Product Pricing Use Cases About Book a Demo

Data Processing Agreement (DPA)

Data Processing Agreement  |  Last updated: August 15, 2026  |  Effective date: August 15, 2026

This document is a standard template. The final legally binding version shall be the document executed between the parties and Super Route. Signing parties: the Customer (Data Controller) and Super Route (Data Processor).

1. Definitions

  • Personal Data: any information relating to an identified or identifiable natural person.
  • Controller: the entity that, alone or jointly with others, determines the purposes and means of the processing of Personal Data, i.e., the Customer.
  • Processor: the entity that processes Personal Data on behalf of the Controller, i.e., Super Route.
  • Sub-processor: a third party engaged by the Processor, with the Controller's authorisation, to further process Personal Data.
  • Data Subject: the natural person to whom the Personal Data relates.
  • Security Incident / Breach: an event resulting in the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.
  • Technical and Organisational Measures (TOMs): the technical and organisational measures taken to ensure the security of Personal Data, as detailed in Appendix B.
  • Standard Contractual Clauses (SCC): the standard contractual clauses approved by the European Commission for cross-border data transfers.

2. Priority of Agreement

This DPA constitutes a supplementary agreement to the service agreement between the Customer and Super Route (including the Terms of Service). In the event of any conflict between this DPA and provisions concerning Personal Data processing in the service agreement, this DPA shall prevail.

If any provision of this DPA conflicts with applicable mandatory data protection law (such as the GDPR or the Personal Information Protection Law (PIPL)), the mandatory law shall prevail.

3. Subject Matter, Purpose, and Duration of Processing

The Processor shall process Personal Data only in accordance with the Controller's written instructions. The details of the processing (categories of data, categories of data subjects, processing activities, and retention periods) are set out in Appendix A.

The Processor shall not process the Controller's Personal Data for its own purposes, nor use it for any purpose inconsistent with this Agreement.

4. Controller's Obligations

The Controller shall ensure that:

  1. it has a lawful basis for processing the Personal Data and has provided data subjects with the necessary privacy information and channels for exercising their rights.
  2. all written instructions issued to the Processor comply with applicable data protection law.
  3. it responds in a timely manner to any questions raised by the Processor regarding the lawfulness of the instructions.
  4. it is responsible for carrying out any necessary data protection impact assessments (DPIA / PIA) and shall provide relevant assistance information upon the Processor's request.

5. Processor's Obligations

5.1 Process Only on Instructions

The Processor shall process Personal Data only in accordance with the Controller's written instructions, unless required to do otherwise by applicable European Union or Member State law (in which case the Processor shall inform the Controller in advance, to the extent permitted by law).

5.2 Confidentiality

The Processor shall ensure that all personnel involved in processing Personal Data have signed confidentiality agreements or are bound by statutory confidentiality obligations, and access Personal Data only to the extent necessary to perform their work.

5.3 Security Measures

The Processor shall implement the technical and organisational measures set out in Appendix B to ensure the security of Personal Data and prevent Security Incidents. When assessing risk, the Processor shall take into account, in particular:

  • the risks of processing, in particular from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data;
  • the nature, scope, context, and purposes of the processing;
  • the state of the art and the costs of implementation available to ensure security.

5.4 Assistance with Data Subject Requests

Taking into account the nature of the processing, the Processor shall, where possible, assist the Controller through appropriate technical and organisational measures in fulfilling its obligation to respond to requests by data subjects to exercise their rights.

5.5 Assistance with DPIAs and Regulatory Consultations

Upon the Controller's request, the Processor shall provide reasonable assistance to help the Controller complete data protection impact assessments (DPIA / PIA) and prior consultations with supervisory authorities.

6. Sub-processors

The Controller authorises the Processor to engage the sub-processors listed in Appendix C to process Personal Data. With respect to new or replacement sub-processors:

  1. The Processor shall notify the Controller at least 14 business days in advance, giving the Controller a reasonable opportunity to object.
  2. If the Controller raises a reasonable objection within the notice period, the Processor shall resolve the matter through consultation with the Controller, including but not limited to: changing the sub-processor, adjusting the processing approach, or the Controller terminating the service agreement.
  3. The Processor shall enter into a written agreement with each sub-processor, ensuring the sub-processor assumes data protection obligations equivalent to those set out in this DPA.

