DRAFT — for counsel review. Not legal advice, and not yet in effect.
Version 0.1 (draft) · Effective [Effective Date] · [Neivan Legal Entity, Inc.]
This Data Processing Agreement (the 'DPA') forms part of, and is incorporated by reference into, the agreement between [Neivan Legal Entity, Inc.] ('Neivan') and the customer organization identified in the applicable order or subscription (the 'Customer') governing the Customer's use of the Synapse platform and related services (the 'Agreement'). This DPA reflects the parties' agreement on the Processing of Personal Data in connection with the Synapse service.
If there is a conflict between this DPA and the Agreement on the subject of data protection, this DPA controls. If there is a conflict between this DPA and the Standard Contractual Clauses incorporated by reference, the Standard Contractual Clauses control with respect to transfers they govern.
1.1 B2B context. Synapse is a business-to-business software-as-a-service platform. The 'Customer' is the organization that subscribes to Synapse. 'Authorized Users' are the Customer's administrators and employees whom the Customer permits to access Synapse.
1.2 Controller and Processor. With respect to the Personal Data of the Customer's Authorized Users and other individuals whose data the Customer submits to or generates within Synapse ('Customer Personal Data'):
1.3 Onward processing (Customer as processor). Where the Customer itself acts as a processor on behalf of a third-party controller (for example, the Customer's own end customers), the Customer remains the Controller as between the Customer and Neivan for purposes of this DPA, and Neivan acts as a sub-processor. The Customer is responsible for ensuring it has the authority from its controller to engage Neivan as a sub-processor.
1.4 Neivan as independent controller. Neivan acts as an independent controller for a limited set of data it Processes for its own purposes — for example, account administration, billing and invoicing, security and abuse prevention, and aggregated, de-identified service-improvement analytics. Such Processing is governed by Neivan's Privacy Policy, not by this DPA.
Capitalized terms not defined here have the meaning given in the Agreement or in applicable Data Protection Law.
3.1 Subject matter. Neivan's Processing of Customer Personal Data in order to provide and support the Synapse platform under the Agreement.
3.2 Duration. The term of the Agreement, plus any period during which Neivan retains Customer Personal Data as permitted under Section 11, plus any retention required by law.
3.3 Nature and purpose. Synapse enables the Customer to deploy AI agents, skills, and workflows that act on connected systems; to use the Jarvis assistant; to build and optimize automations with AI; to teach automations by demonstration; and to run an automation pipeline that observes, maps, and recommends process automations. Neivan Processes Customer Personal Data only to deliver, secure, support, and improve these functions for the Customer.
3.4 Details of Processing. The categories of Data Subjects, categories of Personal Data, and Processing operations are described in Annex I.
4.1 Neivan shall Process Customer Personal Data only on the Customer's documented instructions, including with regard to international transfers, unless required to do otherwise by applicable law (in which case Neivan shall, where legally permitted, inform the Customer of that legal requirement before Processing).
4.2 The Agreement, this DPA, the configuration choices the Customer makes within Synapse (including consent settings, connection scope, observation and Recorder settings, AI-provider selection, and retention settings), and the Customer's use of the documented features of Synapse constitute the Customer's complete and final documented instructions.
4.3 Neivan shall inform the Customer if, in Neivan's opinion, an instruction infringes Data Protection Law, without obligation to actively monitor the Customer's compliance.
Neivan shall ensure that persons authorized to Process Customer Personal Data are bound by appropriate confidentiality obligations (whether contractual or statutory) and have received appropriate data-protection training. Access is restricted to personnel who need it to perform Neivan's obligations under the Agreement.
6.1 Neivan shall implement and maintain appropriate technical and organizational measures to protect Customer Personal Data against a Personal Data Breach, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing, as well as the risk to Data Subjects.
6.2 These measures are described in Annex II and summarized in Neivan's Security Overview (incorporated by reference). They include, at a minimum:
6.3 The Customer is responsible for its own use of Synapse, including configuring access, permissions, consent and observation settings, and connections, and for the security of credentials issued to its Authorized Users.
7.1 General authorization. The Customer provides a general authorization for Neivan to engage Sub-processors to Process Customer Personal Data, subject to this Section 7.
7.2 Current Sub-processors. Neivan's current Sub-processors are listed in Annex III. The list distinguishes payment processing, AI/LLM sub-processing, and infrastructure and operational services.
7.3 AI sub-processing. When an Authorized User invokes an AI feature, the relevant prompts and content may be transmitted to a third-party large language model provider via its API (for example, Anthropic, OpenAI, Google, Perplexity, Mistral, DeepSeek, or xAI), under either a Customer-supplied (bring-your-own) key held in the secret vault or a Neivan-managed prepaid arrangement. Neivan contractually requires, and configures its integrations such that, Customer content is not used to train the provider's models. The Customer selects which AI providers it enables.
7.4 Flow-down. Neivan shall impose data-protection obligations on each Sub-processor that are no less protective than those in this DPA, and remains liable to the Customer for each Sub-processor's performance.
7.5 Change notice and objection. Neivan shall give the Customer notice (for example, by updating Annex III or by email or in-product notice to a designated contact) before authorizing a new Sub-processor that Processes Customer Personal Data. The Customer may object on reasonable, data-protection grounds within [15] days. The parties shall work in good faith to resolve the objection; if they cannot, the Customer may terminate the affected portion of the Agreement as its exclusive remedy.
8.1 Taking into account the nature of the Processing, Neivan shall provide reasonable assistance through appropriate technical and organizational measures, insofar as possible, to help the Customer respond to requests by Data Subjects to exercise their rights (including access, rectification, erasure, restriction, portability, and objection).
