OVERAI
PlatformModulesPricingFAQSign inStart free

Data Processing Addendum

Last updated August 31, 2026

This Data Processing Addendum (“DPA”) forms part of the OverAI Terms of Service or other agreement between Perygee, Inc., doing business as OverAI (“OverAI”), and Customer. It applies when OverAI handles Personal Data on Customer’s behalf in connection with the Services.

1. Definitions

“Personal Data” means information relating to an identified or identifiable person that Customer submits to the Services. “Processing” means any operation performed on Personal Data. “Data Subject” means the person to whom Personal Data relates. “Privacy Laws” means applicable laws governing Personal Data, including applicable US state privacy laws. “Security Incident” means unauthorized or unlawful access to, disclosure, alteration, loss, or destruction of Personal Data.

2. Roles and instructions

Customer is a Controller or, where Customer processes Personal Data for another Controller, a Processor. OverAI is Customer’s Processor or Subprocessor, respectively. Where the California Consumer Privacy Act or a similar US state law applies, Customer is a Business or Controller and OverAI is a Service Provider, Contractor, or Processor. OverAI will process Personal Data only on Customer’s documented instructions, including the agreement and Customer’s use of the Services, unless applicable law requires otherwise. OverAI will notify Customer if an instruction appears to violate Privacy Laws, unless prohibited by law.

OverAI acts as an independent Controller for account administration, billing, security, fraud prevention, support, and product and website analytics described in the Privacy Notice. This DPA does not govern that Processing.

3. Processing details

  • Subject matter: providing the OverAI Services.
  • Nature and purpose: hosting, transmitting, securing, supporting, and operating the Services on Customer’s behalf.
  • Data: names, email addresses, account identifiers, usage records, and other Personal Data Customer submits.
  • Data Subjects: Customer’s personnel, contractors, customers, and end users.
  • Duration: the term of the agreement.

4. Processor obligations

OverAI will:

  • ensure authorized personnel are bound by appropriate confidentiality obligations;
  • assist Customer with reasonable Data Subject requests and compliance obligations, considering the nature of the Processing;
  • provide information reasonably necessary to demonstrate compliance and cooperate with reasonable audits on at least 30 days’ notice;
  • delete or return Personal Data after termination at Customer’s election, unless law requires retention; and
  • not sell Personal Data or use it for targeted advertising.

5. US state privacy requirements

OverAI will process Personal Data only for the business purposes described in this DPA and the agreement. OverAI will not sell or share Personal Data; retain, use, or disclose it outside those business purposes or the direct business relationship with Customer; or combine it with personal data from another person or from OverAI’s own interactions with a Data Subject except as permitted by Privacy Laws. OverAI will provide the same level of privacy protection required of Customer by applicable Privacy Laws.

OverAI will notify Customer if it determines it can no longer meet these obligations. Customer may take reasonable and appropriate steps to verify compliance, stop and remediate unauthorized use, and require OverAI to provide information reasonably necessary for Customer’s privacy impact assessments. The agreement and this DPA constitute Customer’s instructions and identify the limited and specified purposes for Processing.

6. Customer obligations

Customer will ensure its instructions comply with Privacy Laws, provide required notices and permissions, and remain responsible for the accuracy, quality, and legality of Personal Data submitted to the Services.

7. Security

OverAI will maintain measures appropriate to the risk, including encryption in transit and at rest, least-privilege access controls, security testing, incident response, recovery procedures, workforce training, logging, and secure disposal. Upon request and under appropriate confidentiality protections, OverAI will provide security information and independent audit reports then available for the Services.

8. Subprocessors

Customer generally authorizes OverAI to use subprocessors. OverAI will bind each subprocessor to data-protection obligations appropriate to the services it performs and remain responsible for its subprocessors. The currentSubprocessor List is incorporated into this DPA. AI subprocessors process Personal Data only when Customer’s organization selects a model or feature served by that provider.

OverAI will email organization administrators at least 30 days before authorizing a new subprocessor to process Personal Data, unless an emergency or security need requires shorter notice. Customer may object on reasonable data-protection grounds during that period. Third-party integrations and destinations Customer connects or directs OverAI to use are Customer’s instructions, not OverAI subprocessors.

9. Security incidents

OverAI will notify Customer without undue delay after becoming aware of a Security Incident affecting Personal Data. When known, notice will describe the incident, affected records and Data Subjects, likely consequences, and remediation. OverAI will reasonably cooperate in investigation, containment, and remediation.

10. Data Subject rights

OverAI will promptly notify Customer of a Data Subject request concerning Customer’s Personal Data and will not respond except on Customer’s instruction or as required by law. OverAI will provide reasonable assistance so Customer can respond within applicable deadlines.

11. International data transfers

Customer acknowledges that OverAI primarily hosts and processes Personal Data in the United States. International customers must use the Services under an order form or other written approval that incorporates the Standard Contractual Clauses, the UK International Data Transfer Addendum, or another transfer mechanism when Privacy Laws require one. OverAI will provide reasonable assistance documenting the transfer. Transfers through an integration, automation, or destination Customer configures are made on Customer’s instructions.

12. Return and deletion

On expiration or termination, OverAI will delete or return Personal Data at Customer’s written direction within 30 days, unless law requires retention. Personal Data retained in encrypted backups will remain protected by this DPA and will be deleted through OverAI’s normal backup rotation. OverAI will confirm completion upon request.

13. Liability and precedence

The agreement’s liability limits apply to this DPA except where Privacy Laws require otherwise. This DPA controls over conflicting agreement terms about Processing Personal Data.

Questions, objections, and audit requests may be sent tohello@overai.com.

OVERAI

We like to read too, but this is the end.
Sign up for our newsletter.

PlatformModulesPricingFAQEmailLinkedInPrivacyTermsDPASubprocessors
© 2026 OverAI · We <3 privacy. No third-party advertising or cross-site tracking.