Lythe

Data Processing Addendum

Effective Date: 14 JULY 2026

1. Scope and Application

This Data Processing Addendum (this "DPA") forms part of the Fraser Simulation Studio Terms of Service, an Order Form, Master Services Agreement, pilot agreement, customer agreement, or other written agreement that incorporates this DPA (the "Agreement") between the customer identified in the Agreement ("Customer") and Lythe Inc., a Delaware corporation ("Lythe"), concerning Customer's use of Fraser Simulation Studio and related Lythe services (the "Services").

Lythe Inc. provides Lythe's self-serve Services worldwide. Lythe Pte. Ltd., Lythe's Singapore subsidiary, may process Customer Personal Data as an affiliate Subprocessor under this DPA. If Lythe Pte. Ltd. is separately identified as the contracting service provider in an Order Form or other written agreement, references to "Lythe" in this DPA mean Lythe Pte. Ltd. for that agreement unless expressly stated otherwise.

This DPA applies only to the extent Lythe Processes Customer Personal Data on behalf of Customer in connection with the Services. If there is a conflict between this DPA and the Agreement regarding the Processing of Customer Personal Data, this DPA controls to the extent of that conflict. Capitalized terms not defined in this DPA have the meanings given in the Agreement or applicable Data Protection Laws.

2. Definitions

"Applicable Data Protection Laws" means privacy, data protection, and data security laws applicable to the Processing of Customer Personal Data under the Agreement, including, where applicable, the GDPR, UK GDPR, Swiss Federal Act on Data Protection, Singapore Personal Data Protection Act 2012, California Consumer Privacy Act as amended by the California Privacy Rights Act, and other applicable U.S. state privacy laws.

"Customer Personal Data" means personal data, personal information, or similar regulated information included in Customer Data and Processed by Lythe on behalf of Customer through or in connection with the Services.

"Data Subject" means an identified or identifiable natural person to whom Customer Personal Data relates.

"GDPR" means Regulation (EU) 2016/679.

"Process," "Processed," or "Processing" has the meaning given under Applicable Data Protection Laws.

"Security Incident" means a confirmed breach of security resulting in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data Processed by Lythe. Security Incident does not include unsuccessful attempts or activities that do not compromise Customer Personal Data, including pings, port scans, failed login attempts, denial-of-service attempts, or similar events.

"Subprocessor" means an affiliate or third party engaged by Lythe to Process Customer Personal Data on behalf of Customer in connection with the Services.

"Supervisory Authority" means an independent public authority responsible for enforcing Applicable Data Protection Laws.

"UK GDPR" means the GDPR as incorporated into United Kingdom law.

3. Roles and Instructions

3.1 Roles

Customer is the controller, business, or other entity that determines the purposes and means of Processing Customer Personal Data. Lythe is the processor, service provider, contractor, or data intermediary Processing Customer Personal Data on Customer's behalf, as those terms are defined under Applicable Data Protection Laws. Each party remains responsible for its own compliance obligations.

3.2 Documented Instruction

Lythe will Process Customer Personal Data only on Customer's documented instructions, including the Agreement, this DPA, Customer's configuration and use of the Services, and other written instructions accepted by Lythe, unless Processing is required by applicable law. If applicable law requires Processing outside Customer's instructions, Lythe will notify Customer before Processing unless legally prohibited from doing so.

3.3 Lawful Instructions

Customer will ensure that its instructions and use of the Services comply with Applicable Data Protection Laws. Lythe will promptly inform Customer if, in Lythe's reasonable opinion, an instruction infringes Applicable Data Protection Laws, and may suspend the affected Processing until the parties resolve the issue.

3.4 Customer Responsibilities

Customer is responsible for providing required notices, obtaining required consents and lawful bases, responding to Data Subject requests where Customer is responsible, and ensuring that Customer Personal Data submitted to the Services is accurate, lawful, authorized, and limited to what is reasonably necessary for the intended use.

4. Processing Restrictions

4.1 Purpose Limitation

Lythe will Process Customer Personal Data only to provide, operate, secure, support, troubleshoot, evaluate, and administer the Services; comply with Customer's instructions; prevent fraud and abuse; comply with law; and perform the Agreement.

4.2 No Sale or Sharing

Lythe will not sell Customer Personal Data, share Customer Personal Data for cross-context behavioral advertising, or retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer, except as permitted by Applicable Data Protection Laws and the Agreement.

4.3 No Combining

Where required by applicable U.S. state privacy law, Lythe will not combine Customer Personal Data received from Customer with personal information received from or on behalf of another person, or collected from Lythe's own interaction with a Data Subject, except as permitted by law to provide the Services or for permitted security and business purposes.

