Legal
Data Processing Addendum
This Data Processing Addendum (“DPA”) forms part of the agreement between the customer and Impulse Creative (“Peerfold”) whenever Peerfold processes personal data on the customer’s behalf. Capitalized terms follow the Terms of Service.
1. Roles and scope
For personal data of learners and other data subjects in the customer’s workspace, the customer is the controller and Peerfold the processor. Processing lasts for the term of the agreement plus the deletion window in the Data Retention Policy.
2. Nature and purpose of processing
Hosting and operating training workspaces: identity and enrollment, learning progress and assessment, certification, assistant conversations, commerce, notifications, and — at the customer’s direction — synchronization of learner records into the customer’s own CRM systems.
3. Categories of data and data subjects
Data subjects: the customer’s learners, admins, and staff. Categories: contact details (name, email), learning activity and results, certificates, free-text assistant conversations, order records (no card data — payment instruments are held by Stripe), and technical identifiers (sessions, audit actors). The platform is not designed for special categories of data, and the customer agrees not to direct such data into it.
4. Instructions
Peerfold processes personal data only on the customer’s documented instructions: this DPA, the configuration the customer’s admins set in the product (integrations connected, assistants granted, features enabled), and the use of the service itself. Connecting a CRM or granting an AI assistant is an instruction; disconnecting it withdraws it.
5. Confidentiality and personnel
Access to customer data by our personnel is limited to what operating and supporting the service requires, under confidentiality obligations. Support access to a workspace happens through explicit, time-boxed, audit-logged impersonation grants (30 minutes), visible to the customer.
6. Security (technical and organizational measures)
- Workspace isolation enforced structurally on every database query.
- Encryption in transit (TLS) and at rest; third-party credentials and IdP secrets encrypted with AES-256-GCM.
- httpOnly session cookies; single-use, short-lived sign-in codes; PKCE-only public OAuth clients with exact-match callbacks.
- Admin consent required for every AI-assistant grant; one-click revocation kills all derived tokens.
- Comprehensive audit logging of mutations across UI, API and agent surfaces.
- Rate and write limits on API and agent traffic; append-only assistant transcripts.
- Database point-in-time recovery; media on redundant object storage.
7. Subprocessors
The customer generally authorizes the subprocessors listed in the Privacy Policy. We bind subprocessors to materially equivalent obligations, remain responsible for their performance, and update the published list before adding a subprocessor that processes customer personal data — customers with a signed DPA may object on reasonable data-protection grounds. Services the customer connects itself (its own CRM, meeting tools, credential issuers, SSO) are engaged under the customer’s own agreements and are not Peerfold subprocessors.
8. International transfers
The service is currently hosted in the United States. Where data protection law requires a transfer mechanism, the parties incorporate the applicable standard contractual clauses into the signed DPA.
9. Assistance
We assist the customer with data-subject requests (access, export, rectification, erasure — see the Data Retention Policy for how erasure treats certificates and logs), and with security and impact assessments, by providing the information in these pages and reasonable further cooperation.
10. Personal data breach
We notify the customer without undue delay after becoming aware of a personal data breach affecting the customer’s data, with the information needed for the customer’s own notification duties, and keep the customer informed as the investigation proceeds.
11. Deletion and return
On termination, the customer may export its data; thereafter we delete it per the Data Retention Policy, subject to backup expiry within the stated recovery window. Records already written into the customer’s own systems are unaffected.
12. Audit
We make available the information reasonably necessary to demonstrate compliance with this DPA — these published policies, our audit logs concerning the customer’s workspace, and answers to reasonable security questionnaires.
Execution
To execute a signed DPA (including standard contractual clauses where needed), contact legal@peerfold.com.
Questions? Write to hello@peerfold.com and a person will answer.
Contact us