The current list of approved sub-processors is set out in Appendix C.

7. Assistance with Data Subject Rights

Upon receiving a request directly from a data subject, the Processor shall promptly forward the request to the Controller and inform the data subject to contact the Controller to process the request, unless otherwise instructed in writing by the Controller.

The Processor shall cooperate with the Controller, using reasonable technical and organisational measures, to assist it in responding to data subjects' requests to exercise the following rights: the right of access, the right to rectification, the right to erasure, the right to restriction of processing, the right to data portability, and the right to object.

8. Security Incident Notification

Upon becoming aware of a Security Incident involving the Controller's Personal Data, the Processor shall notify the Controller within 72 hours. The notification shall include:

  • the nature of the incident, including the categories and approximate number of data records concerned and the categories and approximate number of data subjects affected;
  • the likely consequences and risks;
  • the remedial measures the Processor has taken or proposes to take, including, where possible, measures to mitigate adverse effects;
  • the contact details of the Processor's designated point of contact for the Controller.

The Processor shall continue to cooperate with the Controller's investigation and remediation efforts until the incident is fully resolved. The Processor shall not notify the public or data subjects of a Security Incident without the Controller's prior written consent.

9. Cross-border Data Transfers

Where the provision of services requires the transfer of Personal Data from the country or region in which the Controller is located to another country or region (in particular, out of the EU/EEA or out of China), the Processor shall ensure that such transfer is carried out through one of the following compliance mechanisms:

  • Standard Contractual Clauses (SCC): the latest version of the SCCs adopted by the European Commission on June 4, 2021 (Decision 2021/914), Module Two (Controller to Processor) or Module Three (Processor to Sub-processor);
  • Standard Contract for the Cross-border Transfer of Personal Information: executed in accordance with Article 38 of the Personal Information Protection Law and the standard contract template issued by the Cyberspace Administration of China;
  • Certification or a decision ensuring an equivalent level of protection: such as a certification mechanism or an adequacy decision recognised by the applicable data protection supervisory authority.

Upon the Controller's request, the Processor shall provide a copy of the executed SCCs or the standard contract for cross-border transfer.

10. Audits and Compliance Certifications

The Controller shall have the right to audit the Processor's data processing activities, or to appoint an independent auditor agreed upon by both parties to do so. The Processor shall provide the necessary assistance and access to information.

To reduce the audit burden on the Controller, the Processor shall provide the following compliance documentation on an annual basis, which the Controller may rely upon in lieu of a direct audit:

  • SOC 2 Type II audit report (issued by an independent third-party audit firm);
  • ISO 27001 certificate and the latest surveillance audit report;
  • a security and compliance whitepaper prepared by the Processor (including a description of the implementation of the TOMs).

If the above documentation is insufficient to satisfy the Controller's compliance requirements, or if a material Security Incident occurs, the Controller shall have the right to request a special audit. The costs of the audit shall be borne by the Controller, unless the audit reveals that the Processor is in breach of this DPA.

11. Return or Deletion of Data Upon Termination

Upon termination of the service agreement, the Processor shall, in accordance with the Controller's written election:

  1. Return: within 30 days of termination, provide all of the Controller's Personal Data to the Controller in a commonly used electronic format;
  2. Deletion: within 30 days of termination, securely delete all of the Controller's Personal Data and its existing copies.

Where laws or regulations require the Processor to retain certain Personal Data, the Processor shall retain only the data necessary to comply with the legal requirements and shall continue to comply with the confidentiality and security obligations under this DPA during the retention period. The Processor shall confirm in writing to the Controller that the deletion has been completed.

12. Liability and Indemnification

The Processor shall be liable to the Controller only for damage directly caused by its breach of the obligations set out in this DPA. The Processor's aggregate liability shall not exceed the liability cap agreed in the service agreement.

