Version 9.14.26 · September 14, 2026
This Data Processing Agreement (this “DPA”, also referred to in the parties’ agreements and on the Platform as the “Data Processing Addendum”) is entered into between Audacity Advisory Corp, d/b/a AI Reserve, a Delaware C corporation (“Audacity”, “we”, “us” or “our”), and the customer identified in the signature block below or in the agreement into which this DPA is incorporated (the “Customer”).
This DPA forms part of, and is incorporated into, the agreement between Audacity and the Customer governing the Customer’s access to and use of the Platform and Services: the AI Rights Agreement, an Evaluation Term Agreement, or the Terms of Service, as applicable (the “Agreement”). Where the Agreement is the AI Rights Agreement, this DPA is incorporated into it by reference and does not form an addendum to it. This DPA governs Audacity’s Processing of Personal Data on the Customer’s behalf in connection with the Services and takes effect on the date last signed below or the effective date of the Agreement, whichever is earlier (the “Effective Date”).
1.1 Roles. As part of providing the Services, Audacity Processes Personal Data on the Customer’s behalf. Audacity acts as a Processor (and as an independent Controller of Service Data as described in Section 9); the Customer acts as a Controller (or, where the Customer causes Audacity to Process Personal Data on behalf of the Customer’s own customers, as a Processor). Capitalized terms not defined in this DPA have the meanings given in the Agreement.
1.2 GDPR Gating. The European Annex (Annex 2) and the standard contractual clauses referenced therein apply solely to Processing of Personal Data that is subject to the GDPR or FADP. For Customers not subject to the GDPR or FADP, Annex 2 does not apply and imposes no obligations on either party. The State Privacy Laws Annex (Annex 3) governs Processing subject to applicable U.S. state privacy laws.
1.3 Definitions.
“Personal Data” means information relating to an identified or identifiable natural person that Audacity Processes on the Customer’s behalf in connection with the Services.
“Processing” (and its cognates) means any operation performed on Personal Data, whether or not by automated means.
“Data Subject”, “Controller”, “Processor”, and “Supervisory Authority” have the meanings given in applicable Data Protection Laws.
“Data Protection Laws” means the privacy and data-protection laws applicable to the Processing of Personal Data under this DPA, including as applicable the GDPR, the UK GDPR, the Swiss FADP, and applicable U.S. state privacy laws.
“Collaboration Surface” means an optional communication surface operated by a disclosed Subprocessor through which the Customer’s users choose to interact with the Services (for example, a Slack Connect shared channel, including its optional mention agent).
“Customer Data” means data submitted to the Services by or on behalf of the Customer, including Inputs and Outputs as defined in the Agreement.
“Stored Customer Content” means the Customer Data stored by the platform: account data, uploaded documents, and any opt-in stored content (such as prompt and response text stored for chat history where the Customer’s organization has content storage enabled).
“Service Data” means data Audacity collects or generates in connection with providing and operating the Services: usage metadata (model, token counts, cost, latency, status, and user, key, and team attribution), billing and ledger records, administrative and access audit logs, and support and account records. Service Data contains no prompt or response content. Classification text snapshots are Stored Customer Content and are not Service Data.
“Derived Data” means data generated by Audacity from use of the Services that does not identify, and cannot reasonably be used to identify, the Customer or any individual.
“Subprocessor” means a third party engaged by Audacity that Processes Personal Data solely on Audacity’s behalf and on the Customer’s documented instructions.
“Subprocessor List” means the current list of Subprocessors maintained on the Platform as set out in Annex 5.
“Information Security Incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data Processed by Audacity under this DPA.
“SCCs” means the standard contractual clauses approved by the European Commission (Implementing Decision (EU) 2021/914), as populated under Annex 2.
“Services” and “Platform” have the meanings given in the Agreement.
