LeaderCoreAI Data Processing Agreement
Data Processing Agreement (B2B)
Version 2.8 – 02.09.2026 – Effective on publication (subject to Clause 14.2 notice for material changes)
What's new in this version:
- Extended the incorporation language to cover Customers that contract directly with Vendor under the LeaderCoreAI Direct Customer Agreement, alongside Customers that purchase through a Reseller (Clauses 1.2, 1.3A, 3.5 and 13.1). No change to processing, Sub-processors or retention.
- Generalised the consent-gated analytics disclosure so that a Customer may designate a Reseller or another training partner (for example an external coach or consultant) as the recipient of its pseudonymised, aggregated cohort view (Annex 3).
- Added Order Form electronic-signature records for direct Customers to the audit and security log categories (Annex 1).
- Speech synthesis now runs by default on a generally available model (Gemini 2.5 Flash TTS) on Google's EU multi-region endpoint, fully within the Google Cloud Data Processing Addendum and Google's data-location commitment. The previously disclosed pre-general-availability model (Gemini 3.1 Flash TTS) remains available only on the Customer's documented instruction under new Clause 4.5, on the terms of Vendor's Preview Speech Model Instruction and Risk Acknowledgement (Annex 3, note on speech synthesis). This closes the qualification carried since version 2.7 for all Customers that do not give that instruction.
- Corrected Vendor's identifiers in Clause 1.1: registration number (CUI 43140466) and intra-EU VAT identification (RO43434054) are now shown separately.
Carried forward from version 2.7:
- Disclosed that speech synthesis ran on a pre-general-availability model which Google's terms exclude from the Google Cloud Data Processing Addendum and from Google's data-location commitment, with the scope and mitigations stated (Annex 3). Superseded in version 2.8: that model is no longer the default — see above.
Carried forward from version 2.6:
- Added Namecheap, Inc. (Private Email) as an authorised Sub-processor for
leadercore.aiemail delivery, with the Google Workspace role narrowed accordingly (Annex 3). - Clarified that AI processing of conversation inputs takes place within the EEA (Google Cloud
europe-central2and the EU multi-region), and disclosed the short-lived context-caching of conversation turns used to improve performance (Annexes 1 and 3). - Clarified the data location for Firebase Authentication: account-level authentication data is processed on Google's global infrastructure under the Google Cloud DPA and EU Standard Contractual Clauses, separately from the EEA-resident database, compute and file-storage services (Annex 3).
- Disclosed consent-gated Reseller analytics access — a pseudonymised, aggregated cohort view a Customer may choose to share with its Reseller (Annex 3) — and added read-only HR analytics viewers to the categories of data subjects (Annex 1).
- Disclosed AI usage / token telemetry held in the analytics warehouse in pseudonymised form (Annexes 1 and 3).
- Disclosed the Platform's spoken-practice processing: voice and audio data as a category of Personal Data, and speech transcription, speech synthesis and direct grading of recorded speech as processing operations carried out at the AI Sub-processor within the EEA. Audio is transmitted for processing and is not stored by Vendor (Annexes 1 and 3).
- Stated the GDPR/UK GDPR standard as a self-sufficient baseline that governs all Customer processing, with country-specific addenda supplementing (not replacing) it (new Clause 1.7).
- Clarified that whether a country-specific addendum applies is determined by the Customer's establishment and governing data protection law as Controller — not by the location, residence or nationality of individual users (Clauses 1.6 and 8.3).
- Added that the Customer, as Controller, is responsible for identifying and instructing Vendor on any law applicable to its processing beyond the baseline (new Clause 4.4).
- Replaced the end-of-term "anonymisation" language with de-identification: at the end of the Subscription Term, performance data is re-keyed and retained in pseudonymised form for research and product improvement under Article 89 GDPR safeguards, held by Vendor as controller; operational records, including all report text, are deleted (new Clause 11.2).
- Stated that activity and performance data held in the analytics warehouse is treated as pseudonymous personal data, not anonymous statistics, and remains within the scope of this DPA (new Clause 3.6).
Part of: the LeaderCoreAI Platform Terms (Conditions of Use – B2B Only) and, for direct Customers, the LeaderCoreAI Direct Customer Agreement (B2B Only)
Blue Horizon Training S.R.L.
