SPOCK

DATA PROCESSING AGREEMENT

Data Processing Agreement

This Data Processing Agreement (“DPA”) forms part of the agreement between Seleya Labs Inc., a Delaware (USA) corporation and operator of the Spock product (“Seleya” or “Spock”, the “Processor”/“Operator”), and the customer accepting the Terms of Service or signing an enterprise order form (the “Customer”, the “Responsible Party”/“Controller”). It is incorporated by reference into the Terms of Service for all business and enterprise customers and applies whenever Spock processes personal information in Customer Content on the Customer’s behalf. For enterprise engagements, a signed Enterprise Addendum may supplement (but not weaken) this DPA.

1. Roles and scope

1.1 The Customer is the controller (GDPR) / responsible party (POPIA) of personal information contained in Customer Content. Spock is the processor / operator, acting only on the Customer’s documented instructions.

1.2 Spock acts as an independent controller for account, billing, telemetry, and support data, as described in the Privacy Policy. Such data is outside the scope of this DPA except for section 6 (security), which applies to all data Spock holds.

1.3 “Applicable Data Protection Law” means the GDPR, the UK GDPR, POPIA, and any other data protection law applying to the processing.

2. Subject matter, duration, nature, and purpose

Subject matterProvision of the Spock AI workspace and agent services
DurationThe term of the Agreement plus the deletion periods in section 11
Nature and purposeStorage and retrieval (EU); AI inference on the model selected by the Customer (EU for the Spock model; US for third-party models); document processing and OCR; code execution; web retrieval; integrations and channels operated at the Customer’s direction; logging, security, and support
Categories of data subjectsThe Customer’s employees, contractors, and clients; individuals referenced in Customer Content
Categories of personal dataNames, contact details, roles, identifiers, usage data, and any personal information the Customer includes in prompts, uploads, connected sources, or channel messages
Special categoriesNot intended. If included, section 4.4 applies

3. Customer instructions

3.1 The Agreement, this DPA, and the Customer’s use of the Service’s features and settings (including model selection, tool invocation, integration connections, and automation configuration) constitute the Customer’s complete documented instructions.

3.2 Spock will inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law.

4. Customer responsibilities

4.1 The Customer warrants it has a lawful basis for all personal information it submits and has provided any required notices to data subjects.

4.2 The Customer acknowledges and instructs that, when a third-party AI model is selected, Customer Content in the relevant request is transferred to the applicable US sub-processor in Annex B. Content processed with the Spock model remains on Spock-managed EU infrastructure.

4.3 The Customer is responsible for the third-party services it connects (MCP servers, integrations operated under the Customer’s own accounts). Those services act at the Customer’s direction and are not Spock’s sub-processors.

4.4 The Customer will not submit special-category personal information unless it has an explicit lawful basis and, where applicable, Prior Authorisation from the South African Information Regulator.

5. Confidentiality

Spock ensures that persons authorised to process Customer Content are bound by confidentiality obligations and access it only as needed to provide and secure the Service.

6. Security (Annex C)

Spock implements and maintains the technical and organisational measures in Annex C, including encryption in transit (TLS 1.3) and at rest, EU hosting of core data, least-privilege access controls, network segregation, logging, and secure development practices. Spock may update Annex C provided the overall level of protection is not reduced.

7. Sub-processors (Annex B)

7.1 The Customer authorises the sub-processors listed in Annex B, maintained at spock.chat/trust.

7.2 Spock will give at least 14 days’ notice (via the Trust Center changelog and email to workspace administrators) before adding or replacing a sub-processor that processes Customer Content. The Customer may object on reasonable data-protection grounds within that period; if the objection cannot be resolved (including by the Customer disabling the relevant feature or selecting the Spock model), either party may terminate the affected services with a pro-rata refund of prepaid fees.

7.3 Spock imposes data-protection obligations on each sub-processor no less protective than this DPA and remains liable for their performance.

8. No training on Customer Content

8.1 Spock will not use Customer Content to train, fine-tune, or otherwise develop any AI model, and will not permit any sub-processor to do so. This obligation is core and non-derogable.

8.2 If Spock breaches section 8.1, the Customer may terminate immediately and receive a refund of all fees paid in the 12 months preceding the breach, without prejudice to other remedies.

9. Data subject requests and assistance

9.1 Spock will, taking into account the nature of the processing, assist the Customer with data subject requests (access, rectification, erasure, restriction, portability, objection) and with the Customer’s obligations regarding security, breach notification, DPIAs, and prior consultation.

9.2 If a data subject contacts Spock directly about Customer Content, Spock will forward the request to the Customer without undue delay and not respond substantively except as legally required.

