Data Processing Agreement
Last Updated: August 24, 2026
This Data Processing Agreement (“DPA”) forms part of the Enterprise Master Subscription Agreement and the Self-Serve Subscription Agreement, as applicable, unless Customer has entered into a superseding written agreement with Day AI, Inc., in which case, it forms part of such written agreement (in either case, the “Agreement”) to reflect the parties’ agreement with regard to the Processing of Personal Data.
Company enters into this DPA on behalf of itself and, to the extent required under Applicable Data Protection Laws (defined below), in the name and on behalf of its Affiliates. For the purposes of this DPA only, and except where indicated otherwise, the term “Company”, shall include Company and its Affiliates. All capitalized terms not defined herein shall have the meaning set forth in the Agreement.
In the course of providing the Services under the Agreement, Day AI may Process certain Customer Data (such terms defined below) on behalf of Customer and where Day AI Processes such Customer Data on behalf of Customer the Parties agree to comply with the terms and conditions in this DPA in connection with the processing of such Customer Data, each acting reasonably and in good faith.
This Data Processing Agreement (“Agreement”) forms part of the Contract for Services (“Principal Agreement”) between
(the “Company”)
and
Day AI, Inc.
115 Kingston St.
Boston, MA 02111
(the “Data Processor”)
(together as the “Parties”)
WHEREAS
(A) The Company acts as a Data Controller.
(B) The Company wishes to subcontract certain Services, which imply the processing of personal data, to the Data Processor.
(C) The Parties seek to implement a data processing agreement that complies with the requirements of the current legal framework in relation to data processing and with the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
(D) The Parties wish to lay down their rights and obligations.
IT IS AGREED AS FOLLOWS:
1. Definitions and Interpretation
1.1 Unless otherwise defined herein, capitalized terms and expressions used in this Agreement shall have the following meaning:
1.1.1 “Agreement” means this Data Processing Agreement and all Schedules;
1.1.2 “Company Personal Data” means any Personal Data Processed by a Contracted Processor on behalf of Company pursuant to or in connection with the Principal Agreement;
1.1.3 “Contracted Processor” means Processor or a Subprocessor;
1.1.4 “Data Protection Laws” means EU Data Protection Laws, the UK GDPR and the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection, and, to the extent applicable, the data protection or privacy laws of any other country or of any U.S. state;
1.1.5 “EEA” means the European Economic Area;
1.1.6 “EU Data Protection Laws” means EU Directive 95/46/EC, as transposed into domestic legislation of each Member State and as amended, replaced or superseded from time to time, including by the GDPR and laws implementing or supplementing the GDPR;
1.1.7 “GDPR” means EU General Data Protection Regulation 2016/679;
1.1.8 “Data Transfer” means:
1.1.8.1 a transfer of Company Personal Data from the Company to a Contracted Processor; or
1.1.8.2 an onward transfer of Company Personal Data from a Contracted Processor to a Subcontracted Processor, or between two establishments of a Contracted Processor,
in each case, where such transfer would be prohibited by Data Protection Laws (or by the terms of data transfer agreements put in place to address the data transfer restrictions of Data Protection Laws);
1.1.9 “Services” means the AI-powered customer relationship management, meeting assistance, transcription services, sales automation, and related artificial intelligence services provided by the Data Processor as specified in the Principal Agreement.
1.1.10 “Subprocessor” means any person appointed by or on behalf of Processor to process Personal Data on behalf of the Company in connection with the Agreement.
1.1.11 “Subprocessor List” means the current list of Subprocessors engaged by Processor, published at day.ai/trust/subprocessors and maintained in accordance with section 5;
1.1.12 “Customer Content” means all data and content submitted to, or generated through, the Services by or on behalf of Company, including Company Personal Data.
1.1.13 “Applicable Laws” means all laws, regulations and binding regulatory guidance applicable to a Party, including Data Protection Laws.
1.2 The terms, “Commission”, “Controller”, “Data Subject”, “Member State”, “Personal Data”, “Personal Data Breach”, “Processing” and “Supervisory Authority” shall have the same meaning as in the GDPR, and their cognate terms shall be construed accordingly.
