Data Processing Addendum

Effective: May 21, 2026·Last updated: May 21, 2026

1. Scope and roles

This Data Processing Addendum ("DPA") forms part of the Terms of Service between Banzai House LLC ("Salesjet," "Processor") and the customer ("Customer," "Controller") and applies whenever Salesjet processes personal data on Customer's behalf in connection with the Service. Customer is the controller and Salesjet is the processor (or, as applicable under U.S. state privacy laws, the "service provider" or "processor") of such personal data.

2. Customer instructions

Salesjet will process personal data only on documented instructions from Customer, including with regard to international transfers, except as required by applicable law. The Terms, this DPA, and Customer's use of the Service's features and configurations constitute Customer's complete and final instructions to Salesjet for processing.

3. Subject matter, duration, and nature of processing

Subject matter: provision of the Service. Duration: for as long as Salesjet processes personal data on behalf of Customer. Nature and purpose: hosting, processing, storing, transmitting, generating, and analyzing Customer Content (which may include personal data) as described in the Documentation. Categories of data subjects: Customer's end users, prospects, customers, employees, and any other individuals whose personal data Customer submits. Categories of personal data: as determined by Customer when configuring and using the Service.

4. Confidentiality

Salesjet ensures that personnel authorized to process personal data are bound by appropriate obligations of confidentiality and have received training on data protection.

5. Security measures

Salesjet implements appropriate technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, as described in Annex II (Security Measures) below.

6. Sub-processors

Customer authorizes Salesjet to engage the sub-processors listed at salesjet.pro/legal/subprocessors. Salesjet imposes data-protection obligations on each sub-processor that are no less protective than those in this DPA. Salesjet will give Customer at least 30 days' prior notice of any intended addition or replacement of a sub-processor (by updating the sub-processor page and, where Customer has subscribed, by email). Customer may object on reasonable data-protection grounds within that notice period; the parties will work in good faith to resolve the objection, and if not resolved, Customer may terminate the affected portion of the Service.

7. Personal data breach notification

Salesjet will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Customer's personal data, and will provide information reasonably necessary for Customer to meet its own notification obligations under applicable law, including GDPR Article 33.

8. Data subject rights and assistance

Taking into account the nature of processing, Salesjet will assist Customer by appropriate technical and organizational measures, insofar as possible, to fulfill Customer's obligation to respond to requests from data subjects to exercise their rights under applicable data protection law, and to assist with data protection impact assessments and prior consultations with supervisory authorities.

9. International data transfers

Where personal data is transferred from the EEA, UK, or Switzerland to a country that has not been deemed to provide an adequate level of protection, the parties incorporate by reference: (a) the European Commission's Standard Contractual Clauses (SCCs) for the relevant transfer scenario (Module Two: Controller-to-Processor; Module Three: Processor-to-Processor as applicable); (b) the UK International Data Transfer Addendum to the EU SCCs; and (c) the Swiss Federal Data Protection and Information Commissioner's (FDPIC) recognized clauses for Swiss transfers. Salesjet has performed and will continue to update a Transfer Impact Assessment and will implement supplementary measures where appropriate.

10. Audits

Salesjet will make available to Customer all information reasonably necessary to demonstrate compliance with this DPA. Salesjet's compliance is independently audited annually (SOC 2 Type II in progress); Salesjet will provide the most recent audit report under NDA. Customer may, at its own cost and not more than once per year (except following a personal data breach or as required by a regulator), request an on-site or remote audit on at least 30 days' written notice, conducted during normal business hours, subject to confidentiality, and limited to information and systems relevant to Salesjet's processing of Customer's personal data.

11. Return or deletion of personal data

Upon termination of the Service, Salesjet will, at Customer's choice, return or delete personal data within 30 days, unless retention is required by applicable law. Backups containing personal data will be overwritten on the normal rotation cycle (up to 90 days).

12. AI processing

Salesjet uses third-party AI sub-processors (currently OpenAI and Google) to generate output in response to prompts. Salesjet does not use Customer Content to train foundation models for Salesjet or any third party, and has enabled zero-retention or enterprise configurations with its AI sub-processors where available.

13. U.S. state privacy laws

For personal information governed by the California Consumer Privacy Act (as amended by the CPRA), Colorado Privacy Act, Connecticut Data Privacy Act, Virginia Consumer Data Protection Act, Utah Consumer Privacy Act, and similar U.S. state laws, Salesjet acts as a "service provider" or "processor" and: (a) will process personal information only for the business purposes set out in the Terms; (b) will not sell or share personal information as those terms are defined under the CCPA/CPRA; (c) will not retain, use, or disclose personal information outside the direct business relationship; (d) will not combine personal information received from Customer with personal information from other sources except as permitted by law; and (e) will notify Customer if it can no longer meet these obligations.

14. Conflicts and order of precedence

In the event of a conflict between this DPA and the Terms of Service, this DPA controls with respect to the processing of personal data. In the event of a conflict between this DPA and the SCCs or UK Addendum, those instruments control with respect to the transfers they govern.

Annex I — Description of processing

  • Data exporter: Customer, acting as controller of personal data submitted to the Service.
  • Data importer: Banzai House LLC d/b/a Salesjet, acting as processor.
  • Categories of data subjects: as determined by Customer.
  • Categories of personal data: as determined by Customer (may include identifiers, contact information, professional information, content of communications, and any other personal data Customer submits).
  • Special categories of personal data: not intended to be processed; Customer must not submit special-category data without a written amendment.
  • Frequency of transfer: continuous, on-demand.
  • Nature of processing: storage, hosting, transmission, generation, and processing of Customer Content as described in the Documentation.
  • Purpose of processing: provision of the Service.
  • Retention: while the Customer account is active and as described in Section 11 above and in the Privacy Policy.

Annex II — Security measures

  • Encryption: TLS 1.2+ in transit, AES-256 at rest.
  • Access management: role-based access control, least privilege, SSO and MFA for all personnel, periodic access reviews.
  • Network security: hardened cloud infrastructure (Cloudflare, Supabase), WAF, DDoS protection, segmentation of production from non-production environments.
  • Logging and monitoring: centralized audit logs, anomaly detection, retention up to 24 months.
  • Vulnerability management: dependency scanning, periodic third-party penetration tests, patch management.
  • Personnel security: background checks where permitted by law, mandatory annual security and privacy training, confidentiality obligations.
  • Incident response: documented incident response plan with notification commitments per Section 7.
  • Vendor management: written agreements with sub-processors including security and data-protection terms.
  • Business continuity: backups with up to 90-day rotation, documented disaster-recovery procedures.

15. How to execute this DPA

This DPA takes effect automatically upon your acceptance of the Terms of Service and is incorporated into them. If your organization requires a separately-executed DPA (e.g., for procurement records), download the countersigned PDF by emailing legal@salesjet.pro with your account email and legal entity name.