2.1 Documented Instructions. Audacity will Process Personal Data as a Processor only in accordance with the Customer’s documented instructions. The parties agree that this DPA, the Agreement, and the configuration choices the Customer makes in the AI Reserve console (including model and provider selections, routing policies, and content-storage, retention, classification, and consent settings) constitute the Customer’s documented instructions. Audacity will Process Personal Data in accordance with those instructions unless required to do otherwise by applicable law. In such a case, Audacity will inform the Customer of the requirement before Processing, unless legally prohibited from doing so. The details of Processing are set out in Annex 1.
2.2 Provider Selection Is an Instruction. The data-handling characteristics of each AI model provider available through the Services (including, as applicable, whether the provider trains or fine-tunes on inputs, its data retention, its processing region, and its role under this DPA) are disclosed on the Platform’s Provider Data Handling page and may be updated from time to time as provider policies change. The Customer’s (or its authorized users’) selection of an AI model or provider constitutes the Customer’s instruction to route the associated request content to that provider on the disclosed terms. Where the provider serving a request changes through a disclosed failover chain, the Customer’s selection likewise constitutes the Customer’s instruction to route the request to the failover provider on that provider’s disclosed terms. Sending prompts and responses to the model providers the Customer’s organization has selected is the performance of the Services itself, not a disclosure to a third party for that party’s own purposes, except that, for providers identified on the Subprocessor List acting as independent controllers (Section 6.2), the Customer’s selection constitutes its authorization of, and instruction to effect, the associated disclosure on that provider’s disclosed terms. Where the Customer’s administrator configures organization-wide instructions or organization-level context, that content is sent to the selected model provider with every request as part of the request content.
2.3 No Sale; Limits on Disclosure. Customer Data is never sold. The only Customer Data that leaves the platform is:
Nothing is shared for advertising, analytics, or any other purpose. Disclosure may occur where required by law (Section 2.4). For organizations that adopt a Collaboration Surface (Section 1.3), the messages participants choose to post in that surface and the completions returned there are processed by the operating Subprocessor as disclosed on the Subprocessor List. Where the mention agent is invoked in a message thread, or responds to a follow-up in a thread in which it is already participating, the messages in that thread (including messages posted by participants who did not invoke the agent) are included as context in the request sent to the selected model provider, on the same terms as other prompt content under the first bullet above. The Customer’s API traffic never passes through a Collaboration Surface; only content participants themselves post there is processed by that Subprocessor.
2.4 Notices to Customer. Audacity will promptly inform the Customer in writing if, in Audacity’s opinion, a Customer instruction infringes applicable Data Protection Laws. Audacity will, to the extent legally permitted, inform the Customer if Audacity receives a legally binding request for disclosure of Customer Data by a law enforcement authority.
3.1 Security Measures. Audacity will implement and maintain the technical, administrative, physical, and organizational measures described in Annex 4 (the “Security Measures”), and may update them from time to time so long as such updates do not substantially diminish the overall level of security provided by the Security Measures.
3.2 Personnel. Audacity requires personnel authorized to access Personal Data to be subject to appropriate confidentiality obligations, and limits access to Personal Data to only that which is specifically required to complete a given task, on a least-privilege basis (each person and system receives only the minimum access needed for the task), with access events audit-logged.
3.3 Incident Notification. Audacity will notify the Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of an Information Security Incident affecting Personal Data, with then-available details and recommended mitigations, and will keep the Customer reasonably informed as material information becomes available. The Customer is solely responsible for its own legal obligations to notify regulators and affected individuals.
3.4 Customer Responsibilities for Security. The Customer is solely responsible for securing its credentials, systems, and devices and for backing up its Personal Data, and has determined that the Services and the Security Measures are adequate for its needs.
Taking into account the nature of the Processing, Audacity will provide the Customer with reasonable assistance, to the extent technically feasible, in responding to Data Subject requests to exercise rights under applicable Data Protection Laws, at no charge. Audacity’s then-current professional services rates apply only where the assistance requested goes beyond the platform’s standard self-service controls. If Audacity receives such a request directly, it will notify the Customer and advise the Data Subject to submit the request to the Customer, who is solely responsible for responding. Self-service controls also satisfy many Data Subject requests directly: users can delete their own chats, documents, or entire account from their profile (Section 8.6).
