Version: July 2026
This Data Processing Agreement governs the Processing of Personal Data carried out by GRADIUM as part of its provision of the Services to Client, as Data Processor.
All capitalized terms used in this Data Processing Agreement will have the following meanings.
All capitalized terms not defined herein shall have the meaning ascribed to them in the Terms of Service.
Client is the Data Controller and GRADIUM is the Data Processor with respect to the Processing detailed in Appendix 1. GRADIUM processes Client Personal Data on behalf of Client when Client uses the Services, as set out in Appendix 1.
If Client is a Data Processor on behalf of a Third-Party Controller, then Client shall (i) act as the single point of contact for GRADIUM; (ii) obtain all necessary authorizations from such Third-Party Controller; (iii) ensure that the Third-Party Controller provided notice and obtained any consents necessary for Processing by GRADIUM as set forth in this Data Processing Agreement; and (iv) undertakes to issue all instructions and exercise all rights on behalf of such other Third-Party Controller.
Each Party shall comply with their respective obligations under the Applicable Privacy Laws and shall not, by any act or omission, cause the other to be in breach of any such obligations under the Applicable Privacy Laws.
The Parties agree that the subject matter, nature, purpose and duration of Processing performed by GRADIUM under this Data Processing Agreement as Data Processor, the type of Personal Data, and categories of Data Subjects, are as described in this Agreement and in Appendix 1.
When providing the Services, GRADIUM makes the following commitments as Data Processor:
GRADIUM has no obligation to assess Client Personal Data in order to identify if they are subject to any specific legal requirements.
Upon Client’s written request, taking into account the nature of the Processing and the information available to GRADIUM, this latter shall provide Client with commercially reasonable assistance to conduct a data protection impact assessment and to conduct a prior consultation with a Supervisory Authority when required by Applicable Privacy Laws and reasonably requested by Client, solely with respect to the Processing and Client Personal Data.
Taking into account the nature of the Processing, GRADIUM shall provide Client with commercially reasonable assistance (by appropriate technical and organizational measures) with respect to the fulfilment of Client’s obligation to respond to requests from Data Subjects to exercise their rights under the Applicable Privacy Laws (a “Data Subject Request”). In the event GRADIUM receives a Data Subject Request directly from a Data Subject, it shall (unless prohibited by applicable laws) promptly notify Client of such Data Subject Request, and direct the Data Subject to Client. Client will be responsible for responding to any such Data Subject Request.
GRADIUM shall immediately inform Client if, in its opinion, Client’s Processing instruction infringes the Applicable Privacy Laws. In such event, GRADIUM is entitled to refuse to perform the Processing of Client Personal Data that it believes to be in violation of the Applicable Privacy Laws.
Client hereby provides a prior and general authorization allowing GRADIUM to appoint any Sub-Processors to assist GRADIUM in the provision of the Services and in the Client Personal Data Processing described in Appendix 1, in accordance with the terms provided in this Data Processing Agreement.
GRADIUM commits that Sub-Processors (i) are to fulfil obligations at least equivalent to those set out in this Data Processing Agreement with respect to Personal Data protection; (ii) provide guarantees regarding Personal Data protection at least equivalent to those presented by the measures implemented by GRADIUM. GRADIUM remains liable to Client for the fulfilment by the Sub-Processors of their contractual obligations towards GRADIUM.
Client hereby agrees that GRADIUM may appoint Sub-Processors from the list of Sub-Processors in Appendix 2 of this Data Processing Agreement. GRADIUM shall update the list of any Sub-Processor to be appointed at least thirty (30) days prior to the date on which the Sub-Processor shall commence the Processing of Client Personal Data.
Client may object in writing to GRADIUM’s appointment of a new Sub-Processor within fifteen (15) days of such notice, provided that such objection is based on reasonable and substantiated grounds relating to compliance with Applicable Privacy Laws. If Client provides observations during this fifteen (15)-day period, GRADIUM and Client will consult and negotiate in good faith to find a mutually acceptable resolution to address any objections raised by Client. If GRADIUM chooses to retain the Sub-Processor, GRADIUM shall inform Client at least thirty (30) days before authorizing the Sub-Processor to Process Client Personal Data, and either party may immediately discontinue providing or using the relevant parts of the Services, as applicable, and may terminate the relevant parts of the Services within thirty (30) days.
Unless GRADIUM otherwise explicitly commits not to transfer any Client Personal Data to a Non-EEA Country, Client authorizes GRADIUM to transfer Client Personal Data directly or indirectly to any country deemed to have an adequate level of data protection by the European Commission. Client also authorizes GRADIUM to perform International Data Transfers directly or indirectly to a Restricted Country (a) on the basis of adequate safeguards in accordance with Applicable Privacy Laws, including but not limited to the EU-US Data Privacy Framework, or (b) pursuant to the SCCs, as the case may be the UK Addendum if applicable, or any other transfer mechanism allowed pursuant to Applicable Privacy Laws.
This Section only applies if Client is located in a Restricted Country. By accepting this Data Processing Agreement, GRADIUM and Client conclude Module 4 (Processor-to-Controller) of the SCCs where Client is a Data Controller, and Module 3 (Processor-to-Processor) of the SCCs to the extent Client is a Data Processor on behalf of a Third-Party Controller, which are hereby incorporated and completed as follows and apply to any International Data Transfer conducted by GRADIUM acting as a Data Processor:
If GRADIUM has explicitly committed not to transfer any Client Personal Data to a Non-EEA Country, the aforementioned parts of this Section shall not apply and GRADIUM undertakes not to transfer any Client Personal Data to a Non-EEA Country.
