Skip to content
Affective

Data Processing Addendum

Last updated: October 11, 2026 · Draft pending legal review

Contact-routing amendment (October 11, 2026): all email communications to Affective, including data-processing notices, go to founder@affective-llc.site.

This Data Processing Addendum (the "DPA") is part of the Master Customer Agreement or other agreement between Affective LLC ("Affective") and Customer for the Services (the "Agreement"). Capitalized terms not defined here have the meanings given in the Agreement. If this DPA conflicts with the Agreement, this DPA controls for personal data.

The short version

  • You control your users' personal data. We process it only to provide the Services and on your instructions.
  • We de-identify appraisal state data before using it to improve our models, and we never try to re-identify it.
  • We train on raw content only if you opt in and your users have opted in.
  • We tell you about a security incident within 72 hours and delete your data within 30 days after the Agreement ends.
01

Scope and roles

1.1 Definitions

"Data Protection Law" means all privacy and data protection laws that apply to the processing of Customer Personal Data, including, as applicable, the EU General Data Protection Regulation ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act ("CCPA"), the Texas Data Privacy and Security Act, and other US state privacy laws. "Customer Personal Data" means personal data, personal information, or any equivalent term under Data Protection Law, contained in Customer Content or Identifiable State Data. "Process" and "Processing" mean any operation performed on Customer Personal Data. "Controller," "processor," "business," "service provider," "data subject," and "consumer" have the meanings given in Data Protection Law.

1.2 Roles

For Customer Personal Data, Customer is the controller (or business), and Affective is the processor (or service provider). Where Customer acts as a processor for another controller, Affective is Customer's subprocessor, and Customer is responsible for passing instructions from, and obligations to, that controller. Each Party will comply with the Data Protection Law that applies to it.

1.3 Details of Processing

Schedule 1 describes the subject matter, nature, purpose, and duration of the Processing and the categories of personal data and data subjects.

02

Processing on instructions

2.1 Documented instructions

Affective will Process Customer Personal Data only to provide the Services and in accordance with Customer's documented instructions. The Agreement, this DPA, and Customer's configuration of the Services are Customer's complete instructions at signing; additional instructions must be in writing and consistent with the Agreement. Unless the law forbids it, Affective will tell Customer if a legal requirement obliges it to Process Customer Personal Data other than on Customer's instructions, or if it believes an instruction violates Data Protection Law.

2.2 Service provider commitments

Affective will not (a) sell or share Customer Personal Data, as "sell" and "share" are defined in the CCPA; (b) retain, use, or disclose Customer Personal Data for any purpose other than the business purposes in the Agreement and this DPA; (c) retain, use, or disclose Customer Personal Data outside the direct business relationship between the Parties; or (d) combine Customer Personal Data with personal data it receives from or on behalf of others, except as Data Protection Law permits. Affective will notify Customer if it can no longer meet its obligations under the CCPA.

2.3 Personnel

Affective will ensure that anyone it authorizes to Process Customer Personal Data is bound by confidentiality obligations and receives access only as needed for their role.

03

State Data and training

3.1 De-identification

Customer instructs Affective to de-identify State Data so that it can be used to train, improve, evaluate, and benchmark models as Section 4.3 of the Agreement describes. Affective will (a) take reasonable technical and organizational measures to ensure de-identified State Data cannot reasonably be used to infer information about, or be linked to, an identified or identifiable person or household; (b) publicly commit to maintain and use it only in de-identified form and not attempt to re-identify it; and (c) contractually require anyone who receives it to meet the same requirements. De-identified State Data that meets this standard is not Customer Personal Data.

3.2 Content Training

Affective will not use Customer Personal Data in Customer Content for Content Training unless Customer has opted in under Section 4.2 of the Agreement. Customer will opt in only for data for which it has obtained the data subjects' explicit consent to that use, and will pass any withdrawal of that consent to Affective without undue delay.

