Data Processing Agreement
Last updated: 2026 · Draft for review
1. Roles
This Data Processing Agreement (“DPA”) applies when your organization (the “Customer”, acting as controller) uses Superadditive (the “Processor”) to run exercises for your people. It forms part of your agreement to use the service and governs our processing of personal data on your behalf. Terms like “controller”, “processor”, and “personal data” have the meaning given in the GDPR.
2. Subject matter, nature & purpose, duration
We process personal data only to provide the service: running AI exercises, storing the resulting reports, and giving your directors and instructors the tools to manage their cohorts. Processing lasts for the term of your use of the service.
3. Types of data & data subjects
- Data subjects: your participants: members, instructors, and directors you invite.
- Personal data: names and emails; the content people enter or speak during exercises and the reports produced; role and cohort membership; and usage records. Please don't use the service to process special categories of data unless you've confirmed a lawful basis and told your people.
4. Our obligations as processor
- Process personal data only on your documented instructions (this DPA and your use of the service), unless required by law.
- Ensure people authorized to process the data are bound by confidentiality.
- Implement appropriate technical and organizational security measures (Annex A).
- Assist you, taking into account the nature of processing, in responding to data-subject requests and in meeting your obligations around security, breach notification, and data protection impact assessments.
- Notify you without undue delay after becoming aware of a personal-data breach.
- On termination, delete or return personal data at your choice, except where retention is required by law. Your people can also export and delete their own data from the app at any time.
- Make available information reasonably necessary to demonstrate compliance, and allow for audits, on reasonable notice and terms.
5. Sub-processors
You give general authorization for us to use the sub-processors listed on our sub-processors page to provide the service. We impose data-protection terms on each of them equivalent to those in this DPA, and we'll update that page before adding a new sub-processor that processes personal data, so you can object.
6. International transfers
Where personal data is transferred outside the EEA / UK to a country without an adequacy decision, the transfer is covered by the Standard Contractual Clauses (or the UK equivalent) incorporated into our agreements with each sub-processor and, where applicable, between you and us.
7. Liability & precedence
This DPA forms part of, and is subject to, the terms of the main agreement. If there's a conflict on the processing of personal data, this DPA controls.
Annex A: Security measures (summary)
- Encryption of data in transit; data at rest protected by the hosting provider.
- Row-level access controls so each user and organization sees only their own data.
- Least-privilege access to production systems and secrets.
- Reputable sub-processors for hosting, database, AI, and payments (see the sub-processors page).
- Self-service data export and deletion for individuals.