Data Processing Agreement
Effective Date: October 1, 2026 · Version dpa-2026-10
This Data Processing Agreement ("DPA") forms part of the Big Sister AI Company Terms of Service (the "Agreement") between Big Sister AI Company ("Provider") and the Customer that accepted the Agreement. It is incorporated into the Agreement under Section 3.1 of the Agreement as modified on its Cover Page, and no signature is needed for it to apply. Capitalized terms not defined here have the meaning given in the Agreement.
A Customer that needs a signed copy of this DPA, or a DPA on its own form, may request one at notices@big-sister.ai. A signed DPA replaces this one from the date of signature.
1. Roles and scope
Customer is the controller and Provider is the processor of the Personal Data described in Annex 1. Each party will comply with the obligations that apply to it under Data Protection Laws.
"Data Protection Laws" means all laws that apply to the processing of Personal Data under this DPA, including, where applicable, the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA"), the Texas Data Privacy and Security Act, other US state privacy laws, the EU General Data Protection Regulation 2016/679 ("GDPR"), and the UK GDPR and Data Protection Act 2018.
This DPA applies only to Provider's processing of Personal Data on Customer's behalf to provide the Product. It does not apply to information Provider processes as a controller for its own business, such as account, billing and usage information, which the Privacy Policy covers.
Where the CCPA applies, Provider is a service provider to Customer. Provider certifies that it understands the restrictions in Section 3 and will comply with them.
2. Location of processing
Customer Content is hosted in the United States and is accessible to Provider's personnel located in the United States and Ukraine, under the controls in Annex 2.
The Product is directed at business customers in the United States. Unless Customer gives notice under this Section, the parties do not expect Personal Data subject to the GDPR or UK GDPR to be processed under this DPA. Customer will notify Provider at notices@big-sister.ai before submitting, or connecting a system that contains, Personal Data subject to the GDPR or UK GDPR. On that notice, Annex 4 takes effect before the relevant processing begins.
This Section does not limit Provider's obligations under this DPA for any Personal Data actually processed, whatever its origin.
3. Processing instructions
Provider will process Personal Data only (a) as necessary to provide the Product; (b) in accordance with the Agreement, this DPA and Annex 1; and (c) in accordance with Customer's further written instructions, provided they are consistent with the Agreement. The Agreement, this DPA and Annex 1 are Customer's complete initial instructions. Customer's configuration choices in the Product (which source to connect, which users to score) are instructions for this purpose.
Provider will inform Customer if, in Provider's opinion, an instruction infringes Data Protection Laws, and may suspend that instruction until it is withdrawn or amended. Provider is not obliged to give legal advice.
Provider will not sell Personal Data, share it for cross-context behavioral advertising, retain, use or disclose it outside the direct business relationship with Customer, combine it with Personal Data from other sources except as the CCPA permits a service provider to do, or process it for any purpose other than providing the Product.
Provider will not use Personal Data or Customer Content to train, fine-tune or develop any artificial intelligence or machine learning model, as set out in Section 1.6 of the Agreement as modified on its Cover Page.
4. Confidentiality and personnel
Provider will ensure that persons authorized to process Personal Data are bound by written confidentiality obligations, are informed of the confidential nature of the Personal Data, and receive appropriate instruction. Provider limits access to personnel who need it to provide, support or secure the Product, and maintains a record of who has access. No individual is granted access to Customer Content until bound by written confidentiality obligations.
5. Security
Provider will implement and maintain the technical and organizational measures in Annex 2, having regard to the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing. Provider may update those measures from time to time provided the overall level of security is not materially reduced.
6. Subprocessors
Customer authorizes Provider to engage the subprocessors listed in Part A of Annex 3 and at https://www.big-sister.ai/subprocessors, and gives general authorization for Provider to engage further subprocessors under this Section.
Provider will give Customer at least 15 days' notice, by email to the workspace's primary contact, before a new subprocessor processes Personal Data. Customer may object on reasonable data-protection grounds within that period. If Customer objects, the parties will discuss in good faith; if no resolution is reached, Provider may provide the Product without the proposed subprocessor or, where that is not reasonably possible, either party may terminate the Agreement on notice, and Customer will receive a pro-rated refund of prepaid Fees for the unused part of the Subscription Period.
Provider will impose on each subprocessor data-protection obligations no less protective than those in this DPA, and remains responsible to Customer for its subprocessors' performance.
The systems in Part B of Annex 3 are Customer's own; Provider accesses them with credentials Customer issues, and they are not Provider's subprocessors.
