Skip to content

Privacy & Data Protection

Data Processing Agreement (DPA)

Risely's Data Processing Agreement, available for customers and prospects to review, covering how we process personal data on your behalf.

Last reviewed: July 2026

This Data Processing Agreement (DPA) is made available for customers and prospects to review. It forms part of Risely’s agreements wherever Risely processes personal data on a customer’s behalf, and it is offered to customers as an exhibit to the Risely SaaS Services Agreement. Risely is a product of Culturro Inc.

Data Processing Agreement

This Data Processing Agreement (“DPA”) forms part of, and is incorporated into, the SaaS Services Agreement or other written agreement (the “Agreement”) between Culturro Inc., a Delaware corporation with its place of business at 16192 Coastal Highway, Lewes, Delaware 19958, USA, provider of the Risely platform (“Processor” or “Risely”), and the customer identified in the Agreement (“Controller” or “Customer”). It governs the Processing of Personal Data by Risely on behalf of Customer in connection with the services described in the Agreement (the “Services”).

1. Definitions

“Personal Data”, “Controller”, “Processor”, “Data Subject”, “Processing”, “Personal Data Breach”, and “Supervisory Authority” have the meanings given in Applicable Data Protection Law.

“Applicable Data Protection Law” means all data protection laws applicable to the Processing of Personal Data under the Agreement, including, where applicable, the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and the UK Data Protection Act 2018, and applicable US state privacy laws.

“Customer Personal Data” means Personal Data Processed by Risely on behalf of Customer under the Agreement, as described in Annex 1. Customer Personal Data does not include data that has been aggregated or de-identified such that it no longer relates to an identified or identifiable individual.

“Sub-processor” means any third party engaged by Risely to Process Customer Personal Data on behalf of Customer.

“EU SCCs” and “UK Addendum” have the meanings given in Section 13.

2. Roles, Scope, and Customer Warranties

Customer is the Controller and Risely is the Processor of the Customer Personal Data Processed under the Agreement. Each party will comply with its obligations under Applicable Data Protection Law. The details of Processing (subject matter, duration, nature and purpose, categories of Personal Data, and categories of Data Subjects) are set out in Annex 1.

Customer warrants that:

  • (a) it has, and will maintain, a lawful basis for the Processing of Customer Personal Data under this DPA, including any required notices to, or consents or consultations with, Data Subjects, employees, or employee representative bodies;
  • (b) its instructions to Risely comply with Applicable Data Protection Law; and
  • (c) it will not instruct or permit its users to submit special categories of personal data, criminal offence data, or personal data of children to the Services.

Risely is not responsible for a failure to perform this DPA to the extent caused by Customer’s breach of this Section or by Processing carried out in accordance with Customer’s instructions.

3. Processing on Instructions

Risely will Process Customer Personal Data only on Customer’s documented instructions, including with regard to international transfers, unless required to do otherwise by law to which Risely is subject. In that case, Risely will inform Customer of that legal requirement before Processing unless the law prohibits it. The Agreement, this DPA, and Customer’s use and configuration of the Services constitute Customer’s documented instructions.

If Customer issues an instruction that falls outside the scope of the Agreement, this DPA, or the standard functionality of the Services, Risely will notify Customer, and the parties will agree in writing on its feasibility, any resulting changes, and any additional fees before Risely is obliged to comply.

Risely will promptly inform Customer if, in its opinion, an instruction infringes Applicable Data Protection Law, and may suspend Processing under such an instruction until it is confirmed or modified.

4. Confidentiality

Risely ensures that all persons authorized to Process Customer Personal Data are bound by written confidentiality obligations or are under an appropriate statutory obligation of confidentiality, and Process Customer Personal Data only as needed to provide the Services.

5. Security

Risely implements and maintains appropriate technical and organizational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, as described in Annex 2. Risely may update these measures from time to time, provided the updates do not materially reduce the overall level of protection.

6. Sub-processors

Customer provides general written authorization for Risely to engage Sub-processors for the Processing of Customer Personal Data. The Sub-processors engaged at the date of this DPA are listed in Annex 3. Risely will:

  • (a) impose data protection obligations on each Sub-processor that are no less protective than those in this DPA;
  • (b) remain liable for the performance of each Sub-processor’s obligations; and
  • (c) give Customer at least 30 days’ prior written notice of the addition or replacement of any Sub-processor, sent to the contact designated under Section 9 or via the Services’ administrative interface.

