Data Processing Agreement

Last updated September 10, 2026

1.Introduction

This Data Processing Addendum ("DPA") supplements the Terms of Service (the "Agreement") entered into by and between Customer (as defined in the Agreement) and Discursive OÜ, a limited company registered in Estonia, located at Sepapaja tn 6, 15551 Tallinn, Estonia ("Company", "Discursive", "we", or "us"), operating the Humaner product. By executing the Agreement, Customer enters into this DPA on behalf of itself and, to the extent required under applicable Data Protection Laws, in the name and on behalf of its Affiliates, if any.

This DPA incorporates the terms of the Agreement. Terms not defined in this DPA have the meaning set forth in the Agreement. Humaner is the product; Discursive OÜ is the company that processes personal data in connection with Humaner.

This DPA applies when Company processes personal data on Customer's behalf in connection with Humaner: the hosted mailbox, Companion, calendar, tasks, workspace Resources (knowledge retrieval), memory, analytics, APIs, and related workspace features.

2.Definitions

For purposes of this DPA:

  • Affiliate — an entity that owns or is owned by a party at fifty percent (50%) or more equity, or is under common ownership of at least fifty percent (50%), for so long as such ownership exists.
  • Authorized Sub-Processor — a third party that needs to know or access Customer Personal Data to enable Company to perform this DPA or the Agreement, listed in this DPA or subsequently authorized under the sub-processor section.
  • Company Account Data — personal data relating to Company's relationship with Customer, including names and contact information of individuals authorized to access Customer's account and billing information associated with the account, and data needed for identity verification or legal compliance.
  • Company Usage Data — Service usage data collected in connection with providing the Services, including activity logs and data used to optimize performance and prevent abuse.
  • Customer Personal Data — personal data contained in mailbox messages and threads, calendar events, workspace Resources and other knowledge content, Companion and agent conversations, session metadata, task and handoff records, and other personal data Customer or its end-users submit for processing on Customer's behalf.
  • Data Protection Laws — applicable laws relating to Personal Data, including the CCPA (where applicable), EU GDPR, UK GDPR, Swiss FADP, UK Data Protection Act 2018, and related e-privacy rules, each as amended. "Data Subject", "Personal Data", "Personal Data Breach", "processing", "processor", "controller", and "supervisory authority" have the meanings in the GDPR.
  • EU SCCs — the standard contractual clauses approved by Commission Decision 2021/914.
  • Services — as defined in the Agreement (Humaner).
  • Standard Contractual Clauses — the EU SCCs and UK SCCs (EU SCCs as amended by the UK Addendum).

3.Relationship of the parties; processing of data

With regard to Customer Personal Data, Customer may act as controller or processor and, except as expressly set forth in this DPA or the Agreement, Company is a processor. Customer shall process Personal Data and provide instructions in compliance with Data Protection Laws, and shall ensure that processing according to Customer's instructions will not cause Company to breach Data Protection Laws. Customer is solely responsible for the accuracy, quality, and legality of Personal Data provided to Company, the means of acquisition, and the instructions it provides. Customer shall not provide Personal Data inappropriate for the Services.

Company shall not process Customer Personal Data (i) for purposes other than those in the Agreement and this DPA, (ii) inconsistently with documented instructions (including regarding transfers), unless required by law (in which case Company will inform Customer unless prohibited), or (iii) in violation of Data Protection Laws. Customer hereby instructs Company to process Customer Personal Data as described here and as initiated by Customer's use of the Services.

Company never uses Customer Personal Data to train third-party foundation models. Company is responsible for Humaner and for the infrastructure and Authorized Sub-Processors Company engages to deliver the Service (including LLMs and related inference). Those Sub-Processors process data for inference and delivery of Humaner — not to train their foundation models on Customer Personal Data. Workspace Resources train Customer's own Companion under this DPA as part of delivering the Service. Optional product-improvement processing (when Customer opts in) is limited to improving Humaner patterns and, separately, Humaner model fine-tuning, as described in the Privacy Policy — not third-party model training.

The subject matter, nature, purpose, and duration of processing, types of Personal Data, and categories of Data Subjects are described under "Details of processing" below.

Following completion of the Services, at Customer's choice, Company shall return or delete Customer Personal Data, unless further storage is required or authorized by law. If return or destruction is impracticable or prohibited, Company will block further processing except as required by law and continue to protect remaining data.

Where CCPA or similar US state laws apply to Customer Personal Data processed as a service provider, Company will not sell that personal information and will retain, use, or disclose it only to provide the Services or as otherwise permitted by those laws.