7. International transfers
Customer Content is hosted in the United States. It is not exported from the European Economic Area or the United Kingdom under this DPA unless Section 2 is triggered.
If Section 2 is triggered, transfers of Personal Data subject to the GDPR or UK GDPR are governed by the Standard Contractual Clauses on the elections pre-agreed in Annex 4, and Provider will procure equivalent terms with each affected subprocessor before the relevant processing begins.
8. Data subject requests
Provider will not respond to a request from a data subject relating to Customer's Personal Data except on Customer's instruction or where required by law, and will forward any such request it receives to Customer without undue delay.
Provider will provide reasonable assistance to Customer in responding to data subject requests and, where the GDPR applies, in fulfilling Customer's obligations under Articles 32 to 36, taking into account the nature of the processing and the information available to Provider. Assistance beyond what the Product's standard functionality provides may be chargeable at Provider's then-current professional rates, agreed in advance.
9. Security incidents
Provider will notify Customer without undue delay, and in any event within 48 hours after Provider confirms a Security Incident affecting Customer Personal Data. "Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data processed by Provider.
The notification will describe, to the extent then known, the nature of the incident, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed. Provider will supply further information as it becomes available and will cooperate reasonably with Customer's investigation and with any notification Customer must make.
Unsuccessful attempts and events with no adverse effect on the security of Personal Data, such as pings, port scans, failed log-in attempts and denial-of-service attempts that do not result in unauthorized access, are not Security Incidents.
Provider's notification is not an acknowledgement of fault or liability.
10. Retention, deletion and return
Call content. Provider will delete Customer call content (recordings, transcripts and data derived from them) 24 months after collection, and within 30 days after the Agreement ends, whichever comes first.
Implementation. Automated storage lifecycle rules giving effect to the 24-month limit are being deployed. Until they are in operation, Provider effects deletion on the same timetable by documented operational process. This paragraph is a commitment as to future operation, not a representation about Provider's configuration on the Effective Date.
Other Customer Personal Data. When the Agreement ends, and in any event within 30 days after Customer's written request, Provider will delete or, at Customer's choice, return Customer Personal Data and delete existing copies, except to the extent retention is required by law.
Backups. Customer Personal Data held in routine encrypted backups is deleted in the ordinary course of Provider's backup cycle and no later than 35 days after the corresponding primary deletion. Data retained under this paragraph remains subject to this DPA until deleted and is not restored to production use.
Export. Customer may export its scores and Interactions Log from the Product at any time during the term. Provider will confirm deletion in writing on request.
11. Audit and information
Provider will make available to Customer, on reasonable request and no more than once in any 12-month period, the information reasonably necessary to demonstrate compliance with this DPA, including written responses to a reasonable security questionnaire and copies of any third-party audit reports or certifications Provider holds. Provider may require a mutual non-disclosure agreement before releasing detailed security information.
An on-site audit or inspection may be conducted where a supervisory authority requires it, where it follows a confirmed Security Incident affecting Customer Personal Data, or where Customer reasonably demonstrates that the information provided above is insufficient. Any such audit will be at Customer's cost, on at least 30 days' notice, during business hours, subject to confidentiality, conducted so as not to disrupt Provider's operations, and will not extend to other customers' data, Provider's source code, or multi-tenant infrastructure.
12. Liability
Each party's liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability in the Agreement, including the Increased Cap Amount for Increased Claims on the Cover Page. This DPA does not create an additional or separate cap.
13. Prohibited data
Customer will not submit Prohibited Data (protected health information, financial account numbers, government identification numbers, biometric identifiers, or GDPR special categories) to the Product, and will not direct the Product at it. Sales calls may contain such data incidentally; Provider does not extract or index it. Where such data is nevertheless processed, this DPA applies to it.
14. Term, precedence and general
This DPA takes effect when Customer accepts the Agreement and continues for as long as Provider processes Customer Personal Data.
In the event of conflict, the order of precedence is: Annex 4 (Standard Contractual Clauses, where in effect), then this DPA, then the Agreement.
This DPA is governed by the law and subject to the courts specified in the Agreement, except where Data Protection Laws require otherwise.
Provider may update this DPA by publishing a new version at https://www.big-sister.ai/dpa. A change that materially reduces Customer's rights takes effect only after 30 days' notice by email, and Customer may terminate before that date with a pro-rated refund of prepaid Fees.
