Last updated: July 20, 2026
This Data Processing Addendum (“DPA”) supplements the MorphCast Terms of Use or another written agreement governing a customer’s use of the Services (the “Agreement”) between Technologies MorphCast Inc., a corporation headquartered at 203-1553 rue du Centre, Montréal, Québec, H3K1H5, Canada (“MorphCast”), and the entity accepting or executing this DPA (“Business Customer”). When incorporated into or accepted under the Agreement, this DPA forms part of the Agreement.
Notice: MorphCast is headquartered in Canada and generally makes the Services available internationally, subject to the current Regional Availability notice. This DPA is intended to support the parties’ compliance with Applicable Data Protection Law, including Canadian privacy laws, the CCPA/CPRA and other applicable U.S. privacy laws, and the GDPR where applicable.
1. Definitions
“Applicable Data Protection Law” means any privacy, data-protection, or data-security law applicable to the Processing of Personal Data under the Agreement, including, where applicable, the Personal Information Protection and Electronic Documents Act (“PIPEDA”), Québec’s Act respecting the protection of personal information in the private sector, other applicable Canadian provincial privacy laws, the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”), other applicable U.S. state privacy laws, the General Data Protection Regulation (EU) 2016/679 (“EU GDPR”), and the United Kingdom GDPR (“UK GDPR”).
“Business Customer” means the entity that accepts the Agreement and determines the purposes and means of Processing Customer Personal Data.
“Controller” or “Business” means the party that determines the purposes and means of Processing Personal Data, including a “business” as defined by the CCPA/CPRA.
“Customer Personal Data” means Personal Data Processed by MorphCast on behalf of Business Customer in connection with the Services. It does not include data for which MorphCast acts as an independent Controller or Business, as described in Section 2.3.
“Data Subject” or “Consumer” means an identified or identifiable natural person to whom Personal Data relates, including a “consumer” as defined by applicable U.S. privacy law.
“Personal Data” means “personal data,” “personal information,” or an equivalent term under Applicable Data Protection Law.
“Process” and “Processing” mean any operation or set of operations performed on Personal Data.
“Processor” or “Service Provider” means a party that Processes Personal Data on behalf of a Controller or Business, including a “service provider” or “contractor” as defined by the CCPA/CPRA.
“Security Incident” means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data Processed by MorphCast.
“Sensitive Personal Data” means sensitive personal information, special-category personal data, biometric data, or an equivalent category protected by Applicable Data Protection Law.
“Services” means the MorphCast services described in the Agreement.
“Sub-processor” means a third party engaged by MorphCast to Process Customer Personal Data on behalf of Business Customer.
2. Roles of the Parties
2.1 Business Customer role. Business Customer acts as the Controller or Business for Customer Personal Data and determines the purposes and means of its Processing.
2.2 MorphCast role. MorphCast acts as the Processor or Service Provider for Customer Personal Data and Processes it only on Business Customer’s documented instructions and as required to provide the Services.
2.3 MorphCast Controller/Business data. This DPA does not apply to Personal Data that MorphCast Processes as an independent Controller or Business to administer customer accounts, billing, subscriptions, licenses, service security, legal compliance, direct customer communications, account-linked operational telemetry, or MorphCast SDK Trial Proactive Assistance. Those activities are governed by the MorphCast Cookies & Privacy Policy.
2.4 On-device Processing. This DPA does not apply to End User data that remains exclusively on the End User’s device and is not received by MorphCast. Nothing in this DPA changes the product-specific and regional data flows described in the MorphCast Cookies & Privacy Policy.
2.5 No joint controllership. The parties do not act as joint controllers for Customer Personal Data under this DPA.
3. Scope and Instructions
3.1 Documented instructions. MorphCast shall Process Customer Personal Data only on documented instructions from Business Customer, including the Agreement, this DPA, Business Customer’s configuration and use of the Services, and any additional written instructions agreed by the parties. MorphCast shall inform Business Customer without undue delay if, in MorphCast’s opinion, an instruction infringes Applicable Data Protection Law, unless the law prohibits that notice.