Documentary audit. Upon Client’s written request, GRADIUM will make available all documents and information to demonstrate that the Processing carried out by GRADIUM as Data Processor complies with this Data Processing Agreement in a timely manner, to the extent that is commercially reasonable and required by the Applicable Privacy Laws, subject to confidentiality and trade secrets. Documentary audits can be requested maximum once per year.
Onsite audit. For this Section, “Auditor” will have the meaning of either Client or the third-party auditor mandated by Client under this Section to conduct an audit or inspection as set out in this Section solely with respect to the Processing and compliance with this Data Processing Agreement. Only to the extent Client cannot reasonably be satisfied with GRADIUM’s compliance with this Data Processing Agreement through the exercise of the documentary audit set out in this Section, Auditor may conduct up to one (1) onsite audit per year to verify GRADIUM’s compliance with this Data Processing Agreement, under the conditions defined below:
Client agrees and commits to the following:
Upon the termination of Client’s access to and use of the Services, GRADIUM will, up to forty-five (45) days following such termination, delete or return to Client, at Client’s choice, all Client Personal Data detained by GRADIUM except as otherwise authorized in writing by Client pursuant to Section 11 (Processing of GRADIUM as Data Controller). Client acknowledges and accepts that Client Personal Data will no longer be accessible upon the expiry of the forty-five (45)-day period.
Without prejudice to any Zero Data Retention feature implemented as applicable, GRADIUM may retain Client Personal Data to the extent required by applicable law but only to the extent and for such period as required by such law and always provided that GRADIUM shall ensure the confidentiality of all such Client Personal Data.
These CCPA Terms apply when the California Consumer Privacy Act of 2018, Cal. Civ. Code §§1798.100–1798.199.100, as amended, and the CCPA regulations, Cal. Code Regs. §§7000–7304 (together, the “CCPA”) applies to Client’s use of the Services to process the Personal Information contained in Client Personal Data and Account Data.
Where the CCPA applies, GRADIUM acknowledges that it does not receive Personal Data as consideration for any Services provided to Client. GRADIUM: (i) is responsible for compliance with its obligations under this Data Processing Agreement, (ii) is responsible for compliance with its obligations as a service provider under the CCPA, and (iii) shall provide the same level of privacy protection as required by the CCPA. GRADIUM shall notify Client if it reasonably determines that it cannot meet its obligations under the CCPA, and in such circumstances, and upon provision of notice to GRADIUM, Client shall be entitled to take reasonable and appropriate steps to remediate unauthorized use of Personal Data. GRADIUM must not process the Personal Data for any purpose other than for the purpose of performance of the Agreement, except where and to the extent permitted by the CCPA.
GRADIUM shall not: (i) Sell or Share Client Personal Data; (ii) retain, use, or disclose Client Personal Data for any purpose other than for the purpose of performance of the Services except as expressly permitted under the CCPA; (iii) retain, use, or disclose Client Personal Data with Personal Data obtained from, or on behalf of, sources other than Client, except as expressly permitted under the CCPA; or (iv) process Client Personal Data for targeted and/or cross context behavioral advertising. GRADIUM certifies that it understands the restrictions set out in this Section and will comply with them. Solely for the purpose of the CCPA, GRADIUM shall promptly notify Client if it determines that it can no longer meet its obligations under the CCPA.
GRADIUM processes Personal Data as Data Controller for the purposes set forth in GRADIUM’s Privacy Policy available at the following link and any succeeding link: https://gradium.ai/privacy.
GRADIUM shall not reuse Client Personal Data for its own purposes, including to improve current and future Services or to train any AI model or product. By exception, GRADIUM may reuse Client Personal Data only where Client has given its prior authorization in the course of the performance of the Agreement.
GRADIUM undertakes to comply with the Applicable Privacy Laws in relation to all Processing for which it is classified as Data Controller. The information related to such Processing are set forth in Gradium’s Privacy Policy and Client undertakes to direct all its users of the Services to this Privacy Policy.
This Data Processing Agreement will remain in force as long as the Client uses the Services.
Any dispute arising from this Data Processing Agreement will be resolved by the competent courts of Paris, France in accordance with the Terms of Service.
This Data Processing Agreement is governed by the laws of France.
Parties
Client as Data Controller or Data Processor of a Third-Party Controller, and data importer for the purposes of SCCs as applicable.
GRADIUM as Data Processor and data exporter for the purposes of SCCs as applicable.
Duration of Processing
If the Zero Data Retention feature is not activated, GRADIUM shall store Client Personal Data as Data Processor solely for the duration of the Services.
If the Zero Data Retention feature is applicable, GRADIUM shall not store any Input and Output after their respective ingestion and generation for a duration longer than necessary to the generation of Output and shall not be retained further. Notwithstanding the foregoing, GRADIUM may retain Voice Sample recordings that are (i) explicitly and separately provided by Client for the sole purpose of Voice Reproduction, and (ii) reasonably necessary to deliver the Voice Reproduction pursuant to the Services.
Subject-Matter and Nature of Processing
Generation of Output and Voice Reproduction based on Client’s Input at Client’s request.
Frequency of the Processing
On a continuous basis.
Purpose of Processing
The purpose of the Processing of Client Personal Data is provision of the Services.
Data Subjects
Data subjects whose characteristics, such as their voice, are present in Client’s Input and, as applicable, reproduced in Output.
Categories of Personal Data
Voice input, voice recordings, text input, or other content included in Client’s Input, and text or voice Output generated by GRADIUM based on Input provided by Client.
Sensitive Data
The Processing is not designed to include sensitive data or special categories of data within the meaning of Applicable Privacy Laws. If such Personal Data are processed, they will only be collected and processed according to Client’s instructions for providing the Services.
The list of Sub-Processors is available on our website trust.gradium.ai.
All the security measures are listed at trust.gradium.ai.