Data Processing Addendum
Last updated: September 1, 2026
This Data Processing Addendum (“DPA”) applies to the processing of personal data by Praesidium Compliance Systems Corporation (“Praesidium”, “Processor”) on behalf of commercial customers (“Customer”, “Controller”) in connection with licensed reinforcement-learning environments and related services.
1. Scope and definitions
Capitalized terms used but not defined here have the meanings given in the applicable service agreement or, where applicable, the EU General Data Protection Regulation (“GDPR”). “Personal data,” “processing,” “controller,” “processor,” and “data subject” have the meanings set out in applicable data protection law.
2. Roles
Praesidium acts as a processor of personal data provided or made available by Customer in connection with the services. Customer is the controller of such personal data unless the parties agree otherwise in writing.
3. Purposes of processing
Praesidium will process personal data only for the purposes specified in the service agreement or as otherwise documented in Customer’s instructions, including providing licensed environments, support, billing, and compliance with legal obligations.
4. Subprocessors
Praesidium may engage subprocessors to assist in providing the services. A current list is available in our Subprocessors page. We will notify Customer of any intended changes to the subprocessor list and provide an opportunity to object where required by applicable law.
5. Data security
Praesidium implements appropriate technical and organizational measures to protect personal data. See our Security & Disclosure page for more information.
6. Data subject rights and assistance
Praesidium will assist Customer in responding to data subject requests, data protection impact assessments, and consultations with supervisory authorities, to the extent required by law and to the extent the requests relate to Praesidium’s processing.
7. Data transfers
Personal data may be transferred to and processed in countries outside the data subject’s jurisdiction. Where such transfers are subject to GDPR, Praesidium will use appropriate safeguards, including Standard Contractual Clauses approved by the European Commission.
8. Return and deletion
Upon termination or expiration of the services, Praesidium will, at Customer’s choice, return or delete Customer personal data, except where retention is required by law.
9. Audit
Praesidium will provide Customer with reasonable information and assistance necessary to demonstrate compliance with this DPA, subject to confidentiality obligations and reasonable notice.
10. Contact
For DPA questions, email arjav@praesidiumsystems.ai.