1. Parties and Scope
1.1 Parties
This Data Processing Agreement ("DPA") is between: Blue Horizon Training S.R.L., Intrarea Biserica Albă 3, Ap. 6, 010298, Bucharest, Romania, CUI 43140466, intra-EU VAT identification RO43434054 ("Vendor" or "Processor"); and the business entity identified as Customer in the relevant order form or subscription arrangement, whether concluded with Vendor or with an authorised reseller ("Customer" or "Controller").
1.2 Incorporation
This DPA forms part of: (a) the LeaderCoreAI Platform Terms (Conditions of Use – B2B Only), where Customer acquires subscriptions through an authorised reseller ("Reseller"); (b) the LeaderCoreAI Direct Customer Agreement, where Customer acquires subscriptions directly from Vendor under an Order Form; and (c) any commercial agreement or order under which Customer acquires subscriptions to the LeaderCoreAI Platform.
1.3 Indirect Sales
Where Customer purchases via a Reseller, this DPA is a separate and direct agreement between Vendor (as Processor) and Customer (as Controller) for the processing of personal data in connection with Customer's use of the Platform. Reseller is not a party to this DPA, but remains responsible for its own processing activities as described in Customer's agreement with the Reseller.
1.3A Direct Sales
Where Customer purchases directly from Vendor, this DPA is concluded between Vendor (as Processor) and Customer (as Controller) on the Effective Date of the first Order Form under the Direct Customer Agreement, and references in this DPA to the "Platform Terms" are read as references to the Direct Customer Agreement, except that the Platform Terms continue to govern the individual use of the Platform by Customer's users as described in that Agreement.
1.4 Role of the Parties
For the Processing of Personal Data described in this DPA, Customer is the Controller, Vendor is the Processor, and Vendor may engage Sub-processors as set out herein.
1.5 Precedence
In case of conflict between this DPA and other terms between the parties regarding data protection, this DPA prevails to the extent of the conflict.
1.6 Country-Specific Addenda
Where Customer, in its capacity as Controller, is established in or otherwise subject to a data protection law that imposes requirements beyond or different from the GDPR in respect of its processing under this DPA, Vendor may make available country-specific addenda. The following country-specific addenda are hereby incorporated into this DPA and apply automatically, without further action by either party, to the extent their respective scope conditions are met:
- (a) UK Data Protection Addendum, available at https://leadercore.ai/legal/uk-dpa-addendum, which applies whenever and to the extent that Customer's processing under this DPA is subject to UK Data Protection Laws (as defined in that Addendum). Whether that Addendum applies is determined by reference to Customer's establishment and the data protection law governing Customer's processing as Controller, and not by the location, residence or nationality of individual data subjects.
Vendor may add further country-specific addenda from time to time in accordance with Clause 14.2 (Amendments), by publishing them at a URL referenced in this Clause 1.6 or otherwise notifying Customer. Where a country-specific addendum is incorporated under this Clause 1.6, it forms part of this DPA, and in case of conflict with this DPA regarding the processing of Personal Data covered by that addendum, the addendum prevails.
1.7 Baseline Data Protection Standard
This DPA constitutes a complete and self-sufficient set of data protection terms that governs all processing of Customer Data, regardless of Customer's location or the location of any data subject. Vendor's obligations under this DPA are designed to meet the requirements of the GDPR and the UK GDPR, which Vendor applies as its baseline standard for all Customer Data. Any country-specific addendum incorporated under Clause 1.6 supplements, and does not replace, this baseline standard, and adds only the additional or different requirements of the relevant jurisdiction. Where no country-specific addendum applies to a particular Customer, this DPA nonetheless governs that Customer's processing in full on the basis of this baseline standard.
2. Definitions
Terms used in this DPA have the meanings given in the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), in the Platform Terms, or as defined below:
- "Personal Data" means any information relating to an identified or identifiable natural person processed under this DPA.
- "Processing", "Controller", "Processor", "Data Subject", "Supervisory Authority" and "Personal Data Breach" have the meanings given in the GDPR.
- "Platform" means the LeaderCoreAI AI-powered leadership simulation platform as defined in the Platform Terms.
- "Customer Data" means Personal Data for which Customer is Controller and which Vendor processes on Customer's behalf in providing the Platform.
- "Sub-processor" means another processor engaged by Vendor to process Customer Data.
- "Applicable Data Protection Law" means the GDPR, and any other data protection or privacy law that applies to the processing of Customer Data under this DPA, including where applicable through a country-specific addendum (e.g., the UK GDPR and Data Protection Act 2018).
3. Subject Matter, Duration, Nature and Purpose of Processing
3.1 Subject Matter
Vendor processes Customer Data solely to provide the Platform, related services and support to Customer in accordance with the Platform Terms and this DPA.
