Data processing agreement
This Data Processing Agreement ("DPA") forms part of the Terms of Service (the "Agreement") between Nori Labs, Inc. ("Spelt", "Processor") and the user of the Services ("Customer", "Controller") and applies to the Processing of Personal Data that is subject to applicable Data Protection Law, including the EU General Data Protection Regulation ("GDPR"), the UK GDPR, the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), and other applicable data protection laws.
This DPA is effective as of June 9, 2026.
1. Definitions
"Personal Data" means any information relating to an identified or identifiable natural person processed by Spelt on behalf of Customer, as further described in Annex I.
"Data Subject" means the identified or identifiable natural person to whom Personal Data relates.
"Processing" has the meaning given in applicable Data Protection Law.
"Sub-processor" means a third party engaged by Spelt to Process Personal Data on Customer's behalf.
"Data Protection Law" means all applicable laws relating to the processing of Personal Data, including the GDPR, UK GDPR, CCPA/CPRA, and equivalent laws.
2. Roles and scope
Customer is the Controller and Spelt is the Processor with respect to the Personal Data of Customer's end users, visitors, and other third parties of Customer's ventures ("End-User Data") that Spelt Processes on Customer's behalf in the course of providing the Services.
The subject matter, duration, nature, and purpose of the Processing, as well as the categories of Data Subjects and types of Personal Data, are set out in Annex I.
3. Customer obligations
Customer represents and warrants that: (a) it has a lawful basis for Processing End-User Data and for instructing Spelt to Process End-User Data; (b) it has provided all notices and obtained all consents required under Data Protection Law; (c) its instructions to Spelt comply with Data Protection Law; and (d) Customer is solely responsible for determining the purposes and means of Processing End-User Data.
4. Processor obligations
Spelt shall: (a) Process End-User Data only on documented instructions from Customer, including as set out in the Agreement and this DPA; (b) ensure that personnel authorized to Process End-User Data are subject to appropriate confidentiality obligations; (c) implement and maintain the technical and organizational measures described in Annex II; (d) assist Customer in responding to Data Subject rights requests to the extent reasonably possible; (e) assist Customer with data protection impact assessments and prior consultations with supervisory authorities where required; (f) notify Customer without undue delay upon becoming aware of a Personal Data breach affecting End-User Data; and (g) at Customer's choice, delete or return End-User Data upon termination of the Agreement, subject to retention required by applicable law.
Spelt shall promptly notify Customer if, in its opinion, an instruction from Customer infringes Data Protection Law.
Notwithstanding the foregoing, Spelt may create and use aggregated and/or de-identified data derived from the Processing of End-User Data to operate, secure, analyze, improve, and develop the Services, including to develop, train, and improve its AI agents, models, and tooling. Such aggregated or de-identified data does not identify any Data Subject, is not Personal Data, and is owned by Spelt. Spelt will not attempt to re-identify such data. This processing is consistent with Spelt's obligations as a service provider under the CCPA/CPRA.
5. Sub-processors
Customer grants Spelt general authorization to engage Sub-processors to Process End-User Data in connection with the Services. A list of current Sub-processors is available in the Privacy Policy and updated from time to time.
Spelt shall: (a) enter into a written agreement with each Sub-processor imposing data protection obligations no less protective than those in this DPA; (b) remain liable to Customer for the acts and omissions of its Sub-processors; and (c) notify Customer of any intended changes concerning the addition or replacement of Sub-processors, thereby giving Customer the opportunity to object to such changes. If Customer reasonably objects on legitimate data protection grounds, the parties shall work together in good faith to resolve the objection; if no resolution is reached, Customer may terminate the affected portion of the Services.
6. International transfers
Where Processing of End-User Data involves a transfer of Personal Data from the European Economic Area, the United Kingdom, or Switzerland to a country not recognized as providing an adequate level of data protection, the parties shall rely on: (a) the Standard Contractual Clauses approved by the European Commission (Module Two: Controller to Processor), which are incorporated into this DPA by reference and deemed entered into between the parties; (b) the UK International Data Transfer Addendum, where applicable; and (c) any additional safeguards required by applicable law.
