Data Processing Agreement

Version: 18 September 2026

This Data Processing Agreement (DPA) governs Specific AI Inc.'s processing of personal data on behalf of Customer in providing the Service. It applies when incorporated into the Agreement between Specific AI Inc. and Customer or otherwise expressly accepted by both parties.

Cover Page

Provider: Specific AI Inc., 251 Little Falls Drive, Wilmington, Delaware 19808, United States of America.

Customer: The company or person identified as Customer in the Agreement. If an individual accepts on behalf of a company, that company is Customer and the individual represents that they have authority to bind it.

Agreement: The Specific Terms of Service accepted by Customer, or a separate agreement governing Customer's use of the Service that incorporates this DPA. A separately agreed DPA continues to govern its subject matter unless the parties agree otherwise.

Acceptance and effective date: This DPA takes effect when the parties accept the Agreement incorporating this DPA, or otherwise expressly accept this DPA electronically or in writing. Electronic acceptance of the Agreement incorporating this DPA constitutes acceptance of this Cover Page and the DPA Standard Terms. No separate signature on this DPA is required in that case. Merely viewing this page does not constitute acceptance.

DPA Standard Terms: This Cover Page, including its Annexes, incorporates the Common Paper DPA Standard Terms Version 1.1. Capitalized terms not defined here have the meanings given in the DPA Standard Terms or the Agreement. For purposes of the DPA Standard Terms, this page is the Cover Page. If a highlighted variable is omitted or not defined, its default meaning is “none” or “not applicable” as provided in the DPA Standard Terms. This Cover Page controls over inconsistent DPA Standard Terms, subject always to the precedence of applicable EEA SCCs or the UK Addendum under Section 9.1 of the DPA Standard Terms.

Key Terms

Provider Security Contact: [email protected].

Security Policy: Provider will use commercially reasonable efforts to secure the Service from unauthorized access, alteration, or use and other unlawful tampering.

Security Reports

Section 5.2 of the DPA Standard Terms is replaced with the following:

On Customer's written request, Provider will provide, on a confidential basis, any then-current independent security audit report relating to the Service that Provider has available and is permitted to disclose. This Section does not represent that Provider holds a certification or has obtained an independent security audit. Nothing in this Section limits the information, cooperation or audit obligations required by Applicable Data Protection Laws or the applicable EEA SCCs or UK Addendum.

Approved Subprocessors

Subprocessor Country of location Anticipated processing task
Amazon Web Services, Inc. United States of America Provision of cloud computing, networking and storage to host and operate the Service and Customer applications, including processing Customer Personal Data contained in application workloads, deployment artifacts and persistent storage.
Databricks, Inc. United States of America Hosting, storage, retrieval and management of Customer Personal Data in managed PostgreSQL databases, including database operations and maintenance.
Tigris Data Inc. United States of America Storage, retrieval and delivery of Customer-uploaded objects and associated metadata, including replication, snapshots and copies used for Customer environments.
ClickHouse, Inc. United States of America Collection, storage, querying and analysis of application and infrastructure logs, metrics, traces and events containing Customer Personal Data to provide observability, troubleshoot failures and maintain the Service.
Temporal Technologies Inc. United States of America Storage and processing of workflow inputs, outputs, event histories and execution metadata to coordinate deployment and infrastructure operations and provide managed Customer workflows.
WorkOS, Inc. United States of America Authentication and access management for Customer's authorized users, including processing identity, organization membership and session information to control access to the Service and protected environments.
Astrodon Corporation (Loops) United States of America Processing recipient contact information and message content to send transactional service communications, including invitations, deployment notifications and operational alerts.
OpenAI OpCo, LLC United States of America Processing prompts, conversation history, configuration and tool outputs to generate responses and assist with configuration and deployment through the Service's AI assistant, where that feature is used.
Slack Technologies, LLC United States of America Storage and transmission of Customer support and feedback communications and operational notifications, including associated contact and project information, to support Customer and resolve service issues.
Specific AI Sweden AB Sweden Provision of service operations and Customer support on behalf of Specific AI Inc., including authorized access to Customer Personal Data as necessary to operate and maintain the Service, investigate and resolve technical issues, and respond to Customer support requests.

