1. Parties and scope
This Data Processing Agreement ("DPA") is entered into between PediaSphere ("Processor" or "PediaSphere") and [Customer legal name] ("Controller" or "Customer") and forms part of the agreement under which PediaSphere provides the Service to Customer (the "Agreement").
This DPA applies to the Processing of Personal Data by PediaSphere on behalf of Customer in connection with the Service. Where Customer is itself a processor for another controller, Customer warrants that it has authority to instruct PediaSphere as a sub-processor on that controller's behalf.
In the event of conflict, this DPA prevails over the Agreement on matters of data protection.
2. Definitions
"Personal Data" means information that identifies, relates to, or could reasonably be linked to an individual. "Data Subject" means the individual to whom Personal Data relates. "Processing" means any operation performed on Personal Data. "Controller" means the party that determines the purposes and means of Processing; "Processor" means the party that Processes Personal Data on the Controller's behalf; "Sub-processor" means a third party engaged by the Processor to assist. "Personal Data Breach" means unauthorized access to, or accidental or unlawful destruction, loss, alteration, or disclosure of, Customer Personal Data. "Data Protection Laws" means the United States federal and state privacy and data-security laws applicable to the Processing of Personal Data under the Agreement, including the California Consumer Privacy Act as amended (CCPA/CPRA) and comparable state laws. "Customer Personal Data" means Personal Data contained in Customer Data.
3. Roles and instructions
- Customer is the Controller (or a Processor acting for a Controller) and PediaSphere is the Processor of Customer Personal Data.
- PediaSphere will process Customer Personal Data only on Customer's documented instructions, which consist of: (a) the Agreement; (b) this DPA; (c) Customer's and its Authorized Users' use of the Service's features and configuration; and (d) other written instructions Customer provides that are consistent with the Agreement.
- PediaSphere will inform Customer if, in its opinion, an instruction infringes Data Protection Laws, and may suspend the affected processing until the instruction is confirmed or withdrawn.
- PediaSphere will not sell Customer Personal Data, retain, use, or disclose it for any purpose other than providing the Service, or combine it with data from other sources except as permitted by the Agreement.
4. Customer obligations
Customer is responsible for: (a) the accuracy, quality, and lawfulness of Customer Personal Data and the means by which it was obtained; (b) providing any required notices to and obtaining any required consents from Data Subjects; (c) configuring roles and permissions in the Service appropriately, including whether demographic or special-category data is collected and who may access it; and (d) ensuring its instructions comply with Data Protection Laws.
5. Confidentiality and personnel
PediaSphere will ensure that persons authorized to process Customer Personal Data are bound by confidentiality obligations, have received appropriate training, and access Customer Personal Data only to the extent necessary to perform their role.
6. Security
PediaSphere will implement and maintain the technical and organizational measures described in Annex II, which are designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. PediaSphere may update these measures from time to time provided the overall level of protection is not reduced.
7. Sub-processors
- Customer authorizes PediaSphere to engage the Sub-processors listed in Annex III.
- PediaSphere will notify Customer at least 30 days before adding or replacing a Sub-processor by email to Customer's billing contact. Customer may object in writing within that period on reasonable data-protection grounds. If the parties cannot resolve the objection, Customer may terminate the affected Service and receive a pro-rated refund of prepaid fees.
- PediaSphere will impose data-protection obligations on each Sub-processor that are no less protective than those in this DPA, and remains liable for their performance.
8. AI processing
Where the Service uses AI models to process Customer Personal Data, PediaSphere will: (a) scope AI requests to Customer's data and the requesting user's permissions; (b) exclude government identifiers, dates of birth, and payment card data from AI prompts; (c) exclude special-category and demographic data at the individual level, providing it to AI models only as aggregates and only for users whose role permits demographic reporting; (d) not use Customer Personal Data to train or fine-tune AI models; and (e) engage AI Sub-processors only under terms that prohibit training and require zero retention of prompts and outputs beyond the request. Details are published at pediasphere.ai/security.asp#ai.
9. Data Subject requests
PediaSphere will promptly (and in any event within 10 business days) notify Customer of any request received directly from a Data Subject and will not respond except on Customer's instruction or where required by law. The Service provides self-service tools to access, correct, export, and delete Customer Personal Data; where those tools are insufficient, PediaSphere will provide reasonable assistance at no charge for ordinary requests.
10. Personal Data Breach
PediaSphere will notify Customer without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notice will describe, to the extent known, the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed. PediaSphere will update Customer as further information becomes available and will cooperate with Customer's investigation and any required notifications to regulators or Data Subjects.
11. Assistance
Taking into account the nature of the processing and the information available to it, PediaSphere will assist Customer in meeting its obligations regarding security, breach notification, data protection or risk assessments, and consultation with regulators where required. Assistance beyond what is reasonably included in the Service may be charged at PediaSphere's then-current rates with Customer's prior approval.
12. Audits
PediaSphere will make available information reasonably necessary to demonstrate compliance with this DPA, including completed security questionnaires and, where available, third-party audit reports or certifications. Not more than once per year (or following a Personal Data Breach), Customer may conduct an audit, on at least 30 days' notice, during business hours, at Customer's expense, by Customer or an independent auditor bound by confidentiality, in a manner that does not unreasonably disrupt PediaSphere's operations or expose other customers' data. PediaSphere will remediate confirmed non-compliance within a reasonable period.
