Legal
Data processing addendum
The data-protection terms that apply when Continual processes personal data in Customer content on a customer's behalf.
Last updated
1. Scope and application
This Data processing addendum (the “DPA”) forms part of the agreement between Continual, Inc. (“Continual”) and the customer using the Service (“Customer”). It applies automatically whenever Continual processes Customer Personal Data on Customer's behalf in connection with the Service. No separate signature is required. A signed copy is available by contacting legal@continual.ai.
This DPA supplements the Terms of service, an applicable order form, or another agreement governing the Service (the “Agreement”). If this DPA conflicts with the Agreement about the processing of Customer Personal Data, this DPA controls. The Agreement controls for other matters.
“Customer Personal Data” means personal data contained in Customer content that Continual processes on Customer's behalf. It does not include account, billing, relationship, or Service data that Continual processes for its own legitimate business purposes as described in the Privacy policy and Agreement. “Data Protection Laws” means privacy, data-protection, and data-security laws applicable to the processing of Customer Personal Data under this DPA.
2. Roles and instructions
Customer is the controller or business and Continual is the processor, service provider, or contractor for Customer Personal Data. If Customer acts as a processor for another controller, Continual acts as Customer's subprocessor. The parties are not joint controllers for Customer Personal Data.
Customer instructs Continual to process Customer Personal Data only to provide, operate, secure, maintain, and support the Service; perform actions initiated by Customer and its authorized users; connect to Customer systems as directed; prevent fraud and abuse; and comply with applicable law. The Agreement, Customer's use and configuration of the Service, and authorized support requests are Customer's documented instructions. The processing details are in Schedule 1.
Continual will notify Customer if it reasonably believes an instruction violates Data Protection Laws. Continual may decline or suspend an instruction that would violate law or materially compromise the security, confidentiality, availability, or operation of the Service. If law requires processing outside Customer's instructions, Continual will notify Customer before processing unless legally prohibited.
3. Customer responsibilities
Customer is responsible for its instructions and use of the Service, including the accuracy, quality, and legality of Customer Personal Data. Customer will provide all notices, obtain all rights and consents, establish a lawful basis, and configure the Service and Customer systems as required by Data Protection Laws. Customer will not instruct Continual to process data in violation of law.
Unless Continual agrees otherwise in writing, Customer will not submit payment-card data subject to PCI DSS or protected health information regulated by HIPAA. Continual is not a HIPAA business associate unless the parties have signed a business associate agreement.
4. Confidentiality and security
Continual will ensure that personnel authorized to process Customer Personal Data are bound by confidentiality obligations and access it only as needed to perform their duties. Continual will maintain reasonable administrative, technical, and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. The current categories of measures are described in Schedule 2.
Customer acknowledges that security is a shared responsibility. Customer is responsible for its authorized users, account credentials, devices, Customer systems, permissions, configurations, and backups outside the Service.
Continual has completed a SOC 2 Type II examination for the systems within its audit scope. The current report is available to appropriate customers and prospective customers on request, subject to confidentiality requirements.
5. Rights requests and compliance assistance
Taking into account the nature of the processing and information available to Continual, Continual will provide reasonable assistance to Customer with data-subject requests, security obligations, regulatory consultations, data-protection impact assessments, and other obligations under Data Protection Laws. If Continual receives a request concerning Customer Personal Data, it will direct the requester to Customer or forward the request to Customer, where identifiable and legally permitted, and will not respond on Customer's behalf unless instructed or legally required.
Continual may charge reasonable, documented fees after advance notice for assistance that requires material work beyond standard Service functionality, except where Data Protection Laws prohibit charging.
6. Security incidents
A “Security Incident” is a confirmed breach of security that results in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data in Continual's possession or control. It does not include unsuccessful attempts that do not compromise Customer Personal Data, such as blocked login attempts, scans, pings, or denial-of-service attacks.
Continual will notify Customer without undue delay after confirming a Security Incident. As information becomes available, Continual will provide a description of the incident, the categories of affected data and individuals where known, likely consequences, mitigation taken or proposed, and a contact for follow-up. Continual will investigate, mitigate, and take reasonable steps designed to prevent recurrence. Notice is not an admission of fault or liability.
7. Subprocessors
Customer gives Continual general written authorization to engage the subprocessors on our current Subprocessors page, which is incorporated into this DPA as Schedule 3. Continual will require each subprocessor to protect Customer Personal Data under written terms materially consistent with this DPA, as applicable to the services it provides. Continual remains responsible for its subprocessors' performance of their data-protection obligations to the extent required by Data Protection Laws.