4.Company's role as a controller

With respect to Company Account Data and Company Usage Data, Company is an independent controller, not a joint controller with Customer. Company processes such data to manage the customer relationship; for accounting, audits, tax, and compliance; to monitor, investigate, and prevent fraud, security incidents, and misuse; for identity verification; to comply with legal obligations; and as otherwise permitted by Data Protection Laws and the Privacy Policy. Company may also process Company Usage Data to provide, optimize, and maintain the Services to the extent permitted by law.

5.Details of processing

Nature and purpose: Company processes Customer's Personal Data as necessary to provide Humaner — including the mailbox, Companion with LLM inference, calendar, tasks, retrieval from workspace Resources, memory, and (only with Customer's opt-in) improving Humaner patterns or Humaner model fine-tuning. Workspace Resources training for Companion is part of the Service under this DPA. Company does not use Customer Personal Data to train third-party foundation models.

Duration: for as long as required to provide the Services, for Company's legitimate business needs consistent with the Privacy Policy, or as required by law. Company Account Data and Company Usage Data are stored as set forth in the Privacy Policy.

Categories of Data Subjects: Customer's employees, consultants, contractors, and agents; people who send or receive mail through Customer's Humaner mailbox; attendees of calendar events; and other individuals whose personal data appears in knowledge sources Customer uploads.

Categories of Personal Data: may include name, email, identifiers, IP address, device/browser information, message content, support history, and other personal data Customer chooses to include. Customer determines categories by how it configures and uses Humaner.

Sensitive / special categories: Customer must not instruct Company to process special-category data unless Customer has a lawful basis and appropriate safeguards. Customer remains responsible for preventing prohibited or high-risk processing.

6.Confidentiality

Company shall ensure that any person it authorizes to process Personal Data has agreed to protect Personal Data consistently with Company's confidentiality obligations in the Agreement. Customer agrees Company may disclose Personal Data to advisers, auditors, or other third parties as reasonably required to perform this DPA, the Agreement, or the Services.

7.Authorized Sub-Processors

Company operates Humaner and remains responsible to Customer for processing under this DPA, including processing performed by Authorized Sub-Processors Company engages to deliver the Service. Customer acknowledges that Company may engage Affiliates and Authorized Sub-Processors to access and process Personal Data as necessary to perform the Services, and provides general written authorization for that engagement.

Optional external products or accounts that Customer chooses to connect to Humaner (for example tools Customer authorizes in the dashboard) are not Company Sub-Processors solely by virtue of that connection. Customer remains responsible for its relationship with those providers and their terms; that does not shift responsibility for Company’s own infrastructure or Authorized Sub-Processors onto Customer.

Current Authorized Sub-Processor categories and examples include:

  • LLM and inference providers (for example Anthropic) — run Humaner agent responses; not for training their foundation models on Customer Content.
  • Redis — vector search, semantic cache, agent memory, and context retrieval.
  • Neon — PostgreSQL database and object storage.
  • Polar — subscription billing.
  • Resend — transactional email.
  • OpenAI — embeddings for knowledge search (not foundation-model training on Customer Content).
  • Hosting and CDN providers — application hosting and delivery.

8.Sub-processor changes

Company will provide a mechanism to receive notice of new Authorized Sub-Processors (for example email or dashboard notice). At least ten (10) days before enabling a new third party to process Personal Data, Company will notify subscribers. Customer may object in writing within ten (10) days on reasonable data-protection grounds. Certain sub-processors are essential; objecting may prevent Company from offering the affected Service.

If Customer reasonably objects and Company cannot provide a commercially reasonable alternative within a reasonable time, Customer may discontinue the affected Service by written notice. Discontinuation does not relieve fees owed under the Agreement. If Customer does not object within ten (10) days, the third party is deemed an Authorized Sub-Processor.

Company will enter into a written agreement with each Authorized Sub-Processor imposing data-protection obligations comparable to those in this DPA. Company remains liable to Customer for the Sub-Processor's performance of those obligations.

9.Security of Personal Data

Taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing, as well as risk to natural persons, Company maintains appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of personal data in transit (TLS) and, where applicable, at rest.
  • Access controls, including least privilege, authentication best practices, and role-based permissions.
  • Confidentiality obligations for personnel and downstream sub-processors.
  • Backups and measures to restore availability after incidents.
  • Logging and monitoring of access to systems that process Customer Data.
  • Change management and secure configuration for production systems.
  • Data minimization and self-service deletion/suppression where available in the Service.
  • Accountability measures including security policies, breach reporting processes, and assigned security responsibilities.

10.Transfers of Personal Data

Company may transfer Personal Data processed under this DPA outside the EEA, UK, or Switzerland as necessary to provide the Services. Company is established in Estonia. Subprocessors may process data in the United States and other countries. Where a transfer is not covered by an adequacy decision, Company will ensure appropriate safeguards under Data Protection Laws.