The Customer is solely responsible for providing all required notices to, and obtaining all required consents from, Data Subjects, and represents and warrants that there is and will be a valid legal basis for Audacity’s Processing of Personal Data under this DPA throughout the term of the Agreement.
Where the voice-cloning capability is enabled for the Customer’s organization, the Customer represents and warrants that it has obtained, from each individual whose voice recording is uploaded, consent in the form required by applicable law to the creation and use of a derived voice model, and that it can produce evidence of that consent on request. The Customer is also responsible for informing its authorized users that the Customer’s administrators can view and export their account information, including the date on which each user last signed in, and that Audacity’s support personnel can access that information in providing support.
6.1 General Authorization. The Customer generally authorizes Audacity to engage third parties as Subprocessors to Process Personal Data in connection with the Services. A current list of Subprocessors, including their functions and jurisdictions, is maintained on the Platform at the location set out in Annex 5. The Customer’s execution of this DPA constitutes the Customer’s authorization of the Subprocessors identified on the Subprocessor List as of the Effective Date, and of Subprocessors added thereafter, in accordance with Section 6.3.
6.2 Subprocessor Characteristics; Independent Controllers.
A third party that Processes Personal Data solely on Audacity’s behalf and on the Customer’s instructions is a Subprocessor. A provider that processes data for its own purposes, including to train or fine-tune its models, acts as an independent controller with respect to such processing and not as Audacity’s Subprocessor. Subprocessors are identified as such on the Subprocessor List, and the Customer’s selection of any such provider constitutes the Customer’s authorization of, and instruction to effect, the associated disclosure.
Except for entries marked on the Subprocessor List as pending verification, the Subprocessor List states, for each entry, its relevant data-handling characteristics, including as applicable whether it trains or fine-tunes on data, its data retention, and its processing region (with per-provider detail on the Provider Data Handling page).
Models served by providers that soften a platform data guarantee (such as training-permitted terms, retention that cannot be turned off or verified, or PRC-hosted processing) are additionally locked for every organization until the Customer’s own administrator enables the corresponding consent in the AI Reserve console. Absent that consent, such models are excluded from routing for the Customer, and requests to them are refused.
6.3 Changes; Notice; Objection. Audacity will update the Subprocessor List before any new Subprocessor Processes Personal Data, and no new Subprocessor other than a model provider will begin Processing Personal Data until the objection period set out in this Section 6.3 has expired. Notice of a change is given by updating the Subprocessor List and by either update on the platform or email to relevant Customers. The Customer may object to a new Subprocessor on reasonable data-protection grounds by written notice within thirty (30) days of notice.
On objection, the parties will cooperate in good faith to resolve the objection: where the new Subprocessor is a model provider, the Customer’s own routing controls (model selection and a provider allowlist that restricts the Customer’s traffic to approved providers, enforced at the gateway) prevent the Customer’s traffic from reaching it, and Audacity will apply that restriction to the Customer’s account on request. A new model provider receives Customer content only when the Customer’s organization’s routing sends traffic to it (Section 2.2). Where the objection cannot reasonably be resolved by such controls or other measures, the Customer may terminate the affected Services in accordance with the Agreement.
6.4 Requirements for Engagement. When engaging any Subprocessor, Audacity will enter into a written contract imposing data protection obligations no less protective than those in this DPA to the extent applicable for the Services provided. For clarity, the preceding sentence applies to Subprocessors as defined in Section 1.3; providers acting as independent controllers under Section 6.2 process under their own disclosed terms pursuant to the Customer’s selection and authorization, and that processing is not subject to this Section 6.4.