If Customer reasonably objects on data protection grounds and the parties cannot resolve the objection, Customer may terminate the affected Services and receive a pro-rata refund of prepaid fees for the terminated portion.

7. No Training on Customer Personal Data

Risely will not use Customer Personal Data to train or improve any machine learning or artificial intelligence model, other than Processing needed to provide the Services to Customer. Risely engages its AI Sub-processors under commercial API terms that, as of the date of this DPA, exclude the use of data submitted through their APIs for the training of their models, and Risely will:

  • (a) maintain such terms with each AI Sub-processor, and
  • (b) if an AI Sub-processor ceases to offer such terms, cease submitting Customer Personal Data to that Sub-processor and notify Customer under Section 6.

8. Assistance with Data Subject Requests

Taking into account the nature of the Processing, Risely will assist Customer by appropriate technical and organizational measures, insofar as this is possible, in fulfilling Customer’s obligation to respond to Data Subjects’ requests to exercise their rights (including access, rectification, erasure, restriction, portability, and objection).

If Risely receives a request directly from a Data Subject relating to Customer Personal Data, Risely will promptly forward it to Customer and will not respond except to direct the Data Subject to Customer.

Customer will reimburse Risely’s reasonable costs of assistance under this Section to the extent the assistance exceeds the self-service features of the Services and is not attributable to Risely’s breach of this DPA.

9. Personal Data Breach

Risely will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects. Risely will provide reasonable ongoing updates and cooperation.

Notifications under this Section will be sent to the contact designated by Customer in writing for privacy notices (or, absent designation, to Customer’s notice address under the Agreement). Customer is responsible for keeping this contact current.

As between the parties, Customer is solely responsible for determining whether to notify, and for notifying, Supervisory Authorities and Data Subjects of a Personal Data Breach, and Risely will provide reasonable cooperation for that purpose. Risely’s notification of a Personal Data Breach is not an acknowledgment of fault or liability.

10. Assistance with DPIAs and Consultations

Taking into account the nature of the Processing and the information available to it, Risely will provide reasonable assistance to Customer with data protection impact assessments and prior consultations with Supervisory Authorities relating to the Services. Customer will reimburse Risely’s reasonable costs of assistance under this Section to the extent the assistance exceeds the self-service features of the Services and is not attributable to Risely’s breach of this DPA.

11. Deletion and Return of Customer Personal Data

Upon termination or expiry of the Agreement, or upon Customer’s written request, Risely will, at Customer’s choice:

  • (a) return Customer Personal Data to Customer in a commonly used, machine-readable format and thereafter delete it, or
  • (b) delete Customer Personal Data,

in each case within 30 days, unless retention is required by law to which Risely is subject (in which case Risely will protect the retained data under Annex 2 and Process it only as required by that law).

Absent an election by Customer within 30 days of termination or expiry, Customer is deemed to have chosen deletion. Upon request, Risely will confirm deletion in writing.

Where Customer requests deletion of Customer Personal Data that is required to provide ongoing Services during the term, the parties acknowledge that the affected Services may cease to function for the affected Data Subjects, and Risely is relieved of the corresponding Service obligations to that extent.

Customer Personal Data held in encrypted backups is deleted as those backups expire under Risely’s backup retention schedule and in any event within 90 days of the deletion deadline above, is not restored to production except as needed for disaster recovery, and remains protected by the measures in Annex 2 until expiry. Where the parties have agreed, identifiable Customer Personal Data may instead be de-identified such that it no longer relates to an identifiable individual.

12. Audit and Information

Risely will make available to Customer information reasonably necessary to demonstrate compliance with this DPA, including its information security policies and this DPA’s annexes, under confidentiality. Risely maintains records of its Processing activities as required by Article 30(2) GDPR.

Customer may conduct an audit (including inspection) of Risely’s compliance with this DPA no more than once per 12-month period, on at least 30 days’ written notice, during normal business hours, without disruption to Risely’s operations, and subject to confidentiality obligations. Audits may be conducted by Customer or by an independent third-party auditor mandated by Customer that is not a competitor of Risely and that has entered into confidentiality obligations reasonably acceptable to Risely. Customer bears its own and its auditor’s costs.

