GDPR Compliance Framework

Data Processing Addendum

Standard contractual terms governing personal data processing for European enterprise clients.

1. Scope and Applicability

This Data Processing Addendum (“DPA”) forms a key part of the Terms of Service between Thriving Billions Private Limited (“Dehurdle”) and subscribing organizations. It applies specifically where Dehurdle processes Personal Data subject to the General Data Protection Regulation (“GDPR”) or other matching privacy frameworks (such as the DPDPA) on behalf of our customers.

2. Roles of the Parties

Under GDPR, the customer acts as the Data Controller, specifying the business purpose of L&D training and simulations. Dehurdle acts strictly as the Data Processor. We process customer transcripts, scorecard averages, speaking metrics, and metadata only in accordance with the controller's instructions and to deliver our services.

Cross-Border Data Transfers & EU SCCs

Where personal data is transferred from the European Economic Area (EEA) to servers or third-party subprocessors located outside countries with adequacy status, Dehurdle incorporates the European Commission's **Standard Contractual Clauses (SCCs)** (Module 2: Controller-to-Processor) into our standard DPA framework.

This ensures compliance under Schrems II and establishes strict contractual obligations regarding biometric transients, transcripts, and metadata protection.

3. Technical & Organizational Security Measures (TOMs)

Dehurdle implements and maintains industry-standard security safeguards to protect customer data against unauthorized access or breaches:

Data Encryption

All customer data is encrypted in transit using TLS 1.3 and at rest in our AWS databases using AES-256 encryption.

Zero Voice Retention

Biometric voice data processed transiently in-memory and auto-deleted post-evaluation. No raw audio files or voiceprints are stored.

Access Controls & MFA

Strict role-based access control (RBAC), Enterprise SSO integration, multi-factor authentication (MFA), and audit logging for all infrastructure administrators.

Audits & Penetration Testing

Annual third-party SOC 2 Type II / ISO 27001 security assessments, automated SAST/DAST penetration testing, and continuous dependency vulnerability scanning.

Incident Response & Notification

Automated breach response playbooks with 72-hour formal notification guarantees to Data Controllers and supervisory authorities (GDPR Art. 33 / DPDPA).

Isolated Regional Residency

Complete tenant data isolation with dedicated cloud boundaries in EU-Frankfurt, APAC-Mumbai, and US-Virginia.

4. Subprocessors

The customer authorizes Dehurdle to engage third-party subprocessors to deliver simulation infrastructure, cache layers, and AI voice processing. All subprocessors are bound by matching data protection terms. A list of active partners and hosting regions is maintained at our dedicated Subprocessors Page.

Request Pre-signed DPA

European enterprise customers can request a copy of our pre-signed DPA template incorporating standard SCC modules for execution.

Email reach@dehurdle.com
Last revised: July 2026