3.2 Duration
This DPA applies for as long as Vendor processes Customer Data on behalf of Customer under any active Subscription Term and during subsequent deletion and de-identification periods described in the Platform Terms.
3.3 Nature and Purpose
The Processing includes collection, storage, organisation, retrieval, use, analysis, transmission, display and deletion, as necessary to:
- register and authenticate users;
- run training simulations and capture user responses;
- generate scores, feedback and reports;
- provide dashboards and analytics to authorised HR/Admin users;
- maintain security, monitor misuse, perform troubleshooting and quality improvements (in aggregated/pseudonymised form); and
- comply with applicable legal obligations.
3.4 Type of Personal Data and Categories of Data Subjects
Typical categories are described in Annex 1 and align with the Platform Terms (Clause 10).
3.5 Retention
Retention periods and deletion and de-identification practices follow the schedule set out in the Platform Terms (currently Clause 10.3) or, for direct Customers, the Direct Customer Agreement (currently Clause 12.4), as updated from time to time, and are deemed incorporated into this DPA.
3.6 Status of Analytics Data
Activity and performance data exported to Vendor's analytics warehouse is keyed by a hashed user identifier derived from the user's account identifier. Vendor treats such data as pseudonymous personal data and not as anonymous statistics. It remains subject to this DPA, including Customer's instructions, the security measures in Annex 2, and the deletion and data-subject-request provisions. A verified erasure request removes the data subject's records from the analytics warehouse as well as from the operational systems.
4. Controller's Instructions
4.1
Vendor shall process Customer Data only on documented instructions from Customer, including with regard to transfers of personal data to a third country or an international organisation, unless required to do so by EU or Member State law (or other Applicable Data Protection Law). In that case, Vendor shall inform Customer of that legal requirement before processing, unless the law prohibits such information.
4.2
The Platform Terms, this DPA (together with any applicable country-specific addendum) and Customer's documented configuration and use of the Platform constitute Customer's complete and final instructions to Vendor.
4.3
If Vendor reasonably believes an instruction infringes the GDPR or other Applicable Data Protection Law, Vendor will inform Customer without undue delay and may suspend the relevant processing until Customer confirms or modifies the instruction.
4.4 Customer's Responsibility for Applicable Law
As between the parties, Customer, as Controller, is responsible for identifying and informing Vendor of any data protection or other law applicable to Customer's processing under this DPA that imposes requirements beyond the baseline standard in Clause 1.7 (for example, requirements arising from Customer's own establishment, operations or activities). Vendor processes Customer Data to that baseline standard and to any country-specific addendum applicable under Clause 1.6, and will provide reasonable assistance in relation to additional requirements that Customer identifies and documents as an instruction under Clause 4.1. Vendor is not required to determine the location, residence or nationality of individual data subjects; the applicability of any country-specific addendum is determined as set out in Clause 1.6.
4.5 Instructed Use of a Preview Speech Model
Speech synthesis of simulated character dialogue runs by default on a generally available model within the EEA as described in Annex 3. Customer may, by a documented instruction under Clause 4.1 given on Vendor's Preview Speech Model Instruction and Risk Acknowledgement form (the "Preview Model Instruction"), instruct Vendor to use instead the pre-general-availability speech model identified in Annex 3 for Customer's tenant. Customer acknowledges that the Preview Model Instruction: (a) is given by Customer as Controller, on its own assessment, in the knowledge of the Sub-processor's stated position on that model as set out in Annex 3, including that the Sub-processor's terms exclude it from the data processing addendum and data-location commitment, advise against its use with personal data, and, on the Sub-processor's reading, permit the Sub-processor to use the input to improve its products and to retain it for the term of Vendor's agreement with the Sub-processor; (b) constitutes Customer's instruction regarding any resulting processing outside the EEA for the purposes of Clause 4.1; (c) may be revoked by Customer at any time with immediate effect by written notice, on which Vendor reverts Customer's tenant to the default model; and (d) lapses automatically when the model reaches general availability with an EEA data-location commitment, or when Vendor withdraws the model. Vendor records each Preview Model Instruction and revocation on Customer's subscription record. Where a Customer purchases through a Reseller, the Preview Model Instruction must nonetheless be given by Customer; a Reseller cannot give it on Customer's behalf.
5. Confidentiality and Personnel
5.1
Vendor shall ensure that persons authorised to process Customer Data are subject to appropriate confidentiality obligations (whether contractual or statutory).