3.2 Legal requirements. If MorphCast is required by law to Process Customer Personal Data other than on Business Customer’s instructions, MorphCast shall notify Business Customer before the Processing unless the law prohibits notice.
3.3 CCPA/CPRA restrictions. MorphCast shall not sell or share Customer Personal Data; retain, use, or disclose it outside the direct business relationship with Business Customer or for a commercial purpose other than the business purposes specified in the Agreement; or combine it with Personal Data received from another person or collected from MorphCast’s own interaction with a Data Subject, except as expressly permitted by the CCPA/CPRA. MorphCast certifies that it understands and will comply with these restrictions.
3.4 Business Customer obligations. Business Customer is responsible for the lawfulness, accuracy, and quality of Customer Personal Data and its instructions; for providing required notices; and for obtaining any consent or other lawful basis required for its deployment and use of the Services.
3.5 Sensitive Personal Data. If Business Customer configures a permitted feature so that emotion or engagement metrics are associated with a display name or another identifier and transmitted to MorphCast, those data may qualify as Sensitive Personal Data under Applicable Data Protection Law. Business Customer is responsible for determining the applicable classification and satisfying all notice, consent, lawful-basis, impact-assessment, and other legal requirements. MorphCast shall Process such data only as a Processor or Service Provider and only where the product configuration and regional restrictions permit the transmission. Nothing in this DPA expands the data transmitted by a MorphCast product.
4. Confidentiality and Security
4.1 Confidentiality. MorphCast shall ensure that personnel authorized to Process Customer Personal Data are subject to appropriate confidentiality obligations and access the data only as necessary to perform their duties.
4.2 Security measures. MorphCast shall implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data, including the measures summarized in Annex 1.
4.3 Inability to comply. MorphCast shall notify Business Customer without undue delay if MorphCast determines that it can no longer meet its obligations under Applicable Data Protection Law with respect to Customer Personal Data. Business Customer may take reasonable and appropriate steps to stop and remediate unauthorized Processing.
5. Sub-Processors and Service Providers
5.1 General authorization. Business Customer provides general written authorization for MorphCast to engage the Sub-processors listed in Annex 2.
5.2 Sub-processor obligations. MorphCast shall enter into a written agreement with each Sub-processor imposing data-protection obligations that provide a level of protection for Customer Personal Data materially equivalent to this DPA, to the extent applicable to the services provided. MorphCast remains responsible for each Sub-processor’s performance of those obligations.
5.3 Changes. Business Customer may subscribe to email notice of material changes to Annex 2 and may object on reasonable data-protection grounds within 10 business days after notice. The parties shall work in good faith to address a timely objection.
5.4 Transparency regarding Controller-side providers. Annex 2 also identifies selected providers used for Personal Data that MorphCast Processes as an independent Controller or Business, including billing, support, and Proactive Assistance data. Listing such a provider does not make it a Sub-processor under this DPA unless it Processes Customer Personal Data on Business Customer’s behalf.
6. Data Subject Requests and Compliance Assistance
6.1 Requests. Taking into account the nature of the Processing, MorphCast shall provide reasonable assistance through appropriate technical and organizational measures to enable Business Customer to respond to Data Subject or Consumer requests under Applicable Data Protection Law, including requests for access, correction, deletion, restriction, portability, objection, opt-out of sale or sharing, and limitation of the use or disclosure of Sensitive Personal Data where applicable.
6.2 Direct requests. If MorphCast receives a request concerning Customer Personal Data directly from a Data Subject or Consumer, MorphCast shall promptly direct the requester to Business Customer or notify Business Customer, unless prohibited by law. MorphCast shall not independently respond to the substance of the request except on Business Customer’s documented instructions or as required by law.
6.3 Additional assistance. Taking into account the nature of the Processing and the information available to MorphCast, MorphCast shall provide reasonable assistance with Business Customer’s data-protection impact assessments, prior consultations with supervisory authorities, security obligations, and breach-notification obligations where required by Applicable Data Protection Law.
