Data Processing Addendum
Last Updated: May 18, 2026

This Data Processing Addendum ("DPA") forms part of the agreement between Brainhive Labs Private Limited ("Calibr") and the Customer, and is incorporated by reference into Calibr's Terms of Service and any Master Service Agreement("MSA") executed between the parties. By accepting the Terms of Service or executing an MSA, the Customer agrees to the terms of this DPA.

This DPA applies where Calibr processes personal data on behalf of the Customer in the course of providing the Services.

1. Definitions
Terms defined in the Terms of Service or MSA have the same meaning in this DPA. Additionally:
TermMeaning
Personal DataAny data relating to an identified or identifiable individual processed by Calibr on behalf of the Customer through the Services, including Learner Data.
ProcessingAny operation performed on Personal Data, including collection, storage, use, disclosure, deletion, or any combination thereof.
Data Fiduciary / ControllerThe Customer, who determines the purposes and means of Processing Personal Data.
Data ProcessorCalibr, which processes Personal Data on behalf of and under the instructions of the Customer.
Data Principal / Data SubjectThe individual to whom the Personal Data relates — primarily the Customer's employees and learners using the Services.
Sub-ProcessorAny third party engaged by Calibr to process Personal Data in connection with the Services.
Security IncidentAny confirmed unauthorised access to, disclosure of, loss of, or destruction of Personal Data processed under this DPA.
Applicable Data Protection LawThe Digital Personal Data Protection Act, 2023 and its Rules, as applicable; and, where the Customer is subject to it, the EU General Data Protection Regulation (EU GDPR) or UK GDPR.
2. Roles of the Parties
As between the parties:
  • The Customer is the Data Fiduciary / Controller. The Customer determines the purposes for which, and the means by which, Personal Data is processed through the Services.
  • Calibr is the Data Processor. Calibr processes Personal Data only to provide the Services to the Customer, and only in accordance with the Customer's documented instructions.

Each party is responsible for its own compliance with Applicable Data Protection Law in its respective role.

3. Details of Processing
The details of the processing activities governed by this DPA are as follows:
ItemDetail
Subject matterThe provision of the Calibr platform and associated Services
DurationThe Subscription Term and the post-termination data retention period set out in Section 8
Nature of processingHosting, storage, access management, delivery of learning content, analytics, and AI-assisted content generation Services
PurposeEnabling the Customer to deliver corporate learning and training to its employees and learners
Categories of Personal DataName, email address, job title, department, learning progress, assessment results, engagement data, and any other data the Customer uploads to the platform
Categories of Data PrincipalsThe Customer's employees, contractors, and other individuals enrolled as learners on the platform
4. Calibr's Obligations
4.1 Processing on Instructions Only

Calibr will process Personal Data solely on the documented instructions of the Customer, including as set out in the Terms of Service, MSA, and this DPA. Calibr will not process Personal Data for any purpose other than providing the Services, unless required to do so by applicable law. Where applicable law requires processing beyond the Customer's instructions, Calibr will inform the Customer as soon as practicable unless prohibited by law.

4.2 Confidentiality of Processing Personnel

Calibr will ensure that personnel authorised to process Personal Data are subject to appropriate confidentiality obligations and receive training on data protection requirements relevant to their role.

4.3 Security Measures

Calibr will implement and maintain appropriate technical and organisational security measures to protect Personal Data against unauthorised access, accidental loss, destruction, or alteration. These measures include, at minimum:

  • Encryption of Personal Data in transit and at rest;
  • Role-based access controls limiting access to Personal Data to personnel who require it to provide the Services;
  • Regular security assessments and vulnerability monitoring;
  • Incident detection and response procedures.

Calibr's security programme is subject to ongoing review as part of its information security management system. Details of specific security measures are available to enterprise Customers upon written request to support@calibr.ai.

4.4 Sub-Processors

Authorisation. The Customer authorises Calibr to engage Sub-Processors to assist in providing the Services. Calibr will ensure that each Sub-Processor is bound by data protection obligations no less protective than those in this DPA.

Current Sub-Processor List. A current list of Sub-Processors is available to Customers upon written request to privacy@calibr.ai. Calibr will update this list as Sub-Processors are added or removed.