5.2
Vendor shall ensure that such personnel only access Customer Data to the extent necessary to perform their role in providing the Platform.
6. Security of Processing
6.1
Vendor shall implement and maintain appropriate technical and organisational measures to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, as required by Article 32 GDPR (and equivalent provisions of any other Applicable Data Protection Law).
6.2
These measures include, where appropriate, measures relating to:
- access control and authentication;
- encryption in transit and at rest (where reasonably feasible);
- network and application security;
- logging and monitoring of security-relevant events;
- regular backup and recovery procedures;
- secure development and change-management practices; and
- incident response and business continuity processes.
6.3
A summary of the technical and organisational measures is set out in Annex 2. Customer is responsible for reviewing this summary and determining whether it satisfies Customer's own security requirements.
7. Sub-processors
7.1
Customer authorises Vendor to appoint Sub-processors for the purposes described in this DPA, subject to the conditions below.
7.2
Vendor shall:
- ensure that Sub-processors are bound by written agreements imposing obligations that are no less protective of Customer Data than this DPA; and
- remain responsible to Customer for the performance of each Sub-processor's obligations.
7.3
Vendor shall maintain a list of current Sub-processors and their relevant processing locations in Annex 3 (or at a URL referenced in Annex 3). Vendor may update this list from time to time.
7.4
Vendor shall provide notice (e.g. via email or posting on a Sub-processor list URL) of any intended addition or replacement of Sub-processors, giving Customer at least 14 days to object. Customer may object on reasonable grounds relating to data protection; in that case the parties will discuss in good faith. If no mutually acceptable solution is found, Customer may, as a sole and exclusive remedy, terminate the affected subscription(s) by written notice, with a pro-rated refund for any prepaid unused Subscription Term.
8. International Transfers
8.1
Vendor shall process Customer Data within the European Economic Area (EEA) or other countries recognised by the European Commission as providing an adequate level of protection, except as necessary to use authorised Sub-processors.
8.2
Where Customer Data is transferred to a country without an adequacy decision, Vendor shall ensure that appropriate safeguards under Article 46 GDPR are in place, such as:
- EU Standard Contractual Clauses (controller-to-processor) between Customer and Vendor or between Vendor and its Sub-processors; and/or
- other mechanisms permitted by Applicable Data Protection Law.
8.3
Where Customer's processing under this DPA is subject to non-EU data protection laws that impose separate transfer requirements (e.g., the UK GDPR) under Clause 1.6, the applicable country-specific addendum shall specify the transfer mechanisms for that jurisdiction.
8.4
Upon Customer's reasonable request, Vendor will provide information about the applicable transfer mechanism for specific Sub-processors listed in Annex 3.
9. Assistance to Customer
9.1 Data Subject Requests
Taking into account the nature of the Processing, Vendor shall assist Customer, by appropriate technical and organisational measures and where reasonably possible, in responding to Data Subjects' requests to exercise their rights under Chapter III GDPR (and equivalent provisions of any other Applicable Data Protection Law), including access, rectification, erasure, restriction, portability and objection.
- If a Data Subject contacts Vendor directly with such a request, Vendor will, where it can identify the Customer concerned, forward the request to Customer without undue delay.
- Vendor shall not respond directly on Customer's behalf unless authorised or legally required to do so.
9.2 Compliance and Impact Assessments
Taking into account the nature of Processing and the information available to Vendor, Vendor shall provide reasonable assistance to Customer in:
- ensuring compliance with the obligations under Articles 32–36 GDPR (security, breach notification, DPIAs, prior consultation) and equivalent provisions of any other Applicable Data Protection Law, and
- responding to inquiries or inspections by Supervisory Authorities relating to the Processing covered by this DPA.
9.3
Vendor may charge a reasonable fee for assistance under this Clause 9 if requests are manifestly unfounded, excessive or repetitive, or if they require effort beyond what is customary for comparable B2B SaaS services.
10. Personal Data Breach Notification
10.1
Vendor shall notify Customer without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a Personal Data Breach involving Customer Data.
10.2
Such notice shall include, to the extent reasonably available:
- a description of the nature of the Personal Data Breach;
- categories and approximate number of Data Subjects and data records concerned;
- likely consequences of the breach; and
- measures taken or proposed by Vendor to address the breach and to mitigate possible adverse effects.
10.3
Customer is responsible for fulfilling any legal notification obligations to Supervisory Authorities and Data Subjects, unless Applicable Data Protection Law expressly requires Vendor to do so.
