject matter. Provision of the RepSensAI salesperson effectiveness and training platform.
Duration. The Term of the Agreement, plus the deletion window in §9.
Nature and purpose. Hosting; storage; computation of performance metrics and ratings; generation of AI-assisted coaching text, daily briefs, and training marks and grades; manager, director, and owner reporting; authentication and session management; support.
Categories of Data Subjects
Categories of Personal Data
| Category | Examples | Notes |
|---|---|---|
| Identity & account | Full name, email, platform username, login PIN, role, store/group membership | PIN visibility: Agreement §3.2 |
| Performance | Units, ups, leads, appointments, demos, write-ups, sales, closing rates, activity counts | The core of the Service |
| Compensation | Salesperson commission and earnings | Rep-private. Never exposed to manager/owner views. Agreement §5.5 |
| Personal financial | Salesperson personal budget entries | Rep-private. Never exposed to manager/owner views |
| Training | Practice transcripts and skill-exercise attempts (responses, per-criterion marks with quoted evidence), mastery bands and review schedules, manager validations and method, plus drill grades, subject ratings and overall rating | Transcripts and attempts are visible to the Rep only; bands, review status and validations are visible to management |
| Presence | Last-seen timestamps, sign-in activity | Employee monitoring — Agreement §4.2 |
| Voice-derived | Text transcripts of spoken drill responses; timing metrics | No audio recording is stored by Provider. See §14 below |
| Retail customer data | None. Feeds are per-salesperson aggregates (§2.3) | Raw source files are deleted at 30 days regardless |
| Technical | IP address, user agent, session token, log and error data |
Special categories. None are intentionally processed. Customer must not submit health, biometric, precise geolocation, government identifiers, or financial account numbers to the Service.
§14 — Voice processing (applies only where voice features are enabled). Speech is converted to text in the Authorized User's browser using the browser's built-in speech recognition. Provider receives and stores the resulting text transcript and derived timing metrics only. Provider does not receive, process, or store audio recordings, and does not create or store voiceprints or any other biometric identifier. Customer acknowledges that the browser's own speech-recognition implementation may transmit audio to the browser vendor (for example, Google for Chrome-based browsers) under that vendor's terms, and that this transmission occurs outside Provider's systems.
Described as implemented at the Effective Date. Provider may update these provided security is not materially degraded.
Access control
Authentication and session management
Encryption
Data minimisation and retention
Operations
Known limitations — stated honestly
Also published at https://repsens.ai/subprocessors.
| Subprocessor | Purpose | Data processed | Location |
|---|---|---|---|
| Anthropic, PBC | AI inference — coaching text, daily briefs, training marking and drill grading, mapping suggestions | Performance metrics, practice transcripts and skill-exercise responses, first names or identifiers as prompt context | United States |
| Supabase, Inc. | Managed PostgreSQL database and authentication | All stored Customer Data | United States |
| Render Services, Inc. | Application hosting and compute | Data in transit and in process | United States |
| Wildbit / ActiveCampaign (Postmark) | Inbound email intake of CRM/DMS reports; operational alerts | Report attachments and message metadata | United States |
Conditional — voice features only. Where an Authorized User enables voice input, their browser vendor (for example, Google LLC for Chrome-based browsers, Apple Inc. for Safari) may process spoken audio to perform speech recognition on the user's device or its own infrastructure. This processing occurs between the user and their browser vendor under that vendor's terms; Provider does not receive the audio. Provider identifies this here for transparency rather than as an engagement of a Subprocessor by Provider.
Model training. Provider has contracted for terms under which Customer Data submitted to its AI Subprocessor for inference is not used to train that Subprocessor's models.