DDScore.ai
For Investors For Evaluators For Founders Example Report Pricing News About
Sign In
For Investors For Evaluators For Founders Example Report Pricing News About Sign In

Data Processing Addendum (DPA)

DDScore.ai | Effective date: 13 August 2026

2026.08.13 22:00

This Data Processing Addendum ("DPA") forms an integral part of the DDScore.ai Terms of Service ("Agreement") between Playful Pixels Oy (the "Processor") and the User (the "Controller").

1. Scope and Roles

This DPA applies to the processing of personal data contained within business documents uploaded by the Controller to the DDScore.ai service, and to personal data obtained from public sources when the Service checks the professional background of an individual named in those documents. That check is carried out only where the Controller enables it for that specific individual, and the Controller's act of enabling it constitutes a documented instruction to carry out the check.

The User acts as the Data Controller for any third-party personal data (e.g., team members, founders, or other individuals) contained in the uploaded materials, and equally for the public-source background data described above. The Controller decides whether any such check is carried out and about whom, is responsible for having the rights and permissions required, and is responsible for any information obligation toward the individuals concerned.

Playful Pixels Oy acts as the Data Processor, performing analysis using a combination of AI-powered methods and mathematical methods, including proprietary Advanced Probabilistic Analysis, strictly on behalf of and according to the documented instructions of the Controller.

This DPA does not cover personal data that Playful Pixels Oy processes as controller in its own right — including account and subscription records, support tickets, survey-campaign data and marketing choices. That processing is described in the Privacy Policy.

2. Subject Matter and Duration

Subject Matter: Analysis of business documents (e.g., pitch decks, business plans) using AI-powered analysis combined with mathematical methods, including proprietary Advanced Probabilistic Analysis, and verification of professional backgrounds via public sources where enabled by the Controller for a specific individual.

Duration of Processing:

(a) Uploaded source files: Extremely short-term — automatically and permanently deleted immediately upon completion of report generation.

(b) Generated analysis reports: Automatically and permanently deleted within 24 hours of report generation. Where the Controller activates a share link, the report is retained for as long as the share link is active and is deleted within 24 hours of the link being deleted — see Section 6(c).

(c) Public-source background data: Retained only for the generation of the report and deleted together with the related report, and therefore subject to the same retention period as the report.

Limited exceptions to the deletion timetable above are set out in Section 6. The nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex 1.

3. Processor's Obligations

The Processor commits to:

  • Process personal data only on documented instructions from the Controller, unless required by EU or Member State law.
  • Ensure that personnel authorized to process the data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. In the context of support-request handling, access to the Controller's submitted materials is restricted to the Processor's support team and development team and is not extended more broadly within the organization.
  • Implement rigorous technical and organizational measures to ensure a level of security appropriate to the risk, including TLS 1.3 encryption in transit and AES-256 encryption at rest.
  • If the Processor becomes aware of a personal data breach affecting the Controller's data, notify the Controller without undue delay, and in any event within 48 hours of such awareness, providing all information reasonably required for the Controller to comply with its notification obligations under GDPR Article 33.
  • Assist the Controller in fulfilling their obligation to respond to requests for exercising data subject rights, to the extent possible given the deletion cycles set out in Sections 2 and 6.
  • Assist the Controller, taking into account the nature of the processing and the information available to the Processor, in complying with Articles 32 to 36 GDPR, including notification of data subjects under Article 34, data protection impact assessments under Article 35, and prior consultation under Article 36.
  • Make available to the Controller the information necessary to demonstrate compliance with this DPA, in the first instance as documentation: a description of the technical and organisational measures, applicable certifications, and summaries of penetration testing. Where documentation is not sufficient to demonstrate compliance, the Controller or an auditor mandated by the Controller may audit the Processor once in any twelve-month period, on 30 days' written notice, during business hours, subject to confidentiality. The Controller bears its own audit costs and reimburses the Processor's reasonable costs of preparing for and supporting the audit. This does not limit any audit or inspection required by a supervisory authority.

4. Sub-processors

The Processor operates its own machine room and its own hardware in Finland, and hosts its own language and other AI models on it. That infrastructure, and those models, are operated by the Processor and are not sub-processors. No external party administers the Processor's systems or has access to them.

The Controller provides a general authorisation for the Processor to engage sub-processors in the following category:

CategoryLocation
General-purpose AI model servicesProviders established in the United States, each certified under the EU–US Data Privacy Framework or covered by Standard Contractual Clauses

This table lists the sub-processors engaged for the personal data within the scope of this DPA. Service providers that Playful Pixels Oy engages for personal data it processes as controller in its own right — including payment processing and email delivery — are outside this DPA and are described in the Privacy Policy. Support requests, including any report or source materials attached to them, are handled within the Service and are not transmitted through an external email provider.

The current list of named sub-processors is available to the Controller on request.