4.5 Security Incident Notification

Calibr will notify the Customer without undue delay upon becoming aware of a confirmed Security Incident affecting Personal Data processed under this DPA. Notification will be made to the Customer's registered account email address and will include, to the extent known at the time of notification:

  • A description of the nature of the Security Incident;
  • The categories and approximate volume of Personal Data and Data Principals affected;
  • The likely consequences of the Security Incident;
  • The measures taken or proposed to address the Security Incident.

Calibr will provide further information as it becomes available. Calibr's notification under this Section does not constitute an admission of fault or liability.

4.6 Assistance with Data Principal Rights
Calibr will provide the Customer with reasonable technical assistance to enable the Customer to respond to requests from Data Principals exercising their rights under Applicable Data Protection Law — including requests for access, correction, and erasure, and any other rights prescribed under Applicable Data Protection Law. Where the Services include self-service tools that enable the Customer to respond to such requests directly, the Customer will use those tools in the first instance.
4.7 Demonstration of Compliance and Audit
Upon reasonable written request (no more than once per twelve-month period unless a Security Incident has occurred), Calibr will provide information reasonably necessary to demonstrate compliance with this DPA, which may include responses to a written security questionnaire, summaries of relevant third-party certifications (including ISO 27001 certification), or confirmation of applicable security measures.
5. Customer's Obligations

The Customer warrants and agrees that:

(a) it has a lawful basis under Applicable Data Protection Law for collecting and transferring Personal Data to Calibr for processing under this DPA;

(b) it has provided all required notices to, and obtained all required consents from, Data Principals in connection with the processing activities described in this DPA;

(c) its instructions to Calibr regarding the processing of Personal Data comply with Applicable Data Protection Law;

(d) it is responsible for the accuracy, quality, and legality of the Personal Data it submits to the Services;

(e) it will promptly notify Calibr if it becomes aware of any actual or potential breach of Applicable Data Protection Law in connection with the processing activities under this DPA.

6. Deletion and Return of Personal Data

Upon expiry or termination of the Customer's Subscription, Calibr will:

(a) make Customer Data available for export for a period of thirty (30) days following termination (the "Data Access Period"), via the account dashboard or upon written request to support@calibr.ai; and

(b) following the Data Access Period, permanently delete or anonymise all Personal Data processed under this DPA, unless retention is required by applicable law.

Upon the Customer's written request, Calibr will provide written confirmation that deletion has been completed.

7. International Data Transfers

Personal Data processed by Calibr under this DPA is stored and processed in India and may be transferred to Sub-Processors located in other jurisdictions in connection with the delivery of the Services.

DPDP Act. Cross-border transfers of Personal Data are subject to the Digital Personal Data Protection Act, 2023 and any restrictions notified by the Government of India under that Act. Calibr will not transfer Personal Data to a jurisdiction notified as a restricted destination.

8. Liability

Each party's liability under this DPA is subject to the limitations and exclusions set out in the Terms of Service or, where applicable, the MSA. This DPA does not create any additional or separate liability cap beyond what is agreed in those instruments.

9. Term and Termination
This DPA remains in force for as long as Calibr processes Personal Data on behalf of the Customer. It terminates automatically upon the expiry of the post-termination Data Access Period and completion of data deletion under Section 6.
10. Conflict

In the event of a conflict between this DPA and the Terms of Service or MSA on matters relating to the processing of Personal Data, this DPA will take precedence.

11. Updates to This DPA

Calibr may update this DPA from time to time to reflect changes in Applicable Data Protection Law, regulatory guidance, or Calibr's data processing practices. For material changes, Calibr will give the Customer no less than thirty (30) days' prior written notice via email to the registered account address. Continued use of the Services after the effective date of a material change constitutes acceptance of the updated DPA.

Contact

For questions about this DPA, data protection matters, or to request the Sub-Processor list please contact:

Data Protection Contact Brainhive Labs Private Limited 106, Block 10, Zenith, Suncity Apartments, Iblur, Outer Ring Road, Bangalore, Karnataka, India – 560102 Email: privacy@calibr.ai