NEURONETIX LLC / NerveLab
DATA PROCESSING ADDENDUM
Effective July 27, 2026
This Data Processing Addendum (“DPA”) forms part of the agreement between the NerveLab customer (“Customer”) and NEURONETIX LLC (“NerveLab”) when NerveLab processes personal information on Customer’s behalf.
1. Definitions
“Applicable Data Protection Law” means privacy or data-protection law applicable to the processing. “Customer Personal Data” means personal information processed by NerveLab on Customer’s behalf. “Process,” “controller,” “business,” “processor,” “service provider,” “contractor,” and similar terms have the meanings provided by applicable law.
2. Roles and instructions
Customer is the controller or business for Customer Personal Data, and NerveLab is the processor, service provider, or contractor, except where NerveLab independently determines a processing purpose disclosed in the Privacy Policy.
NerveLab will process Customer Personal Data only to provide, secure, support, and improve the contracted Services; follow documented Customer instructions; comply with law; and exercise rights permitted to a processor or service provider.
The agreement, Customer configuration, authorized support requests, and use of the Services constitute documented instructions.
3. Customer obligations
Customer will:
Provide lawful instructions.
Have a valid basis for processing and communications.
Provide required notices and obtain required consents.
Avoid providing data unnecessary for the Services.
Configure permissions, retention, recording, channels, and safeguards appropriately.
Respond to individuals and regulators where Customer is responsible.
4. Processing details
Subject matter: Operation of AOS, Artemis, and contracted communications, relationship, memory, workflow, analytics, and support capabilities.
Duration: The subscription and any limited retention period permitted by the agreement or law.
Nature and purpose: Hosting, organizing, analyzing, transmitting, generating, securing, and supporting customer-authorized information and communications.
Data subjects: Customer users, administrators, prospects, leads, customers, and authorized communication participants.
Data categories: Contact and professional information; account identifiers; Customer Content; communication content and metadata; approved business facts; relationship context; preferences; objections; commitments; outcomes; recordings and transcripts when enabled; consent, suppression, audit, and security records.
Sensitive data: Not intended unless expressly authorized and protected by additional written terms. Customer must not provide highly sensitive information unnecessary for the Services.
5. Confidentiality and personnel
NerveLab will ensure that personnel authorized to process Customer Personal Data are subject to confidentiality obligations and receive access appropriate to their duties.
6. Security
NerveLab will maintain reasonable administrative, technical, and organizational safeguards appropriate to the nature of processing and risk, including access controls, authentication, tenant separation, transmission protection, logging, vulnerability management, backup practices, and incident response appropriate to the deployed Services.
Specific security claims will be documented in a security schedule or Trust Center only after operational verification.
7. Subprocessors
Customer generally authorizes NerveLab to use subprocessors necessary to provide the Services. NerveLab will impose data-protection obligations appropriate to their processing. NerveLab will make a current subprocessor list available before production activation or in an applicable Trust Center and will provide a reasonable mechanism for notice of material changes.
8. Individual requests
Taking into account the nature of processing, NerveLab will provide reasonable assistance for Customer to respond to valid rights requests. If NerveLab receives a request relating solely to Customer Personal Data, NerveLab may direct the requester to Customer unless law requires otherwise.
9. Security incidents
NerveLab will notify Customer without undue delay after confirming a security incident affecting Customer Personal Data when required by law or agreement. Notice will include available information reasonably necessary for Customer’s response. NerveLab’s notice is not an admission of fault.
10. Compliance assistance
Taking into account the nature of processing and information available, NerveLab will provide reasonable assistance with legally required security assessments, impact assessments, consultations, and regulatory inquiries. Extraordinary assistance may be subject to reasonable fees unless caused by NerveLab’s breach.
11. Return and deletion
Following termination or Customer instruction, NerveLab will delete or return Customer Personal Data within a commercially reasonable period, subject to backup cycles, suppression requirements, legal retention, security, and dispute needs. Retained data remains protected and is not used for another purpose.
12. Audits
NerveLab will make information reasonably necessary to demonstrate compliance available to Customer. Where required by law and not satisfied by reports or documentation, Customer may conduct an audit no more than annually on reasonable notice, during business hours, without disrupting operations or exposing another customer’s information. Customer bears its costs unless an audit identifies a material NerveLab breach.
13. U.S. state restrictions
Where NerveLab acts as a California service provider or contractor, NerveLab will not sell or share Customer Personal Data, retain, use, or disclose it outside the business purposes specified in the agreement, or combine it with unrelated personal information except as permitted by law. NerveLab certifies that it understands and will comply with these restrictions.
14. International transfers
If international transfer mechanisms are legally required, the parties will execute applicable standard contractual clauses or another lawful mechanism before the transfer.
15. Conflict
If this DPA conflicts with the Terms concerning processing of Customer Personal Data, this DPA controls. All other provisions of the Terms remain effective.