10. Personal data breaches

Spock will notify the Customer of a personal data breach affecting Customer Content without undue delay, and in any event within 72 hours of becoming aware, providing the information reasonably required for the Customer’s own notification obligations, and will cooperate in the investigation and remediation.

11. Deletion and return

11.1 During the term, the Customer can delete Customer Content through the Service, and individual users can delete their accounts in Settings.

11.2 On termination, Spock will, at the Customer’s choice, provide a structured export of Customer Content (where technically feasible) and thereafter delete or irreversibly anonymise it within 12 months, except where retention is required by law. Content in backups is removed through the rolling backup deletion cycle. Third-party AI providers retain request data for up to 30 days under their own API terms.

12. Audits

12.1 Spock will make available information reasonably necessary to demonstrate compliance with this DPA, including summaries of third-party audit reports and certifications held by Spock and its hosting sub-processors (e.g. ISO 27001, SOC 2).

12.2 Where Applicable Data Protection Law grants the Customer a mandatory audit right that cannot be satisfied by documentation, the Customer may conduct (at its own cost, once per 12 months, on 30 days’ notice, under confidentiality, and without access to other customers’ data) an audit of Spock’s relevant processing environments and records. Physical inspection of third-party data centres is excluded; the operators’ own certifications apply.

13. International transfers

13.1 Transfers of Customer Content from the EEA to the US sub-processors in Annex B are governed by the EU Standard Contractual Clauses (2021/914), Module 3 (processor to processor) or Module 2 as applicable, entered into with each vendor, supplemented by the measures described in the Transfer Impact Assessments published on the Trust Center.

13.2 For transfers subject to the UK GDPR, the UK International Data Transfer Addendum to the EU SCCs applies. For transfers subject to Swiss law, the SCCs apply as adapted for Switzerland (references to the GDPR read as the FADP; competent authority the FDPIC).

13.3 For transfers from South Africa, the parties rely on s. 72(1)(b) POPIA: the SCCs and vendor DPAs constitute binding agreements providing an adequate level of protection. The protections of this DPA extend to personal information of juristic persons to the extent POPIA protects them.

14. Liability

Each party’s liability under this DPA is subject to the limitations and the enhanced data-protection cap in the Terms of Service, except to the extent Applicable Data Protection Law prohibits such limitation.

15. Order of precedence; governing law

In case of conflict regarding the processing of personal information, this DPA prevails over the Terms of Service, and the SCCs prevail over this DPA. This DPA is governed by the law governing the Agreement, except where the SCCs or Applicable Data Protection Law require otherwise.


Annex A — Details of processing

As set out in section 2.

Annex B — Authorised sub-processors

The authoritative, current version of this list (with change history) is published at spock.chat/trust.

Sub-processorLocationPurposeSafeguard
OpenAI, L.L.C.USAI inference (when an OpenAI model is selected)DPA + SCCs; no training; ≤30-day retention
Anthropic, PBCUSAI inference (when an Anthropic model is selected)DPA + SCCs; no training; ≤30-day retention
Google LLC (Gemini API / Vertex AI)USAI inference; image generation; voice-note transcriptionDPA + SCCs; no training; ≤30-day retention
xAI Corp.USAI inference (when an xAI model is selected); traffic routed via a Spock-operated US relayDPA + SCCs; no training; ≤30-day retention
Fireworks AI, Inc.USHosted open-source model inferenceDPA + SCCs; no training; ≤30-day retention
Hetzner Online GmbHGermanyHosting of core dataDPA; EU processing
DigitalOcean LLCGermany (region)Hosting of core dataDPA + SCCs; EU region
DaytonaEUSandboxed code execution; input files transferred per runDPA; EU processing
SerperGlobal (treated as a third-country transfer)Web search queriesDPA + SCCs
ZenRows S.L.Spain (EU)Web page retrieval on user requestDPA
Meta Platforms (WhatsApp Business Platform)US/globalWhatsApp channel messaging (only when connected)Meta Business terms + SCCs
Cloudflare, Inc.US/global (EU delivery)Transactional email (mail.spock.chat)DPA + SCCs
Stripe, Inc.US/globalPayment processing (independent controller for card data)DPA + SCCs
Slack Technologies (Salesforce)USInternal support and incident alerting (support requests, response reports, error alerts: identifiers, workspace names, submitted text)DPA + SCCs

Not sub-processors: the Spock model and embeddings (self-hosted on Spock-managed EU infrastructure); OCR (self-hosted); third-party apps and MCP servers the Customer connects under its own accounts.

Annex C — Technical and organisational measures