Effective: April 1, 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Piqued AI, LLC ("Processor," "we," "us") and the entity agreeing to these terms ("Controller," "you," "your") for the use of our hosted services including piqued.cc, Piqued Forge, and Collabynt (the "Service").
This DPA applies when you use the Service to process Personal Data of individuals located in the European Economic Area ("EEA"), the United Kingdom ("UK"), or Switzerland, or where otherwise required by applicable data protection law.
1.1"Personal Data" means any information relating to an identified or identifiable natural person that is processed by the Processor on behalf of the Controller through the Service.
1.2"Processing" means any operation performed on Personal Data, including collection, storage, retrieval, use, disclosure, erasure, or destruction.
1.3"Data Protection Laws" means all applicable laws relating to the processing of Personal Data, including the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection, and the California Consumer Privacy Act ("CCPA").
1.4"Subprocessor" means any third party engaged by the Processor to process Personal Data on behalf of the Controller.
1.5"Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to processors established in third countries, as approved by the European Commission.
2.1 Role Determination.The Controller determines the purposes and means of processing Personal Data. The Processor processes Personal Data only on behalf of and in accordance with the Controller's documented instructions.
2.2 Types of Personal Data Processed. The Service may process the following categories of Personal Data contained within Governance Data uploaded by the Controller: names of project participants, email addresses, session records containing participant identifiers, decision records attributing actions to individuals, and any other Personal Data the Controller includes in state files or governance artifacts.
2.3 Data Subjects.Data subjects may include the Controller's employees, contractors, collaborators, and any individuals referenced in governance records uploaded to the Service.
2.4 Duration.Processing continues for the duration of the Controller's use of the Service, plus the data retention periods described in the Privacy Policy.
3.1 Instructions.The Processor will process Personal Data only in accordance with the Controller's documented instructions, unless required to do otherwise by applicable law. If the Processor believes an instruction violates Data Protection Laws, it will promptly notify the Controller.
3.2 Confidentiality. The Processor ensures that all personnel authorized to process Personal Data are bound by obligations of confidentiality.
3.3 Security. The Processor will implement and maintain appropriate technical and organizational measures to protect Personal Data, including:
3.4 No AI Training. The Processor will not use Personal Data or Governance Data to train artificial intelligence models, machine learning systems, or any automated learning systems.
3.5 No Selling. The Processor will not sell Personal Data to any third party. The Processor will not use Personal Data for advertising or marketing purposes beyond service-related communications with the Controller.
4.1 Authorized Subprocessors. The Controller authorizes the Processor to engage the subprocessors listed at https://piqued.cc/subprocessors as of the effective date of this DPA.
4.2 New Subprocessors. The Processor will provide the Controller with at least 30 days' notice before engaging a new subprocessor that will process Personal Data. Notice will be provided by updating the subprocessor list at https://piqued.cc/subprocessors and notifying the Controller by email.
4.3 Objection. If the Controller objects to a new subprocessor within the 30-day notice period, the parties will work in good faith to resolve the objection. If no resolution is reached, the Controller may terminate the affected Service with no penalty.
4.4 Subprocessor Agreements. The Processor will enter into written agreements with each subprocessor imposing data protection obligations no less protective than those in this DPA.
4.5 Liability. The Processor remains liable for the acts and omissions of its subprocessors to the same extent as if the Processor were performing the processing directly.
5.1 Assistance. The Processor will assist the Controller in responding to requests from data subjects exercising their rights under Data Protection Laws (access, rectification, erasure, portability, restriction, objection). The Processor will promptly notify the Controller if it receives a request directly from a data subject.
5.2 Self-Service. Where possible, the Processor will enable the Controller to fulfill data subject requests through self-service features in the Service (export, deletion, correction).
6.1 Notification. The Processor will notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data breach. Notification will include:
6.2 Cooperation. The Processor will cooperate with the Controller and take commercially reasonable steps to assist in the investigation, mitigation, and remediation of the breach.
6.3 No Public Disclosure.The Processor will not inform any third party of a Personal Data breach without the Controller's prior written consent, unless required by applicable law.
7.1 Processing Location. Personal Data is processed in the United States. By entering into this DPA, the Controller authorizes the transfer of Personal Data to the United States.
7.2 Transfer Mechanisms. For transfers of Personal Data from the EEA, UK, or Switzerland to the United States, the parties agree to the Standard Contractual Clauses (Module Two: Controller to Processor) as adopted by the European Commission, which are incorporated by reference into this DPA. The details required by the SCCs are set forth in Annex 1.
7.3 Supplementary Measures. In addition to the SCCs, the Processor implements the technical measures described in Section 3.3 as supplementary measures to protect transferred Personal Data.
8.1 During Service.The Processor retains Personal Data for the duration of the Controller's use of the Service.
8.2 Upon Termination.Upon termination of the Service, the Processor will make the Controller's data available for export for a minimum of 30 days. After the export period, the Processor will delete Personal Data from active systems within 90 days and from encrypted backups within 180 days.
8.3 Certification.Upon the Controller's written request, the Processor will certify in writing that it has deleted Personal Data in accordance with this section.
9.1 Information. The Processor will make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA.
9.2 Audit Right.The Controller may audit the Processor's compliance with this DPA once per calendar year, with 30 days' written notice. Audits will be conducted during normal business hours and will not unreasonably interfere with the Processor's operations.
9.3 Third-Party Audits. The Processor may satisfy audit requests by providing the Controller with relevant third-party audit reports or certifications (such as SOC 2).
Liability under this DPA is subject to the limitations set forth in the Terms of Service.
11.1 Term.This DPA takes effect when the Controller first uses the Service to process Personal Data and remains in effect for the duration of the Controller's use of the Service.
11.2 Survival.The Processor's obligations regarding data deletion (Section 8), confidentiality (Section 3.2), and cooperation with audits for the preceding period (Section 9) survive termination.
12.1 Governing Law. This DPA is governed by the laws of the State of Delaware. Any legal action arising from this DPA shall be brought exclusively in the state and federal courts located in Kent County, Delaware.
12.2 Conflict. In the event of a conflict between this DPA and the Terms of Service, this DPA governs with respect to the processing of Personal Data.
12.3 Amendments. This DPA may be amended only by written agreement of both parties.
Required by Standard Contractual Clauses
Name: [Customer entity name]
Address: [Customer address]
Contact: [Customer contact]
Role: Controller
Name: Piqued AI, LLC
Address: 1111B S Governors Ave, Ste 28392, Dover, Delaware 19904
Contact: legal@piqued-ai.com
Role: Processor
| Element | Detail |
|---|---|
| Subject matter | Processing of governance data uploaded to the Service |
| Duration | Duration of the Controller's subscription to the Service |
| Nature and purpose | Storage, display, querying, and export of project governance records |
| Types of Personal Data | Names, email addresses, participant identifiers in session and decision records |
| Categories of data subjects | Controller's employees, contractors, and collaborators |
See Section 3.3 of this DPA and the Processor's Privacy Policy at https://piqued.cc/privacy.