The data-processing terms that govern how PitchSense processes customer personal data on behalf of its customers.
This Data Processing Addendum ("DPA") forms part of the agreement between the customer identified in the applicable order form ("Customer") and HSV Media Private Limited, operating as PitchSense ("PitchSense"), for the provision of PitchSense services (the "Agreement").
For Customer Personal Data, Customer is the Controller/Data Fiduciary and PitchSense is the Processor/Data Processor.
PitchSense may act as an independent Controller/Data Fiduciary for limited personal data processed for its own account administration, security, support, website operation, product analytics, billing and legal compliance. Such processing is governed by the PitchSense Privacy & Personal Data Notice and is outside this DPA to the extent PitchSense independently determines its purposes and means.
PitchSense will process Customer Personal Data only:
If PitchSense reasonably believes an instruction violates Applicable Data Protection Law, it will notify Customer and may suspend the affected processing until the issue is resolved.
Customer is responsible for:
PitchSense will ensure that personnel authorised to process Customer Personal Data:
PitchSense will maintain reasonable technical and organisational measures appropriate to the nature of Customer Personal Data and processing risks, including:
Additional measures are listed in Annex B.
Customer gives PitchSense general written authorisation to use the subprocessors listed at https://pitchsense.ai/trust/subprocessors and in Annex C.
PitchSense will:
If the parties cannot resolve an objection, PitchSense may provide a commercially reasonable alternative or permit termination of the materially affected service without penalty for the unused prepaid period.
PitchSense may submit Customer Personal Data to approved commercial AI API providers to deliver roleplays, evaluations and other AI features. Current AI providers include OpenAI and Anthropic for text inference and ElevenLabs for voice synthesis and speech-to-text, as listed in Annex C.
PitchSense configures and contracts for commercial use so that Customer Personal Data is not used to train general-purpose provider models. Where a provider's standard terms would otherwise permit use of submitted data for model development or improvement, PitchSense applies the available account-level opt-out or equivalent contractual control.
Unless a verified zero-data-retention arrangement applies, AI providers may retain API inputs and outputs for the periods listed in Annex C for abuse monitoring, security or legal compliance. PitchSense does not represent that zero-data retention applies unless the relevant account and endpoint configuration has been contractually and technically verified.
Taking into account the nature of processing, PitchSense will reasonably assist Customer with requests to access, correct, update, delete, restrict, object to or export Customer Personal Data, where applicable.
If PitchSense receives a request relating to Customer-controlled data, PitchSense will:
Customer is responsible for determining the appropriate response.
PitchSense will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data.
The notification will include available information about:
PitchSense may provide information in phases as the investigation progresses. Notification does not constitute an admission of fault or liability.
Customer is responsible for regulatory and individual notifications where Customer is the Controller/Data Fiduciary, with PitchSense providing reasonable assistance.
Retention of roleplay recordings, transcripts, evaluations, scores, reports and manager notes follows the schedule documented in the Order Form, workspace configuration or another written instruction.
If no customer-specific schedule is documented, the default retention period is 12 months.
On termination or Customer's written request, PitchSense will return or delete Customer Personal Data from active systems within 30 days, unless retention is required by law.
Residual copies in backups will expire according to PitchSense's standard backup lifecycle within a maximum of 90 days, unless longer retention is legally required.
Security and audit logs may be retained for a longer period where reasonably necessary for security, legal compliance or dispute resolution.
PitchSense will make available information reasonably necessary to demonstrate compliance with this DPA, which may include security documentation, audit summaries, policies and written responses.
Customer may request an audit no more than once annually, unless required by a regulator or following a material security incident. Audits must:
PitchSense will provide reasonable information and assistance required for Customer's data-protection impact assessment or regulator consultation relating to the service, taking into account the nature of processing and information available to PitchSense.
Customer Personal Data is hosted and processed in the United States.
Customer authorises transfers to the United States and other disclosed subprocessor locations, subject to appropriate safeguards.
Where the EU GDPR applies and Customer Personal Data is transferred from the EEA to a country without an adequacy decision, the European Commission Standard Contractual Clauses adopted under Decision (EU) 2021/914 are incorporated as follows unless the parties sign a different transfer mechanism:
For UK transfers, the applicable UK International Data Transfer Addendum or another recognised mechanism applies.
Unless legally prohibited, PitchSense will notify Customer of a binding request by a public authority for Customer Personal Data. PitchSense will review the request for legal validity and disclose only the data legally required.
Liability under this DPA is subject to the exclusions and limitations in the Agreement, except where prohibited by Applicable Data Protection Law.
If this DPA conflicts with the Agreement on processing of Customer Personal Data, this DPA controls. If incorporated Standard Contractual Clauses conflict with this DPA, the Standard Contractual Clauses control for the relevant transfer.
This DPA remains effective for as long as PitchSense processes Customer Personal Data under the Agreement.
Provision of the PitchSense AI sales-readiness and learning platform.
For the term of the Agreement and the deletion/return period described in Section 11.
Not intentionally required. Customer must not submit special-category or sensitive data unless expressly approved in writing and protected by additional agreed safeguards.
Continuous or on-demand during Customer's use of the service.