Service Provider Relationship

To the extent California Consumer Privacy Act, Cal. Civ. Code § 1798.100 et seq (“CCPA”) applies, the parties acknowledge and agree that Provider is a service provider and is receiving Personal Data from Customer to provide the Service as agreed in the Agreement and detailed below (see Nature and Purpose of Processing), which constitutes a limited and specified business purpose. Provider will not sell or share any Personal Data provided by Customer under the Agreement. In addition, Provider will not retain, use, or disclose any Personal Data provided by Customer under the Agreement except as necessary for providing the Service for Customer, as stated in the Agreement, or as permitted by Applicable Data Protection Laws. Provider certifies that it understands the restrictions of this paragraph and will comply with all Applicable Data Protection Laws. Provider will notify Customer if it can no longer meet its obligations under the CCPA.

Restricted Transfers

Governing Member State for EEA Transfers: Sweden.

The applicable transfer provisions and safeguards are set out in Section 3 of the DPA Standard Terms.

Annex I A List of Parties

Data Exporter

Name: Customer as identified in the Agreement and the associated account records.

Address and contact person: Customer's legal address and designated contact recorded in the Agreement or the associated account records, as updated by Customer.

Activities relevant to transfer: See Annex I B below.

Role: Controller, or Processor where Customer processes Customer Personal Data on behalf of another Controller, as described in Section 1 of the DPA Standard Terms.

Acceptance: Customer's electronic or written acceptance described in this Cover Page also applies for purposes of Annex I A of the applicable EEA SCCs.

Data Importer

Name: Specific AI Inc.

Address: 251 Little Falls Drive, Wilmington, Delaware 19808, United States of America.

Contact person: Fabian Lindfors, CEO, [email protected].

Activities relevant to transfer: See Annex I B below.

Role: Processor or Subprocessor, as applicable under Section 1 of the DPA Standard Terms.

Acceptance: Provider's acceptance described in this Cover Page also applies for purposes of Annex I A of the applicable EEA SCCs.

Annex I B Description of Transfer and Processing Activities

Service

Specific is a cloud infrastructure platform for building, deploying, hosting and operating Customer applications. The Service includes application compute, managed PostgreSQL databases, object storage, persistent storage, workflow orchestration, deployment management, observability and related technical support, as selected by Customer. Customer Personal Data is processed in Customer application workloads and associated operational records to provide and maintain these services. Where used by Customer, the Service also includes AI-assisted configuration and deployment.

Categories of Data Subjects

  • Customer's end users or customers
  • Customer's employees

Categories of Personal Data

  • Name
  • Contact information such as email, phone number, or address
  • Transactional information such as account information or purchases
  • User activity and analysis such as device information or IP address

User and account identifiers; authentication, authorization and organization-membership records; and technical or operational records, including application logs, request metadata, deployment events, traces and workflow metadata, to the extent these identify or relate to an individual. Customer application, database, object and workflow content may contain the categories of Personal Data identified in this Annex, as determined by Customer's use of the Service.

Special Category Data

No Special Category Data, as defined in Article 9 of the GDPR, is included in the Processing described in this DPA.

Frequency of Transfer

Continuous.

Nature and Purpose of Processing

Provider will Process Customer Personal Data as instructed in Section 2.3 of the DPA Standard Terms. The nature of processing includes:

  • Receiving data, including collection, accessing, retrieval, recording, and data entry
  • Holding data, including storage, organization, and structuring
  • Updating data, including correcting, adaption, alteration, alignment, and combination
  • Protecting data, including restricting, encrypting, and security testing
  • Sharing data, including disclosure, dissemination, allowing access, or otherwise making available
  • Returning data to the data exporter or data subject
  • Erasing data, including destruction and deletion

Processing is carried out to provision, deploy, host and operate Customer applications and the resources selected by Customer; execute application and workflow operations; manage authorized access; provide logs, metrics, diagnostics, service notifications and technical support; and enable retrieval, export, updating and deletion of data in accordance with Customer's instructions and the Agreement. Where Customer uses the AI assistant, prompts and associated configuration and tool context are processed to generate responses and assist with configuration and deployment.

Duration of Processing

Provider will process Customer Personal Data as long as required (i) to conduct the Processing activities instructed in Section 2.2(a)-(d) of the Standard Terms; or (ii) by Applicable Laws.

Annex I C Competent Supervisory Authority

The supervisory authority will be the supervisory authority of the data exporter, as determined in accordance with Clause 13 of the EEA SCCs or the relevant provision of the UK Addendum.

Annex II Technical and Organizational Security Measures

See Security Policy.