Annex 1: Details of processing
| Subject matter | Provision of the Big Sister AI platform: ingestion, storage, analysis and scoring of Customer's sales interactions. |
| Duration | The Subscription Period, plus the retention periods in Section 10. |
| Nature and purpose | Collection from Customer's connected source, storage, transcription where needed, analysis by large language models, scoring against a skill rubric, aggregation into rep and team views, and delivery of scores, summaries, coaching output and reports to Customer. |
| Categories of data subjects | Customer's personnel who hold a Sales or Manager role; individuals at Customer's prospects, customers and partners who take part in recorded calls or meetings; individuals recorded in Customer's CRM (Team and Custom plans). |
| Categories of Personal Data | Name, business contact details, job title and employer; voice recordings and transcripts of calls and meetings; CRM records including notes, activity history and deal data (Team and Custom plans); metadata such as timestamps and participant lists; scores and assessments derived from the above. |
| Special category data | None intended. See Section 13. |
| Frequency | Continuous during the Subscription Period. |
| Retention | Section 10. |
Annex 2: Technical and organizational measures
The measures below describe Provider's controls as verified against live infrastructure in August 2026. Where a measure is stated as taking effect on a future date, that is a commitment as to future operation. Provider may update these measures provided the overall level of security is not materially reduced.
| Measure | Description |
|---|---|
| Access control | Role-based access with least-privilege defaults. Individual named accounts for access to the Product, Customer Content and cloud infrastructure. A limited number of shared service credentials for third-party tooling are held in a managed team password manager with per-person authentication and access logging. Multi-factor authentication is enforced by policy for all administrative console access to Provider's cloud environment. Access is reviewed on personnel change and at least annually against a documented removal checklist. |
| Confidentiality of personnel | Written confidentiality obligations are executed and held for each individual with access to Customer Content. No individual is granted access until so bound. |
| Encryption | TLS 1.2 or above in transit. Customer data stores (object storage, relational databases, file storage and the warehouse) are encrypted at rest with AES-256 or keys managed by Provider in AWS KMS. Encryption by default is enforced for newly provisioned block storage. Provider does not offer customer-managed keys. |
| Tenant separation | Customer data is logically separated by a tenant identifier, with per-tenant storage prefixes and access scoping enforced by the application layer and covered by automated regression tests that fail the build if an endpoint omits authentication. Customer data is not stored in physically separate databases. |
| Non-production environments | Production data may be readable from Provider's staging environment, which is access-restricted and not publicly reachable. Production data is not copied into local development environments. |
| Logging and monitoring | Infrastructure and administrative activity is logged centrally (AWS CloudTrail, multi-region, with log-file integrity validation) and retained for investigation. Object-level access to customer data stores is logged and can resolve individual read events to the affected tenant. Automated threat detection (AWS GuardDuty) is deployed with findings routed to named individuals; the alert path has been tested end to end. Operational alarms cover availability, latency, capacity and worker liveness. Provider does not deploy insider-threat detection or user-behavior analytics. |
| Backup and resilience | Backups are encrypted at rest. Production databases are retained for 35 days with deletion protection enabled. Restore procedures are documented and tested; restore drills are performed quarterly. |
| Vulnerability management | Dependencies are monitored continuously for known vulnerabilities (GitHub Dependabot) across all repositories, with security patches applied on a prioritized basis. Infrastructure is monitored for threats via AWS GuardDuty. Provider does not currently operate static application security testing or automated configuration-compliance benchmarking. |
| Subprocessor governance | Subprocessors are engaged under their published data-processing terms, incorporated by reference. Each subprocessor's terms on model training and data retention are reviewed and re-checked quarterly. A subprocessor register is maintained and published at https://www.big-sister.ai/subprocessors. |
| Incident response | A written incident-response procedure defines named roles including an incident lead and deputy, a three-level severity classification, evidence-preservation and containment steps, a procedure for determining which customer objects were accessed, and customer notification responsibilities consistent with Section 9. |
| Physical security | Provider operates no data centers. Hosting is provided by the infrastructure subprocessors in Annex 3, which maintain their own physical security controls and certifications. |
| Deletion | Deletion of Customer Personal Data on request and on termination is performed under Provider's written retention policy and an operational deletion procedure identifying the stores, storage prefixes and warehouse objects to be cleared, with a verification step confirming deletion. |
Annex 3: Subprocessors and customer-controlled source systems
The current list is published at https://www.big-sister.ai/subprocessors and is incorporated here. On the Effective Date it reads as follows. Section 6 governs additions.