2. Processing of Company Personal Data
2.1 Processor shall:
2.1.1 comply with all applicable Data Protection Laws in the Processing of Company Personal Data; and
2.1.2 not Process Company Personal Data other than on the relevant Company’s documented instructions.
2.2 The Company instructs Processor to process Company Personal Data solely for the purpose of providing the Services in accordance with the Principal Agreement and the Company’s documented instructions, and for no other purpose, save that Company additionally instructs Processor to create and use aggregated and de-identified data derived from Company Personal Data for the purposes described in section 2.3.
2.3 No Training of Artificial Intelligence or Machine Learning Models. Processor does not, and shall not, and shall not permit any Contracted Processor or Subprocessor to, use Company Personal Data or any other Customer Content to train, fine-tune, calibrate, develop or otherwise improve any artificial intelligence or machine learning model. This prohibition applies to Company Personal Data and Customer Content in every form, including identifiable, pseudonymized, de-identified, anonymized, aggregated and derived forms, and to any output, insight or other data derived from them. This prohibition applies equally to data that Processor receives through its integrations with third-party services, including all data received from Google APIs. For the avoidance of doubt, Processor’s permitted use of aggregated and de-identified data for service operation, security, support, analytics and benchmarking purposes does not include, and shall never include, the training, fine-tuning, calibration, development or improvement of any artificial intelligence or machine learning model. For the further avoidance of doubt, submitting Company Personal Data or Customer Content to an already-trained model as an input, in order to generate an output requested by Company through the Services, is not training, fine-tuning, calibration, development or improvement of that model, and neither is Processor’s operation, monitoring, securing, troubleshooting or performance tuning of the Services.
2.4 Processor shall not sell, rent or license Company Personal Data, shall not disclose Company Personal Data for cross-context behavioral or targeted advertising, and shall not use Company Personal Data for its own marketing purposes. This section 2.4 does not restrict a disclosure or use that Company has expressly authorized in writing, including through an opt-in feature of the Services.
2.5 Processor shall promptly inform Company if, in Processor’s opinion, an instruction from Company infringes Data Protection Laws.
3. Processor Personnel
Processor shall take reasonable steps to ensure the reliability of any employee, agent or contractor of any Contracted Processor who may have access to the Company Personal Data, ensuring in each case that access is strictly limited to those individuals who need to know / access the relevant Company Personal Data, as strictly necessary for the purposes of the Principal Agreement, and to comply with Applicable Laws in the context of that individual’s duties to the Contracted Processor, ensuring that all such individuals are subject to confidentiality undertakings or professional or statutory obligations of confidentiality.
4. Security
4.1 Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Processor shall in relation to the Company Personal Data implement appropriate technical and organizational measures to ensure a level of security appropriate to that risk, including, as appropriate, the measures referred to in Article 32(1) of the GDPR.
4.2 In assessing the appropriate level of security, Processor shall take account in particular of the risks that are presented by Processing, in particular from a Personal Data Breach.
4.3 Without limiting section 4.1, Processor shall maintain and enforce an information security program that includes, at a minimum: (a) encryption of Company Personal Data at rest and in transit using industry-standard algorithms; (b) role-based access controls provisioned on a least-privilege basis and reviewed no less than annually; (c) multi-factor authentication for administrative and remote access; (d) continuous monitoring and logging of access to systems containing Company Personal Data; (e) vulnerability management, patching and periodic penetration testing; (f) a documented incident response plan that is tested no less than annually; (g) background screening, confidentiality obligations and periodic security training for personnel with access to Company Personal Data; (h) secure software development practices, including code review and separation of development, test and production environments; and (i) a documented security risk assessment of each Subprocessor before that Subprocessor Processes Company Personal Data, and periodically thereafter, except where section 5.4 applies, in which case the assessment shall be completed as soon as reasonably practicable.
4.4 Processor maintains a SOC 2 Type II examination covering the Services, and shall make its then-current report available to Company on request, subject to confidentiality obligations. Processor shall not materially decrease the overall security of the Services during the term of the Principal Agreement.