Ex-EEA Transfers are made pursuant to the EU SCCs, deemed entered into and incorporated by reference: Module One when Company processes as controller under this DPA; Module Two when Customer is controller and Company is processor; Module Three when Customer is processor and Company is sub-processor. Optional docking in Clause 7 does not apply; Clause 9 Option 2 (general authorization) applies with the notice period in the sub-processor section; Clause 11 optional language does not apply; Clause 17 Option 1 — governing law Ireland; Clause 18(b) — courts of Ireland. By entering this DPA, the parties are deemed to have signed the EU SCCs.

Ex-UK Transfers are made pursuant to the UK Addendum to the EU SCCs. Transfers from Switzerland use the EU SCCs with modifications recognizing Swiss FADP and the FDPIC where applicable.

Supplementary measures: Company will not voluntarily disclose Personal Data to government agencies. If compelled, Company will give Customer reasonable notice where legally permitted and cooperate so Customer may seek a protective order. Parties will discuss whether transfers should be suspended or additional measures applied if government access risks change.

Further details of transfer safeguards are available on request at privacy@humaner.io.

11.Rights of Data Subjects

Company shall, to the extent permitted by law, notify Customer upon receipt of a Data Subject request to exercise access, rectification, erasure, portability, restriction, withdrawal of consent, or objection to automated decision-making relating to Customer Personal Data. Company will advise the Data Subject to submit the request to Customer, and Customer is responsible for responding, including using Service functionality where available.

Company shall, at Customer's request and taking into account the nature of processing, apply appropriate measures to assist Customer in responding to Data Subject Requests where Customer cannot respond without assistance and Company can do so lawfully. Customer is responsible for reasonable costs of such assistance to the extent legally permitted.

12.Assistance, DPIAs, and audits

Taking into account the nature of processing and information available to Company, Company will provide reasonable cooperation for Customer's DPIAs and prior consultation with supervisory authorities where required by GDPR and Customer lacks the information. Customer bears reasonable costs to the extent legally permitted.

Company will maintain records sufficient to demonstrate compliance with this DPA for three (3) years after Agreement termination. Upon reasonable notice, Customer may review such records during business hours subject to confidentiality.

Upon written request at reasonable intervals and subject to confidentiality, Company shall either (i) make available certifications or reports demonstrating compliance with prevailing security standards, or (ii) if insufficient under Data Protection Laws, allow an independent third-party audit of relevant security infrastructure no more than once per calendar year, during business hours, without unreasonable disruption, limited to data relevant to Customer. Customer bears audit costs, including reasonable reimbursement for on-site time.

Company shall notify Customer if an instruction, in Company's opinion, infringes Data Protection Laws.

13.Personal Data Breach

In the event of a Personal Data Breach affecting Customer Personal Data, Company shall without undue delay inform Customer and take steps Company reasonably deems necessary to remediate (to the extent within Company's control).

Taking into account the nature of processing and information available, Company shall provide reasonable assistance for Customer to notify supervisory authorities and affected Data Subjects as required by GDPR.

These obligations do not apply to breaches resulting from Customer's actions or omissions. Notification is not an admission of fault or liability.

For security incidents, email security@humaner.io in addition to privacy contacts.

14.Return and deletion

Upon termination of the Service, or upon Customer's written request, Company will delete Customer Personal Data or return it, and delete existing copies, unless retention is required by law or necessary for security, dispute resolution, or limited backup cycles.

Default conversation retention is 90 days unless Customer configures otherwise. Knowledge sources remain until Customer deletes them or the account is closed.

15.Customer obligations

Customer represents that it has a lawful basis to process Customer Personal Data and to instruct Company. Customer will not instruct Company to process data in violation of Data Protection Laws.

Customer is responsible for notices to end-users, consents where required, configuring retention and access, and ensuring knowledge uploads do not include data Customer is not permitted to process.

16.Liability and order of precedence

Each party's liability under this DPA is subject to the limitations and exclusions in the Agreement, except to the extent Data Protection Laws prohibit such limitation.

In the event of conflict regarding Personal Data processing, the order of precedence is: (1) applicable Standard Contractual Clauses; (2) this DPA; (3) the Agreement; (4) the Privacy Policy (for Company's independent controller activities). Claims under this DPA are subject to the Agreement's terms, including exclusions and limitations.

17.Contact

For DPA or processor questions, email privacy@humaner.io or alexandre@humaner.io.

Write to Discursive OÜ, Sepapaja tn 6, 15551 Tallinn, Estonia (Attn: Alexandre Neyret). For security incidents, email security@humaner.io.