Last Updated: March 2026

Legal

Data Processing Addendum

This Data Processing Addendum ("DPA") forms part of the agreement between Cultara ("Processor", "we", "our", or "us") and the customer entity using the Cultara platform ("Controller", "Customer", or "you"). This DPA governs the processing of Personal Data by Cultara on behalf of the Customer in connection with the Cultara platform and related services.

By using the platform, the Customer represents and warrants that it has full authority to enter into this DPA and to provide, upload, authorize, and process data in accordance with its terms, including where the Customer acts on behalf of clients, portfolio companies, affiliates, or other third parties.

1. Purpose and Scope

This DPA applies where Cultara processes Personal Data on behalf of the Customer in connection with the Cultara platform, application, analytics services, support services, and related operational activities.

This DPA is intended to support compliance with applicable data protection laws, including privacy, security, and data processing requirements that may apply to the Customer’s use of the Service.

2. Definitions

For purposes of this DPA:

  • Customer Data means data uploaded, submitted, or otherwise provided by or on behalf of the Customer to the Cultara platform.
  • Personal Data means information relating to an identified or identifiable individual, as defined under applicable data protection law.
  • Processing means any operation performed on Personal Data, including collection, storage, use, analysis, organization, retrieval, disclosure, deletion, or destruction.
  • Controller means the party that determines the purposes and means of processing Personal Data.
  • Processor means the party that processes Personal Data on behalf of the Controller.
  • Subprocessor means a third party engaged by Cultara to process Customer Data in support of the Service.
  • Security Incident means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data.

3. Data Roles

Customer as Controller

The Customer determines the purposes and means of processing Customer Data and acts as the Controller, business, or equivalent role under applicable law.

Customer Acting on Behalf of Third Parties

The Customer may use Cultara on behalf of other organizations, including clients, portfolio companies, affiliates, or advisory customers. In such cases, the Customer represents and warrants that:

  • It has legal authority to upload, authorize, and process data on behalf of those organizations.
  • It has provided all required notices and obtained all necessary permissions, approvals, consents, or other legal bases.
  • It is authorized to bind those organizations to applicable data processing terms where required.
  • It remains responsible for ensuring that use of the Service complies with applicable law and contractual obligations.

Cultara as Processor

Cultara processes Customer Data on behalf of the Customer and acts as a Processor, service provider, or equivalent role under applicable law.

Website Data

For limited website interactions, including contact forms, demo requests, basic analytics, and website security, Cultara may act as an independent Controller.

4. Customer Instructions

Cultara will process Customer Data only on documented instructions from the Customer, including instructions contained in the applicable agreement, this DPA, platform configuration, customer uploads, and Customer’s use of the Service.

If Cultara believes an instruction may violate applicable data protection law, Cultara may notify the Customer and may suspend the relevant processing until the issue is resolved.

5. Nature and Purpose of Processing

Cultara processes Customer Data for the purpose of providing the Service, including:

  • Receiving and storing customer-uploaded data.
  • Processing customer-provided data into structured signals.
  • Generating classifications, scores, summaries, dashboards, and analytical outputs.
  • Supporting workspace, assessment, and configuration functionality.
  • Providing account administration, user management, support, maintenance, and security operations.
  • Monitoring platform performance, availability, reliability, and integrity.

6. Customer Responsibility for Data and Anonymization

The Customer is solely responsible for the data it uploads, submits, or authorizes for processing through the Service.

  • The Customer determines what data is uploaded.
  • The Customer is responsible for lawful processing, minimization, anonymization, and de-identification where applicable.
  • The Customer is responsible for ensuring that uploaded data is appropriate for analysis under applicable law.
  • The Customer is responsible for reviewing data before upload.
  • Cultara does not verify the completeness of anonymization performed by the Customer.

Cultara is designed to operate on anonymized, tokenized, or de-identified data wherever practicable. Cultara may provide tooling to assist with anonymization, but the Customer remains responsible for validating that any data uploaded complies with applicable legal and contractual requirements.

7. Subject Matter and Duration

The subject matter of processing is the provision of the Cultara platform and related services. Processing will continue for the duration of the Customer’s use of the Service, unless otherwise required by law or agreed in writing.

8. Categories of Data

Depending on Customer configuration and use of the Service, categories of data may include:

  • Account and user information, including name, email address, role, organization, and authentication data.
  • Workspace, assessment, configuration, and permission data.
  • Anonymized, tokenized, or de-identified communication-derived content.
  • Metadata associated with uploaded content, such as functional group mappings or timestamps where provided.
  • Assessment outputs, scores, summaries, dashboards, and analytical results.
  • Usage, diagnostic, audit, support, and security data.

9. Categories of Data Subjects

Categories of data subjects may include:

  • Customer employees, contractors, administrators, and platform users.
  • Individuals referenced in customer-provided source data before anonymization or de-identification.
  • Business contacts and representatives.
  • Employees, contractors, or representatives of customer clients, portfolio companies, affiliates, or other third parties.
  • Website visitors and individuals who submit inquiries.

