This Data Processing Addendum ("DPA") forms part of the Terms of Service (the "Agreement") entered into by and between you ("Controller") and Dyspute Inc., a Delaware Corporation ("Processor" or "Dyspute").
1. Scope and Applicability
This DPA applies to the extent that Dyspute processes information that relates to an identified or identifiable individual (“Personal Data”) on behalf of the Controller while providing content, services, tools, features, and functionality offered on or through the website https://www.dyspute.ai (collectively, the “Services”), including Personal Data relating to Controller’s employees, customers, opposing parties, counterparties, or other third-party data subjects involved in a dispute (collectively, "Data Subjects").
- Nature and Scope of Processing: In connection with the Services, Dyspute provides mediation, letter-generation, settlement-agreement, and other dispute-resolution functionalities to enable users to create, edit, send, and manage various types of documents and information. This includes AI-assisted tools for case summaries, settlement proposals, and document drafting.
- Jurisdiction and Cross-Border Transfers: Dyspute primarily operates from the United States and serves users physically located in the United States and Canada. Data is processed in accordance with the California Consumer Privacy Act (“CCPA”), California Privacy Rights Act (“CPRA”), Personal Information Protection and Electronic Documents Act (“PIPEDA”), and Quebec Law 25. The Controller acknowledges that Personal Data may be transferred to, and processed within, the United States, making it subject to local jurisdictions and lawful access requests by U.S. authorities.
- Exclusions: Dyspute's services are not directed toward persons under 18, and the processing of children's data is strictly out of scope.
2. Processing of Personal Data
- Types of Data Processed: The Controller authorizes Dyspute to process data necessary to deliver Dyspute’s Services, including but not limited to account information, third-party log-in data (e.g., Google API), dispute information and case documents (including evidence, correspondence, and financial details involving counterparties), communications, and usage data automatically collected via tracking technologies (“Dispute Data”). Payment Information is processed directly by third-party payment vendors and is not retained by Dyspute.
- Processor Obligations: Dyspute will process Personal Data strictly on the documented instructions of the Controller. Dyspute acts as a "Service Provider" under the CCPA/CPRA and will not sell Personal Data or share it with third parties for cross-context behavioral advertising. Dyspute will not use Personal Data contained in Controller’s Dispute Data to train public or foundational third-party AI models.
- Controller Obligations & Counterparty Warranties: The Controller represents and warrants that it has provided all necessary notices and obtained all required permissions, legal bases, or statutory rights under applicable privacy laws to disclose Personal Data (including Personal Data of opposing parties or counterparties) to Dyspute for Controller to use the Services. The Controller bears sole responsibility for ensuring that its submission of Dispute Data to Dyspute complies with all applicable laws, court orders, confidentiality agreements, and privacy regulations.
3. Sub-processors
The Controller grants Dyspute general authorization to engage third-party sub-processors to assist in delivering Dyspute’s Services.
- Current Sub-processors: Dyspute utilizes affiliates, third-party infrastructure providers, payment processors, messaging gateways, and AI model providers. This includes, without limitation, enterprise cloud hosting and database providers, generative AI providers, firewalls, login authentication services, payment gateways, email/SMS delivery vendors, and analytics providers (e.g., Convex, Vercel, Cloudflare, Stripe, Google, OpenAI, Resend) used to support platform security, route user inputs, process payments, deliver communications, and generate outputs.
- Sub-processor Agreements: Dyspute maintains appropriate agreements with Sub-processors that govern the Sub-processors’ compliance with applicable data protection standards and privacy laws.
4. Security of Processing
Dyspute implements and maintains reasonable organizational, technical, and administrative measures to protect Personal Data against unauthorized access, destruction, loss, alteration, or misuse. These measures are overseen jointly by the Chief Operating Officer (Governance/Chief Privacy Officer) and Chief Technology Officer (Technical) and include:
- Access Control: Personal Data is only accessed by a limited number of personnel who require access to perform their duties. Strict personnel security policies govern onboarding, access provisioning, and endpoint security.
- Vulnerability Management: Dyspute conducts ongoing tracking and remediation of vulnerabilities in Dyspute’s systems, code, and third-party dependencies.
- AI Risk Management: Dyspute adheres to the NIST AI Risk Management Framework (AI RMF) 1.0.
- Business Continuity: Dyspute operates under a formalized Business Continuity and Disaster Recovery Plan prioritizing the protection of customer authentication, active mediation sessions, and document generation workflows.
5. Incident Response and Breach Notification
Dyspute maintains a formalized Incident Response Plan.
- Notification: In the event of a confirmed breach of customer data, Dyspute will notify the Controller without undue delay.
- Assistance: Dyspute will provide reasonable assistance and sufficient information to allow the Controller to meet its regulatory breach notification obligations.
6. Data Subject Rights
Dyspute’s Chief Operating Officer serves as the Chief Privacy Officer and manages compliance with privacy obligations. As a Service Provider, Dyspute processes Data Subject data on behalf of the Controller.
- Routing Requests: If Dyspute receives a privacy request from any Data Subject related to Data Subject’s Personal Data provided by Controller to Dyspute (including opposing parties or counterparties regarding data uploaded by Controller), Dyspute will direct the Data Subject to submit the request directly to the Controller.
- Assistance & Evidence Protection: Dyspute will provide reasonable technical assistance to help the Controller fulfill valid requests to the extent required by applicable law. Dyspute will not unilaterally delete active dispute materials uploaded by Controller without Controller's written instruction or a legal/court mandate.
7. Dual-Role Clarification
If a Data Subject independently registers for a Dyspute account or submits data directly to Dyspute, such data submitted directly by that Data Subject shall be governed by Dyspute’s direct Agreement and Privacy Policy with that individual or entity, while data uploaded by Controller regarding that Data Subject shall remain governed by this DPA.
8. Data Deletion and Retention
Dyspute retains Personal Data for as long as it is providing Dyspute’s Services to the Controller. Upon termination of the Agreement or when an account is closed, Dyspute will keep Personal Data only to the extent necessary to comply with legal, reporting, and record-keeping obligations, and to support the ongoing development of Dyspute’s Services, in accordance with applicable limitation periods and internal privacy and data-deletion policies.