11. Return and Deletion of Data
11.1
At the end of the relevant Subscription Term (or upon earlier termination in accordance with the Platform Terms), Vendor shall delete or de-identify Customer Data in accordance with the retention schedule in the Platform Terms and Clause 11.2, unless EU or Member State law (or other Applicable Data Protection Law) requires storage of certain data.
11.2 De-identification at Subscription End
At the end of the relevant Subscription Term, performance data — dimension and overall scores, scenario, difficulty, duration and message counts — is re-keyed and retained as structured, name-free records in pseudonymised form for research and product improvement under Article 89 GDPR safeguards; operational records, including all report text, are deleted, save for certificate records retained as described in Annex 1. Vendor retains those de-identified records as controller for its own research and product-improvement purposes; the mapping between those records and the operational identifiers is destroyed, and the records inform no decision about any data subject.
11.3
During the active Subscription Term, Customer may export or request export of certain data via in-product features or reasonable assistance from Vendor, as described in the Platform Terms.
11.4
Upon Customer's written request within the applicable retention period, Vendor shall confirm deletion or de-identification of Customer Data processed as Processor, subject to any legal obligations to retain data.
12. Audit Rights
12.1
Vendor shall provide Customer with all information reasonably necessary to demonstrate compliance with this DPA and Article 28 GDPR (and equivalent provisions of any other Applicable Data Protection Law), including:
- responses to security and compliance questionnaires;
- copies of relevant third-party certifications or audit reports (e.g. ISO, SOC), if available; or
- high-level descriptions of its controls and procedures.
12.2 Audit and Information Rights
- (a) Vendor will make available to Customer, upon reasonable request, information necessary to demonstrate compliance with this DPA and Article 28 GDPR, for example by providing written descriptions of its technical and organisational measures, responses to security/privacy questionnaires, or relevant third-party audit reports or certifications (if available).
- (b) If, after reviewing such information, Customer still reasonably considers that it needs an audit, Vendor shall allow and reasonably cooperate with an audit of the processing activities covered by this DPA to the extent required by Article 28(3)(h) GDPR. Any such audit shall:
- – be subject to at least 30 days' prior written notice;
- – be carried out during normal business hours;
- – be limited in scope to what is necessary to verify compliance with this DPA; and
- – be subject to appropriate confidentiality undertakings.
- (c) Customer is responsible for its own audit costs. Vendor may charge a reasonable fee for time spent by its personnel on audits, particularly where audits are requested more than once in any 12-month period, unless an additional audit is required by a Supervisory Authority.
13. Liability and Limitation
13.1
The limitations of liability in the Platform Terms or the Direct Customer Agreement (as applicable) and any applicable commercial agreement between the parties apply to this DPA and all claims arising from or in connection with it, to the maximum extent permitted by law.
13.2
Nothing in this DPA excludes or limits liability where such exclusion or limitation is not allowed under Applicable Data Protection Law or other applicable law.
14. Miscellaneous
14.1 Governing Law and Jurisdiction
This DPA is governed by Romanian law and subject to the exclusive jurisdiction of the courts of Bucharest, without prejudice to mandatory provisions of Applicable Data Protection Law (including the rights of data subjects and Supervisory Authorities under such law).
14.2 Amendments
Vendor may update this DPA, and may add or update country-specific addenda under Clause 1.6, to reflect changes in law or industry practice. Updates that increase only Vendor's obligations as Processor, or that are required to comply with applicable law, take effect on publication. Other material updates affecting Customer's data protection rights or Vendor's data protection obligations will be communicated via the Platform Terms URL or by other reasonable means at least 30 days before taking effect. If Customer objects to such a material update, Customer may terminate the affected subscription(s) by written notice within that 30-day period, with a pro-rated refund for any prepaid unused Subscription Term. If Customer does not object within that period, the updated DPA shall apply.
14.3 Severability
If any provision of this DPA is held invalid, the remaining provisions remain in effect.
Annex 1 – Description of Processing
Categories of Data Subjects
- Employees, contractors and other authorised users of Customer and its affiliates who access the Platform (including HR/Admin users and read-only HR analytics viewers ("hrViewer")).
- Reseller staff only to the extent they use the Platform as users of a Customer tenant.
Types of Personal Data
- Identification data: name, business email address, role/department, organisation, country.
- Account data: username, authentication data (hashed passwords if stored by Vendor, access tokens), subscription key used, seat allocations, last login time.
