Data Processing Addendum
Last updated August 5, 2026
This Data Processing Addendum (“DPA”) forms part of the OverAI Terms of Service or other agreement between Perygee, Inc., doing business as OverAI (“Processor”), and Customer (“Controller”). It applies when Processor handles Personal Data on Customer’s behalf in connection with the Services.
1. Definitions
“Personal Data” means information relating to an identified or identifiable person that Customer submits to the Services. “Processing” means any operation performed on Personal Data. “Data Subject” means the person to whom Personal Data relates. “Privacy Laws” means applicable laws governing Personal Data. “Security Incident” means unauthorized or unlawful access to, disclosure, alteration, loss, or destruction of Personal Data.
2. Roles and instructions
Customer is Controller and OverAI is Processor. OverAI will process Personal Data only on Customer’s documented instructions, including the agreement and Customer’s use of the Services, unless applicable law requires otherwise. OverAI will notify Customer if an instruction appears to violate Privacy Laws, unless prohibited by law.
3. Processing details
- Subject matter: providing the OverAI Services.
- Nature and purpose: hosting, transmitting, securing, supporting, and operating the Services on Customer’s behalf.
- Data: names, email addresses, credentials, usage records, and other Personal Data Customer submits.
- Data Subjects: Customer’s personnel, contractors, customers, and end users.
- Duration: the term of the agreement.
4. Processor obligations
OverAI will:
- ensure authorized personnel are bound by appropriate confidentiality obligations;
- assist Customer with reasonable Data Subject requests and compliance obligations, considering the nature of the Processing;
- provide information reasonably necessary to demonstrate compliance and cooperate with reasonable audits on at least 30 days’ notice;
- delete or return Personal Data after termination at Customer’s election, unless law requires retention; and
- not sell Personal Data or use it for targeted advertising.
5. Customer obligations
Customer will ensure its instructions comply with Privacy Laws, provide required notices and permissions, and remain responsible for the accuracy, quality, and legality of Personal Data submitted to the Services.
6. Security
OverAI will maintain measures appropriate to the risk, including encryption in transit and at rest, least-privilege access controls, security testing, incident response, recovery procedures, workforce training, logging, and secure disposal. OverAI maintains an annual SOC 2 Type II audit report and will make the current report available under appropriate confidentiality protections upon request.
7. Subprocessors
Customer generally authorizes OverAI to use subprocessors. OverAI will bind each subprocessor to data-protection obligations no less protective than this DPA, remain responsible for its subprocessors, maintain a current list, and give at least 14 days’ notice of a new subprocessor. Customer may object on reasonable data-protection grounds during that period.
8. Security incidents
OverAI will notify Customer without undue delay and no later than 48 hours after becoming aware of a Security Incident affecting Personal Data. When known, notice will describe the incident, affected records and Data Subjects, likely consequences, and remediation. OverAI will reasonably cooperate in investigation, containment, and remediation.
9. Data Subject rights
OverAI will promptly notify Customer of a Data Subject request concerning Customer’s Personal Data and will not respond except on Customer’s instruction or as required by law. OverAI will provide reasonable assistance so Customer can respond within applicable deadlines.
10. Data transfers
OverAI will not transfer Personal Data outside the United States without Customer’s authorization or a lawful transfer mechanism, except as required by law.
11. Return and deletion
On expiration or termination, OverAI will delete or return Personal Data at Customer’s written direction and certify completion within 30 days, unless law requires retention. Retained data remains protected by this DPA.
12. Liability and precedence
The agreement’s liability limits apply to this DPA except where Privacy Laws require otherwise. This DPA controls over conflicting agreement terms about Processing Personal Data.
Questions and audit requests may be sent tohello@overai.com.