8.2 Where Neivan receives a request directly from a Data Subject relating to Customer Personal Data, Neivan shall not respond on the merits but shall, where permitted, promptly forward the request to the Customer.
9.1 Security and DPIAs. Neivan shall provide the Customer reasonable assistance with the Customer's obligations under Articles 32 to 36 GDPR (and equivalents), including data protection impact assessments and prior consultations with Supervisory Authorities, taking into account the nature of Processing and the information available to Neivan.
9.2 Breach notification. Neivan shall notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and shall provide information reasonably available to Neivan to help the Customer meet its own notification obligations. Notifications are descriptions of Neivan's investigation and remediation and are not an acknowledgment of fault or liability.
10.1 Where Neivan's Processing of Customer Personal Data involves a transfer from the European Economic Area, the United Kingdom, or Switzerland to a country not subject to an adequacy decision, the parties incorporate the Standard Contractual Clauses by reference to provide appropriate safeguards.
10.2 Module selection. For Customer-as-Controller / Neivan-as-Processor transfers, Module Two applies. For Customer-as-Processor / Neivan-as-Sub-processor transfers, Module Three applies. The parties' details and selections are populated from Annex I; Clause 7 (docking) applies; Clause 9 reflects the general authorization in Section 7; Clause 11 optional redress does not apply; the governing law and forum are those of [Governing-Law Jurisdiction] to the extent permitted; and Annexes I, II, and III of the SCCs are populated by the corresponding Annexes of this DPA.
10.3 UK transfers. The UK Addendum applies to transfers subject to UK GDPR, incorporating the SCCs as amended by the Addendum.
10.4 If the transfer mechanism is invalidated or superseded, the parties shall cooperate in good faith to implement an alternative lawful mechanism.
11.1 Upon termination or expiry of the Agreement, and at the Customer's choice, Neivan shall return or delete Customer Personal Data, and delete existing copies, unless retention is required by applicable law.
11.2 During any post-termination period and pending deletion, the protections of this DPA continue to apply. Neivan may retain Customer Personal Data in routine backups for a limited period in accordance with its backup-rotation schedule, after which it is deleted or rendered inaccessible.
12.1 Neivan shall make available to the Customer information reasonably necessary to demonstrate compliance with this DPA, which may be satisfied through the Security Overview, security documentation, and (where available) third-party audit reports or certifications.
12.2 The Customer may, no more than once per twelve months (and additionally following a Personal Data Breach affecting the Customer, or where required by a Supervisory Authority), audit Neivan's compliance, on reasonable prior notice, during business hours, subject to confidentiality, and in a manner that does not compromise the security or confidentiality of other customers' data or Neivan's systems.
Where the Customer is a Business and Neivan is a Service Provider under CCPA/CPRA, Neivan shall:
Neivan certifies that it understands and will comply with these restrictions.
| Category | Examples |
|---|---|
| Identity and profile | Name, email, role, department, permissions |
| Compensation (heightened sensitivity) | Salary or hourly rate, stored privately and access-restricted |
| Cognitive / voice profiles | Assistant personalization and voice data |
| Activity and observation events | Cloud activity metadata only (never contents), consent-gated |
| Desktop observation (Synapse Recorder) | Active-window and accessibility metadata; optional redacted screen frames; consent-gated, with redaction and retention controls |
| Training and SOP captures | Teach-by-demonstration and SOP capture content |
| Connected-system content | Email, calendar, drive, CRM, and custom-API data the Customer chooses to connect |
| AI interaction content | Prompts and content submitted to AI features |
The parties acknowledge that compensation data and screen-observation data (redacted frames and Recorder metadata) are sensitive and warrant heightened safeguards: private storage, restricted access, consent-gating where applicable, redaction, and retention limits.
Hosting, executing AI agents/skills/workflows, the Jarvis assistant, building/optimizing/teaching automations, the automation pipeline, consent-gated observation, support, security, and billing, as described in Section 3.
Continuous, for the duration of the Agreement.
For the term plus the periods described in Section 11 and the Customer's configured retention settings, plus any legally required retention.
Neivan maintains the measures below; details are in the Security Overview.
| Domain | Measures |
|---|---|
| Encryption | TLS in transit; encryption at rest |
| Access control | RBAC, least privilege, authentication controls, periodic access reviews |
| Tenant isolation | Logical separation of each Customer's data in the multi-tenant environment |
| Secrets management | Server-side vault for BYO AI keys and connection credentials; card data tokenized via Stripe (PCI SAQ-A), never stored by Neivan |
| Logging and monitoring | Administrative and security audit logging; monitoring and alerting |
| Application security | Input validation, dependency management, and the principle that AI providers receive only what is needed |
| Observation safeguards | Consent-gating, redaction, retention controls, and transparency to Authorized Users |
| Resilience | Backups and business-continuity practices |
| Incident response | Breach detection, response, and notification without undue delay |
The current Sub-processor list (bracketed entries are to be confirmed):
| Sub-processor | Purpose |
|---|---|
| Stripe | Payment processing (card data tokenized; PCI SAQ-A) |
| Anthropic | AI / LLM processing |
| OpenAI | AI / LLM processing |
| AI / LLM processing | |
| Perplexity | AI / LLM processing |
| Mistral | AI / LLM processing |
| DeepSeek | AI / LLM processing |
| xAI | AI / LLM processing |
| [Hosting / Cloud Provider] | Infrastructure hosting |
| [Transactional Email] | Service and notification email |
| [Error Monitoring] | Application error monitoring |
| [Product Analytics] | Product usage analytics |
AI/LLM Sub-processors receive only the prompts and content required for the invoked feature, and do not use Customer content to train their models (Section 7.3).
This is a first-pass draft prepared for review and finalization by qualified legal counsel before use. It does not constitute legal advice and is not yet in effect. Direct questions to [[email protected]].