Continual may add, remove, or replace subprocessors as the Service changes and will keep the Subprocessors page current. Where Data Protection Laws require advance notice, Continual will inform Customer of an intended addition or replacement by email, in-product notice, or another reasonable method and provide an opportunity to object before the new subprocessor begins processing Customer Personal Data. No minimum notice period applies except where required by law. An objection must be based on reasonable, documented data-protection grounds. The parties will work in good faith on a commercially reasonable resolution. If none is available, Customer may stop using the affected feature or terminate it under the Agreement. Refunds and credits remain governed by the Agreement. Continual may make a change without advance notice when reasonably necessary to address an emergency, security risk, service interruption, or provider unavailability and will give any legally required notice as soon as reasonably practicable.
A Customer system that Customer connects under its own agreement with the provider is not a Continual subprocessor merely because the Service exchanges data with it at Customer's direction. Its processing is governed by Customer's agreement and settings with that provider.
8. International transfers
Continual is based in the United States. Continual and its subprocessors may process Customer Personal Data in the United States and other countries identified in Schedule 3 or the applicable provider's documentation. Continual will use a legally recognized transfer mechanism where Data Protection Laws require one.
EEA transfers
For a restricted transfer governed by the GDPR, the Standard Contractual Clauses adopted by European Commission Implementing Decision (EU) 2021/914 (the “EU SCCs”) are incorporated by reference. Module Two applies when Customer is a controller and Module Three applies when Customer is a processor. For the EU SCCs:
- Clause 7, the optional docking clause, applies;
- Clause 9(a), Option 2 applies using the notice process in Section 7, without a fixed minimum period except where required by law;
- the optional language in Clause 11 does not apply;
- Ireland is the governing Member State under Clause 17 and its courts have jurisdiction under Clause 18; and
- Schedules 1, 2, and 3 complete Annexes I, II, and III respectively.
United Kingdom and Switzerland
For restricted transfers governed by the UK GDPR, the EU SCCs are modified by and incorporate the mandatory clauses of the UK International Data Transfer Addendum, template B.1.0 issued by the Information Commissioner and in force March 21, 2022, as revised under its terms. The parties and transfer details are those in this DPA, and either party may end the UK Addendum as permitted by its mandatory clauses. For transfers governed by Swiss data-protection law, the EU SCCs apply with references adapted to Swiss law and the competent Swiss authority, as required.
If a transfer mechanism becomes invalid or unavailable, the parties will cooperate in good faith to implement another lawful mechanism. Continual may suspend the affected transfer or processing until an appropriate mechanism is in place.
9. U.S. state privacy laws
To the extent U.S. state privacy laws apply, Customer discloses Customer Personal Data to Continual only for the limited and specific business purposes in Section 2 and Schedule 1. Continual acts as a service provider or contractor and will:
- process Customer Personal Data only for those purposes and as otherwise permitted by applicable law;
- not sell or share Customer Personal Data or use it for cross-context behavioral advertising;
- not retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer;
- not combine Customer Personal Data with personal data received from another person or collected from Continual's own interaction with an individual, except as permitted by applicable law;
- provide the same level of privacy protection required of service providers and contractors and notify Customer if Continual determines it can no longer meet those obligations; and
- cooperate with reasonable requests to stop and remediate unauthorized use and allow Customer to take reasonable steps to verify compliance, subject to Section 12.
By agreeing to this DPA, Continual certifies that it understands and will comply with these restrictions.
10. Service data and AI model training
Continual does not use Customer Personal Data to train, retrain, fine-tune, or otherwise develop generalized artificial-intelligence or machine-learning models, and requires platform-managed model providers not to use it for those purposes. Customer Personal Data may be used for model improvement only if Customer's workspace administrator expressly opts in to a separately described program.
Continual may process operational, security, billing, usage, and performance data as described in the Agreement. Service data may include feature and tool usage, provider and model identifiers, token and resource quantities, timing, latency, retries, success or failure states, and sanitized error codes. Service data is not Customer Personal Data to the extent it does not contain, reveal, or reasonably identify Customer Personal Data, Customer, or an individual.
Continual may use Service data and aggregated or de-identified information to operate, secure, troubleshoot, evaluate, and improve the Service, including its system prompts, routing, tool selection, retrieval, orchestration, guardrails, and runtime behavior. Continual does not use raw prompts, responses, files, code, connected-system records, tool inputs or outputs, or content-bearing error payloads for generalized product improvement except when needed to provide support requested by Customer or when Customer expressly opts in.