7. Security Incidents
MorphCast shall notify Business Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data. As information becomes available, MorphCast shall provide a description of the nature of the Security Incident, the categories of affected data and Data Subjects, the likely consequences, and the measures taken or proposed to address and mitigate it. MorphCast may provide this information in phases and shall reasonably cooperate with Business Customer’s investigation and legally required notifications. Notification does not constitute an admission of fault or liability.
8. Retention, Return, and Deletion
8.1 Customer Personal Data. Upon termination of the Agreement, or earlier upon Business Customer’s written request where technically feasible and legally permitted, MorphCast shall, at Business Customer’s choice, return or delete Customer Personal Data and delete existing copies within 60 days. Customer Personal Data retained solely in backups shall be deleted within a maximum of 90 days and shall remain encrypted and inaccessible to ordinary operations until deletion, unless longer retention is required by law.
8.2 Controller/Business data. Data that MorphCast Processes as an independent Controller or Business is retained in accordance with the MorphCast Cookies & Privacy Policy. SDK Trial Operational Assistance Data and Proactive Assistance Communication Data are retained for 12 months. This controller-side data is not subject to Business Customer’s return instructions under this DPA, without prejudice to rights available under Applicable Data Protection Law.
9. Information and Audit Rights
MorphCast shall make available information reasonably necessary to demonstrate compliance with this DPA. Once in any 12-month period, Business Customer may request a summary of MorphCast’s most recent relevant independent security assessment or, if that information is insufficient to demonstrate compliance, an audit of relevant systems and records, subject to the following conditions:
- at least 30 days’ prior written notice, unless a shorter period is required by a regulator or following a Security Incident;
- the audit occurs during normal business hours, is limited to the Processing covered by this DPA, and does not unreasonably disrupt MorphCast’s operations or compromise the security or confidentiality of other customers; and
- the auditor is independent, appropriately qualified, not a competitor of MorphCast, and bound by written confidentiality obligations.
Business Customer shall bear its audit costs unless the audit identifies material non-compliance by MorphCast with this DPA. Information provided under this Section is MorphCast Confidential Information.
10. International Data Transfers
10.1 Hosting and availability. MorphCast is headquartered in Canada, and its infrastructure is primarily hosted in the United States, including AWS us-west-2. Current product and territorial availability is stated in the Regional Availability notice.
10.2 Transfer safeguards. Where Applicable Data Protection Law restricts an international transfer of Customer Personal Data, the parties shall ensure that an appropriate transfer mechanism applies before the transfer, such as an applicable adequacy decision, the then-current European Commission Standard Contractual Clauses, the UK International Data Transfer Addendum or Agreement, or another legally recognized safeguard. MorphCast shall provide or enter into the applicable transfer documentation where reasonably required and shall implement supplementary measures where required by law.
10.3 Onward transfers. MorphCast shall require Sub-processors receiving Customer Personal Data in another jurisdiction to protect it through legally valid transfer safeguards and contractual obligations consistent with this DPA.
11. Limitation of Liability
Each party’s liability arising from or related to this DPA is subject to the limitation-of-liability provisions in the Agreement, except to the extent such limitation is prohibited by Applicable Data Protection Law.
12. Order of Precedence and Term
If this DPA conflicts with the Agreement regarding the Processing of Customer Personal Data, this DPA controls. If an applicable transfer mechanism conflicts with this DPA, that transfer mechanism controls for the restricted transfer. This DPA remains in effect while MorphCast Processes Customer Personal Data and terminates after that data has been deleted or returned in accordance with Section 8.
13. Effectiveness and Signatures
This DPA becomes binding when it is incorporated by reference into the Agreement, accepted electronically by Business Customer, or signed by both parties.
A customer that requires a countersigned copy may execute this DPA separately. A separately executed copy is effective as of the date of the last signature below.
| For Technologies MorphCast Inc. | For Business Customer |
|---|---|
| Name: Stefano Bargagni | Name: ____________________ |
| Title: CEO | Title: ____________________ |
| Date: ____________________ | Date: ____________________ |
| Signature: ____________________ | Signature: ____________________ |
Annex 1 — Security Measures (Summary)
- TLS 1.2 or higher encryption in transit and AES-256 encryption at rest for stored data and backups.