3.3 Sensitive data

Emotional state inferences may reveal information about a person's mental or physical health and may be special category or sensitive data under Data Protection Law. Affective applies the additional safeguards in Schedule 2 to State Data. Customer is responsible for having a lawful basis, and any consent Data Protection Law requires, for Processing such data through the Services. Customer will not submit protected health information unless the Parties have signed a business associate agreement.

04

Subprocessors

4.1 Authorization

Customer gives Affective general authorization to engage subprocessors. Affective publishes its current subprocessor list as described in Schedule 3. Affective will impose on each subprocessor, by written contract, data protection obligations at least as protective as this DPA to the extent relevant to its services, and remains responsible for each subprocessor's performance, subject to the limitations of liability in the Agreement.

4.2 New subprocessors

Affective will notify Customer at least 15 days before a new subprocessor begins Processing Customer Personal Data. Customer may object on reasonable data protection grounds by written notice within that period. The Parties will discuss the objection in good faith. If they cannot resolve it within 30 days, Customer may terminate the affected Services by written notice, and Affective will refund prepaid, unused Fees for them. This is Customer's sole remedy for an objection.

05

Assistance

5.1 Data subject requests

Affective will promptly forward to Customer any request it receives from a data subject about Customer Personal Data and will not respond to it except to direct the requester to Customer. Taking into account the nature of the Processing, Affective will provide reasonable assistance, including the export and deletion functions of the Services, so that Customer can respond to requests to access, correct, delete, or port personal data, including export of the persistent memory stored for an End User.

5.2 Revocation and deletion

  • When an End User or Customer revokes persistent memory, Affective will purge the memory for that End User within 30 days of the verified revocation.
  • When consent to Content Training or to the use of de-identified State Data is withdrawn, the affected records are excluded from datasets Affective builds after the withdrawal.
  • Deleting data removes it from future training runs. Models already trained on de-identified patterns cannot unlearn them individually.

5.3 Other assistance

Affective will provide reasonable information and assistance Customer needs to carry out data protection impact assessments and prior consultations with supervisory authorities required by Data Protection Law, in each case relating to the Services. Affective may charge reasonable fees for assistance beyond what the Services provide through self-service functions.

06

Security

6.1 Security measures

Affective will implement and maintain appropriate technical and organizational measures to protect Customer Personal Data, including those in Schedule 2. Affective may update these measures as long as the update does not materially reduce the overall protection of Customer Personal Data.

6.2 Security incidents

Affective will notify Customer without undue delay, and in any case within 72 hours, after becoming aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data (a "Security Incident"). Affective will provide information about the Security Incident as it becomes available, take reasonable steps to contain, investigate, and remediate it, and reasonably assist Customer with any notifications Customer must make. Notice of a Security Incident is not an admission of fault.

6.3 Audits

Once every 12 months, on written request, Affective will answer Customer's reasonable written security questionnaire and provide summaries of any third-party audit reports it holds. If those materials are insufficient to demonstrate compliance with this DPA, or a supervisory authority requires it, Customer may audit Affective's relevant controls, at Customer's cost, during business hours, with reasonable advance notice, under a confidentiality agreement, and within a scope the Parties agree in advance. Customer may use audit results only to verify compliance with this DPA and meet its regulatory obligations.

07

Return and deletion

Customer may export Customer Content and persistent memory through the Services during the Term. Within 30 days after the Agreement ends, Affective will delete Customer Personal Data, except copies that Data Protection Law requires it to keep and copies in backups, which are deleted as the backups expire in the ordinary course. Retained copies remain protected under this DPA. De-identified State Data is not deleted.

08

International transfers

8.1 Location

Affective Processes Customer Personal Data in the United States. Customer authorizes transfers of Customer Personal Data to the United States and to the locations of the subprocessors in Schedule 3, subject to this Section 8.