13. Processing locations
Customer authorizes PediaSphere and its Sub-processors to Process Customer Personal Data in the United States and in the other locations listed in Annex III. PediaSphere's team operates from North America, South America, and Western Europe; support personnel in those locations access Customer Personal Data only through the Service's access controls and only as needed to provide support. If Customer later requires PediaSphere to Process Personal Data that is subject to the data-protection laws of a jurisdiction outside the United States (for example, the EU or UK), the parties will execute any additional transfer terms required by those laws before such Processing begins.
14. Return and deletion
During the term, Customer may export Customer Personal Data at any time using the Service's export features. Following termination, PediaSphere will, at Customer's election made within 30 days, return Customer Personal Data in a commonly used format or delete it. Absent an election, PediaSphere will delete Customer Personal Data from active systems within 90 days of termination. Data in backups will be overwritten in the normal backup cycle (30 days) and will not be restored except as required to comply with law. PediaSphere may retain Customer Personal Data to the extent required by law, subject to continued confidentiality.
15. Liability and term
Each party's liability under this DPA is subject to the limitations in the Agreement. This DPA remains in force for as long as PediaSphere Processes Customer Personal Data.
16. Governing law
This DPA is governed by the law specified in the Agreement.
Annex I — Description of processing
| Item | Description |
|---|---|
| Controller | [Customer legal name, address, contact] |
| Processor | PediaSphere, legal@pediasphere.ai |
| Subject matter | Provision of the PediaSphere membership, event, and analytics platform and related support. |
| Nature and purpose | Hosting, storage, retrieval, analysis, reporting, and AI-assisted querying of Customer Data to operate Customer's membership program and/or events; support by email and AI; backups and security monitoring. |
| Duration | The term of the Agreement plus the return/deletion period in Section 14. |
| Categories of Data Subjects | Customer's members, prospective members, event registrants and attendees, abstract authors and reviewers, committee members, officers, and staff. |
| Categories of Personal Data | Identification and contact data (name, email, postal address, phone); professional data (institution, specialty, credentials, membership category and status); financial data (dues and registration payments, invoice history — not full card numbers); event data (registrations, sessions, abstracts, reviews); account and audit data (sign-in events, actions taken). |
| Special categories (if Customer elects to collect them) | [e.g. race/ethnicity, gender identity, disability status, collected for diversity reporting]. Processed only in aggregate for reporting; excluded from AI prompts at the individual level; access restricted to roles designated by Customer. |
| Frequency | Continuous, for the duration of the Agreement. |
| Retention | As set out in Section 14. |
Annex II — Technical and organizational measures
| Measure | Implementation |
|---|---|
| Hosting and physical security | Microsoft Azure data centers, Central US, with Microsoft's physical, environmental, and network controls. |
| Encryption in transit | TLS 1.2 or higher on all connections; HTTP redirected to HTTPS; certificates auto-renewed. |
| Encryption at rest | Azure SQL Transparent Data Encryption; backups encrypted with the same keys; keys managed and rotated by Azure. |
| Authentication | Passwordless sign-in via one-time email link, SMS code, or authenticator app (TOTP); short-lived single-use tokens; automatic session expiry. |
| Access control | Role-based access with row-level permissions enforced on every query; Customer administrators manage roles; PediaSphere production access limited to named engineers with separate credentials per environment. |
| Tenant isolation | Logical separation of each Customer's data in the database and at the AI layer. |
| Backups and recovery | Continuous backups with point-in-time restore; geo-redundant copies in a second Azure region; restores tested periodically. |
| Logging and monitoring | Append-only audit log of sign-ins, role changes, exports, record edits, and AI exchanges; 24/7 uptime and anomaly monitoring with alerting. |
| AI safeguards | As described in Section 8: scoping, sensitive-field exclusion, aggregate-only demographics, no training, zero-retention provider terms, human review sampling, prompt-injection defenses, read-only by default. |
| Secure development | Parameterized queries, input validation, output encoding; dependency review; platform patching by Azure. |
| Incident response | Documented process; Customer notification per Section 10; post-incident review with corrective actions. |
| Personnel | Confidentiality obligations; least-privilege access; access revoked on role change or departure. |
| Data minimization and deletion | Self-service export and delete tools; deletion on termination per Section 14. |
Annex III — Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Microsoft Corporation (Azure) | Cloud hosting, database, storage, backups | Central US |
| Anthropic PBC and OpenAI | AI-assisted support and analytics under zero-retention, no-training terms | United States |
| Microsoft Corporation (Microsoft Graph, via PediaSphere's in-house mail gateway) | Transactional and support email | United States |
| Customer's payment processor of choice (e.g. PayPal, Stripe) | Invoicing and payments | Global |
The current list is maintained on this page. Customers receive notice of changes per Section 7.
Signatures
By signing below (or by accepting the Agreement, which incorporates this DPA by reference), the parties agree to this DPA including its Annexes.