Data Processing Addendum (DPA)
Terms that apply when Chordize AI processes personal information on behalf of a business customer.
1. Definitions
Capitalised terms not defined here have the meaning given in the Terms of Service or in applicable data-protection law (GDPR, UK GDPR, PIPEDA/CPPA, CCPA/CPRA, and equivalents). For clarity:
- "Customer" means the organisation entering into the Chordize AI Terms of Service through an authorised representative.
- "Customer Personal Data" means personal information Chordize AI processes on Customer's behalf under the Terms of Service.
- "Processor", "Controller", "Data Subject", and "Personal Data Breach" have the meanings given in GDPR (or the equivalent under other applicable law).
2. Acceptance
This DPA is entered into by Customer and Chordize AI Inc. It is accepted when Customer's authorised representative accepts it at checkout, in an order form, in an account setting labelled "Business / Team", or by signing a countersigned copy. Once accepted, this DPA forms part of the agreement between the parties.
3. Roles
For Customer Personal Data processed to provide the Service, Customer is the Controller (or, under CCPA, the Business) and Chordize AI is the Processor (or, under CCPA, the Service Provider). For information Chordize AI processes for its own purposes — for example account billing, fraud prevention, security, service improvement, and compliance — Chordize AI is an independent Controller under its Privacy Policy.
4. Scope of processing
| Element | Description |
|---|---|
| Subject matter | Providing the Chordize AI Service (accounts, wallet/billing, AI analysis, AI-detection, desktop app, support) to Customer. |
| Duration | For the term of the underlying Terms of Service plus the retention period described in the Privacy Policy. |
| Nature and purpose | Automated processing, storage, transmission, model routing, moderation, security, and support required to run the Service. |
| Categories of Data Subjects | Customer's authorised users, and, at Customer's choice, anyone about whom Customer submits User Content. |
| Categories of personal data | Account, identity, and preference data; content Customer submits (prompts, selected text); usage, device, and security data; billing metadata (Stripe processes payment details directly). Customer must not submit special-category data unless it has confirmed the additional risks with us in writing. |
5. Chordize AI's obligations as Processor
Chordize AI will:
- process Customer Personal Data only on Customer's documented instructions, including instructions embedded in the Service (for example, Customer's model, prompt, and settings choices), and as required by law (in which case we notify Customer where legally permitted);
- ensure that personnel authorised to process Customer Personal Data are bound by confidentiality;
- implement appropriate technical and organisational security measures, including access controls, password hashing, transport encryption, logging, monitoring, least-privilege access, and provider security controls;
- assist Customer, taking into account the nature of processing, in responding to Data Subject requests (access, correction, deletion, portability, restriction, objection, opt-out) and in complying with security, breach-notification, and data-protection-impact-assessment obligations;
- notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and provide information Customer reasonably needs to notify regulators and Data Subjects;
- at Customer's choice, delete or return all Customer Personal Data at the end of the provision of the Service, subject to retention required by law or by our legitimate legal, tax, audit, security, and dispute purposes; and
- make available information reasonably necessary to demonstrate compliance with this DPA, and permit and contribute to audits, on the terms in Section 9.
6. Sub-processors
Customer authorises Chordize AI to engage the sub-processors listed on our Sub-processors page, and any successor or additional sub-processor we add from time to time. We will:
- impose data-protection obligations on each sub-processor materially no less protective than those in this DPA;
- remain liable to Customer for the acts and omissions of each sub-processor to the same extent Chordize AI would be liable if performing the services directly; and
- where the underlying order form or account plan requires it, give Customer prior notice of new sub-processors and an opportunity to object on reasonable data-protection grounds.
7. International transfers
Where Chordize AI transfers Customer Personal Data out of the EEA, the UK, or Switzerland, the parties agree to the applicable Standard Contractual Clauses (Module 2 or Module 3, as appropriate) and, for UK transfers, the UK International Data Transfer Addendum or the UK IDTA, incorporated by reference. Docking, governing law, and optional clauses are populated as follows: governing law of the Republic of Ireland (Module 2/3), supervisory authority of Ireland (Module 2/3), and the option for Data Subject third-party beneficiary rights is included.
8. CCPA-specific terms (California)
For personal information subject to the CCPA/CPRA: Chordize AI is a Service Provider. Chordize AI will not sell or share Customer Personal Data, will not retain, use, or disclose it for any purpose other than performing the services or as otherwise permitted by the CCPA, and will not combine it with personal information received from other sources except as permitted by the CCPA. Customer may take reasonable and appropriate steps to help ensure that Chordize AI uses Customer Personal Data consistent with these obligations.
9. Audits
Chordize AI will respond to reasonable audit or information requests. Where an on-site audit is required by law, Customer must give at least 30 days' written notice, use an independent qualified auditor bound by confidentiality, respect the security, confidentiality, and continuity of Chordize AI's operations and other customers, and conduct no more than one audit per 12 months except where law or a Personal Data Breach requires more. Customer bears the cost of audits unless a material non-compliance is identified.
10. Liability
Each party's liability under this DPA is subject to the limitations of liability in the Terms of Service. Nothing in this DPA excludes or limits liability that cannot be excluded or limited by law.
11. Priority
If there is a conflict between this DPA and the Terms of Service on the processing of Customer Personal Data, this DPA controls. If Customer needs additional country-specific terms, or additional Standard Contractual Clauses modules, contact us at support@chordize.com.
12. Contact
DPA questions: support@chordize.com
Chordize AI Inc., #1219, 39 Niagara Street, Toronto ON M5V 0T6, Canada.