5. Subprocessing
5.1 General Authorization. Company grants Processor a general written authorization, for the purposes of Article 28(2) of the GDPR, to engage Subprocessors to Process Company Personal Data, subject to this section 5. By entering into the Principal Agreement and using the Services, Company authorizes the disclosure of Company Personal Data to the Subprocessors identified on the Subprocessor List as of the date of that authorization.
5.2 Published Subprocessor List; Notification of Changes. Processor publishes and maintains the Subprocessor List at day.ai/trust/subprocessors. The Subprocessor List identifies, for each Subprocessor, its legal name, its corporate location, the Processing activities it performs, and the country or countries in which it Processes Company Personal Data. Company may subscribe to receive notice of additions to and replacements on the Subprocessor List at day.ai/trust/subprocessors, and Processor shall maintain that subscription mechanism throughout the term of the Principal Agreement.
5.3 New Subprocessors; Right to Object. Processor shall give Company at least thirty (30) days’ prior notice before authorizing any new Subprocessor to Process Company Personal Data. Notice shall be given through the subscription mechanism described in section 5.2 and, where Company has not subscribed, by email to Company’s administrative contact of record. Processor shall not permit the new Subprocessor to Process Company Personal Data before that notice period has expired. Company may object to the new Subprocessor within that thirty (30) day period by written notice to privacy@day.ai on reasonable grounds relating to data protection. If Company objects, the Parties shall work together in good faith for thirty (30) days to identify a commercially reasonable alternative that addresses Company’s objection. If no such alternative is available and Processor nonetheless proceeds with the engagement, Company may terminate the affected Services on written notice without penalty and shall receive a pro-rata refund of any prepaid, unused fees for the terminated Services.
5.4 Emergency Replacement. Where Processor must engage or replace a Subprocessor on an emergency basis in order to preserve the security, availability or lawfulness of the Services, Processor may do so before the notice period in section 5.3 has expired, provided that Processor gives Company notice as soon as reasonably practicable and Company’s objection and termination rights under section 5.3 apply from the date of that notice.
5.5 Subprocessor Obligations; Liability. Processor shall enter into a written agreement with each Subprocessor that imposes data protection obligations no less protective than those set out in this Agreement, including the obligations required by Article 28(3) of the GDPR and the prohibition on model training in section 2.3. Processor remains fully liable to Company for the acts and omissions of each Subprocessor to the same extent as for its own acts and omissions.
5.6 Standard Contractual Clauses; disclosure of Subprocessor agreements. Company agrees that, by complying with this section 5, Processor fulfils its obligations under Clause 9(a) and Clause 9(b) of the EU SCCs. Company further acknowledges that, for the purposes of Clause 9(c) of the EU SCCs, Processor may be restricted from disclosing its agreements with Subprocessors to Company (or to a relevant third-party controller) by confidentiality obligations owed to those Subprocessors. Notwithstanding that restriction, Processor shall use reasonable efforts to require its Subprocessors to permit disclosure of those agreements to Company and shall in any event provide to Company, on request and on a confidential basis, all information it reasonably can in connection with those agreements.
6. Data Subject Rights
6.1 Taking into account the nature of the Processing, Processor shall assist the Company by implementing appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Company obligations, as reasonably understood by Company, to respond to requests to exercise Data Subject rights under the Data Protection Laws.
6.2 Processor shall:
6.2.1 promptly notify Company if it receives a request from a Data Subject under any Data Protection Law in respect of Company Personal Data; and
6.2.2 ensure that it does not respond to that request except on the documented instructions of Company or as required by Applicable Laws to which the Processor is subject, in which case Processor shall to the extent permitted by Applicable Laws inform Company of that legal requirement before the Contracted Processor responds to the request.
6.3 Processor shall provide the assistance described in this section 6 at no additional charge, except where a Data Subject request requires materially more than routine effort, in which case the Parties shall agree reasonable fees in advance.
7. Personal Data Breach
7.1 Processor shall notify Company of any Personal Data Breach affecting Company Personal Data without undue delay, and in any event no later than seventy-two (72) hours after Processor becomes aware of the Personal Data Breach. Notice shall be given to Company’s administrative and security contacts of record by email, and by such other means as are reasonably practicable in the circumstances.