Part A: Subprocessors (engaged under Provider's own accounts)
| Subprocessor | Location | Purpose | Personal Data |
|---|---|---|---|
| Amazon Web Services, Inc. | United States (US East) | Hosting, storage, compute and encrypted backups. No replication outside the region. | Yes |
| Microsoft Corporation (Azure AI Foundry) | United States (East US) | Model inference for scoring and analysis. All scoring models run here. Inputs are not used for vendor model training. | Yes: transcripts, metadata, prompts |
| Snowflake Inc. | United States | Analytics warehouse. Scores and derived data, which may include business contact details. | Yes: limited |
| Langfuse GmbH | United States (hosted) | Model-call observability. Prompts and completions contain transcript content. | Yes: transcript content |
| Granola, Inc. | United States | Provider's notetaker for calls its personnel hold with Customer. | Yes: recordings of calls with Provider staff |
| Google LLC (Google Workspace) | United States | Provider's email, documents and file storage. | Yes: incidental |
| Anthropic, PBC (Claude workspace) | United States | Internal tooling used by Provider personnel. May process Customer Personal Data incidentally. Inputs are not used for model training. Not used inside the Product. | Yes: incidental |
| Mango Technologies, Inc. (ClickUp) | United States | Work management; support records. | Yes: contact details |
| Nango, Inc. | United States | Credential broker for Part B systems. Holds no Customer Content. | Credentials only |
| PostHog, Inc. | United States | Product usage analytics. No call content. | Yes: identifiers and usage events |
| Functional Software, Inc. (Sentry) | United States | Application error monitoring. Tenant identifiers only. | Telemetry only |
| Stripe, Inc. | United States | Payments and billing portal. | Yes: billing contact |
Part B: Customer-controlled source systems (accessed under Customer-issued credentials)
| System | Location | Purpose | Basis of access |
|---|---|---|---|
| Fireflies.ai, Inc., or another notetaker Customer connects | Vendor-dependent | Meeting recording and transcription in Customer's own workspace | API key or webhook issued by Customer |
| Ringostat | European Union / United States | Telephony call audio, Customer's own PBX | Authentication key issued by Customer |
| Pipedrive, Zoho CRM, HubSpot or Creatio (Team and Custom plans) | United States / European Union | CRM records | OAuth authorized by Customer |
Annex 4: Transfer mechanism (held in reserve)
This Annex is not in effect unless Section 2 is triggered. The elections below are agreed in advance so the mechanism can take effect without renegotiation.
| Election | Value |
|---|---|
| Instrument | The Standard Contractual Clauses approved by European Commission Implementing Decision (EU) 2021/914, together with the UK International Data Transfer Addendum (version B1.0) for transfers subject to the UK GDPR. |
| Modules | Module Two (controller to processor) between Customer and Provider. Module Three (processor to processor) between Provider and each subprocessor, executed separately, with a copy available to Customer on request. |
| Clause 7 (docking) | Applies. |
| Clause 9 (subprocessors) | Option 2, general written authorization, with the 15-day notice period in Section 6. |
| Clause 11(a) (redress) | Optional independent dispute-resolution body not selected. |
| Clause 17 (governing law) | The law of Ireland. |
| Clause 18(b) (forum) | The courts of Ireland. |
| Annexes I, II and III | Populated from Annexes 1, 2 and 3 of this DPA. |
| Supervisory authority | Identified at the time of completion by reference to the location giving rise to the application of the GDPR. |
Supplementary measures, which apply to all access to Customer Content from outside the United States whether or not this Annex is in effect: access is through the Product or Provider's cloud console using individually named accounts with multi-factor authentication; bulk export of Customer Content and storage on personal or unmanaged devices are prohibited by Provider's policy; Customer Content is encrypted in transit and at rest with keys held by Provider in the United States; Prohibited Data is excluded from the Product; access is removed on a personnel change.
Government access requests. Provider has not received any request from a public authority for Customer Content. If it receives one it will notify Customer promptly unless legally prohibited, use reasonable efforts to obtain a waiver of any prohibition, challenge requests that are overbroad or unlawful, disclose only the minimum required, and make no voluntary disclosure of Customer Content to any public authority.
Change log
| Version | Date | Change |
|---|---|---|
dpa-2026-10 | 2026-10-01 | First click-through version, incorporated into the Terms of Service. Derived from the Data Processing Agreement executed with a customer in August 2026, with engagement-specific terms removed and CCPA service-provider language added. |