# Data Processing Agreement (DPA)

**Between**

**Examiverse Technologies Private Limited**, a company incorporated under the
Companies Act, 2013 (CIN: U62011KA2026PTC214753), having its registered office at
73, KST Town, Valagerehalli, Kengeri, Bangalore South, Bengaluru – 560060,
Karnataka, India ("**Examiverse**", the "**Processor**")

**and**

**[CUSTOMER LEGAL NAME]**, [entity type], having its registered office at
[CUSTOMER ADDRESS] ("**Customer**", the "**Controller**" / "**Data Fiduciary**")

Effective from: **[DATE]**

> **Note for internal use — delete before sending.** This is a template, not legal
> advice, and it has not been reviewed by counsel. It is written to be accurate about
> what the platform actually does, which is the part most templates get wrong. Have a
> lawyer review it before the first signature, and never edit a factual clause
> (sections 4, 5, 6, 9) to make a deal easier — those clauses describe the system, and
> changing the words does not change the system.

---

## 1. Definitions

1.1 **"DPDP Act"** means the Digital Personal Data Protection Act, 2023 (India) and
any rules made under it.

1.2 **"GDPR"** means Regulation (EU) 2016/679, where applicable.

1.3 **"Personal Data"** means any data about an individual who is identifiable by or
in relation to such data, processed by Examiverse on behalf of the Customer under the
Principal Agreement.

1.4 **"Processing"** has the meaning given in the DPDP Act and, where applicable, the
GDPR.

1.5 **"Principal Agreement"** means the subscription, order form or terms of service
under which Examiverse provides the Services to the Customer.

1.6 **"Services"** means the Examiverse AI Studio platform and, where subscribed, the
Examiverse Enterprise Hosting portal.

1.7 **"Sub-processor"** means any third party engaged by Examiverse to process
Personal Data on the Customer's behalf.

---

## 2. Roles of the parties

2.1 The Customer is the Data Fiduciary (Controller) and determines the purposes and
means of Processing.

2.2 Examiverse is the Data Processor and processes Personal Data only on the
Customer's documented instructions.

2.3 The Principal Agreement, together with this DPA and the Customer's use of the
Services, constitutes the Customer's documented instructions.

2.4 Examiverse acts as a Data Fiduciary in its own right only in respect of the
personal data of its own account holders (billing contacts, platform administrators),
governed by its Privacy Policy rather than by this DPA.

---

## 3. Scope of processing

3.1 **Subject matter.** Provision of the Services: converting Customer-supplied source
material into training and educational video, and where subscribed, hosting and
delivering that output to Customer-nominated learners.

3.2 **Duration.** For the term of the Principal Agreement, plus the retention periods
set out in section 6.

3.3 **Nature and purpose.** Storage, transformation, synthesis, rendering, hosting and
delivery, as required to provide the Services.

3.4 **Categories of Data Principal.** The Customer's employees, contractors, learners
and nominated administrators.

3.5 **Categories of Personal Data.**
(a) Identity and contact data of Customer administrators and learners (name, email);
(b) Any Personal Data contained within source material the Customer uploads;
(c) Where the Customer elects to use custom voice or avatar features, voice recordings
and facial reference images of individuals the Customer has obtained consent from;
(d) Usage and access telemetry.

3.6 **Customer responsibility for uploaded content.** The Customer warrants that it
has a lawful basis and, where required, valid consent for all Personal Data it
uploads, including any voice or facial data of its personnel. Examiverse does not
inspect Customer content for Personal Data and cannot verify the Customer's basis for
processing it.

---

## 4. Examiverse's obligations

4.1 Process Personal Data only on the Customer's documented instructions, unless
required otherwise by law, in which case Examiverse will inform the Customer before
processing unless legally prohibited from doing so.

4.2 Ensure that personnel authorised to process Personal Data are bound by
confidentiality obligations.

4.3 Implement and maintain the technical and organisational measures set out in
**Annex A**.

4.4 **Not use Customer Personal Data or Customer content to train, fine-tune or
improve any artificial intelligence model**, whether operated by Examiverse or by any
third party. Custom voice and avatar models derived from Customer content are
partitioned to the Customer's account and are never applied to another customer's
output.

4.5 Assist the Customer, insofar as reasonably possible, in responding to requests
from Data Principals exercising their rights.

4.6 Assist the Customer in meeting its obligations regarding security, breach
notification and any data protection impact assessment, taking into account the nature
of the Processing and the information available to Examiverse.

4.7 On termination, delete Personal Data in accordance with section 6, save where
retention is required by law.

4.8 Make available the information reasonably necessary to demonstrate compliance with
this DPA, and permit the Customer to conduct an audit no more than once in any
twelve-month period on thirty (30) days' written notice, at the Customer's expense,
subject to reasonable confidentiality undertakings. Where Examiverse holds a relevant
independent certification or report, provision of it satisfies this obligation.

---

## 5. Sub-processors

5.1 The Customer grants general authorisation for Examiverse to engage
Sub-processors, subject to this section.

5.2 The Sub-processors authorised as at the effective date are:

| Sub-processor | Purpose |
|---|---|
| Cloudflare | Edge delivery, object storage, serverless databases, DDoS protection |
| Amazon Web Services | GPU compute instances operated and controlled by Examiverse |
| Microsoft Azure | Containerised render workers; speech synthesis |
| Google Cloud (Vertex AI) | Production-planning stage; certain image generation |
| Google Firebase | Authentication and identity |
| Razorpay | Payment processing (India) |
| Upstash | Job queueing and ephemeral cache |

5.3 **AI model processing, stated expressly.** The Customer acknowledges and agrees
that source text supplied to the Services is transmitted to Google Cloud Vertex AI for
the production-planning stage of generation. This processing is governed by Google
Cloud's enterprise terms, under which customer data submitted to Vertex AI is not used
to train Google's foundation models. All other generation stages — narration, imagery,
motion and presenter synthesis — are performed on models hosted by Examiverse on
compute it controls, and Customer content is not transmitted to any external model
provider for those stages.