7.2 Each notice given under section 7.1 shall include, to the extent then known to Processor: (a) a description of the nature of the Personal Data Breach, including where possible the categories and approximate number of Data Subjects and of records concerned; (b) the name and contact details of Processor’s point of contact for the incident; (c) a description of the likely consequences of the Personal Data Breach; and (d) a description of the measures taken or proposed to be taken to address the Personal Data Breach and to mitigate its possible adverse effects. Where and to the extent that it is not possible for Processor to provide all of that information within the seventy-two (72) hour period, Processor shall provide the information then available to it within that period and shall provide the remaining information in phases, as it becomes available, without further undue delay.
7.3 Processor shall not delay notice under section 7.1 on the ground that its investigation is incomplete. Processor shall provide Company with sufficient information, on a continuing basis, to allow Company to meet any obligation to report the Personal Data Breach to a Supervisory Authority or to inform Data Subjects under Data Protection Laws. Processor’s notification of, or response to, a Personal Data Breach is not an acknowledgement by Processor of fault or liability. Unsuccessful attempts and activities that do not compromise the security of Company Personal Data, including pings, port scans, denial-of-service attempts and failed log-in attempts, do not constitute a Personal Data Breach.
7.4 Processor shall co-operate with the Company and take reasonable commercial steps as are directed by Company to assist in the investigation, mitigation and remediation of each such Personal Data Breach.
8. Data Protection Impact Assessment and Prior Consultation
Processor shall provide reasonable assistance to the Company with any data protection impact assessments, and prior consultations with Supervising Authorities or other competent data privacy authorities, which Company reasonably considers to be required by article 35 or 36 of the GDPR or equivalent provisions of any other Data Protection Law, in each case solely in relation to Processing of Company Personal Data by, and taking into account the nature of the Processing and information available to, the Contracted Processors.
9. Deletion or return of Company Personal Data
9.1 Deletion during the Term. Processor shall enable Company to delete Company Personal Data during the term of the Principal Agreement in a manner consistent with the functionality of the Services. Where Company uses the Services to delete Company Personal Data in a manner that would prevent Company from recovering it, that action constitutes Company’s instruction to Processor to delete that Company Personal Data from Processor’s systems, and Processor shall comply with that instruction within the periods published in the Privacy Policy and, in any event, without undue delay.
9.2 Deletion on expiry or termination. Following the date of cessation of any Services involving the Processing of Company Personal Data (the “Cessation Date”), Processor shall delete, and procure the deletion of, all copies of Company Personal Data, subject to sections 9.4 and 9.5. Company is responsible for exporting, before the end of any post-termination export period provided for in the Principal Agreement, any Company Personal Data it wishes to retain.
9.3 Applicable retention and deletion periods. The periods within which Company Personal Data is deleted from active production systems and from backups, including the periods applicable to particular categories of Company Personal Data, are those published in the Storage period section of Processor’s Privacy Policy, as updated from time to time. Those published periods are incorporated into this Agreement by this reference for the purposes of this section 9, notwithstanding any order of precedence in the Principal Agreement. Processor maintains different periods for different categories of Company Personal Data, and may adjust them as the Services change.
9.4 Floor; no material degradation. Notwithstanding section 9.3: (a) Processor shall not materially extend a published deletion period in a manner adverse to Company during the term of the Principal Agreement without giving Company at least thirty (30) days’ prior notice; (b) Processor shall not retain Company Personal Data for longer than is necessary for the purposes for which it is Processed; and (c) Company Personal Data awaiting deletion, including Company Personal Data residing in routine backups, shall continue to be protected in accordance with this Agreement and shall not be Processed for any purpose other than secure storage and restoration.
9.5 Retention required by law. Processor may retain Company Personal Data to the extent, and for so long as, required by applicable law. Where Processor does so, it shall (a) notify Company of that requirement where legally permitted to do so, (b) retain only the minimum Company Personal Data necessary and for the minimum period required, (c) isolate and protect that Company Personal Data from any further Processing except for the purpose that requires its retention, and (d) delete it in accordance with this section 9 once that requirement ends.
