Back to Legal Hub
Effective: July 2026Version: 1.3

Data Processing Agreement

Master Data Processing Agreement

DataBillity, Inc. · doing business as Billity AI

Version 1.3 | July 2026

Confidential & proprietary — This document contains confidential and proprietary information of DataBillity, Inc. · © 2026 DataBillity, Inc. All rights reserved.

1. Purpose and Scope

This Data Processing Agreement ("DPA") forms part of and supplements the Subscriber Agreement, Order Form, Terms of Service, Privacy Policy, and Third-Party Data Sharing Network Participation Agreement (collectively, the "Agreement") between DataBillity, Inc. d/b/a Billity AI ("Processor" or "Billity AI") and the subscribing entity ("Controller" or "Subscriber"), and governs the Processor's handling of Personal Data provided, generated, or made accessible by the Controller in connection with the Billity AI platform.

This DPA is intended to ensure compliance with applicable data protection and privacy regimes, including: GDPR (EU General Data Protection Regulation); UK GDPR; CCPA/CPRA (California Consumer Privacy Act / California Privacy Rights Act); PIPEDA and Canadian provincial privacy legislation; APP (Australian Privacy Principles); APPI (Japan Act on Protection of Personal Information); PDPA (Thailand Personal Data Protection Act); LFPDPPP (Mexico Federal Law on Protection of Personal Data); and applicable United States state privacy laws.

The parties acknowledge that their respective roles as Controller and Processor are determined by the nature of each processing activity as described in Annex 1.

2. Definitions

"Personal Data" means any information relating to an identified or identifiable individual, including billing and transaction data, mobility and geolocation data, device identifiers, behavioral and engagement data, communications metadata, and contact information processed through the Billity AI platform.

"Processing" means any operation performed on Personal Data, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, or destruction, whether by automated means (including by autonomous AI agents) or otherwise.

"Controller" means the Subscriber entity that determines the purposes and means of Processing of Personal Data through the Billity AI platform.

"Processor" means DataBillity, Inc. d/b/a Billity AI, processing Personal Data on behalf of the Controller.

"Subprocessor" means any third party engaged by the Processor that processes Personal Data on behalf of the Controller, including cloud infrastructure providers, AI model providers, communication service providers, and analytics partners.

"Data Protection Laws" means all applicable data protection and privacy laws, including GDPR, UK GDPR, CCPA/CPRA, PIPEDA, and other global legislation.

"Data Subject" means an identified or identifiable natural person to whom Personal Data relates.

"Supervisory Authority" means any governmental authority responsible for supervising compliance with applicable Data Protection Laws.

"Special Categories of Data" means Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, or data concerning sex life or sexual orientation.

"Data Breach" means any accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.

"Autonomous Agent" means any AI-powered automated system within the Billity AI platform that performs sales engagement, customer communication, data analysis, or decision-making functions with limited or no real-time human oversight.

"Network Data" means (a) aggregated, anonymized, or pseudonymized data derived from multiple Subscribers' datasets and shared through the Billity AI Third-Party Data Sharing Network via the enrichment-engine intermediary model; (b) effective with Network Agreement Version 1.4, Directly Shared Data transmitted between Participating Subscribers through the Direct Data Share framework; and (c) effective with Network Agreement Version 1.5, identifiable and pseudonymous End Customer records disclosed to Named Partners for network-wide personalization and loyalty under the Partner Direct Data Share framework, conditioned on Partner Direct Data Share Consent (Layer 6).

"Directly Shared Data" means End Customer Personal Data that a Contributing Subscriber discloses directly to a Receiving Subscriber over a Sharing Connection under the Direct Data Share framework described in Section 4.6 of the Third-Party Data Sharing Network Participation Agreement, as distinct from enrichment output generated by the Billity AI enrichment engine.

"Cross-Network Consent Engine" means the Billity AI platform module that manages, records, and enforces end-user consent preferences across the Data Sharing Network.

3. Roles of the Parties

3.1 The Subscriber acts as Controller with respect to the processing activities described in Annex 1. Billity AI acts as Processor and shall process Personal Data only in accordance with documented instructions from the Controller, except where required by applicable law.

3.2 The parties shall review and update the allocation of roles if the nature or scope of processing activities changes materially, including upon activation of new platform modules or expansion of Autonomous Agent capabilities.

3.3 With respect to Network Data, each participating Subscriber acts as an independent Controller for the Personal Data it contributes. Billity AI acts as Processor for each contributing Controller.