4.4 No Model Training

Lythe will not use Customer Personal Data, call recordings, transcripts, CRM data, product materials, research data, simulation inputs, AI persona outputs, session replay data, or other personal data submitted to or generated through Customer's use of the Services to train Lythe models, shared models, general-purpose models, or systems used for the benefit of other customers, unless expressly agreed in writing with Customer and permitted by applicable law. Lythe will not permit third-party AI or model providers to use Customer Personal Data to train their models.

4.5 Confidentiality

Lythe will ensure that personnel authorized to Process Customer Personal Data are subject to confidentiality obligations and receive appropriate privacy and security instructions.

4.6 Compliance Notification and Remediation

Lythe will notify Customer without undue delay if Lythe determines that it can no longer meet its obligations under applicable U.S. state privacy laws with respect to Customer Personal Data. Upon reasonable notice, Customer may take reasonable and appropriate steps to verify, stop, and remediate any unauthorized use of Customer Personal Data, subject to the confidentiality, security, audit, and cost conditions set out in this DPA.

5. Security Measures

5.1 Safeguards

Lythe will implement and maintain reasonable and appropriate administrative, technical, and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. The current measures are described in Schedule 2.

5.2 Security Program

Lythe may update its security measures from time to time, provided that updates do not materially reduce the overall level of protection for Customer Personal Data during the applicable term.

5.3 Customer Security

Customer is responsible for configuring its accounts, workspaces, permissions, integrations, credentials, retention settings, and uploads securely and for promptly notifying Lythe of suspected unauthorized access or misuse.

5.4 Customer Data Separation

Lythe will maintain reasonable controls designed to prevent unauthorized cross-customer access to or exposure of Customer Personal Data. Lythe will not intentionally disclose Customer Personal Data to another customer except at Customer's direction, through Customer-authorized integrations, or as otherwise permitted by the Agreement, this DPA, or applicable law.

5.5 Session Replay

Where Lythe uses product analytics or session replay technologies, Lythe will apply consent controls where required by law and will mask or exclude passwords, payment information, authentication credentials, API keys, security codes, and other sensitive fields. Access to session replay recordings will be limited to authorized personnel with a business need.

6. Security Incidents

6.1 Notification

Lythe will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data and, where practicable, within seventy-two (72) hours after confirmation. Notification may be provided in phases as information becomes available.

6.2 Information

To the extent known and legally permitted, Lythe's notice will describe the nature of the Security Incident, categories of affected Customer Personal Data and Data Subjects, likely consequences, measures taken or proposed, and a contact for further information.

6.3 Cooperation

Lythe will take reasonable steps to contain, investigate, and remediate a Security Incident and will reasonably assist Customer with legally required notifications. Customer is responsible for determining whether notices to Data Subjects, regulators, or others are required, except where Lythe has an independent legal obligation.

6.4 No Admission

Notification of a Security Incident is not an acknowledgment of fault or liability.

7. Data Subject Requests

7.1 Customer Responsibility

Customer is responsible for responding to Data Subject requests relating to Customer Personal Data, including requests to access, correct, delete, restrict, object, or obtain a portable copy.

7.2 Assistance

Taking into account the nature of the Processing, Lythe will provide reasonable assistance through available product functionality and, where necessary, additional reasonable measures to help Customer respond to Data Subject requests.

7.3 Direct Requests

If Lythe receives a request directly from a Data Subject relating to Customer Personal Data, Lythe will, where legally permitted, direct the request to Customer or notify Customer and will not substantively respond except on Customer's instructions or as required by law.

8. Subprocessors

8.1 General Authorization

Customer provides general authorization for Lythe to engage Subprocessors to Process Customer Personal Data in accordance with this DPA.

8.2 Current Subprocessors

Customer authorizes the Subprocessors identified in the then-current Lythe Subprocessor List made available by Lythe or otherwise provided to Customer in connection with the Agreement. The Subprocessor List may identify each provider's purpose, data categories, and processing location.

8.3 Subprocessor Obligations

Lythe will enter into written agreements with Subprocessors that impose data protection obligations appropriate to the Processing and no less protective in material respects than the obligations applicable to Lythe under this DPA. Lythe remains responsible for its Subprocessors' performance of those obligations to the extent required by Applicable Data Protection Laws.

8.4 Changes

Where required by the Agreement or Applicable Data Protection Laws, Lythe will provide notice of an intended addition or replacement of a Subprocessor through an updated Subprocessor List, email, product notice, or another agreed method at least thirty (30) days before the new Subprocessor begins Processing Customer Personal Data, unless an emergency replacement is reasonably necessary for security, availability, or service continuity.