The Customer may audit Audacity’s compliance with this DPA up to once per year (and as required by applicable law), with at least two weeks’ advance written notice and a proposed audit plan, subject to a mutually acceptable non-disclosure agreement. Given the nature of the Services, on-site audits are not generally necessary; however, an on-site audit is available where a Supervisory Authority requires it, or following a confirmed Information Security Incident affecting the Customer’s Personal Data. Audacity will complete reasonable written security questionnaires up to once per year in support of such audits. Once Audacity’s SOC 2 Type II examination (in progress as of the version date of this DPA) results in an issued report, a current SOC 2 Type II, ISO, NIST, or similar report issued within the prior twelve months, where controls are unchanged, will be accepted in lieu of an audit of the covered controls. Audits are at the Customer’s sole expense, and the Customer shall reimburse Audacity for time expended at its then-current professional services rates.
8.1 Deletion on Verified Request. At any time during the term of the Agreement, on a verified request, the Customer Data stored (account data, uploaded documents, and any opt-in stored content: together, the Stored Customer Content) is deleted within a fourteen (14)-day window of the verified request, to the extent technically possible, subject to retention required by applicable law as set out in Section 8.4; billing and audit records are retained as set out in Section 8.3. A “verified request” is a written deletion request from the Customer’s Admin User or other authorized representative whose identity and authority Audacity has verified. Deletion requests may be directed to the Customer’s AI Reserve point of contact or to security@aireserve.com.
8.2 Return and Deletion at End of Services. Upon cessation of the Services involving Processing of Personal Data (the “Cessation Date”), Audacity will cease Processing except for storage or as otherwise permitted under this DPA. On the Customer’s written request made within fourteen (14) days after the Cessation Date, Audacity will, within fourteen (14) days and to the extent technically possible, either (i) return a complete copy of structured Personal Data in a commonly used, machine-readable format and then delete or anonymize remaining copies, or (ii) delete or anonymize all structured Personal Data. Absent instruction, Audacity will delete or anonymize such data after the storage period. Full data deletion is available on account offboarding.
8.3 Billing and Audit Records. Billing and audit records (Service Data such as usage metadata: model, token counts, cost, latency, status, and user, key, and team attribution; invoices and ledger entries; and administrative and access audit logs) are retained as follows: invoices and ledger entries for three (3) years, and administrative and access audit logs and usage metadata for 24 months after account closure, in each case for billing integrity, audit, and compliance (Section 9). These records contain no prompt or response content. Deletion under Sections 8.1 and 8.2 removes Stored Customer Content; billing and audit records are retained as set out in this Section 8.3. The ownership and consent records for the voice-cloning capability described in Annex 1 are retained for five (5) years after account closure. Authentication records, including the last sign-in timestamp, are retained for the life of the account.
8.4 Legal Retention. Audacity may retain Personal Data where and for so long as required or expressly permitted by applicable law, protected under this DPA and Processed only as necessary for the purpose that required its retention. This DPA refers to this as retention required by applicable law.
8.5 Backups. Deleted content is removed from production systems promptly and from backups on their rotation schedule (database backups currently roll off after seven (7) days).
8.6 Self-Service Controls. Independently of this Section 8: users can delete all their chats and documents while keeping their account, or delete their account entirely, from their profile; and enterprise administrators can permanently delete all previously stored content for their organization on demand (including classification text snapshots), disable content storage for their organization entirely, and set an automatic retention window that deletes stored content older than a chosen number of days. Deleting a user account deletes that user’s stored content; deleting an organization deletes all of its stored content. Billing and audit records are retained in each case as set out in Section 8.3.
The Customer acknowledges that Audacity may collect, use, and disclose Service Data for its own business purposes, including accounting, billing, audit, and compliance; to provide, improve, and maintain the Services; to investigate fraud or misuse; and to de-identify data for lawful business purposes. In respect of such Processing, Audacity acts as an independent Controller, complies with applicable Data Protection Laws, and applies safeguards no less protective than the Security Measures where possible. Service Data contains no prompt or response content (Section 1.3).
Audacity may use aggregated, de-identified usage data, metadata, and derived data generated through use of the Services to develop, train, improve, and optimize its, third-party AI models and to enhance the performance, functionality, and security of the Services. Identifiable Customer Data is never used by Audacity to train models; any product-improvement use is limited to de-identified, aggregated data as set out in this Section 10. The use of classification text snapshots to measure and improve classifier quality is within the permission in this Section 10, so long as classifiers are used in a manner consistent with de-identification outlined in this section.