- Simulation interaction data: free-text responses, selections, scenario choices, timestamps, scores, grading outputs and feedback texts.
- Certificate records: name as it appeared at time of issuance, certificate type (scenario completion or scenario mastery, or collection-level equivalent), scenario name(s), score(s), difficulty, collection name, product name, date of award. Stored with permanent retention to support third-party verification of attainment, surviving end of Subscription Term and account deletion. On a verified Article 17 erasure request, Vendor redacts the data subject's name on the certificate record (replacing it with a tombstone value) while preserving the certificate's verifiable metadata. The public verification endpoint is designed to never return the data subject's name regardless of redaction status.
- Voice and audio data: where a user chooses to use the Platform's spoken-practice features, the audio of their spoken input, the transcript produced from it, and — in the spoken-communication module — scores derived from acoustic characteristics of the delivery (such as pace, clarity and vocal variety). Audio is transmitted to the AI Sub-processor for transcription or grading within the EEA and is not stored by Vendor; the resulting transcript and scores are retained as Simulation interaction data. Audio is not used to identify any individual.
- Usage and telemetry data: feature usage, event logs, performance metrics, error messages; AI usage/token-consumption events (keyed by a pseudonymous user hash; no transcript text).
- Audit and security logs: login attempts; IP addresses and user-agent strings captured for (a) demo account creation and demo-related fraud prevention, (b) Platform Terms click-wrap acceptance (evidence of contract formation), (c) Reseller Agreement click-wrap acceptance (evidence of contract formation), (d) reseller user-invitation rate-limiting, and (e) Order Form electronic-signature records for direct Customers (evidence of contract formation); consent and click-wrap acceptance events together with the IP and user-agent associated with each acceptance event. IP addresses captured for click-wrap acceptance are retained on the parent user/reseller record for the life of that record (i.e., for the duration of the relevant Subscription Term plus the post-termination retention periods set out in the Platform Terms).
Special Categories of Data
Voice recordings processed for transcription and for grading of spoken delivery are not used to uniquely identify any individual, and are therefore not biometric data within the meaning of Article 9 GDPR.
The Platform is not intended to process special categories of data within the meaning of Article 9 GDPR (e.g. health data, religious beliefs) or criminal offence data. Customer shall instruct users not to enter such data into free-text fields. If such data is incidentally submitted, Vendor will take reasonable steps to delete it upon becoming aware of its presence, and will not intentionally use it for profiling or any other purpose.
Processing Operations
- Collection via user registration and interaction with the Platform;
- Storage, organisation and retrieval in databases and logs;
- Analysis (e.g. generating scores, feedback and aggregated analytics);
- AI-powered processing of conversation text inputs for leadership scenario simulations (via Google Cloud Vertex AI, within the EEA — Google Cloud
europe-central2and theeuEU multi-region); - Where the user uses the Platform's spoken-practice features: transcription of the user's recorded speech to text; synthesis of simulated character speech; and, in the spoken-communication module, direct grading of the user's recorded audio. All three take place at the AI Sub-processor within the EEA (
europe-central2and theeuEU multi-region), save that synthesis of character speech for a Customer that has given a Preview Model Instruction under Clause 4.5 runs on a pre-general-availability model whose processing location is not contractually committed by the Sub-processor (Annex 3). Audio is processed transiently for these operations and is not stored by Vendor; - Short-lived ("context") caching of recent conversation turns at the AI Sub-processor within the EEA, to reduce repeated processing of the same tokens; cache entries carry a short time-to-live (in the order of minutes) and are deleted at session end or on expiry;
- Pseudonymisation/aggregation for analytics, including export of pseudonymised activity data to the analytics warehouse;
- Deletion or de-identification following retention periods.
Duration
For the Subscription Term and the post-termination retention periods described in the Platform Terms.
Annex 2 – Technical and Organisational Measures (TOMs)
Vendor implements, among others, the following measures (adapted as needed over time):
- Access control: role-based access to production systems; unique user accounts; least-privilege principles; periodic access reviews.
- Authentication: strong authentication mechanisms for internal staff; password policies for Customer users.
- Infrastructure security: use of reputable cloud providers with physical and environmental security; network segmentation; firewalls and security groups.
- Encryption: encryption of data in transit using TLS; encryption at rest using industry-standard algorithms, where reasonably feasible.
- Logging and monitoring: logging of security-relevant events; automated alerts for suspicious activity; retention of logs for security analysis in line with the Platform Terms.
- Backup and recovery: regular backups of critical databases; tested restore procedures; geo-redundant or regionally redundant storage depending on provider.