8.5 Objection

Customer may object to a new Subprocessor on reasonable data protection grounds by notifying Lythe within fifteen (15) days after receiving notice. The parties will work in good faith to resolve the objection. If no reasonable resolution is available, Lythe may terminate the affected Services or Customer may discontinue the affected Services, subject to the Agreement.

9. International Data Transfers

9.1 Transfers

Customer authorizes Lythe and its Subprocessors to Process Customer Personal Data in the United States, Singapore, and other countries in which authorized Subprocessors operate, subject to this DPA and Applicable Data Protection Laws.

9.2 Transfer Safeguards

Where a transfer requires an approved transfer mechanism, the parties will use applicable standard contractual clauses, transfer addenda, contractual protections, adequacy decisions, or other recognized mechanisms.

9.3 EEA Transfers

For transfers of Customer Personal Data subject to the GDPR to a country not recognized as providing adequate protection, the European Commission Standard Contractual Clauses adopted by Implementing Decision (EU) 2021/914 ("EU SCCs") are incorporated into this DPA by reference. Module Two applies where Customer is a controller and Lythe is a processor. Module Three applies where Customer is a processor and Lythe is a subprocessor. Clause 7 applies. Option 2 in Clause 9 applies with the notice periods in Section 8. Clause 11 does not apply. The competent supervisory authority and governing law are determined under the EU SCCs based on Customer's establishment and the Data Subjects concerned. Schedule 1 provides Annex I information and Schedule 2 provides Annex II information.

9.4 UK Transfers

For restricted transfers subject to the UK GDPR, the EU SCCs as completed by this DPA are modified by and incorporated with the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner and effective from 21 March 2022, as lawfully amended, replaced, or updated. The parties agree that the information in Schedules 1 through 3 completes the relevant tables of that addendum.

9.5 Swiss Transfers

For transfers subject to Swiss data protection law, references in the EU SCCs to the GDPR and European Union will be interpreted to include applicable Swiss law and Switzerland, and the competent authority will be the Swiss Federal Data Protection and Information Commissioner where applicable.

9.6 Supplementary Measures

Each party will reasonably cooperate in conducting transfer assessments and implementing supplementary measures where required by Applicable Data Protection Laws.

10. Deletion, Return, and Retention

10.1 During the Term

Customer may access, export, or delete certain Customer Personal Data through available product features, subject to the Agreement and applicable technical limitations.

10.2 Termination

Upon termination or expiration of the Agreement, Lythe will, at Customer's choice and subject to applicable law, delete or return Customer Personal Data in active systems within thirty (30) days, unless retention is required by law, reasonably necessary for documented legal, security, fraud-prevention, or compliance purposes, or agreed in writing.

10.3 Backups

Customer Personal Data retained in backups will be deleted or rendered inaccessible in accordance with Lythe's backup cycle, generally within ninety (90) days after deletion from active systems, unless a longer period is required by law or reasonably necessary for security or disaster recovery. During that period, backup data will remain protected and will not be restored except for disaster recovery, security, or legal purposes.

10.4 Suppression Records

Lythe may retain limited records necessary to honor opt-outs, prevent fraud or abuse, establish legal claims, or demonstrate compliance, provided those records are used only for those purposes.

11. Assistance and Compliance

11.1 Assessments

Taking into account the nature of the Processing and information available to Lythe, Lythe will provide reasonable assistance with data protection impact assessments, prior consultations, and similar obligations where required by Applicable Data Protection Laws and related to Lythe's Processing.

11.2 Regulatory Cooperation

Lythe will reasonably cooperate with Customer and competent Supervisory Authorities regarding Lythe's Processing of Customer Personal Data, subject to applicable law and confidentiality restrictions.

11.3 Compliance Information

Upon reasonable written request, Lythe will provide information reasonably necessary to demonstrate compliance with this DPA, which may include security documentation, policy summaries, questionnaire responses, or independent reports where available.

12. Audits

12.1 Audit Rights

Where required by Applicable Data Protection Laws, Customer may audit Lythe's compliance with this DPA no more than once annually, unless a Security Incident or regulator requires additional review. Customer will first use available documentation and questionnaires before requesting an on-site audit.

12.2 Conditions

Any audit must be conducted during normal business hours, on reasonable prior notice, without unreasonable disruption, and subject to confidentiality, security, and access restrictions. Customer may use an independent auditor that is not a Lythe competitor and is bound by confidentiality obligations.