9.6 Certification. Processor shall, on Company’s written request, certify in writing that it has complied with this section 9.
10. Audit rights
10.1 Subject to this section 10, Processor shall make available to the Company on request all information necessary to demonstrate compliance with this Agreement, and shall allow for and contribute to audits, including inspections, by the Company or an auditor mandated by the Company in relation to the Processing of the Company Personal Data by the Contracted Processors.
10.2 Information and audit rights of the Company only arise under section 10.1 to the extent that the Agreement does not otherwise give them information and audit rights meeting the relevant requirements of Data Protection Law.
10.3 Company’s audit rights under section 10.1 shall be satisfied in the first instance by Processor’s then-current SOC 2 Type II report (or equivalent independent third-party audit report), its security documentation, and its responses to Company’s reasonable security questionnaires. Where those materials do not reasonably enable Company to verify Processor’s compliance with this Agreement, Company may conduct an on-site or remote audit, provided that any such audit is (a) conducted no more than once in any twelve (12) month period, except following a Personal Data Breach affecting Company Personal Data or where required by a Supervisory Authority; (b) preceded by at least thirty (30) days’ written notice; (c) conducted during normal business hours, subject to Processor’s security and confidentiality requirements, and in a manner that does not unreasonably disrupt Processor’s operations; (d) limited to information and systems relevant to the Processing of Company Personal Data and excluding other customers’ data and Processor’s confidential commercial information; and (e) conducted at Company’s cost, save where the audit reveals a material breach of this Agreement by Processor.
11. Data Transfer
11.1 Transfer Mechanisms. Processor shall not transfer, or authorize the transfer of, Company Personal Data from the EEA, the United Kingdom or Switzerland to a country that is not the subject of an adequacy decision unless an appropriate safeguard under Chapter V of the GDPR (or the equivalent provisions of UK or Swiss law) is in place. For all such transfers: (a) the standard contractual clauses approved by the European Commission in Implementing Decision (EU) 2021/914 (the “EU SCCs”) are incorporated into this Agreement by reference and apply, with Module Two (controller to processor) applying where Company acts as a controller and Module Three (processor to processor) applying where Company itself acts as a processor; (b) for transfers subject to the UK GDPR, the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner applies; and (c) for transfers subject to Swiss law, the EU SCCs apply with the adaptations set out in the guidance of the Swiss Federal Data Protection and Information Commissioner.
11.2 Data Privacy Framework. Where Processor is certified to the EU-U.S. Data Privacy Framework, the UK Extension to that Framework, or the Swiss-U.S. Data Privacy Framework, Processor may additionally rely on that certification for transfers within its scope. Such reliance does not displace the EU SCCs, which apply as an independent transfer mechanism and remain in effect regardless of the status of any adequacy decision.
11.3 EU SCC Elections. For the purposes of the EU SCCs: (a) the optional docking clause in Clause 7 does not apply; (b) Option 2 (general written authorisation) of Clause 9(a) applies, with the notice period specified in section 5.3 of this Agreement; (c) the optional redress provision in Clause 11(a) does not apply; (d) Clause 17 is governed by the law of Ireland; (e) Clause 18(b) designates the courts of Ireland; and (f) Annex I.A (Parties) is populated by the details of the Parties set out in the heading of this Agreement, with Company as data exporter and controller (or, where Module Three applies, processor) and Processor as data importer and processor, and with each Party’s contact for data protection matters being the address given in section 12.2 or, for Processor, privacy@day.ai; Annex I.B (Description of transfer) is populated by Schedule 1 to this Agreement; Annex I.C designates the competent supervisory authority identified in Schedule 1; and Annex II is populated by section 4 of this Agreement and Schedule 2. Because Option 2 of Clause 9(a) applies, Annex III is not completed; the Subprocessor List referred to in section 5.2 serves as the current list of Subprocessors for information. In the event of a conflict between the EU SCCs and the remainder of this Agreement in respect of a transfer to which the EU SCCs apply, the EU SCCs prevail.
11.4 Processor shall notify Company without undue delay if it becomes unable to comply with the transfer mechanisms described in this section 11. In that event the Parties shall work together in good faith to agree an alternative lawful transfer mechanism, and if no such mechanism can be agreed within thirty (30) days, Company may terminate the affected Services on written notice without penalty.