- Development security: use of version control; code reviews; dependency management; vulnerability scanning; separation of development, staging and production environments where appropriate.
- Incident management: a designated point of contact (the Administrator) for security incidents; incidents are triaged, contained and remediated on becoming aware, and affected Customers are notified in accordance with Clause 10; findings are used to harden the Platform.
- Organisational controls: confidentiality obligations for staff; security and privacy awareness training; policies covering acceptable use, device security and data handling.
Annex 3 – Authorised Sub-processors and Locations
Vendor uses the Sub-processors listed below, each providing infrastructure or services necessary to operate the Platform:
| Sub-processor | Service | Data Location(s) | Transfer Safeguard (if outside EEA) |
|---|---|---|---|
| Google Cloud Platform / Firebase | Hosting (Cloud Functions/Cloud Run), database (Cloud Firestore), file storage (Firebase Storage) | europe-central2 (Poland, EEA) | n/a (EEA) |
| Google Cloud – Firebase Authentication | User authentication and account management (sign-in; business email/identifier, authentication credentials, internal user identifier) | Google's global infrastructure (includes EU data centers); account data may be processed outside the EEA | Google Cloud DPA + EU Standard Contractual Clauses (controller-to-processor) |
| Google Cloud – Vertex AI | Generative AI processing of conversation text inputs for leadership scenario simulations, including short-lived context caching of conversation turns to reduce repeated token processing | Gemini 2.5 models: europe-central2 (Poland, EEA) via Genkit. Gemini 3.5 models: EU multi-region (eu, EEA) via the @google/genai SDK | n/a (EEA) |
| Google Cloud – Vertex AI (speech) | Transcription of the user's recorded speech; synthesis of simulated character speech (default: Gemini 2.5 Flash TTS, generally available); and, in the spoken-communication module, direct grading of the user's recorded audio. Audio is transmitted for processing and is not stored by Vendor | EU multi-region (eu, EEA) and europe-central2 (Poland, EEA). For a Customer that has given a Preview Model Instruction (Clause 4.5): EU endpoint pinned by Vendor, location not contractually committed by Google — see the note on speech synthesis below | n/a (EEA) for the default model; for the instructed preview model, no Sub-processor safeguard is available and processing proceeds on Customer's documented instruction (Clause 4.5) |
| Google BigQuery | Analytics data warehouse: pseudonymised session/results data, monitoring, telemetry, and AI usage/token-consumption events (keyed by a pseudonymous user hash; no transcript text) | europe-central2 (Poland, EEA) | n/a (EEA) |
| Vercel Inc. | Frontend hosting (Next.js application), edge network | Primarily EEA regions (Frankfurt, Amsterdam) with global CDN | Vercel EU infrastructure + DPA with SCCs |
| Gmail / Google Workspace | Legal-entity correspondence (privacy/GDPR, legal/contract notices, billing) and internal system/ops alerts via SMTP with OAuth2; fallback transport for leadercore.ai transactional email | Google's global infrastructure (includes EU data centers) | Google Cloud DPA + SCCs + Article 49(1)(b) (contract performance) |
| Namecheap, Inc. (Private Email) | Customer-facing email for the leadercore.ai domain: inbound mailboxes and primary outbound transactional/notification email via SMTP | United States | Namecheap Data Processing Addendum + EU Standard Contractual Clauses (controller-to-processor) + Article 49(1)(b) (contract performance) |
Vendor will keep this Annex up to date. Any changes to Sub-processors will be communicated in accordance with Clause 7 of this DPA.
Note on Firebase Authentication. Firebase Authentication does not offer EEA-only data residency; account identifiers and authentication metadata may be processed on Google's global infrastructure, governed by the Google Cloud DPA and EU Standard Contractual Clauses. No simulation content or grading outputs are stored in this service.
Note on speech synthesis (two modes).
Default mode. Speech synthesis of simulated character dialogue runs on Gemini 2.5 Flash TTS, a generally available model, called at Google's eu multi-region (EEA). As a generally available Service it is covered by the Google Cloud Data Processing Addendum and by the general data-location commitment in Google's terms. Google's per-model residency table does not at present list any Gemini text-to-speech model; Vendor has asked Google to confirm that calls to the eu multi-region are processed within the EU and will update this note on receipt. No Customer action is needed; this is the mode in which every Customer tenant operates unless the Customer gives the instruction described next.