8.2 EEA transfers

For transfers of Customer Personal Data from the European Economic Area to a country without an adequacy decision, the Parties enter into the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914 (the "EU SCCs"): Module 2 where Customer is a controller, and Module 3 where Customer is a processor. For both modules: Customer is the data exporter and Affective the data importer; the docking clause in Clause 7 applies; Clause 9 option 2 applies, with the notice period in Section 4.2; the optional language in Clause 11 does not apply; Clause 17 option 1 applies, with the law of Ireland; the courts of Ireland are chosen under Clause 18; Annex I is completed by Schedule 1; and Annex II is completed by Schedule 2.

8.3 UK and Swiss transfers

For transfers from the United Kingdom, the EU SCCs apply as amended by the International Data Transfer Addendum issued by the UK Information Commissioner, with Tables 1 to 3 completed by this DPA and the Agreement, and either Party may end the Addendum as allowed by Table 4. For transfers from Switzerland, the EU SCCs apply with references to the GDPR read as references to the Swiss Federal Act on Data Protection, the Swiss Federal Data Protection and Information Commissioner as the competent supervisory authority, and Swiss courts as an alternative forum for data subjects habitually resident in Switzerland.

8.4 Alternative mechanisms

If Affective adopts another lawful transfer mechanism, such as certification under the EU-US Data Privacy Framework, that mechanism will apply in place of the EU SCCs to the extent permitted by Data Protection Law.

Schedule 1: Details of Processing

  • Data exporter: Customer, as identified in the Order. Activities: using the Services as described in the Agreement. Role: controller or processor.
  • Data importer: Affective LLC, [NOTICE ADDRESS], founder@affective-llc.site. Activities: providing the Services. Role: processor or subprocessor.
  • Data subjects: End Users, Customer Users, and any person whose personal data Customer includes in Input.
  • Categories of personal data: content of Input (text, audio, images, transcripts) as determined by Customer; End User identifiers such as user keys; Identifiable State Data, including inferred appraisal states, emotional trajectories, and persistent memory; Customer User account and contact details.
  • Sensitive data: inferred emotional and mental states, which may reveal health information. Safeguards: the State Data measures in Schedule 2, field-level encryption, restricted and logged access to crisis-related content, and no clinical processing without a business associate agreement.
  • Frequency: continuous for the Term.
  • Nature of Processing: hosting, storage, model inference, state derivation, persistent memory, de-identification, security monitoring, support, and deletion.
  • Purpose: providing the Services under the Agreement.
  • Retention: Identifiable State Data up to 90 days unless Customer configures otherwise, except persistent memory, which is kept until cleared or revoked; Customer Content only as long as needed to provide the Services; all Customer Personal Data deleted as Section 7 describes.
  • Subprocessor transfers: for the subject matter, nature, and duration described above.
  • Competent supervisory authority: as determined under Clause 13 of the EU SCCs.

Schedule 2: Security measures

  • Encryption in transit with TLS 1.3 and encryption at rest with AES-256, with cloud-managed keys rotated on a regular schedule.
  • Field-level encryption for State Data, a tier above other stored data.
  • Data minimization by default: persistent memory stores derived appraisal states rather than raw conversations unless Customer configures otherwise.
  • Logical separation of each customer's data, and no cross-customer emotional profiling.
  • Role-based access control, least privilege, single sign-on for personnel, and scoped API credentials with rate limits.
  • Restricted, logged access to crisis-related content, which is retained only as far as safety review requires.
  • Immutable audit logs of access to production data, with monitoring and an incident response process.
  • Secrets kept in a managed vault, never in code or configuration files.
  • Private networking for production services, with edge protection against denial-of-service and web application attacks.
  • Confidentiality obligations and security training for personnel with access to Customer Personal Data.

Schedule 3: Subprocessors

Affective will publish its subprocessor list on its Security page, including each subprocessor's name, function, and location, before the Services Process any Customer Personal Data. Until then, the Services do not Process Customer Personal Data.