- Segmented production networks and least-privilege identity and access management.
- Security monitoring and regular vulnerability scanning.
- Regular penetration testing.
- Encrypted backups managed under documented retention and deletion schedules.
- Incident-response procedures and breach-notification protocols.
Annex 2 — Approved Sub-Processors and Service Providers
| # | Service Provider | Service / Primary Function | Affected Products (examples) | Primary Data Location |
|---|---|---|---|---|
| 1 | Amazon Web Services, Inc. (including Amazon CloudFront) | Cloud infrastructure, storage, databases, compute, media processing, telemetry endpoints, cache, global CDN, edge caching, and edge security | SDK license API, Ready-to-Use Web Apps, Studio, Portal, Video Conference, Zoom App, Media Player, and Website | United States (us-west-2) and global edge locations |
| 2 | Cloudflare, Inc. | CDN, web application firewall, and bot management | Website (morphcast.com) | Global |
| 3 | Google LLC — Cloud Services | Cloud Storage, Firestore, Apps Script automations, and reCAPTCHA bot detection | Contact Form, Portal billing exports, and internal administrative automations | United States |
| 4 | Google LLC — Workspace / Drive | Email, documents, file storage, internal ticketing, and business communications | Corporate communications, support records, and authorized outreach records | United States |
| 5 | Stripe, Inc. | Payment processing, subscription billing, and invoice emails | Portal license purchases and Studio paid tier | United States |
| 6 | Voiceflow Inc. | Website chat widget backend and transient message storage for no more than 24 hours | Website chat support | United States |
| 7 | Twilio SendGrid | Operational email routing and delivery, including delivery, bounce, complaint, and suppression processing | Portal operational communications and MorphCast SDK Trial Proactive Assistance | Global SendGrid region; data may be processed or stored outside the EU, including in the United States |
SendGrid data minimization: For MorphCast SDK Trial Proactive Assistance, Twilio SendGrid receives the designated business email address, message or template identifier, minimum message variables, provider message ID, and delivery, bounce, complaint, and suppression metadata. It does not receive license keys, raw SDK telemetry, Emotion AI outputs, Customer Content, or End User identifiers.
Annex 3 — Details of Processing
Subject matter. Processing of Customer Personal Data as necessary to provide, secure, maintain, and support the Services selected and configured by Business Customer.
Duration. For the term of the Agreement and the deletion periods stated in Section 8, unless Applicable Data Protection Law requires a longer period.
Nature and purpose. Collection, transmission, organization, storage, retrieval, consultation, hosting, support, security, deletion, and other Processing necessary to provide the Services on Business Customer’s documented instructions.
Frequency. Continuous or event-driven, depending on Business Customer’s configuration and use of the Services.
Categories of Data Subjects. Business Customer’s authorized users, employees, contractors, customers, End Users, meeting or media participants, and other individuals whose Personal Data Business Customer submits to or causes to be Processed through a cloud-enabled Service.
Categories of Customer Personal Data. Identifiers and contact details submitted by Business Customer; authentication and access metadata; IP address, browser, device, event, and security-log data; Customer Content uploaded to a cloud-enabled Service; support communications; and, only where a permitted product configuration transmits them to MorphCast, emotion or engagement metrics associated with an identifier. Core SDK camera frames, full video, biometric templates, face templates, and per-user Emotion AI outputs are not transmitted to MorphCast unless a separate product notice expressly states otherwise.
Sensitive Personal Data. Business Customer may cause the Processing of Sensitive Personal Data only where the selected Service and applicable regional configuration permit it. Business Customer must identify and document the applicable legal basis and safeguards before such Processing begins.
Business Customer’s rights and obligations. Business Customer may issue lawful documented instructions, retrieve or delete data using available product controls, request assistance under this DPA, and exercise the audit rights in Section 9. Business Customer remains responsible for the lawfulness of its Processing, the accuracy and minimization of the data it provides, and compliance with notice, consent, and Data Subject rights obligations.