3.4 With respect to Directly Shared Data (Network Agreement Version 1.4, Section 4.6), each disclosure is a Controller-to-Controller transfer. The Contributing Subscriber is and remains an independent Controller of the Personal Data it discloses and is solely responsible for establishing a lawful basis for the disclosure to the specific Receiving Subscriber. Upon delivery, the Receiving Subscriber becomes an independent Controller of the Directly Shared Data it receives and is solely responsible for its own subsequent Processing, including notice and Data Subject rights owed to the affected individuals. Billity AI acts solely as Processor to each Controller and does not determine the purposes or means of either Controller's Processing. Billity AI shall not enable outbound Direct Data Share of any Data Scope classified as PII or high-sensitivity (including contacts.pii and transactions.line_item) unless and until the conditions in Section 4.6.3 of the Network Agreement are satisfied, including the Contributing Subscriber's captured lawful basis and DPA acknowledgment, valid Cross-Network Consent from each affected End Customer, and confirmation that the runtime consent gate and erasure-cascade controls are operative.

3.5 Erasure propagation for Directly Shared Data

Where an End Customer withdraws Cross-Network Consent or a Data Subject erasure request is verified at the Contributing Subscriber, Billity AI shall propagate a deletion or redaction instruction to each Receiving Subscriber that received the affected Directly Shared Data, and each Receiving Subscriber, as an independent Controller, shall delete or redact the affected Personal Data within twenty-four (24) hours of the instruction and confirm completion through the Platform audit trail, subject to the legal-hold and retention exceptions in the Data Retention Schedule. For clarity, the twenty-four (24) hour deletion window in this Section 3.5 governs enrichment-aligned Directly Shared Data under Section 4.6 of the Network Agreement; the thirty (30) day guaranteed-erasure window applicable to Named Partners under a Partner Direct Data Share is governed separately by Section 3.6 of this DPA and Section 4.7.6 of the Network Agreement.

3.6 Partner Direct Data Share and Layer 6 Consent (Network Agreement Version 1.5, Section 4.7)

Effective with Network Agreement Version 1.5, Directly Shared Data also includes identifiable and pseudonymous End Customer records disclosed to Named Partners for network-wide personalization and loyalty under the Partner Direct Data Share framework. Each such disclosure is a Controller-to-Controller transfer conditioned on the affected End Customer's Partner Direct Data Share Consent (Layer 6), a distinct, purpose-specific affirmative consent that is never satisfied by or inferred from any other consent layer. Billity AI enforces the Layer 6 consent gate at the data query layer and fails closed, such that no record is served for any individual absent that individual's active Layer 6 Consent. Each Named Partner, as an independent Controller, guarantees deletion or irreversible redaction of records received through a Partner Direct Data Share, and confirmation through the Platform, no later than thirty (30) days after an erasure instruction is issued, except where the Named Partner records a documented, legally required retention basis (e.g., tax, accounting, or legal hold), in which case the retained records must be suppressed from all active use and deleted promptly upon expiry of the retention obligation, consistent with the Data Retention Schedule. Billity AI maintains a delivery ledger of each record served over a Partner Direct Data Share to enable this erasure guarantee.

3.7 Third-Party Advertising Platforms (Ad Engine Direct Publishing)

Where the Controller uses the Platform's direct ad-publishing capability to build matched advertising audiences, the Processor transmits only cryptographically hashed End Customer identifiers (SHA-256 of normalized email, phone, or name-and-postal-code) to third-party advertising platforms, including Google Ads Customer Match and Meta Custom Audiences, and only for End Customers who hold active ad-targeting consent as enforced at the Platform's query layer. With respect to the hashed identifiers they receive and match, these advertising platforms act as independent Controllers or independent businesses under their own customer-match and data-processing terms, and are not Subprocessors of the Processor; the Controller is responsible for entering into and complying with the applicable advertising-platform terms as the advertiser of record. The Processor does not transmit raw contact identifiers or advertising creative containing raw identifiers to these platforms. Upon withdrawal of ad-targeting consent or a verified erasure request, the Processor propagates removal of the affected individual's hashed identifiers from already-deployed platform audiences within twenty-four (24) hours. The transmission of hashed identifiers to a third-party advertising platform for matched-audience targeting may constitute "sharing" (cross-context behavioral advertising) under the CCPA/CPRA and analogous laws; the Controller is responsible for providing notice and honoring opt-out rights for that sharing, and the Processor operates the query-layer consent gate and the 24-hour removal propagation that give effect to those opt-outs.