The Processor will inform the Controller at least 30 days before adding or replacing a sub-processor. The Controller may object on reasonable data-protection grounds within that period. If the parties cannot resolve the objection, the Controller may terminate the affected processing without penalty.

The Processor ensures that these sub-processors are bound by data protection obligations at least as restrictive as those in this DPA.

No Training: The Processor shall not use the Controller's data, uploaded documents, or generated reports to train or fine-tune any machine learning models. The same applies to the anonymous, aggregated statistical data described in Section 6(b) below — such data is not used for training or fine-tuning machine learning models and is not transferred to third parties.

5. International Transfers

Data is primarily stored and processed within the EU/EEA.

If data is processed outside the EEA, the Processor relies on Standard Contractual Clauses (SCCs) or other valid transfer mechanisms to ensure a level of protection equivalent to that guaranteed within the EU.

6. Zero Trace, Deletion, and Limited Exceptions

(a) Zero Trace baseline. In accordance with the Processor's "Zero Trace Policy":

  • Uploaded source files are automatically and permanently deleted immediately upon completion of report generation.
  • Generated analysis reports are automatically and permanently deleted within 24 hours of generation.

No backups of the processed business documents are maintained; once deleted, the data is unrecoverable.

(b) Anonymous statistical data. The Processor retains anonymous, aggregated statistical data consisting of the 12 section scores, GICS-based industry classification, country/region, and timestamp, as further described in the Terms of Service (Section 3.5). This data is statistical, contains no link to the Controller or to the submitted material, and is not personal data within the meaning of the GDPR. It is retained indefinitely for product development purposes only. It is not used to train or fine-tune machine learning models and is not transferred to third parties.

(c) Public sharing. If the Controller chooses to use the in-service share link function as set out in Section 7 of the Terms of Service, the published version of the report or main image and the corresponding generated report are retained on the Processor's servers for as long as the share link is active. Source files remain subject to the immediate-deletion rule in Section 6(a) and are not retained for the share function. Upon deletion of the share link or closure of the Controller's account, the published version is removed from the Processor's servers immediately, and the corresponding generated report is deleted within 24 hours of that deletion.

The Controller should note that the retained generated report is the unredacted version and may therefore contain personal data that does not appear in the published version, for as long as the share link remains active.

(d) Support requests. Materials submitted with a support request — including the report (automatically attached) and any voluntarily attached source materials — are retained for up to 14 days from submission. Either the Controller or the Processor may request an extension where investigation requires more time; any extension requires the mutual agreement of both parties, which may be communicated via the email address or phone number (SMS) provided in the support request. The text content of the support ticket is retained per the standard support-ticket retention period set out in the Privacy Policy.

(e) Metadata and account records. The deletion rules in this Section 6 do not apply to system metadata and account records. Playful Pixels Oy processes those as controller in its own right, outside the scope of this DPA as stated in Section 1, and their retention periods are set out in the Privacy Policy.

(f) End of the provision of services. At the end of the provision of services, the Processor returns or deletes all personal data at the choice of the Controller. Because uploaded source files are deleted immediately upon report completion and generated reports within 24 hours of generation, return is not possible after those periods have elapsed; the Controller's means of retaining a report is to download it during the 24-hour window described in Section 2(b). No copies are retained after deletion, except as set out in this Section 6.


Annex 1 — Nature of processing, types of personal data, and categories of data subjects

Nature and purpose of the processing. Generating a due diligence analysis of a company from materials submitted by the Controller, and, where the Controller enables it for a specific individual, checking that individual's professional background against public sources.

The check compares what the submitted materials state about that individual's professional background against public sources and surfaces references to those sources. The analysis then evaluates whether the combined background and composition of the team named in the materials appears adequate for the plans, claims and objectives presented. That evaluation concerns the team as a whole; the Service does not evaluate the personal suitability of an individual.

Types of personal data. The Controller determines what personal data the submitted materials contain. Typically this is limited to the name and role of individuals connected with the analysed company. Where the Controller enables a background check, the Service additionally processes professional and educational background information about that individual obtained from public sources.

The Controller must not deliberately submit materials containing special categories of personal data (Article 9 GDPR) or personal data relating to criminal convictions and offences (Article 10 GDPR).

Where such data nonetheless appears — for example clinical or patient information in the materials of a health-sector company — the Controller is responsible for having the condition required by Article 9(2) and any authorisation required by Article 10 and national law.

The Processor does not screen submitted materials for such data.

Categories of data subjects. Individuals named in the materials the Controller submits — typically founders, executives, board members and other people connected with the analysed company — and individuals for whom the Controller enables a background check.

© 2026 Playful Pixels Oy | Business ID 2410516-5 | Espoo, Finland

DDScore.ai - Make Better Decisions

Company

Login For Investors For Evaluators For Founders Pricing News About

Legal

Terms of Service Data Processing Addendum Privacy Policy Register Description

© 2026 DDScore.ai — A Playful Pixels Product