Data Processing Addendum

Effective and last updated: September 14, 2026

1. Parties and scope

This addendum forms part of the Terms of Service between SVA Products, LLC (Spikey AI) and the business customer accepting those terms. It applies to personal information Spikey AI processes on the customer's behalf (Customer Personal Data). The customer is the controller or business; Spikey AI is its processor, service provider or contractor, as those terms apply under US privacy laws. If the customer acts for another controller, it must be authorized to give the instructions in this addendum. This addendum controls conflicting service terms concerning Customer Personal Data.

Spikey AI's separate account administration, billing, fraud prevention and legal responsibilities are described in the Privacy Policy. This distinction does not authorize using customer call content for independent advertising, profiling or general-purpose model training. This addendum is not a HIPAA business associate agreement or authorization for a restricted workflow.

2. Processing details and instructions

  • Subject and purposes: provide the ordered inbound call assistant, transcribe conversations, respond using approved business information, capture requests, suggest follow-ups, deliver transactional business notices and provide enabled calendar availability, support and security.
  • Nature: receiving, transmitting, hosting, organizing, retrieving, analyzing, summarizing, disclosing to authorized recipients, correcting, returning and deleting information for those purposes.
  • People: callers, business customers and contacts, and the customer's authorized personnel and notification recipients.
  • Data: names, phone numbers and contact details; business instructions; live voice and conversation text; messages, summaries and suggested actions; call and delivery metadata; consent records; and selected calendar metadata, encrypted authorization credentials and availability for enabled connections.
  • Duration: the service period and time needed to return or delete data under lawful customer instructions and this addendum, subject to specifically required legal retention.
  • Instructions: this addendum, the ordered features, lawful workspace settings and subsequent documented instructions consistent with them. Sensitive and child-directed workflows are excluded by the standard service terms.

The customer determines a lawful basis, supplies required privacy notices, obtains valid consent, honors individual rights and supplies accurate, proportionate data. Spikey AI will process only on documented instructions or as required by law. If law requires different processing, Spikey AI will notify the customer before processing unless legally prohibited. Spikey AI will inform the customer if it believes an instruction violates applicable privacy law and may suspend that instruction while the parties resolve it.

3. Purpose restrictions and US state requirements

Spikey AI will comply with the privacy-law obligations applicable to its processing role and provide the level of protection those laws require. Spikey AI will not sell or share Customer Personal Data for cross-context behavioral advertising; use it for targeted advertising; retain, use or disclose it outside the direct business relationship or for a purpose other than those specified here, except as applicable law expressly permits; or combine it with personal information from other customers or its own consumer interactions except for a permitted business purpose under applicable law. It will not use Customer Personal Data to train general-purpose AI models or make independent consequential decisions about people.

Spikey AI certifies that it understands these restrictions and will comply with them. It will promptly notify the customer if it determines that it can no longer meet its applicable obligations. The customer may take reasonable steps to verify compliance and, upon notice, stop and remediate unauthorized processing, including through the assessment provisions below. Neither party may use this addendum to reduce rights or obligations that cannot lawfully be limited.

4. Confidentiality and security

Spikey AI will restrict access to authorized people who need the data for these purposes and are bound by confidentiality duties. Spikey AI will maintain technical and organizational safeguards appropriate to the data and processing risks, including access restrictions, encrypted transport, protection of credentials, separation of customer access, change management and incident-response procedures. It will review safeguards and remediate identified material weaknesses. These commitments do not represent a certification or guarantee that incidents cannot occur.

The customer is responsible for its authorized users, forwarding setup, devices, and copies in its email, SMS and other systems. Each party will cooperate on security issues affecting shared processing.

5. Subprocessors

The customer authorizes the processing providers identified in our provider directory for their stated functions. Before allowing a subprocessor to handle Customer Personal Data, Spikey AI will enter a written agreement imposing applicable confidentiality, security and processing obligations that protect the data to the standard required by this addendum and applicable law. Spikey AI remains responsible for its subprocessors' performance of the delegated processing obligations.

Spikey AI will give affected customers advance notice of a new or replacement subprocessor, ordinarily at least 30 days before access, by account email. Customers may object on reasonable data-protection grounds during that period. The parties will seek a reasonable alternative. If no alternative resolves the objection, the customer may terminate the affected service before the new processing begins and receive a refund of unused prepaid fees for that service. Necessary emergency replacements will be communicated as soon as practicable with an opportunity to object; legally required prior authorization remains required.

6. Requests, assessments and incidents

Taking account of the processing and information available, Spikey AI will provide reasonable assistance with the customer's obligations concerning individual requests, consent withdrawals, security, impact assessments and regulator inquiries. It will forward requests concerning Customer Personal Data to the customer or advise the individual to contact the customer, and will not independently deny a right the customer must evaluate. Spikey AI may respond where authorized or legally required.

After becoming aware of a security breach involving Customer Personal Data, Spikey AI will notify the customer without undue delay, provide available information about the affected data, likely consequences and response measures, and give updates as more information becomes available. It will investigate, mitigate and cooperate in remediation and legally required notices. An initial report need not await a completed investigation and is not an admission of fault.

Spikey AI will make information reasonably needed to demonstrate compliance available to the customer and allow and cooperate with reasonable assessments by the customer or its designated independent assessor. The parties may use documentation and available independent reports first; an appropriate further assessment remains available when necessary. Assessments must protect other customers' data and security, use reasonable notice and confidentiality, and avoid unnecessary disruption. Routine assessments may be annual; a breach, substantiated concern or legal/regulatory requirement can justify additional assessment. Spikey AI will address material findings without undue delay.

7. Return, deletion and retention

On the customer's documented request or termination, Spikey AI will, at the customer's choice, return or delete Customer Personal Data and direct relevant subprocessors to do the same, unless applicable law requires retention. Requests can be sent to hello@spikeyai.com or through the privacy request form. The parties will coordinate verification, format and scope without delaying mandatory deadlines. An outstanding payment dispute does not suspend legally required individual rights.

Data retained solely for a legal obligation will be restricted to that obligation and removed when it ends. Residual backups will remain protected and isolated from ordinary use until the applicable deletion cycle, with deletion reapplied if restored. Spikey AI will confirm completion or explain any legally justified remaining retention upon request. Customer-controlled recipient copies must be addressed by the customer. Disconnection or subscription cancellation alone is not confirmation that all personal information has been deleted.

8. Contact and continuing obligations

Processing instructions and notices: SVA Products, LLC, 169 Madison Ave, New York; hello@spikeyai.com. Confidentiality, use restrictions and security obligations continue for as long as Spikey AI retains Customer Personal Data. Any required additional agreement for another jurisdiction or restricted sector must be completed before that processing begins.