12.3 Costs

Customer will bear its audit costs and reimburse Lythe for reasonable costs of supporting an audit beyond routine compliance assistance, unless an audit identifies a material breach by Lythe.

13. Liability

The liability of each party arising out of or relating to this DPA is subject to the exclusions and limitations of liability in the Agreement, except to the extent those limitations are prohibited by Applicable Data Protection Laws. Nothing in this DPA limits Data Subject rights or regulatory authority under applicable law.

14. Term and Termination

This DPA begins when it is incorporated into the Agreement and remains in effect for as long as Lythe Processes Customer Personal Data on behalf of Customer. Sections that by their nature should survive termination, including confidentiality, deletion, audit, transfer, and liability provisions, will survive as applicable.

15. General

15.1 Order of Precedence

If the EU SCCs, UK transfer addendum, or other mandatory transfer terms conflict with this DPA, the mandatory transfer terms control for the relevant transfer. Otherwise, this DPA controls over conflicting data protection terms in the Agreement.

15.2 Updates

Lythe may update this DPA to reflect changes in law, regulatory guidance, or the Services. Material changes will apply prospectively and will be notified as required by the Agreement or Applicable Data Protection Laws.

15.3 Electronic Acceptance

This DPA may be incorporated and accepted electronically through the Agreement, checkout flow, product interface, or an executed Order Form. Enterprise customers may request a countersigned copy.

15.4 Contact

Privacy and DPA inquiries may be sent to team@lythe.ai.

Schedule 1 - Details of Processing

1. Subject Matter and Duration

Lythe Processes Customer Personal Data to provide Fraser Simulation Studio and related Services under the Agreement. Processing continues for the term of the Agreement and any limited post-termination period required for deletion, return, security, legal, or compliance purposes.

2. Nature and Purposes of Processing

  • Providing, operating, hosting, securing, supporting, troubleshooting, evaluating, and administering the Services.
  • Creating, configuring, running, and evaluating AI personas, subagents, simulations, automated evaluators, visual evaluations, bug-testing workflows, and reports.
  • Processing Customer-provided product materials, URLs, screenshots, prototypes, APK files, research data, customer feedback, CRM records, call recordings, transcripts, and conversation metadata as instructed by Customer.
  • Generating synthetic feedback, product critiques, usability findings, evaluation reports, bug-testing results, analytics, and related Outputs.
  • Providing integrations, account administration, billing, customer support, logging, monitoring, security, fraud prevention, abuse detection, and compliance.
  • Providing product analytics and, where enabled and lawfully consented to, session replay for debugging, usability analysis, and product improvement.
  • Updating prompts, configurations, or workflows for Customer's own deployment without training shared or general-purpose models.

3. Categories of Data Subjects

  • Customer personnel, administrators, authorized users, contractors, and business contacts.
  • Customer's users, leads, customers, employees, research subjects, interview participants, and other individuals represented in Customer Data.
  • Individuals whose call recordings, transcripts, feedback, support records, CRM records, or interaction data are uploaded or connected by Customer.
  • Website and application users whose account, device, browser, usage, interaction, or session replay data is collected through Lythe-operated environments.

4. Categories of Customer Personal Data

  • Names, business contact information, account information, identifiers, roles, and authentication-related metadata.
  • Prompts, scripts, instructions, AI persona configurations, simulation settings, evaluation criteria, and workflow data.
  • Product materials, websites, URLs, screenshots, prototypes, landing pages, product flows, APK files, files, records, and datasets.
  • CRM records, customer feedback, research notes, interview materials, support tickets, call audio, call recordings, transcripts, summaries, conversation metadata, and related interaction records.
  • Simulation inputs and outputs, AI persona responses, product critiques, usability observations, bug-testing results, evaluation scores, reports, and analytics.
  • IP addresses, device and browser information, logs, page activity, feature usage, navigation paths, interaction events, cookies, session identifiers, and session replay data.
  • Billing contacts, subscription identifiers, invoices, payment status, and limited payment tokens or transaction metadata.

5. Sensitive Data

Customer may not submit sensitive or special-category personal data unless authorized by the Agreement, legally permitted, necessary for the intended use, and protected by appropriate safeguards. Sensitive data may include health data, biometric data, government identifiers, precise location, financial account data, credentials, children's data, or other regulated information. Lythe does not intentionally collect passwords, full payment card numbers, authentication secrets, API keys, or security codes through session replay.

6. Processing Frequency

Continuous or intermittent, depending on Customer's use, configuration, uploads, integrations, simulations, and support requests.

7. Customer Instructions

The Agreement, this DPA, Customer's configuration and use of the Services, and other written instructions accepted by Lythe.