Audacity shall not use Customer Data in a manner that identifies the Customer or any individual, or that would reasonably be expected to permit re-identification of such data, when used for AI model training or product improvement, and will not re-identify de-identified Personal Data.
11.1 Liability. Audacity’s aggregate liability arising out of or relating to this DPA is subject to the limitations, exclusions, and caps on liability set out in the Agreement (for the Terms of Service, its Limitation of Liability section).
11.2 Order of Precedence. Except as modified by this DPA, the Agreement remains in full force. In any conflict between this DPA and the other documents comprising the Agreement, the order of precedence set out in the Agreement controls, provided that this DPA prevails over the other documents solely with respect to the Processing of Personal Data.
11.3 Updates. Audacity may update the Subprocessor List and the Security Measures as set out in Sections 6 and 3. Material changes to this DPA itself are made in accordance with the Agreement’s modification provisions.
11.4 Governing Law; Severability. This DPA is governed by the law governing the Agreement. If any portion of this DPA is held invalid or unenforceable, the remainder remains in full force and effect.
This DPA may be executed in counterparts, including by electronic signature, each of which is deemed an original. Where this DPA is incorporated by reference into an Agreement executed by both parties, execution of that Agreement constitutes execution of this DPA and no separate signature is required.
AUDACITY ADVISORY CORP (d/b/a AI Reserve)
Signature:
Name:
Title:
Date:
CUSTOMER
Signature:
Name:
Title:
Date:
Data Importer (Processor): Audacity Advisory Corp (d/b/a AI Reserve), a U.S. corporation, 860 Broadway, New York, NY 10003, United States. Data protection contact: security@aireserve.com. Role: Processor (and independent Controller of Service Data, Section 9).
EU Representative (Article 27 GDPR): Instant EU GDPR Representative Ltd, Office 2, 12A Lower Main Street, Lucan, Co. Dublin, K78 X5P8, Ireland, contact@gdprlocal.com. UK Representative (Article 27 UK GDPR): GDPRLocal Ltd., 1st Floor Front Suite, 27-29 North Street, Brighton, England BN1 1EB, contact@gdprlocal.com.
Data Exporter (Controller): The Customer / counterparty to the Agreement. Address and contact as in the signature block or the Agreement. Role: Controller (or Processor on behalf of its own customers, Section 1.1).
Categories of Data Subjects. Authorized users, employees, customers, and prospective customers of the Customer, in each case as the Customer causes Audacity to Process in providing the Services. Where the optional voice-cloning capability is enabled for the Customer’s organization, this also includes the individuals whose voice recordings the Customer causes to be Processed (see Sensitive Data below).
Categories of Personal Data. Personal details; authentication details; technological details (IP addresses, identifiers, device data); user-service details (support content, logs); demographic and profile data; transactional and payment data; communications content and metadata; employment and education information, in each case only as the Customer causes Audacity to Process. Where the optional voice-cloning capability is enabled for the Customer’s organization, this also includes voice recordings and derived voice models (see Sensitive Data below). Where the Customer uses the image, audio, or video generation features, this also includes the media inputs the Customer supplies for that generation.
Sensitive Data. Voice cloning is the only source of Sensitive Data, and only as an optional capability: voice recordings and derived voice models (biometric-class data) are Processed only where the optional voice-cloning capability has been expressly enabled for the Customer’s organization at the Customer’s request; uploads require the recorded consent of the individual whose voice is being cloned, obtained and recorded before upload; such recordings and derived voice models are Processed by xAI (a Subprocessor, Annex 5), which retains the source voice recording only for as long as the derived voice model exists and deletes it with the voice model, and the derived voice model is retained until the Customer deletes the voice, and in any event is deleted no later than thirty (30) days after the voice-cloning capability is disabled for the Customer’s organization or the account is closed, whichever is earlier, otherwise subject to Section 8. Audacity itself stores no voice audio, only the ownership and consent record, retained as an audit record (Section 8.3).
