← Back to piqued.cc

Data Processing Agreement

Effective: April 1, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Piqued AI, LLC ("Processor," "we," "us") and the entity agreeing to these terms ("Controller," "you," "your") for the use of our hosted services including piqued.cc, Piqued Forge, and Collabynt (the "Service").

This DPA applies when you use the Service to process Personal Data of individuals located in the European Economic Area ("EEA"), the United Kingdom ("UK"), or Switzerland, or where otherwise required by applicable data protection law.

1. Definitions

1.1"Personal Data" means any information relating to an identified or identifiable natural person that is processed by the Processor on behalf of the Controller through the Service.

1.2"Processing" means any operation performed on Personal Data, including collection, storage, retrieval, use, disclosure, erasure, or destruction.

1.3"Data Protection Laws" means all applicable laws relating to the processing of Personal Data, including the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection, and the California Consumer Privacy Act ("CCPA").

1.4"Subprocessor" means any third party engaged by the Processor to process Personal Data on behalf of the Controller.

1.5"Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to processors established in third countries, as approved by the European Commission.

2. Scope and Roles

2.1 Role Determination.The Controller determines the purposes and means of processing Personal Data. The Processor processes Personal Data only on behalf of and in accordance with the Controller's documented instructions.

2.2 Types of Personal Data Processed. The Service may process the following categories of Personal Data contained within Governance Data uploaded by the Controller: names of project participants, email addresses, session records containing participant identifiers, decision records attributing actions to individuals, and any other Personal Data the Controller includes in state files or governance artifacts.

2.3 Data Subjects.Data subjects may include the Controller's employees, contractors, collaborators, and any individuals referenced in governance records uploaded to the Service.

2.4 Duration.Processing continues for the duration of the Controller's use of the Service, plus the data retention periods described in the Privacy Policy.

3. Processor Obligations

3.1 Instructions.The Processor will process Personal Data only in accordance with the Controller's documented instructions, unless required to do otherwise by applicable law. If the Processor believes an instruction violates Data Protection Laws, it will promptly notify the Controller.

3.2 Confidentiality. The Processor ensures that all personnel authorized to process Personal Data are bound by obligations of confidentiality.

3.3 Security. The Processor will implement and maintain appropriate technical and organizational measures to protect Personal Data, including:

3.4 No AI Training. The Processor will not use Personal Data or Governance Data to train artificial intelligence models, machine learning systems, or any automated learning systems.

3.5 No Selling. The Processor will not sell Personal Data to any third party. The Processor will not use Personal Data for advertising or marketing purposes beyond service-related communications with the Controller.

4. Subprocessors

4.1 Authorized Subprocessors. The Controller authorizes the Processor to engage the subprocessors listed at https://piqued.cc/subprocessors as of the effective date of this DPA.

4.2 New Subprocessors. The Processor will provide the Controller with at least 30 days' notice before engaging a new subprocessor that will process Personal Data. Notice will be provided by updating the subprocessor list at https://piqued.cc/subprocessors and notifying the Controller by email.

4.3 Objection. If the Controller objects to a new subprocessor within the 30-day notice period, the parties will work in good faith to resolve the objection. If no resolution is reached, the Controller may terminate the affected Service with no penalty.

4.4 Subprocessor Agreements. The Processor will enter into written agreements with each subprocessor imposing data protection obligations no less protective than those in this DPA.

4.5 Liability. The Processor remains liable for the acts and omissions of its subprocessors to the same extent as if the Processor were performing the processing directly.

5. Data Subject Rights

5.1 Assistance. The Processor will assist the Controller in responding to requests from data subjects exercising their rights under Data Protection Laws (access, rectification, erasure, portability, restriction, objection). The Processor will promptly notify the Controller if it receives a request directly from a data subject.

5.2 Self-Service. Where possible, the Processor will enable the Controller to fulfill data subject requests through self-service features in the Service (export, deletion, correction).

6. Data Breach Notification

6.1 Notification. The Processor will notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data breach. Notification will include:

6.2 Cooperation. The Processor will cooperate with the Controller and take commercially reasonable steps to assist in the investigation, mitigation, and remediation of the breach.

6.3 No Public Disclosure.The Processor will not inform any third party of a Personal Data breach without the Controller's prior written consent, unless required by applicable law.

7. Data Transfers

7.1 Processing Location. Personal Data is processed in the United States. By entering into this DPA, the Controller authorizes the transfer of Personal Data to the United States.

7.2 Transfer Mechanisms. For transfers of Personal Data from the EEA, UK, or Switzerland to the United States, the parties agree to the Standard Contractual Clauses (Module Two: Controller to Processor) as adopted by the European Commission, which are incorporated by reference into this DPA. The details required by the SCCs are set forth in Annex 1.

7.3 Supplementary Measures. In addition to the SCCs, the Processor implements the technical measures described in Section 3.3 as supplementary measures to protect transferred Personal Data.

8. Data Retention and Deletion

8.1 During Service.The Processor retains Personal Data for the duration of the Controller's use of the Service.

8.2 Upon Termination.Upon termination of the Service, the Processor will make the Controller's data available for export for a minimum of 30 days. After the export period, the Processor will delete Personal Data from active systems within 90 days and from encrypted backups within 180 days.

8.3 Certification.Upon the Controller's written request, the Processor will certify in writing that it has deleted Personal Data in accordance with this section.

9. Audits

9.1 Information. The Processor will make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA.

9.2 Audit Right.The Controller may audit the Processor's compliance with this DPA once per calendar year, with 30 days' written notice. Audits will be conducted during normal business hours and will not unreasonably interfere with the Processor's operations.

9.3 Third-Party Audits. The Processor may satisfy audit requests by providing the Controller with relevant third-party audit reports or certifications (such as SOC 2).

10. Liability

Liability under this DPA is subject to the limitations set forth in the Terms of Service.

11. Term and Termination

11.1 Term.This DPA takes effect when the Controller first uses the Service to process Personal Data and remains in effect for the duration of the Controller's use of the Service.

11.2 Survival.The Processor's obligations regarding data deletion (Section 8), confidentiality (Section 3.2), and cooperation with audits for the preceding period (Section 9) survive termination.

12. General

12.1 Governing Law. This DPA is governed by the laws of the State of Delaware. Any legal action arising from this DPA shall be brought exclusively in the state and federal courts located in Kent County, Delaware.

12.2 Conflict. In the event of a conflict between this DPA and the Terms of Service, this DPA governs with respect to the processing of Personal Data.

12.3 Amendments. This DPA may be amended only by written agreement of both parties.


Annex 1 — Details of Processing

Required by Standard Contractual Clauses

Data Exporter (Controller)

Name: [Customer entity name]

Address: [Customer address]

Contact: [Customer contact]

Role: Controller

Data Importer (Processor)

Name: Piqued AI, LLC

Address: 1111B S Governors Ave, Ste 28392, Dover, Delaware 19904

Contact: legal@piqued-ai.com

Role: Processor

Description of Processing

ElementDetail
Subject matterProcessing of governance data uploaded to the Service
DurationDuration of the Controller's subscription to the Service
Nature and purposeStorage, display, querying, and export of project governance records
Types of Personal DataNames, email addresses, participant identifiers in session and decision records
Categories of data subjectsController's employees, contractors, and collaborators

Technical and Organizational Security Measures

See Section 3.3 of this DPA and the Processor's Privacy Policy at https://piqued.cc/privacy.