LegalFaster AI, Inc. d/b/a Faster Wholesale

Data Processing Addendum

This Data Processing Addendum (“DPA”) forms part of the Terms of Service or other written agreement (the “Agreement”) between Faster AI, Inc. d/b/a Faster Wholesale (“Processor,” “we”) and the customer identified in the Agreement (“Controller,” “Customer”). It applies when we process Personal Data on Customer’s behalf. If the Agreement and this DPA conflict on data protection, this DPA controls.

1. Definitions

“Data Protection Laws” means all laws applicable to processing under this DPA, including the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and US state privacy laws including the California Consumer Privacy Act as amended (“CCPA”). “Controller,” “Processor,” “Data Subject,” “Personal Data,” “Processing,” and “Supervisory Authority” have the meanings given in the GDPR, and “Business,” “Service Provider,” “Sell,” and “Share” have the meanings given in the CCPA. “Customer Personal Data” means Personal Data contained in Customer Data that we process under the Agreement.

2. Roles and scope

Customer is the Controller (or Business, or a Processor acting for another controller) and we are the Processor (or Service Provider) for Customer Personal Data. Each party will comply with its own obligations under Data Protection Laws. Customer is responsible for the lawfulness of the Personal Data it provides and for having a legal basis and any required notices or consents, including consent to record meetings and calls where the law requires it.

The subject matter, duration, nature and purpose of processing, the types of Personal Data, and the categories of Data Subjects are described in Annex 1.

3. Our processing obligations

We will:

4. De-identified and aggregated data

Customer instructs us to process Customer Personal Data to provide, secure, support, and improve the Services, which includes developing, training, fine-tuning, and evaluating the AI models and features used to deliver them, and includes onward processing by the model providers listed in our Subprocessors list for the same purposes under their own terms. We may also create de-identified and aggregated data, which we keep in de-identified form and do not attempt to re-identify.

5. Subprocessors

Customer gives general authorization for us to engage subprocessors. Our current subprocessors are listed in the Subprocessors list referenced in the Agreement. We will impose data protection obligations on each subprocessor that are no less protective than this DPA, and we remain liable for their performance.

We will give Customer at least 30 days’ notice before adding or replacing a subprocessor, by email to the address on the account or through the Services. Customer may object on reasonable data protection grounds within that period. If we cannot offer a reasonable alternative, Customer may terminate the affected Services and receive a pro-rata refund of prepaid fees for the unused term.

6. Security

We will implement and maintain appropriate technical and organizational measures as described in Annex 2, taking into account the state of the art, costs, and the risks to Data Subjects. We may update these measures provided they do not materially reduce the level of protection.

7. Personal Data breach

We will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data breach affecting Customer Personal Data. The notice will describe the nature of the breach, the likely consequences, the measures taken or proposed, and a contact point, to the extent known. We will reasonably assist Customer with its own notification obligations. Our notice is not an acknowledgment of fault.

8. Assistance

Taking into account the nature of processing, we will assist Customer with:

9. Audits

We will make available information reasonably necessary to demonstrate compliance with this DPA, including third-party reports where we hold them. Customer may, no more than once in any 12-month period and on at least 30 days’ notice, conduct an audit of our processing, during business hours, without unreasonably disrupting our operations, and subject to confidentiality. If a Supervisory Authority requires a further audit, we will cooperate. Customer bears the cost of audits it conducts.

10. International transfers

Where Customer Personal Data protected by the GDPR is transferred to a country without an adequacy decision, the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), Module Two (controller to processor) or Module Three (processor to processor) as applicable, are incorporated into this DPA and completed as follows:

For UK transfers, the UK International Data Transfer Addendum (Version B1.0) is incorporated, with Tables 1 to 3 populated by this DPA and Table 4 selecting “neither party.” For Swiss transfers, references to the GDPR are read as references to the Swiss FADP, the Swiss Federal Data Protection and Information Commissioner is the competent authority, and “member state” includes Switzerland.

11. Return and deletion

On termination of the Agreement, Customer may export Customer Personal Data for 30 days. We will then delete it within 90 days, except where law requires retention or it remains in routine backups that are overwritten on a rolling 35-day schedule. We will confirm deletion in writing on request.

12. Liability

Each party’s liability under this DPA is subject to the limitations and exclusions in the Agreement, except where Data Protection Laws prohibit that limitation.

13. Term and order of precedence

This DPA applies for as long as we process Customer Personal Data. If the Standard Contractual Clauses conflict with this DPA, the Clauses control.

Annex 1 — Description of processing

Categories of Data Subjects: Customer’s employees and contractors who use the Services (Authorized Users); Customer’s own customers, prospects, and their staff; participants in meetings and calls recorded through the Services; senders and recipients of email and calendar invitations connected to the Services.

Categories of Personal Data: name, job title, employer, business contact details (email, phone, address); account credentials and profile data; contact and CRM records and notes; business card images and extracted details; audio recordings of in-person meetings, phone calls and video meetings, transcripts and summaries; email and calendar content from connected accounts; prompts and AI-generated output; device identifiers, IP address, usage logs; approximate and precise location where enabled; billing contact details.

Special categories: none requested or required. Customer should not submit special category data. Incidental special category data may appear in free-text notes, recordings, or email content; where it does, we apply the measures in Annex 2.

Nature and purpose: hosting, storage, transcription, indexing and search, AI-assisted drafting and answering, calendar and meeting preparation, route planning, and related support, all to provide the Services described in the Agreement.

Duration: the term of the Agreement plus the retention periods in Section 11.

Frequency: continuous, for as long as Authorized Users use the Services.

Annex 2 — Technical and organizational measures

Signature

Where this DPA is executed as a standalone document:

Faster AI, Inc. d/b/a Faster Wholesale — Name: __ Title: _ Date: ___

Customer — Entity: __ Name: _ Title: Date: ___