11. Return and deletion
During the term, Customer may access or export Customer Personal Data using available Service functionality. After termination, Customer Personal Data is generally available for export for 30 days. Continual may then delete or de-identify it unless law requires retention or the Agreement states otherwise. Deleted data may remain in backups until overwritten through normal retention cycles and will remain protected under this DPA while retained.
On written request, Continual will confirm deletion where required by Data Protection Laws. Continual may retain billing, transaction, security, fraud-prevention, and legal records for its own lawful purposes; those records are not Customer Personal Data governed by Customer's deletion instruction.
12. Information and audits
Continual will make information reasonably necessary to demonstrate compliance with this DPA available to Customer, which may include security documentation, summaries, questionnaires, or independent reports that Continual then maintains. Customer will first use that information before requesting an audit.
If the available information is insufficient and Data Protection Laws require further review, Customer may conduct one audit in a 12-month period, or an additional audit after a Security Incident, through a qualified independent auditor bound by confidentiality. The audit must occur during normal business hours on reasonable advance notice, avoid disruption, protect other customers and Continual's confidential information, and exclude vulnerability testing and access to data not relevant to Customer. Customer bears its costs, and Continual may charge reasonable costs for material assistance, unless the audit identifies a material breach by Continual.
13. Liability and general terms
Liability arising from this DPA is subject to the exclusions and caps in the Agreement, including any higher cap that expressly applies to confidentiality, security, or data-protection obligations. Those caps apply in the aggregate across the Agreement and this DPA and are not cumulative.
This DPA begins when it first applies under Section 1 and continues for as long as Continual processes Customer Personal Data. The governing law and dispute terms in the Agreement apply except where the EU SCCs, UK Addendum, or Data Protection Laws require otherwise. If a provision is unenforceable, it will be modified to the minimum extent necessary and the remainder will continue.
Schedule 1 — Processing details
- Parties
- The data exporter is Customer and permitted affiliates using the Service. The data importer is Continual, Inc., 95 3rd St, San Francisco, CA 94103, United States. Privacy contact: privacy@continual.ai. Customer's address and contact information are those in its account or order form.
- Subject matter and duration
- Processing Customer Personal Data to provide the Service for the term of the Agreement and the limited retention period described in Section 11.
- Nature and purpose
- Hosting, storage, organization, retrieval, transmission, compilation, indexing, analysis, AI-assisted generation, software development and deployment, automation, execution of Customer instructions and connected-system actions, support, security, maintenance, and deletion.
- Categories of individuals
- Customer's authorized users, administrators, employees, contractors, business contacts, customers and prospective customers; users of Customer applications; and other individuals whose information Customer includes in Customer content or makes accessible through Customer systems.
- Categories of personal data
- Account and profile details; contact and business information; communications; prompts, instructions, responses, and outputs; files, code, documents, records, project and application data; connected-system data; configuration and authorization data; credentials and secrets; device, network, usage, diagnostic, and security information; and other personal data Customer chooses to process through the Service.
- Sensitive data
- Sensitive or special-category data only to the extent Customer is permitted to process it and the Service is configured and authorized for that use. PCI-regulated payment-card data and HIPAA-regulated protected health information are excluded unless Continual agrees otherwise in writing.
- Frequency
- Continuous or on demand, as initiated by Customer's use and configuration of the Service.
Schedule 2 — Security measures
Continual's security measures are designed to reflect the nature and risk of the processing and may evolve with the Service. They include, as appropriate:
- security ownership, risk review, workforce confidentiality, and security-aware vendor management;
- identity-based access, least-privilege authorization, authentication controls, and review of privileged access;
- protection of data in transit and at rest using appropriate encryption, including separate protection for stored credentials and secrets;
- logical separation of customer workspaces and server-side authorization for access to Customer content;
- software-change controls, code review, dependency and vulnerability management, infrastructure controls, and production safeguards;
- logging, monitoring, audit records, incident detection and response, and procedures for security-event escalation;
- availability, backup, recovery, and business-continuity measures appropriate to the relevant component of the Service; and
- retention and deletion processes and contractual protections for subprocessors.
Current deployment, access, SOC 2 Type II scope, and assurance details are available for enterprise review by contacting support@continual.ai.
Schedule 3 — Authorized subprocessors
The current Subprocessors page is incorporated into this DPA as Schedule 3. It identifies the provider, processing role, and typical processing location for each listed subprocessor.