10. Customer Obligations

The Customer will:

  • Ensure a valid legal basis for processing Customer Data.
  • Provide all required notices and disclosures to data subjects.
  • Obtain all necessary permissions, consents, or authorizations.
  • Ensure authority when acting on behalf of third parties.
  • Ensure Customer Data is accurate, lawful, and appropriate for processing.
  • Use the Service in compliance with applicable laws and agreements.
  • Maintain appropriate administrative, technical, and organizational controls over its own systems, source data, and users.
  • Ensure that users access the platform only as authorized.

11. Cultara Obligations

Cultara will:

  • Process Customer Data only on Customer instructions.
  • Maintain appropriate technical and organizational security measures.
  • Limit access to authorized personnel and systems with a need to know.
  • Ensure personnel with access to Customer Data are subject to confidentiality obligations.
  • Provide reasonable assistance to the Customer as required by applicable data protection law.
  • Notify the Customer of confirmed Security Incidents affecting Customer Data as described in this DPA.
  • Use subprocessors only as permitted under this DPA.
  • Delete or return Customer Data as described in this DPA.

12. Confidentiality

Cultara will ensure that personnel authorized to process Customer Data are subject to confidentiality obligations or professional obligations of confidentiality. Cultara will take reasonable steps to ensure that access to Customer Data is limited to personnel and systems necessary to provide and support the Service.

13. Security Measures

Cultara will maintain commercially reasonable technical and organizational measures designed to protect Customer Data against unauthorized access, loss, alteration, or disclosure. Measures may include:

  • Encryption in transit and at rest where appropriate.
  • Role-based access controls.
  • Authentication and authorization controls.
  • Logical data isolation between tenants.
  • Monitoring, logging, and security event tracking.
  • Infrastructure hardening and operational controls.
  • Backup, recovery, and availability controls where applicable.
  • Procedures for responding to security events.

Security measures may be updated from time to time, provided such updates do not materially reduce the overall level of protection for Customer Data.

14. Security Incidents

Cultara will notify the Customer without undue delay after becoming aware of a confirmed Security Incident affecting Customer Data. Cultara will provide information reasonably available to assist the Customer in meeting applicable legal obligations, which may include the nature of the incident, categories of data affected, mitigation steps taken, and recommended customer actions where applicable.

Notification of a Security Incident does not constitute an admission of fault or liability by Cultara.

15. Subprocessors

Cultara may engage subprocessors to provide hosting, infrastructure, storage, email delivery, monitoring, analytics, AI processing, authentication, support, or other services necessary to operate and support the platform.

Cultara will impose data protection obligations on subprocessors that are materially consistent with this DPA, to the extent applicable to the services provided by the subprocessor. Cultara remains responsible for the performance of subprocessors as required by applicable law.

A current list of subprocessors may be made available through Cultara’s website or upon reasonable request.

16. International Transfers

Customer Data may be processed in jurisdictions outside the Customer’s location. Where required by applicable law, Cultara will use appropriate safeguards for international transfers, which may include contractual commitments, standard contractual clauses, transfer impact assessments, adequacy mechanisms, or other lawful transfer mechanisms.

17. Data Subject Requests

The Customer is responsible for responding to requests from data subjects relating to Customer Data. To the extent required by applicable law and reasonably possible, Cultara will provide reasonable assistance to the Customer in responding to such requests.

If Cultara receives a request directly from a data subject relating to Customer Data, Cultara may direct the individual to contact the Customer, unless otherwise required by law.

18. Assistance and Compliance Support

Taking into account the nature of processing and information available to Cultara, Cultara will provide reasonable assistance to the Customer with obligations relating to security, data protection impact assessments, prior consultations, breach notifications, and data subject requests, where required by applicable law.

19. Audit and Information Rights

Upon reasonable written request and no more than once annually, Cultara will provide information reasonably necessary to demonstrate compliance with this DPA. Such information may include summaries of security practices, compliance documentation, subprocessor information, or other relevant materials.

Any audit or review must be conducted in a manner that does not compromise the security, confidentiality, availability, or integrity of Cultara systems, customer environments, or third-party information. On-site audits, penetration testing, or direct access to systems require prior written agreement.

20. Return and Deletion of Data

Upon Customer request or termination of the services relationship, Cultara will delete or return Customer Data in accordance with the applicable agreement, platform functionality, and legal requirements.

Unless otherwise agreed in writing, Customer Data will generally be deleted within sixty (60) days following termination or expiration of the services relationship, subject to legal, regulatory, audit, backup, dispute resolution, security, or legitimate business retention requirements.

21. Aggregated and Anonymized Information

Cultara may create or use aggregated, anonymized, or de-identified information derived from use of the Service, provided such information does not identify the Customer, any individual, or any specific organization. Such information may be used to operate, secure, maintain, improve, and benchmark the Service, and to develop general industry insights.

22. AI Processing

Cultara may use AI models, machine learning systems, classifiers, retrieval systems, and related analytical technologies to process Customer Data and generate outputs. Customer Data is processed to provide the Service and generate Customer-specific outputs.

Cultara does not use Customer Data to train public AI models. Where third-party AI providers are used, Cultara will configure such use in a manner intended to prevent Customer Data from being used to train those providers’ public models, where such controls are available.

23. Order of Precedence

If there is a conflict between this DPA and another agreement between the parties, this DPA will control with respect to the processing of Personal Data, unless the parties expressly agree otherwise in writing.

24. Contact

Questions regarding this DPA may be directed to:

Email: connect@cultara.ai