DATA PROCESSING ADDENDUM (DPA)

This Data Processing Addendum (“DPA”) forms part of the agreement (“Agreement”) between Neuralwaves Systems Private Limited, acting through its product LeigoSapien (“Processor”), and the customer entity executing or accepting the Agreement (“Controller”). This DPA governs the Processing of Personal Data by the Processor on behalf of the Controller in connection with the Services and is intended to satisfy the requirements of Article 28 of the General Data Protection Regulation (“GDPR”).

  1. Definitions

For the purposes of this DPA:
• “Personal Data” means any information relating to an identified or identifiable natural person.
• “Processing” shall have the meaning assigned under applicable Data Protection Laws.
• “Data Subject” means the identified or identifiable individual to whom Personal Data relates.
• “Subprocessor” means any third party engaged by the Processor to process Personal Data on behalf of the
Controller.
• “Data Protection Laws” means GDPR and other applicable privacy and data protection laws.

2. Scope and Roles

The Controller appoints the Processor to Process Personal Data solely for the purpose of providing access to and operation of the LeigoSapien platform and related services.

3. Nature and Purpose of Processing

The Processor may Process Personal Data for AI-based training and assessments, interviews and evaluation workflows, learning analytics and reporting, communication and support services, platform administration and security, and service improvement and operational monitoring.

4. Categories of Data Subjects

Students, candidates, employees, faculty members, institutional administrators, and other authorized users of the Services.

5. Types of Personal Data

Name and identification details, email address and contact information, educational and academic information, assessment and interview responses, performance metrics and analytics, audio and video recordings, login and system usage information, and AI-generated insights and reports.

6. Controller Obligations

The Controller shall comply with applicable Data Protection Laws, provide documented instructions where required, ensure lawful sharing of Personal Data, and respond to Data Subject requests unless otherwise agreed.

7. Processor Obligations

The Processor shall Process Personal Data only on documented instructions, ensure confidentiality obligations, implement security measures, assist with Data Subject rights requests, notify of breaches without undue delay, and cooperate in demonstrating compliance.

8. Security Measures

The Processor shall maintain appropriate technical and organizational security measures including access controls, authentication, encryption in transit, infrastructure security, monitoring, backups, vulnerability management, and incident response procedures.

9. Subprocessors

The Processor may engage Subprocessors to support delivery of the Services including cloud hosting, AI processing, analytics, communication, authentication, infrastructure, and support services. The Processor remains responsible for the acts and omissions of its Subprocessors.

10. International Data Transfers

Where Personal Data is transferred outside the EEA, appropriate safeguards shall be implemented in accordance with GDPR requirements, including Standard Contractual Clauses or other lawful transfer mechanisms.

11. Assistance with Data Subject Rights

The Processor shall provide reasonable assistance to the Controller in responding to Data Subject requests relating to access, rectification, erasure, restriction, portability, and objection to Processing.

12. Personal Data Breach Notification

The Processor shall notify the Controller without undue delay after becoming aware of a Personal Data Breach affecting Personal Data Processed under this DPA.

13. Retention and Deletion

The Processor shall notify the Controller without undue delay after becoming aware of a Personal Data Breach affecting Personal Data Processed under this DPA.

14. Audit Rights

The Controller may request reasonable information necessary to demonstrate compliance and may conduct reasonable audits subject to confidentiality obligations and operational safeguards.

15. Limitation of Liability

The liability of each party under this DPA shall be subject to the limitations and exclusions of liability set forth in the Agreement unless otherwise prohibited by applicable law.

16. Governing Law

This DPA shall be governed by and construed in accordance with the governing law specified in the Agreement between the parties.

17. Contact Information

Data Protection Contact: Vidya Nair
Organization: Neuralwaves Systems Private Limited
Product: LeigoSapien
Email: vidya@leigosapien.com

Annex A – Categories of Subprocessors

Subprocessor Category Purpose of Processing Data Location
Microsoft Azure
Cloud Hosting Provider
Infrastructure hosting, storage, backup, networking, disaster recovery
India / Region selected by Customer
OpenAI
AI/LLM Service Provider
AI model inference and natural language processing
As per OpenAI DPA
Microsoft Entra ID (Azure AD)
Authentication Provider
User authentication, access management, SSO and MFA
Global
SendGrid
Communication Provider
Transactional emails and notifications
Global
Google Analytics (if applicable)
Analytics Provider
Usage monitoring, platform analytics and performance measurement
Global
Jira
Customer Support Tools
Used for bug tracking
Global

Annex B – Subject Matter and Duration of Processing

Item Description
Subject Matter
Provision of AI-enabled educational and assessment services
Nature of Processing
Collection, storage, analysis, reporting, and support
Duration
For the term of the Agreement and as required by law
Data Subjects
Students, candidates, employees, faculty, administrators
Data Categories
Contact, educational, assessment, system, and analytics data
Scroll to Top