12. General Terms
12.1 Confidentiality. Each Party must keep this Agreement and information it receives about the other Party and its business in connection with this Agreement (“Confidential Information”) confidential and must not use or disclose that Confidential Information without the prior written consent of the other Party except to the extent that:
(a) disclosure is required by law;
(b) the relevant information is already in the public domain.
12.2 Notices. All notices and communications given under this Agreement must be in writing and will be delivered personally, sent by post or sent by email to the address or email address set out in the heading of this Agreement at such other address as notified from time to time by the Parties changing address.
12.3 Relationship to the Principal Agreement; Liability. This Agreement supplements the Principal Agreement. In the event of a conflict between this Agreement and the Principal Agreement with respect to the Processing of Personal Data, this Agreement prevails. Nothing in this Agreement varies the allocation of risk agreed by the Parties in the Principal Agreement, and each Party’s liability arising out of or in connection with this Agreement is subject to the exclusions and limitations of liability set out in the Principal Agreement.
12.4 Data Protection Contact. Processor’s data protection contact is privacy@day.ai. Company may direct any request, objection or notice under this Agreement to that address.
13. Governing Law and Jurisdiction
13.1 This Agreement is governed by the laws of Delaware.
13.2 Any dispute arising in connection with this Agreement, which the Parties will not be able to resolve amicably, will be submitted to the exclusive jurisdiction of the courts of the state of Delaware, subject to possible appeal to the Delaware Supreme Court.
Schedule 1 – Details of the Processing
Subject matter of the Processing: Processor’s provision of the Services to Company under the Principal Agreement.
Duration of the Processing: The term of the Principal Agreement, followed by the deletion periods set out in section 9 of this Agreement.
Nature and purpose of the Processing: Hosting, storage, organization, structuring, transcription, analysis, retrieval and display of Company Personal Data in order to deliver AI-powered customer relationship management, meeting assistance, transcription, sales automation and related functionality, together with the support, security and service-operation activities necessary to provide the Services.
Types of Personal Data: Names, business contact details, job titles and organizational affiliations; user account and authentication data; email content, headers and metadata; calendar entries and participant lists; meeting audio and video recordings, transcripts and derived summaries and insights; communications and notes recorded in the Services; usage and device logs; and, where Company enables voice identification, voice characteristics used for speaker identification.
Categories of Data Subjects: Company’s personnel and Authorized Users; Company’s customers, prospective customers and business contacts; and participants in meetings and communications processed through the Services.
Frequency of the transfer: Continuous, for the duration of the Principal Agreement.
Special categories of Personal Data: None by default. The Services are not designed to Process special categories of Personal Data within the meaning of Article 9 of the GDPR, and Company shall not submit such data to the Services. The sole exception is that, where Company enables the optional voice identification feature, Processor Processes voice characteristics for the purpose of uniquely identifying a natural person, which constitutes biometric data under Article 9(1). Where that feature is enabled: Company is responsible for establishing a lawful basis under Article 9(2) and for obtaining any consent required by applicable biometric privacy laws (including the Illinois Biometric Information Privacy Act) directly from each affected individual; the feature is enabled only by Company’s affirmative opt-in; voiceprints are encrypted at rest, access to them is restricted to personnel who require it to operate the feature, and they are not used for any other purpose; and voiceprints are deleted within thirty (30) days after the feature is disabled or Company requests their deletion.
Competent Supervisory Authority (Clause 13, EU SCCs): The supervisory authority of the EEA Member State in which Company is established or, where Company is not established in the EEA, in which Company’s Article 27 representative is established.
Schedule 2 – Technical and Organizational Measures
The technical and organizational measures implemented by Processor are those set out in section 4 of this Agreement, as further described in Day AI’s Data Retention & Protection Policy and in its Security Policy (available on request via privacy@day.ai) and evidenced by Processor’s SOC 2 Type II report. The Subprocessors to which Company Personal Data may be disclosed, and the locations in which they Process it, are set out on the Subprocessor List at day.ai/trust/subprocessors.