4. Processor Obligations

The Processor shall:

  • (a) Process Personal Data only on documented instructions from Controller, including with respect to the configuration and deployment of Autonomous Agents.
  • (b) Ensure that persons authorized to process Personal Data have committed themselves to confidentiality.
  • (c) Implement appropriate technical and organizational measures as detailed in the TOMs Appendix.
  • (d) Notify Controller of any suspected or actual Data Breach in accordance with Section 9.
  • (e) Cooperate with Controller in responding to Data Subject rights requests in accordance with Section 8.
  • (f) Assist Controller with data protection impact assessments where relevant.
  • (g) Delete or return all Personal Data upon termination of services in accordance with Section 10.
  • (h) Make records available for audit upon reasonable notice in accordance with Section 11.
  • (i) Immediately inform Controller if an instruction infringes applicable Data Protection Laws.
  • (j) Not process Personal Data for any purpose other than as set forth in this DPA, and not sell, share, or otherwise make available Personal Data for the Processor's own commercial purposes. Processor shall not use Subscriber Personal Data for the training, fine-tuning, or improvement of any AI or machine learning models without prior written consent of Controller.
  • (k) Maintain a written record of all categories of processing activities carried out on behalf of Controller.
  • (l) Designate a point of contact for data protection matters.
  • (m) Ensure that all Autonomous Agents process Personal Data in accordance with Controller's documented instructions and applicable consent preferences.

5. Subprocessors

5.1 Processor shall not engage any Subprocessor without prior written authorization of Controller. Processor shall provide at least fourteen (14) days' prior written notice before engaging a new Subprocessor.

5.2 Controller may object to a new Subprocessor within fourteen (14) days. Processor shall work in good faith to address the objection.

5.3 Processor shall enter into written agreements with each Subprocessor imposing data protection obligations no less protective than those in this DPA.

5.4 Where a Subprocessor provides AI model inference or machine learning services, Processor shall ensure such Subprocessor does not retain or use Personal Data beyond the specific processing request and does not use Personal Data for model training.

5.5 Independent Software Vendors and Developer API Clients

Where the Controller authorizes a third-party application or independent software vendor ("ISV") to access the Controller's Personal Data through the Billity AI Developer API (including via OAuth-authorized access or the ISV marketplace), that ISV acts on the Controller's own authorization and instruction. An ISV that processes Personal Data solely on the Controller's behalf and under the Controller's authorization is a Subprocessor with respect to that processing only where the Processor engages it to process Personal Data on the Controller's behalf; an ISV that the Controller independently authorizes to receive Personal Data for the ISV's own or the Controller's purposes acts as an independent Controller or as the Controller's own processor, as determined by the nature of the authorization. The Processor enforces the Controller's authorization scope, token revocation, and per-tenant isolation at the API layer, and maintains an audit record of API access. The Controller is responsible for the ISV authorizations it grants and for revoking any authorization it no longer wishes to maintain.

6. International Data Transfers

Processor shall not transfer Personal Data outside the originating jurisdiction without appropriate safeguards, including:

  • (a) European Economic Area: EU Standard Contractual Clauses (Module 2: Controller to Processor).
  • (b) United Kingdom: UK International Data Transfer Addendum.
  • (c) Canada: PIPEDA accountability requirements for cross-border transfers.
  • (d) Other Jurisdictions: Compliance with applicable local transfer mechanisms.

Transfer Impact Assessments shall be conducted prior to any cross-border transfer relying on Standard Contractual Clauses.

7. Security Measures

Processor shall implement and maintain technical, organizational, and physical security controls as set forth in the TOMs Appendix, including AI-specific security measures: input validation and output filtering for Autonomous Agents; logging and audit trails; rate limiting and anomaly detection; segregation of Subscriber data environments; and encryption of Personal Data at rest (AES-256) and in transit (TLS 1.2+).

8. Data Subject Rights

Processor shall assist Controller in fulfilling obligations to respond to Data Subject requests, including rights of access, rectification, erasure, restriction, portability, objection, and withdrawal of consent. Processor shall forward any Data Subject request to Controller within two (2) business days. Where Autonomous Agents interact directly with Data Subjects, mechanisms shall be in place for exercising rights including opt-out of automated processing.

9. Breach Notification

Processor shall notify Controller of any Data Breach within twenty-four (24) hours of becoming aware. Within seventy-two (72) hours, Processor shall provide a detailed written report including root cause analysis, data affected, mitigation measures, and corrective action plan. Processor shall preserve all evidence and records related to the breach.

10. Return or Deletion of Data

Upon termination, Processor shall return or securely delete all Personal Data within thirty (30) days. Written certification of deletion shall be provided within ten (10) days of completion. Irreversibly anonymized or aggregated Network Data is not subject to return or deletion obligations.

