Data Processing Addendum
Standard contractual terms governing personal data processing for European enterprise clients.
1. Scope and Applicability
This Data Processing Addendum (“DPA”) forms a key part of the Terms of Service between Thriving Billions Private Limited (“Dehurdle”) and subscribing organizations. It applies specifically where Dehurdle processes Personal Data subject to the General Data Protection Regulation (“GDPR”) or other matching privacy frameworks (such as the DPDPA) on behalf of our customers.
2. Roles of the Parties
Under GDPR, the customer acts as the Data Controller, specifying the business purpose of L&D training and simulations. Dehurdle acts strictly as the Data Processor. We process customer transcripts, scorecard averages, speaking metrics, and metadata only in accordance with the controller's instructions and to deliver our services.
Cross-Border Data Transfers & EU SCCs
Where personal data is transferred from the European Economic Area (EEA) to servers or third-party subprocessors located outside countries with adequacy status, Dehurdle incorporates the European Commission's Standard Contractual Clauses (SCCs) (Module 2: Controller-to-Processor) into our standard DPA framework.
This ensures compliance under Schrems II and establishes strict contractual obligations regarding voice data processing, transcripts, and metadata protection.
3. Technical & Organizational Security Measures (TOMs)
Dehurdle implements and maintains industry-standard security safeguards to protect customer data against unauthorized access or breaches:
All customer data is encrypted in transit using TLS 1.3 and at rest in our AWS databases using AES-256 encryption.
Voice data processed live in real time and automatically deleted post-evaluation. No voice audio files or voiceprints are stored.
Strict role-based access control (RBAC), Enterprise SSO integration, multi-factor authentication (MFA), and audit logging for all infrastructure administrators.
SOC 2 Type II / ISO 27001 aligned security assessments, automated SAST/DAST penetration testing, and continuous dependency vulnerability scanning.
Automated breach response playbooks with 72-hour formal notification guarantees to Data Controllers and supervisory authorities (GDPR Art. 33 / DPDPA).
Complete tenant data isolation with dedicated cloud boundaries in EU-Frankfurt, APAC-Mumbai, and US-Virginia.
4. Subprocessors
The customer authorizes Dehurdle to engage third-party subprocessors to deliver simulation infrastructure, cache layers, and AI voice processing. All subprocessors are bound by matching data protection terms. A list of active partners and hosting regions is maintained at our dedicated Subprocessors Page.
5. Data Subject Rights & Breach Response
Dehurdle shall promptly assist the Data Controller by appropriate technical and organizational measures in fulfilling its obligations to respond to data subject requests (access, rectification, erasure, data portability, and restriction of processing under Chapter III GDPR). In the event of a confirmed personal data breach affecting Customer Personal Data, Dehurdle shall notify the Data Controller without undue delay and in any event within 72 hours of becoming aware of the breach.
Specific Provisions for Customers Subject to Dutch Law (UAVG)
For customers established in the Netherlands or processing personal data of Dutch citizens subject to the Dutch GDPR Implementation Act (Uitvoeringswet Algemene verordening gegevensbescherming — UAVG):
The parties acknowledge that the Dutch Data Protection Authority (Autoriteit Persoonsgegevens — AP, Bezuidenhoutseweg 30, 2594 AV Den Haag) shall act as the competent supervisory authority for all processing operations governed by this Appendix.
Dehurdle warrants and represents that no audio voice recordings, acoustic voiceprints, or biometric identifier templates are stored, retained, or written to persistent media during or after user simulations. Audio is processed in memory for the live conversation only. User speech data is not used by Dehurdle for model training, and Google Cloud Vertex AI terms do not permit Google to use it to train its models.
The Controller acknowledges that Dehurdle engages Google Cloud Platform as an authorized AI subprocessor for: (1) transient conversational simulation inference (Gemini Live), (2) Dutch speech-to-text recognition (BCP-47 tag nl-NL), and (3) Dutch neural text-to-speech voice synthesis (nl-NL-Neural2-A). Google Cloud processes this data under the Google Cloud Data Processing Addendum, with encryption in transit (TLS). Processing primarily takes place in Google Cloud region asia-south1 (Mumbai).
The Controller and Processor agree that Dehurdle is procured as a formative learning and capability-building tool, and does not operate as an employee tracking or surveillance system (personeelsvolgsysteem). A complete legal assessment, pre-filled DPIA, and submission packet are accessible in our Works Council (OR) Readiness Packet.
Dehurdle's primary hosting is in India (AWS ap-south-1, Mumbai), so customer personal data is processed outside the EEA. The parties incorporate the European Commission's Standard Contractual Clauses (Decision 2021/914, Module 2: Controller-to-Processor). The technical and organizational measures set forth in Section 3 of this DPA serve as supplementary measures for these transfers.
Request Pre-signed DPA (EU & NL Edition)
European enterprise customers can request a countersigned DPA template incorporating standard EU SCC modules and the Dutch Appendix.