Separately, and disclosed here for completeness although it does not by itself involve Sensitive Data: at the Customer’s request, Audacity may provision for the Customer’s organization a private set of text, image and video models served with the upstream provider’s content-moderation filter disabled (“Advanced Themes”). Advanced Themes are disabled by default for every organization, are API-only, and are not listed in the portal or the model catalog. Serving requires all three of the following: (i) Audacity has provisioned the models for the Customer’s organization; (ii) the Customer’s Admin User has switched access on for the organization; and (iii) the specific API key has been enabled by a user who has personally accepted the then-current third-party policy terms (Terms of Service, Section 3.2), which acceptance Audacity records with its version and timestamp. Every request is attributed in the Customer’s usage ledger to the serving API key (and its bound user where the key is personal), the model and the timestamp, and usage is monitored in accordance with Audacity’s agreement with the upstream provider. Content that is illegal in any applicable jurisdiction is prohibited, including any sexual content involving minors, non-consensual sexual content, and content that sexualizes real, identifiable individuals without their consent; violations result in immediate suspension and, where required, reporting to the appropriate authorities, and Sections 1.5 and 1.6 of the Terms of Service apply. Inputs and Outputs for Advanced Themes are Processed by the providers identified for those models on Audacity’s published provider data handling page (Alibaba Cloud, MuleRouter and WaveSpeed, each a Subprocessor, Annex 5) on the terms disclosed there; Audacity itself stores no Advanced Themes content beyond the usage metadata described in Section 2.
Nature and Purpose of Processing. Processing operations required to provide the Services as initiated and configured by the Customer: routing AI requests to the model providers the Customer selects; generating images, audio, and video through the media providers the Customer selects; operating chat history, search, document, and analytics features where enabled; metering, billing, and spend controls; security, authentication, and abuse prevention; and customer support.
Duration / Retention. As determined under the Agreement and Section 8 of this DPA.
Application. This Annex 2 applies solely to Processing of Personal Data subject to the GDPR or FADP. For Customers not subject to the GDPR or FADP, this Annex imposes no obligations on either party.
1. Processing. Where Audacity receives an instruction from the Customer that, in its reasonable opinion, infringes the GDPR, Audacity shall inform the Customer. The Customer acknowledges that its instructions shall comply with the GDPR and all other applicable laws.
2. Impact Assessments and Prior Consultation. Taking into account the nature of the Processing and the information available to it, Audacity shall provide reasonable assistance to the Customer, at the Customer’s sole cost (at Audacity’s then-current professional services rates), with data protection impact assessments and prior consultations with Supervisory Authorities that the Customer reasonably considers required under Articles 35 or 36 of the GDPR, solely in relation to Processing of Personal Data by Audacity.
3. Restricted Transfers. To the extent any Processing under this DPA involves an EU restricted transfer from the Customer to Audacity, the parties shall comply with the SCCs, which are deemed entered into by the parties and incorporated by reference into this DPA, populated as follows:
4. UK and Swiss Transfers. To the extent any Processing involves a UK restricted transfer, the SCCs apply as varied by the UK International Data Transfer Addendum, with Tables 1–3 populated with the details in Annex 1 and this Annex and Table 4 completed with the “Data Importer” box ticked. The parties agree to be bound by the Mandatory Clauses of the UK Addendum. To the extent any Processing involves a Swiss restricted transfer, the SCCs apply with the following substitutions: “GDPR” means the FADP; “European Union”, “Union”, and “Member State(s)” mean Switzerland; and “supervisory authority” means the Swiss Federal Data Protection and Information Commissioner. Nothing in the applicable SCCs limits Data Subjects’ rights under Clause 18(c) to bring proceedings in Switzerland where Switzerland is their place of habitual residence.