If an audit (other than one following a Personal Data Breach affecting Customer Personal Data, or one required by a Supervisory Authority) requires more than two business days of Risely personnel time, Risely may charge Customer for the additional time at its then-standard professional services rates, notified in advance. The parties will first seek to satisfy audit requests through written information, documentation, and policy review.

13. International Transfers

13.1 Customer Personal Data is hosted in the United States and may be remotely accessed from India by the affiliate Sub-processor identified in Annex 3.

13.2 To the extent the Processing involves a transfer of Personal Data subject to the GDPR to a country not benefiting from an adequacy decision, the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021, Module Two (Controller to Processor) (the “EU SCCs”), are incorporated into and form part of this DPA, with Customer as data exporter and Risely as data importer, completed as set out in Annex 4 Part A. The parties agree that execution of this DPA constitutes execution of the EU SCCs and their Annexes by both parties.

13.3 To the extent the Processing involves a transfer of Personal Data subject to the UK GDPR, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner (version B1.0, in force 21 March 2022) (the “UK Addendum”) is incorporated into and forms part of this DPA and amends the EU SCCs as set out therein, completed as set out in Annex 4 Part B.

13.4 In the event of a conflict between this DPA and the EU SCCs or the UK Addendum, the EU SCCs and the UK Addendum prevail to the extent of the conflict and in respect of the transfers to which they apply.

14. US State Privacy Laws

To the extent Customer Personal Data is subject to US state privacy laws (including the California Consumer Privacy Act, as amended), Risely acts as a “service provider” or “processor”. Risely will not:

  • (a) sell or share Customer Personal Data;
  • (b) retain, use, or disclose Customer Personal Data other than to provide the Services and as permitted by such laws;
  • (c) retain, use, or disclose Customer Personal Data outside the direct business relationship between the parties; or
  • (d) combine Customer Personal Data with personal data it receives from other sources, except as permitted for a service provider.

Risely certifies that it understands and will comply with these restrictions, will notify Customer if it determines it can no longer meet them, and grants Customer the right, upon notice, to take reasonable steps to stop and remediate unauthorized use of Customer Personal Data.

15. Liability

Each party’s liability arising out of or related to this DPA is subject to the exclusions and limitations of liability set out in the Agreement.

16. Term and General

This DPA takes effect on the effective date of the Agreement and remains in force for as long as Risely Processes Customer Personal Data on behalf of Customer. In the event of a conflict between this DPA and the Agreement with respect to the Processing of Customer Personal Data, this DPA prevails. This DPA is governed by the law governing the Agreement, except where Applicable Data Protection Law requires otherwise.

Annex 1: Details of Processing

Subject matter: Provision of the Risely AI leadership coaching platform and related support, as described in the Agreement.

Duration: The term of the Agreement, plus the deletion period in Section 11.

Nature and purpose of Processing: Hosting, storage, transmission, and analysis of Personal Data to deliver AI-powered coaching sessions, role plays, skill assessments, coaching plans, notifications, and aggregated administrative analytics, and related technical support.

Categories of Data Subjects: Customer’s employees and other individuals authorized by Customer to use the Services.

Categories of Personal Data: Name, work email address, role/function and related profile details; coaching conversation content (text; voice interactions are transcribed in real time and the audio is not stored); assessment responses and skill scores; usage and engagement data. The Services are not intended for the Processing of special categories of personal data, and Customer agrees not to instruct its users to submit such data. The parties acknowledge that Data Subjects may incidentally volunteer information in free-text or voice coaching interactions that constitutes special categories of personal data. Such data is not requested or used by the Services for any distinct purpose, is protected by the measures in Annex 2, and Customer is responsible for informing its users about appropriate use of the Services.

Frequency: Continuous, for the duration of the Agreement.

