Legal

Data Processing Addendum

Effective date: August 14, 2026 · Version 2026-08-14

Part of the customer agreement

This Data Processing Addendum (“DPA”) forms part of the agreement between an organization customer (“Customer”) and Eria Studios, Inc. (“Eria”) governing Customer’s use of Enspeller. It applies when Eria processes Customer Personal Data as a processor or service provider for Customer.

1. Formation and authority

This DPA is incorporated into the Enspeller Terms of Service, an order form, or another written agreement that references it (the “Agreement”). A person accepting the Agreement for a Customer represents that they have authority to bind Customer. The parties agree that electronic acceptance and records satisfy a requirement that this DPA be in writing. If Customer has a separately signed data-processing agreement with Eria, the signed agreement controls to the extent of a conflict.

2. Definitions

“Applicable Data Protection Law” means privacy and data-protection law applicable to the processing, including the EU General Data Protection Regulation 2016/679 (“EU GDPR”), the EU GDPR as incorporated into United Kingdom law (“UK GDPR”), the Swiss Federal Act on Data Protection, and United States state privacy laws where applicable. “Customer Personal Data” means personal data, personal information, or equivalent regulated information contained in Customer Data that Eria processes for Customer under the Agreement. “Customer Data” means content and account data submitted to Enspeller by or for Customer. “Subprocessor” means a processor appointed by Eria to process Customer Personal Data.

“Controller,” “processor,” “processing,” “personal data,” “data subject,” “sell,” “share,” “service provider,” and “contractor” have the meanings given by Applicable Data Protection Law. If a term has different meanings, the meaning under the law being applied controls.

3. Roles and instructions

Customer is the controller or a processor acting on another controller’s instructions. Eria is Customer’s processor or subprocessor for Customer Personal Data. Customer instructs Eria to process Customer Personal Data only to provide, secure, support, and maintain Enspeller; perform actions initiated by authorized users; comply with the Agreement and documented Customer instructions; and meet applicable law. The Agreement, Customer’s configuration and use of features, support requests, and this DPA are Customer’s documented instructions.

Eria will process Customer Personal Data only on those instructions unless law requires otherwise. In that case, Eria will tell Customer about the legal requirement before processing unless law prohibits notice. Eria will promptly inform Customer if, in Eria’s opinion, an instruction infringes Applicable Data Protection Law and may suspend the affected processing while the parties resolve it.

4. Customer responsibilities

Customer is responsible for its instructions; the lawfulness, fairness, transparency, accuracy, and minimization of Customer Personal Data; giving required notices; obtaining required permissions; responding as controller to data subjects; and configuring access appropriately. Customer will not submit data prohibited by the Agreement and will not instruct Eria to process personal data in violation of law. Customer determines whether Enspeller is appropriate for its processing and must not use Enspeller for regulated health, financial-account, government-classified, or similarly restricted workloads unless a signed agreement expressly authorizes that use.

5. Personnel and confidentiality

Eria will limit access to Customer Personal Data to personnel who need it for the Agreement, ensure they are bound by confidentiality obligations or an appropriate statutory duty, provide relevant privacy and security training, and apply least- privilege access. Confidentiality obligations continue after access or employment ends.

6. Security

Considering the state of the art, implementation costs, the nature and scope of processing, and risks to individuals, Eria will maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Current measures are described in Schedule 2. Eria may update them without materially reducing the overall protection of the service.

7. Subprocessors and written authorization

Customer gives Eria general written authorization to use the subprocessors in the Subprocessor Register. Eria will enter a written agreement with each Subprocessor imposing data-protection obligations that provide substantially the same protection required by this DPA for the processing it performs. Eria remains responsible to Customer for a Subprocessor’s performance of those obligations to the extent required by Applicable Data Protection Law.

Eria will provide at least 14 days’ advance notice to the Customer organization owner and recorded legal/privacy contact before a new Subprocessor processes Customer Personal Data. Customer may object during that period on reasonable data-protection grounds by emailing compliance@eriastudios.com. The parties will work in good faith on a commercially reasonable alternative. If none is available, either party may discontinue the affected feature or terminate the affected service, and Eria will refund prepaid fees for the terminated period. An emergency security appointment may take effect sooner, with notice as soon as practicable.

8. Data-subject requests

Taking into account the nature of processing, Eria will provide reasonable technical and organizational assistance for Customer to respond to verified requests to access, correct, delete, restrict, object, port, or otherwise exercise rights under Applicable Data Protection Law. If Eria receives a request concerning Customer Personal Data directly, Eria will direct the requester to Customer and will not independently respond except on Customer’s documented instruction or as legally required. Customer is responsible for responding and for reasonable costs of unusually burdensome assistance.

9. Compliance assistance

Taking into account the nature of processing and information available to Eria, Eria will reasonably assist Customer with security obligations, breach notifications, data- protection impact assessments, and prior consultation with regulators. Eria will make available information reasonably necessary to demonstrate compliance with processor obligations under Applicable Data Protection Law.

10. Personal Data Breach

Eria will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notice will include, as information becomes available, the nature of the breach, affected data and individuals, likely consequences, measures taken or proposed, and a contact for follow-up. Eria will take reasonable steps to contain, investigate, mitigate, and remediate the breach and will provide updates. Notice is not an admission of fault. Customer is responsible for notices to regulators and individuals unless law requires Eria to notify directly.