7. Data subject rights
Spelt shall provide reasonable assistance to Customer, taking into account the nature of the Processing, to enable Customer to respond to requests from Data Subjects to exercise their rights under Data Protection Law. If Spelt receives a request directly from a Data Subject relating to Customer's End-User Data, Spelt shall promptly forward the request to Customer and shall not respond to the request except on Customer's documented instructions or as required by law.
8. Security and breach notification
Spelt shall implement and maintain appropriate technical and organizational measures to protect End-User Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, as described in Annex II.
Spelt shall notify Customer without undue delay, and in any event within seventy-two (72) hours, of becoming aware of a Personal Data breach affecting End-User Data. Such notification shall include, to the extent known at the time, the nature of the breach, the categories and approximate number of Data Subjects and records affected, likely consequences, and measures taken or proposed to address the breach.
9. Audits
Spelt shall make available to Customer all information reasonably necessary to demonstrate compliance with this DPA and shall allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer, subject to reasonable advance notice, confidentiality obligations, and reasonable cost reimbursement. Spelt may satisfy audit obligations by providing third-party audit reports, certifications, or similar documentation.
10. Return and deletion
Upon termination of the Agreement or upon Customer's written request, Spelt shall, at Customer's choice, return or delete End-User Data, subject to retention required by applicable law. Backup copies will be deleted in accordance with Spelt's standard retention and deletion schedule.
11. Liability
Each party's liability under this DPA is subject to the limitations of liability set out in the Agreement. Nothing in this DPA excludes or limits either party's liability to Data Subjects under Data Protection Law.
12. CCPA/CPRA
To the extent Spelt Processes Personal Information of California residents on behalf of Customer, Spelt acts as a "service provider" as defined under the CCPA/CPRA. Spelt shall not: (a) sell or share such Personal Information; (b) retain, use, or disclose such Personal Information outside the direct business relationship with Customer or for any purpose other than providing the Services; or (c) combine such Personal Information with Personal Information received from other sources, except as permitted by the CCPA/CPRA. Spelt certifies that it understands these restrictions and will comply with them.
13. Term and general
This DPA is effective for the duration of the Agreement and survives termination of the Agreement to the extent necessary to comply with applicable law. In case of conflict between this DPA and the Agreement with respect to the Processing of End-User Data, this DPA prevails. This DPA is governed by the law specified in the Agreement, except where Data Protection Law requires otherwise.
Annex I — Description of processing
Subject matter: Provision of AI-assisted venture building, deployment, and operation services.
Duration: The duration of the Agreement, plus any period thereafter required for deletion or return of End-User Data.
Nature and purpose: Hosting, storage, processing, transmission, analysis, and other operations necessary for Spelt to provide the Services to Customer, including operating Customer's venture on Customer's behalf.
Categories of Data Subjects: Customer's end users, customers, visitors, leads, prospects, and other third parties interacting with Customer's venture.
Types of Personal Data: As determined by Customer, typically including identifiers (name, email, phone), account data, device and log data, commercial information, communications, and any other categories of Personal Data Customer chooses to Process via the Services.
Annex II — Technical and organizational measures
Spelt implements and maintains technical and organizational measures appropriate to the risk, including: (a) encryption of Personal Data in transit and at rest; (b) access controls, authentication, and authorization for personnel and systems; (c) network segmentation and firewalling; (d) logging, monitoring, and intrusion detection; (e) secure software development practices; (f) regular backups and disaster recovery procedures; (g) personnel training on data protection and security; (h) background checks for personnel with access to Personal Data where permitted by law; (i) incident response procedures; and (j) regular review and testing of security measures. Specific details are available upon reasonable request, subject to confidentiality.
Contact
Questions regarding this DPA should be directed to:
Nori Labs, Inc.
1111B S Governors Ave # 91173
Dover, DE 19904
legal@joinspelt.com