Instructed preview mode (Clause 4.5). A Customer may instruct Vendor to use Gemini 3.1 Flash TTS, a pre-general-availability model, for its tenant. As at 2 September 2026, Google's Service Specific Terms provide that no data processing terms (including the Cloud Data Processing Addendum) apply to pre-general-availability offerings and that the customer "should not use Pre-GA Offerings to process personal data or other data that is subject to legal or regulatory compliance requirements"; Google's data-location commitment likewise does not apply. Vendor pins the operation to Google's EU endpoint and verifies that configuration, but the processing location is not contractually committed by Google. Google has further stated to Vendor in writing (1 September 2026) that data processed under its pre-general-availability programme is not subject to data-location or Access Transparency requirements, and that, under Google's Pre-GA Program Agreement, Google may use such data, including personal data, to provide, test, analyse, develop and improve its products without restriction, and deletes it only on expiry of Vendor's Google Cloud agreement rather than during its term. Vendor disputes that the Pre-GA Program Agreement binds its account, has put that question to Google, and will update this note on receipt of Google's answer; until then Customers are informed of Google's stated position as Google stated it. Google's Generative AI Preview Products terms (last modified 31 August 2026) exempt this model, by name, from their prohibition on commercial and production use; Vendor checks that exemption before enabling the model for any Customer and, for as long as any Customer's tenant is running the model, at each review of this DPA, and will withdraw the model, reverting affected tenants to the default mode, if the exemption is removed.
What the synthesis model receives, in either mode. Synthesis input is limited to one segment of the simulated character's generated dialogue and a style directive drawn from Vendor's own vocabulary. The user's recorded speech is never processed by a speech-synthesis model, and no path supplies the user's name to it; every name in the synthesis input belongs to the fictional cast. Character dialogue is, however, generated in response to the user's turn and can paraphrase or echo what the user said, including anything the user chose to disclose about themselves or another person. The input is therefore not reliably free of personal data, and that is the extent of the personal data reaching the model. Transcription and direct grading of user audio run on generally available models fully covered by Google's Cloud Data Processing Addendum and data-location commitments in both modes.
Note on the Namecheap transfer mechanism. Namecheap's Data Processing Addendum incorporates the EU Standard Contractual Clauses (Commission Decision 2021/914, controller-to-processor) and the UK SCCs/IDTA; as the processor-to-processor module is not separately offered, the transfer additionally relies on Article 49(1)(b) (necessary to deliver email the data subject's use of the service requires). The data transferred is limited to the recipient's email address and message content.
Disclosure: public-authority recipients (not Sub-processors)
The following public-authority services may receive a Customer's or Reseller's company VAT/tax identifier during onboarding for the sole purpose of validating that identifier. These services are not Article 28 Sub-processors of Customer Data; they are independent public authorities receiving a company tax identifier provided by Customer/Reseller during onboarding. Where the tax identifier relates to a sole-trader natural person rather than a legal entity, that identifier is personal data and the recipient is disclosed for transparency:
| Recipient | Service | Purpose | Lawful basis for the disclosure |
|---|---|---|---|
| European Commission – VIES (VAT Information Exchange System) | https://ec.europa.eu/taxation_customs/vies/ | Validation of EU VAT numbers submitted by Customer or Reseller | Article 6(1)(c) GDPR – legal obligation (Romanian and EU VAT rules require validation of cross-border VAT numbers) |
| Romanian National Agency for Fiscal Administration (ANAF) | https://webservicesp.anaf.ro/ | Validation of Romanian fiscal identifiers (CUI/CIF) | Article 6(1)(c) GDPR – legal obligation (Romanian Tax Code) |
Disclosure: consent-gated analytics access for a Customer's training partner (not a Sub-processor relationship)
Where a Customer enables analytics access for its subscription (via an authorised HR/Admin user, or via Vendor acting on the Customer's documented request), Vendor discloses to the Customer's authorised Reseller or other training partner designated by the Customer (for example an external coach or consultant) (the "Training Partner") a pseudonymised, aggregated view of the Customer's cohort analytics. Real user names are masked (display aliases only) and no row-level or CSV export is made available to the Training Partner. The Training Partner receives this disclosure in its own capacity in respect of its relationship with the Customer, on the basis of the Customer's documented instruction/consent; the lawful basis as between the Customer and its users is the Customer's responsibility. The enablement flag and an append-only consent ledger are stored on the Customer's subscription record. Access ceases immediately on disablement and, in any event, within 30 days after the end of the Subscription Term.
END OF DATA PROCESSING AGREEMENT