For vendors and service providers processing personal information
Effective date: August 11, 2026
When to use Attach this DPA to vendor agreements where a provider handles member, attendee, applicant, sponsor, subscriber, speaker, or other personal information on behalf of AI Insiders.
1. Scope and Roles
This Data Processing Addendum ("DPA") applies to personal information processed by Provider on behalf of Marvelous United, Inc. in connection with AI Insiders. The parties will act as business/controller and service provider/processor, or equivalent roles, to the extent those concepts apply under applicable privacy law.
2. Processing Instructions
Provider will process personal information only on documented instructions from AI Insiders and only for the limited, specified purposes in the underlying agreement, unless otherwise required by law. Provider will not sell or share personal information for cross-context behavioral advertising, combine it with unrelated data, or retain, use, or disclose it outside the direct business relationship except as permitted by applicable law and the agreement.
3. Confidentiality and Access
Provider will limit access to personnel with a need to know who are bound by appropriate confidentiality obligations and will implement least-privilege access controls appropriate to the services.
4. Security
Provider will maintain reasonable and appropriate administrative, technical, and physical safeguards proportionate to the nature and sensitivity of the personal information, including access control, authentication, encryption where appropriate, logging, vulnerability management, backup/recovery, incident response, and secure deletion practices.
5. Security Incidents
Provider will notify AI Insiders without undue delay after discovering unauthorized access to, acquisition of, use of, or disclosure of personal information processed under this DPA. Notice will include available details about affected data, individuals, cause, containment, remediation, and contact information, and Provider will reasonably cooperate with investigation, legal analysis, notices, and remediation.
6. Subprocessors
Provider may use subprocessors only under written terms that impose privacy and security obligations appropriate to the services. Provider remains responsible for subprocessors to the extent required by applicable law and contract. Provider will maintain an up-to-date list or provide notice of material subprocessor changes where required.
7. Consumer / Data Subject Requests
Taking into account the nature of processing, Provider will reasonably assist AI Insiders with access, deletion, correction, portability, opt-out, restriction, objection, appeal, and similar privacy requests, and will not respond directly except on instruction or as legally required.
8. Retention and Deletion
Provider will retain personal information only as necessary to perform the services or comply with law and, on termination or instruction, will return or securely delete it, subject to lawful archival requirements.
9. Assessments and Compliance Information
Provider will make information reasonably necessary to demonstrate compliance available to AI Insiders and will permit reasonable assessments, questionnaires, certifications, or audits where required by law or justified by material risk, subject to confidentiality, security, and proportionality safeguards.
10. International Transfers
If personal information is transferred across borders and transfer safeguards are legally required, the parties will cooperate to implement appropriate mechanisms, including applicable standard contractual clauses or equivalent safeguards.
11. Conflict
If this DPA conflicts with the underlying agreement on personal-information protection, this DPA controls for that subject matter. More protective obligations in the underlying agreement remain effective.
12. AI Systems; No Unrelated Training or Enrichment
Provider will not use personal information processed for Marvelous to train, fine-tune, evaluate, or improve a general-purpose or third-party model, build unrelated profiles, enrich external datasets, conduct facial recognition or voice identification, or create data products for Provider or another customer unless expressly authorized in writing by Marvelous and legally permitted. This restriction does not prohibit security, abuse-prevention, or service-operation processing that is necessary to provide the contracted service and is subject to appropriate safeguards.
13. Segregation and Purpose Controls
Provider will use reasonable logical or organizational controls to prevent personal information supplied by Marvelous from being combined with unrelated data for unauthorized marketing, cross-customer profiling, or participant outreach. Provider will not sell or share such personal information except as expressly permitted by the underlying agreement and applicable law.
| Signature: ____________________________ | Date: ____________________________ | |----|----| | Printed name: ____________________________ | Title: ____________________________ | | Company / Organization: ____________________________ | Email: ____________________________ | | : ____________________________ | : ____________________________ |
| Signature: ____________________________ | Date: ____________________________ | |----|----| | Printed name: ____________________________ | Title: ____________________________ | | Company / Organization: ____________________________ | Email: ____________________________ | | : ____________________________ | : ____________________________ |