11. Return and deletion

During the service term, Customer may export supported Customer Data using available features. At termination or on Customer’s documented request, Eria will delete or return Customer Personal Data unless law requires retention. Deletion propagates through live systems and then encrypted backups through scheduled rotation. Until deletion, retained data remains protected and is not used for another purpose. Eria may retain minimal contract, billing, security, or legal-claim records as an independent controller where law permits or requires it.

12. Audits

Eria will first provide relevant policies, summaries, questionnaires, and independent assurance reports available for the service. If that information is insufficient, Customer may conduct one audit in a 12-month period, and additional audits after a Personal Data Breach or where a regulator requires, through an independent auditor bound by confidentiality. Customer must give at least 30 days’ notice, keep the audit within normal business hours and scope, avoid access to other customers’ data, and reimburse reasonable costs. Eria may object to an auditor that is a competitor or presents a security or confidentiality risk. Regulatory audit rights are not limited by this section.

13. International transfers

Eria will use a lawful transfer mechanism for Customer Personal Data transferred to a country not recognized as providing adequate protection. Where applicable, the EU Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 (“EU SCCs”) are incorporated as described in Schedule 3. The UK International Data Transfer Addendum and Swiss modifications in Schedule 3 apply where relevant. Eria will implement supplementary measures where reasonably necessary following a transfer-risk assessment. Nothing here reduces a party’s duty to comply with localization or transfer requirements that apply to it.

14. United States state privacy terms

For Customer Personal Data subject to a United States comprehensive state privacy law, Eria acts as Customer’s service provider, contractor, or processor. Eria will not sell or share Customer Personal Data; retain, use, or disclose it outside the direct business relationship with Customer or for a commercial purpose other than the Agreement; or combine it with personal information received from another person or from Eria’s own consumer interactions, except as the law permits. Eria understands these restrictions, will provide the same level of privacy protection required of Customer for the covered data, and grants Customer the right to take reasonable and appropriate steps to verify compliance and stop and remediate unauthorized use. Eria will notify Customer if it determines it can no longer meet those obligations.

15. Government requests

Unless legally prohibited, Eria will notify Customer of a binding government request for Customer Personal Data. Eria will review the request for legal validity, challenge unlawful or overbroad requests where there are reasonable grounds, disclose only what is legally required, and document requests and responses as law permits.

16. Liability, conflict, and duration

The Agreement’s liability limits apply to this DPA to the maximum extent allowed by law, except that the EU SCCs and mandatory law control where they do not permit a limitation. If this DPA conflicts with the Agreement on processing Customer Personal Data, this DPA controls; the EU SCCs control over both for a transfer they govern. This DPA continues while Eria processes Customer Personal Data.

Schedule 1 — Details of processing

Subject matter and purpose Providing, securing, supporting, and maintaining Enspeller, including account administration, offline/cloud synchronization, collaboration, storage, export, billing administration, and user-requested analytical AI features.
Duration The Agreement term plus the deletion and backup-rotation period described in this DPA, unless law requires longer retention.
Nature of processing Collection, recording, organization, storage, retrieval, consultation, transmission, synchronization, analysis, embedding, restriction, export, deletion, and other operations initiated by authorized users or necessary to provide the service.
Data subjects Customer users, administrators, invited collaborators, personnel and contractors; support contacts; and individuals identified in content that Customer elects to submit.
Personal-data categories Names, email addresses, account and organization IDs, roles and permissions, authentication/security events, device and usage data, billing and subscription metadata, communications, manuscript/project content, prompts and requested analysis, derived continuity/lore/pacing information, and user-provided audio when voice is enabled.
Sensitive data Account credentials and any sensitive or special-category data Customer chooses to include in user content. Enspeller does not require special-category data for ordinary use. Customer must apply appropriate safeguards and may not submit prohibited regulated data.
Frequency Continuous for account, storage, sync, and security operations; event-driven for billing, email, support, exports, AI analysis, and voice.
Controller instructions The Agreement, this DPA, documented account configuration, actions by authorized users, and lawful written support instructions.

Schedule 2 — Technical and organizational measures

Schedule 3 — Restricted transfers

European Economic Area

For a transfer governed by the EU GDPR without another lawful transfer mechanism, the EU SCCs are incorporated by reference. Module Two applies where Customer is a controller and Eria a processor; Module Three applies where Customer is a processor and Eria a subprocessor. Clause 7 (docking) applies. For Clause 9, Option 2 applies with the 14-day period in this DPA. The optional language in Clause 11 does not apply. In Clause 17, Option 1 applies and the law of Ireland governs; under Clause 18, the courts of Ireland have jurisdiction. The competent supervisory authority under Clause 13 is determined by that clause. Schedule 1 is Annex I, Schedule 2 is Annex II, and the Subprocessor Register is Annex III. The parties’ identities and contact details are those in the Agreement; entering the Agreement is deemed signature of the EU SCCs.

United Kingdom

For a transfer governed by the UK GDPR, the then-current UK International Data Transfer Addendum issued by the Information Commissioner is incorporated. Its Part 1 tables are completed with the parties and selections above, including the applicable EU SCC module and appendices; either party may terminate the Addendum as permitted by its mandatory clauses if the approved form changes.

Switzerland

For a transfer governed by Swiss law, references in the EU SCCs to the EU GDPR include the Swiss Federal Act on Data Protection, “Member State” includes Switzerland, data subjects may enforce rights in Switzerland, and the competent authority is the Swiss Federal Data Protection and Information Commissioner where required. Governing law and forum are interpreted to permit those rights.

17. Contact

Eria Studios, Inc.

1111B S Governors Ave STE 34533
Dover, DE 19904
United States
DPA, audit, transfer, and privacy notices: compliance@eriastudios.com