11. Audit Rights

Controller may audit Processor's compliance: (a) annually; (b) following a Data Breach; (c) following material changes to processing operations. In lieu of onsite audit, Processor may supply current SOC 2 Type II or ISO 27001 certification with a written attestation of compliance.

12. AI-Specific Processing

12.1 Scope of Autonomous Processing

Autonomous Agents shall operate only within the parameters and guardrails defined by Controller through the Platform's configuration.

12.2 Human Oversight

Processor shall implement mechanisms enabling Controller to require human review of specified categories of automated decisions.

12.3 Model Training Restrictions

Processor shall not use Customer Data for training or improving AI models without prior written consent. Third-party AI model providers shall be subject to equivalent restrictions.

12.4 Transparency and Explainability

Processor shall provide documentation of AI model types, data categories used, decision logic, and confidence scoring methodology.

12.5 Bias and Fairness

Processor shall implement monitoring procedures to detect potential bias in AI-driven outputs and shall take corrective action upon identification of material bias.

13. Liability and Indemnification

Processor shall indemnify Controller for losses arising from Processor's breach of this DPA, non-compliance with Data Protection Laws, or Data Breaches attributable to Processor or its Subprocessors, subject to the liability limitations in the Subscriber Agreement.

14. Governing Law

This DPA shall be governed by the laws of the State of Delaware. To the extent the EU SCCs apply, Irish law governs. To the extent the UK Addendum applies, the laws of England and Wales govern. Where the Subscriber Agreement or Terms of Service reference Subscriber location or country for interpretive purposes, the same “as shown in the Platform at the time a dispute arises” rule described in those documents applies, without altering Processor’s actual data hosting locations or subprocessors.

15. General Provisions

This DPA, together with its Annexes and Appendix, constitutes the entire agreement between the parties with respect to data processing. Amendments require written agreement. If any provision is held invalid, the remaining provisions continue in full force.

16. Execution

This DPA is executed electronically through the Billity AI Platform as part of Subscriber's agreement suite. By completing the Platform's electronic acceptance process for this DPA (including typed name, title, and authority affirmation, or an equivalent clickwrap process), each party acknowledges that it has read, understands, and agrees to be bound by the terms set forth herein. DataBillity's separate wet-ink or dual electronic countersignature is not required for mutual assent; Subscriber's electronic acceptance of this DPA as presented in the Platform forms a binding DPA. Billity AI retains an electronic record of acceptance. For negotiated enterprise transactions, the parties may instead execute a dual-signature electronic or paper counterpart.

APPENDIX — SECURITY AND PRIVACY CONTROLS (TOMs)

1. Access Control

Role-based access control (RBAC) with least privilege; MFA for administrative access; unique credentials; automated provisioning/de-provisioning; session timeout and lockout.

2. Physical and Environmental Security

SOC 2 Type II and ISO 27001 certified data centers (AWS); biometric access controls; environmental controls.

3. Data Encryption

AES-256 at rest; TLS 1.2+ in transit; regular key rotation via AWS KMS.

4. Logging and Monitoring

Access events, authentication, administrative actions, and Autonomous Agent operations logged; anomaly detection; minimum 12-month retention.

5. Data Minimization

Only required Personal Data processed; role-based access restrictions; Autonomous Agents access minimum required data categories.

6. Secure API Handling

OAuth 2.0 token-based authentication; secure token storage; periodic rotation; input validation and output sanitization; rate limiting.

7. Backup and Recovery

Automated encrypted backups; separate storage; tested restoration procedures; defined RTO/RPO.

8. Secure Data Deletion

NIST SP 800-88 aligned; removal from production, backup, and logs; written confirmation; Subprocessor equivalent processes.

9. Data Segregation

Logical tenant separation via database schemas and access controls; no cross-tenant access outside consented Network Data; AI inference pipeline isolation.

10. Vulnerability Management

Regular scanning; documented patch management; critical patches within 48 hours; annual penetration testing.

11. Incident Response

Documented escalation paths; prompt investigation; 24-hour Controller notification; forensic cooperation.

12. Subprocessor Governance

Approved list only; due diligence; written agreements; regular compliance review.

13. Employee Security

Background checks; confidentiality agreements; annual security awareness training; specialized AI training.

14. Business Continuity

BCP maintained; redundant infrastructure; tested failover procedures.

15. AI-Specific Controls

Autonomous Agent action logging; configurable guardrails; prompt injection defense; model output validation; regular behavior testing.

Have questions about our legal policies?

Contact our team