Annex 2: Technical and Organizational Measures

  • Hosting: Production systems and Customer Personal Data are hosted on Google Cloud Platform in the United States. Physical and environmental security is inherited from Google’s certified data center operations (ISO/IEC 27001, SOC 2).
  • Encryption: Customer Personal Data is encrypted in transit (TLS 1.2 or higher) and at rest (AES-256).
  • Access control: Production data access is restricted to named, authorized personnel on a least-privilege basis; two-factor authentication is enforced on all company accounts; access is reviewed quarterly for production systems and revoked within one business day of personnel termination.
  • Application access: End users authenticate via one-time passcodes delivered to their verified work email. Customer administrators control user invitation and deactivation. Administrators receive AI-generated summaries and engagement metrics; they do not receive raw conversation transcripts.
  • Backups: Automated encrypted database snapshots at least weekly, retained on a rolling schedule, with restoration testing at least annually.
  • Organizational measures: A documented information security policy set (including access control, encryption, data classification, data deletion, incident management, breach notification, vendor and sub-processor management, and AI governance), reviewed at least annually; confidentiality obligations for all personnel; security incident management with defined severity levels and response procedures.

Annex 3: Authorized Sub-processors

  • Google LLC (Google Cloud Platform), cloud infrastructure and hosting, United States.
  • OpenAI, L.L.C., large language model and speech-to-text API services used to deliver coaching functionality, United States.
  • Anthropic, PBC, large language model API services used to deliver coaching functionality, United States.
  • Google LLC (AI services), large language model and text-to-speech API services used to deliver coaching functionality, United States.
  • ELTV Technologies Pvt. Ltd, wholly owned affiliate of Culturro Inc. providing engineering, operations, and support services, India.

All AI service Sub-processors are engaged under commercial API terms that exclude the use of submitted data for the training of their models. Provider data-usage commitments are established in Risely’s written agreements with each Sub-processor; the providers’ published policies are informational only and do not form part of this DPA.

Annex 4: Completion of the EU SCCs and UK Addendum

Part A: EU SCCs (Module Two)

The EU SCCs are completed as follows:

  • Clause 7 (Docking clause): shall not apply.
  • Clause 9(a): Option 2 (General written authorisation) applies; the time period for prior notice of Sub-processor changes is 30 days, as set out in Section 6 of this DPA.
  • Clause 11(a): the optional language (independent dispute resolution body) shall not apply.
  • Clause 13 / Annex I.C: the competent supervisory authority is the supervisory authority of the EU Member State in which the data exporter is established; where the data exporter is not established in the EU but falls within Article 3(2) GDPR, it is the supervisory authority of the Member State in which the data exporter’s representative under Article 27 GDPR is established or, absent such appointment, of the Member State in which the Data Subjects are predominantly located.
  • Clause 17: Option 1 applies; the EU SCCs are governed by the law of Ireland.
  • Clause 18(b): disputes shall be resolved before the courts of Ireland.
  • Annex I.A: Data exporter: the Customer identified in the Agreement (contact: the notice contact designated under the Agreement or under Section 9 of this DPA); role: controller; activities: use of the Services as controller. Data importer: Culturro Inc., 16192 Coastal Highway, Lewes, Delaware 19958, USA (contact: [email protected]); role: processor; activities: provision of the Services.
  • Annex I.B: as set out in Annex 1 to this DPA, supplemented as follows. Sensitive data: none is intended to be transferred, and Customer has agreed not to instruct its users to submit such data. Frequency: continuous. Retention: the term of the Agreement plus deletion within 30 days per Section 11, with backup copies expiring per Section 11. Transfers to Sub-processors: as set out in Annex 3, for the purposes and locations there stated (United States and India).
  • Annex II: as set out in Annex 2 to this DPA. Annex III: as set out in Annex 3 to this DPA.

Part B: UK Addendum

The UK Addendum is completed as follows:

  • Table 1 (Parties): as set out in Annex 4 Part A (Annex I.A), with the effective date of this DPA as the start date.
  • Table 2 (Selected SCCs, Modules and Selected Clauses): the EU SCCs, Module Two, as incorporated and completed under Part A of this Annex.
  • Table 3 (Appendix Information): Annex 1A and 1B, as per Annex 1 to this DPA and Annex 4 Part A; Annex II, as per Annex 2 to this DPA; Annex III, as per Annex 3 to this DPA.
  • Table 4 (Ending this Addendum when the Approved Addendum changes): neither party may end this Addendum as set out in Section 19 of the UK Addendum, save as required by law.

Contacting us about this DPA

To request a signed copy or ask questions, contact us at [email protected].

← Back to Trust Center

Questions about this policy? [email protected]