5.4 Examiverse will give the Customer at least thirty (30) days' notice before adding
or replacing a Sub-processor that processes Personal Data. The Customer may object on
reasonable data protection grounds within that period, in which case the parties will
discuss in good faith; if no resolution is reached the Customer may terminate the
affected Services without penalty.

5.5 Examiverse imposes data protection obligations on each Sub-processor no less
protective than those in this DPA, and remains fully liable to the Customer for each
Sub-processor's performance.

---

## 6. Data residency, retention and deletion

6.1 **Storage.** All Personal Data at rest is stored in the Asia-Pacific (APAC)
region.

6.2 **Processing.** The Customer acknowledges that rendering and inference are
performed on multi-region compute, which may include the United States, India
(Mumbai), Singapore, Western Europe and Sweden. Content resides in those regions only
for the duration of the processing job and is written back to APAC storage.

6.3 Examiverse does not transfer Personal Data to any territory restricted by the
Government of India under Section 16 of the DPDP Act. Where the GDPR applies,
transfers outside the EEA are made under appropriate safeguards.

6.4 **Region-pinned processing** may be agreed in writing as a separate schedule to
this DPA. Absent such a schedule, section 6.2 applies.

6.5 **Retention.** Examiverse applies the following automatic bounds, enforced on
scheduled timers that operate independently of user activity:

| Data | Retention |
|---|---|
| Generated videos and lesson history | 100 most recent per account, maximum 180 days |
| Custom voice models and source recordings | Maximum 20 per account, deleted 90 days after last use |
| Intermediate render artefacts and checkpoints | 72 hours; purged on delivery |
| Temporary render workspaces | 24 hours |
| Job logs | 6 hours |
| Enterprise hosting content and learner rosters | Deleted 45 days after subscription expiry |
| Account deletion | 30-day restorable grace period, then permanent purge |

6.6 **Legally mandated retention.** Invoices and financial records are retained for the
period required by the Companies Act, 2013 and applicable Indian tax law (up to eight
years) and are not subject to deletion on request.

6.7 On written request following termination, Examiverse will delete Customer Personal
Data within thirty (30) days, save as required by section 6.6.

---

## 7. Data Principal rights

7.1 Where Examiverse receives a request directly from a Data Principal relating to
Personal Data processed on the Customer's behalf, it will not respond substantively
and will forward the request to the Customer without undue delay.

7.2 Examiverse provides self-service functionality for account deletion and output
export, and will provide reasonable additional assistance for access, correction and
erasure requests.

7.3 **Grievance Officer.** Darshan A C, Grievance Officer & Co-founder,
admin@examiverse.com, 73, KST Town, Valagerehalli, Kengeri, Bangalore South,
Bengaluru – 560060, Karnataka, India. Grievances are acknowledged within 24 hours and
resolved within 30 days.

---

## 8. Personal data breach

8.1 Examiverse will notify the Customer without undue delay, and in any event within
seventy-two (72) hours, of becoming aware of a Personal Data breach affecting the
Customer's Personal Data.

8.2 The notification will describe, to the extent known: the nature of the breach, the
categories and approximate number of Data Principals and records affected, the likely
consequences, the measures taken or proposed, and a contact point.

8.3 Examiverse will provide reasonable cooperation to enable the Customer to meet its
own notification obligations to the Data Protection Board of India, affected Data
Principals or any other competent authority.

---

## 9. Security measures — Annex A

**Access control.** Authentication delegated to a managed identity provider; no
passwords received or stored. Short-lived signed JWTs re-verified server-side on every
request touching Customer content. Per-account storage path isolation with
authorisation evaluated per request. Administrative surfaces gated by a server-side
allowlist that fails closed.

**Encryption.** TLS 1.3 in transit, enforced. AES-256 server-side encryption at rest.
Keys managed by the underlying cloud providers' key management services.

**Content delivery.** HLS with HMAC-signed short-expiry playback authorisations
verified per request.

**Network.** Global CDN with DDoS mitigation and WAF in front of all public endpoints.

**Segregation.** Billing, invoicing and analytics run on separate database instances
from user content. Payment card data is never received, transmitted or stored by
Examiverse.

**Resilience.** Render workers containerised across two cloud providers with
cross-cloud failover. Long renders checkpoint per scene and resume rather than
restart. The planning stage has a self-hosted fallback provider.

**Retention enforcement.** Automatic, timer-driven, independent of user activity.

**Certification status.** Examiverse does not hold ISO/IEC 27001 certification or a
SOC 2 attestation, and makes no such representation. Its infrastructure providers
(Cloudflare, AWS, Microsoft Azure, Google Cloud) hold those certifications in respect
of the layers they operate.

---

## 10. General

10.1 This DPA is incorporated into and forms part of the Principal Agreement. In the
event of conflict on the subject matter of data protection, this DPA prevails.

10.2 Liability under this DPA is subject to the limitations and exclusions in the
Principal Agreement.

10.3 This DPA is governed by the laws of India, and the courts at Bengaluru, Karnataka
have exclusive jurisdiction, save where a mandatory provision of applicable data
protection law requires otherwise.

10.4 If any provision is held invalid, the remainder continues in full force.

---

**Signed for and on behalf of Examiverse Technologies Private Limited**

Name: ................................ Title: ................................

Signature: ................................ Date: ................................

**Signed for and on behalf of [CUSTOMER LEGAL NAME]**

Name: ................................ Title: ................................

Signature: ................................ Date: ................................