5. New Transfer Mechanisms. Audacity may, on notice, vary this DPA and replace the relevant SCCs with any new or replacement form of the SCCs prepared and populated accordingly, or with another transfer mechanism that enables the lawful transfer of Personal Data in compliance with Chapter V of the GDPR. On specific written request of a Supervisory Authority, a Data Subject, or a further Controller (with suitable supporting evidence), Audacity shall provide the Customer an executed version of the relevant SCCs for countersignature and onward provision.
6. Operational Clarifications. When complying with transparency obligations under Clause 8.3 of the SCCs, the Customer shall protect Audacity’s and its licensors’ trade secrets, confidential information, and commercially sensitive information. The Subprocessor terms of Section 6 of this DPA apply to Audacity’s use of Subprocessors under the SCCs, and the Customer’s authorization under Section 6 constitutes documented instruction to effect disclosures under Clause 8.8. Audit rights under Clauses 8.9(c)–(d) are subject to Section 7 of this DPA. Certification of deletion under Clauses 8.5 and 16(d) shall be provided on the Customer’s written request.
7. Transfer Impact Assessments. The parties shall carry out and document an assessment of the restricted transfers made under this DPA and any onward transfers, taking into account the circumstances of the transfers, the laws and practices of the destination countries (including any government access laws), and any supplementary measures applied. Each party shall provide the other with the reasonable assistance and information required to complete the assessment, and the assessment shall be reviewed at least annually and on any material change in the law or practice of a destination country.
For purposes of this Annex, “business”, “commercial purpose”, “sell”, “share”, “targeted advertising”, and “service provider” have the meanings given in the applicable U.S. state privacy laws (the “State Privacy Laws”), and “personal information” means Personal Data governed by those laws.
It is the parties’ intent that Audacity is a service provider with respect to personal information. Audacity: (a) acknowledges that personal information is disclosed only for the limited and specified purposes described in the Agreement; (b) will comply with applicable obligations under the State Privacy Laws and provide the same level of privacy protection they require; (c) agrees the Customer may take reasonable steps to ensure Audacity’s use of personal information is consistent with the Customer’s obligations; (d) will notify the Customer if it determines it can no longer meet its obligations; and (e) agrees the Customer may take reasonable steps to stop and remediate unauthorized use.
Audacity shall not (a) sell or share personal information; (b) retain, use, or disclose personal information for any purpose other than providing the Services; (c) retain, use, or disclose personal information outside the direct business relationship; or (d) combine personal information with data from other sources, except in each case as necessary to provide the Services or as otherwise permitted for a service provider under the State Privacy Laws. Audacity certifies that it understands and will comply with these obligations. Audacity’s engagement of Subprocessors is authorized by the Customer’s general authorization in Section 6 and satisfies any obligation to identify subcontractors under the State Privacy Laws.
Sensitive Personal Information. The parties acknowledge that biometric information, including voice recordings and derived voice models Processed through the optional voice-cloning capability, constitutes sensitive personal information (or sensitive data) under the State Privacy Laws. Audacity will not collect, use, retain, or disclose such information except as necessary to perform the Services, and will honor, and provide the Customer with reasonable assistance in honoring requests to limit the use or disclosure of sensitive personal information to the extent required by the State Privacy Laws.
Biometric Statutes. Where a biometric privacy statute that is not a State Privacy Law applies to Processing under this DPA, the Customer remains responsible for the notice, consent, and retention-schedule obligations that statute imposes on it, and Audacity will provide reasonable assistance at the Customer’s request.
Audacity maintains the following technical, administrative, physical, and organizational measures, which reflect how the platform actually operates:
A current list of Subprocessors engaged by Audacity to Process Personal Data, including their functions and jurisdictions, together with the identification of providers acting as independent controllers, is maintained and available on the Platform at privacy.aireserve.com/subprocessors, which is the authoritative Subprocessor List for purposes of this DPA. Per-provider training, retention, and processing-region detail is documented at privacy.aireserve.com/data-handling. The Customer’s execution of this DPA constitutes the Customer’s authorization of the Subprocessors identified on the Subprocessor List as of the Effective Date and of Subprocessors added thereafter in accordance with Section 6, including its notice and objection mechanics (Section 6.3).