Schedule 2 - Technical and Organizational Measures

1. Access Control

  • Role-based access and least-privilege principles for production systems and Customer Personal Data.
  • Authentication controls for personnel and administrative access, including multi-factor authentication where appropriate.
  • Periodic review and revocation of access when no longer required.

2. Encryption and Transmission Security

  • Encryption in transit using industry-standard transport security.
  • Encryption at rest where supported and appropriate for the relevant storage system.
  • Secure management of credentials, secrets, and API keys.

3. Infrastructure and Application Security

  • Network, hosting, content-delivery, and web-security controls appropriate to the deployment.
  • Logging, monitoring, abuse detection, and alerting for suspicious or unauthorized activity.
  • Vulnerability management, security updates, dependency review, and remediation processes proportionate to risk.
  • Controls designed to prevent unauthorized cross-customer access or exposure.

4. Data Minimization and Privacy Controls

  • Collection and Processing limited to data reasonably necessary for the Services and Customer instructions.
  • Masking or exclusion of passwords, payment information, authentication credentials, API keys, security codes, and other sensitive fields from session replay.
  • Consent gating for analytics and session replay where required by applicable law.
  • Retention, deletion, export, and suppression controls as described in the Agreement and this DPA.

5. Personnel and Vendor Security

  • Confidentiality obligations for personnel with access to Customer Personal Data.
  • Privacy and security awareness appropriate to personnel roles.
  • Due diligence and contractual data protection obligations for relevant Subprocessors.

6. Incident Response and Continuity

  • Procedures for investigating, containing, remediating, and communicating Security Incidents.
  • Backup and recovery processes appropriate to the Services and deployment environment.
  • Business continuity and service restoration measures proportionate to operational risk.

7. Auditability

  • Logging and records appropriate to access, system activity, security events, and material configuration changes.
  • Reasonable documentation and compliance information made available as described in this DPA.

Schedule 3 - Authorized Subprocessors

The current authorized Subprocessors are identified in the then-current Lythe Subprocessor List, incorporated into this DPA by reference. As of the Effective Date, Lythe's disclosed Subprocessors include the following, subject to actual use, deployment, and Customer configuration:

  • Amazon Web Services, Inc. - cloud infrastructure, compute, storage, networking, backups, and security services.
  • Cloudflare, Inc. - content delivery, DNS, web security, traffic management, bot protection, and network performance.
  • PostHog, Inc. - product analytics, event analytics, feature-usage measurement, debugging, and session replay where enabled; PostHog US Cloud.
  • Lythe Pte. Ltd. - affiliate engineering, customer support, operations, administration, and security services from Singapore.

Customer-authorized integrations selected, configured, and controlled by Customer under Customer's own account or agreement may not be Lythe Subprocessors. Lythe will update the Subprocessor List where it independently engages an integration provider to Process Customer Personal Data on Lythe's behalf.

Schedule 4 - Transfer Information

1. Data Exporter

The Customer identified in the Agreement. Customer's contact details and activities relevant to the transfer are set out in the Agreement and Schedule 1.

2. Data Importer

Lythe Inc., United States, or Lythe Pte. Ltd., Singapore, where expressly identified as the contracting entity. Privacy contact: team@lythe.ai.

3. Transfer Details

The categories of Data Subjects, categories of Customer Personal Data, nature and purposes of Processing, frequency, duration, and retention are described in Schedule 1. The technical and organizational measures are described in Schedule 2. The authorized Subprocessors are identified in Schedule 3 and the then-current Lythe Subprocessor List.

4. Competent Supervisory Authority

The competent Supervisory Authority is determined in accordance with the EU SCCs based on Customer's establishment, representative, and affected Data Subjects. Where the UK GDPR applies, the competent authority is the UK Information Commissioner. Where Swiss law applies, the competent authority is the Swiss Federal Data Protection and Information Commissioner.

5. Governing Law and Forum

For purposes of Clause 17 of the EU SCCs, the EU SCCs will be governed by the laws of Ireland.

For purposes of Clause 18 of the EU SCCs, the parties submit to the jurisdiction of the courts of Ireland.

For purposes of Annex I.C of the EU SCCs, the competent Supervisory Authority will be the authority responsible for supervising the Data Exporter under the GDPR. Where the Data Exporter is not established in the European Union and no other Supervisory Authority is identified in the Agreement, the Irish Data Protection Commission will be the competent Supervisory Authority. For the UK addendum, English law and courts apply as required by the addendum. For Swiss transfers, applicable Swiss law and courts apply where required.