If the Processor's fault causes the Controller to be held liable by a data subject or a supervisory authority, the Processor shall indemnify the Controller for the relevant losses in proportion to its share of fault in causing the damage.

13. Notices and Amendments

All notices relating to this DPA shall be sent in writing to the contact details designated by the parties. If the Processor needs to change the list of sub-processors or the TOMs in the Appendix, it shall provide notice in accordance with the procedure set out in Section 6 of this Agreement.

Material amendments to this DPA require the written consent of both parties. If changes in applicable data protection law require corresponding adjustments to the provisions of this DPA, the parties shall promptly negotiate such amendments.

14. Governing Law and Dispute Resolution

This DPA shall be governed by the governing law agreed in the service agreement. If the service agreement does not specify a governing law, this DPA shall be governed by the laws of the People's Republic of China.

Any dispute arising out of or in connection with this DPA shall first be resolved through friendly negotiations between the parties. If the negotiation fails, the dispute shall be resolved in accordance with the dispute resolution mechanism agreed in the service agreement. If the service agreement does not specify a dispute resolution mechanism, either party may submit the dispute to the China International Economic and Trade Arbitration Commission (CIETAC) for arbitration in Beijing in accordance with its arbitration rules. The arbitration award shall be final and binding upon both parties.

Appendix A — Data Processing Details

A.1 Categories of Data

  • data contained in business documents uploaded by the Customer, such as business plans, research reports, financial statements, and data room documents;
  • user account information (name, email address, organisation, and job title);
  • platform usage behaviour logs (feature access, search queries, and activity records);
  • AI analysis outputs (investment memos, financial model outputs, and industry summaries).

A.2 Categories of Data Subjects

  • the Customer's employees and investment team members;
  • individuals related to the projects/companies evaluated by the Customer (founders, management, and shareholders);
  • the Customer's limited partners (LPs) and investment committee members.

A.3 Processing Activities

  • document parsing and data extraction (NLP / OCR processing);
  • financial modelling and sensitivity analysis calculations;
  • automated generation and editing of investment memos;
  • industry research and market data aggregation;
  • portfolio monitoring and alert metric calculations;
  • user authentication and access control.

A.4 Retention Periods

The retention periods for each category of data are set out in Section 7 of the Privacy Policy. Upon termination of the service agreement, data shall be handled in accordance with Section 11 of this DPA.

Appendix B — Technical and Organisational Measures (TOMs)

B.1 Encryption

  • Encryption in transit: TLS 1.2+, with downgrade protocols disabled;
  • Encryption at rest: AES-256, with keys managed by an independent KMS and rotated on a regular basis;
  • End-to-end encryption: optionally available to Institutional edition customers.

B.2 Access Control

  • role-based access control with the principle of least privilege (RBAC + Principle of Least Privilege);
  • multi-factor authentication (MFA) required for all production environment access;
  • dual control (two-person approval) required for privileged operations;
  • periodic review of access permissions (quarterly).

B.3 Data Backup and Recovery

  • daily incremental backups and weekly full backups;
  • backup data stored encrypted and physically isolated from production data;
  • disaster recovery with RTO ≤ 4 hours and RPO ≤ 1 hour.

B.4 Security Monitoring

  • 24/7 security log monitoring and anomalous behaviour detection (SIEM system);
  • automated vulnerability scanning (weekly) and penetration testing (at least annually);
  • intrusion detection and prevention systems (IDS/IPS).

B.5 Incident Response

  • maintain a written security incident response plan, reviewed and tested annually;
  • clear incident classification, response procedures, and notification mechanisms;
  • emergency collaboration agreements with external security partners.

B.6 Personnel Management

  • all employees sign confidentiality agreements and receive onboarding and annual security/privacy training;
  • employees who process Personal Data are limited to authorised roles, with all access rights revoked immediately upon departure;
  • third-party contractors are subject to the same obligations.

Appendix C — List of Approved Sub-processors

The following are the sub-processors generally authorised by the Controller as of August 15, 2026. Any new or replacement sub-processors shall follow the notification procedure set out in Section 6 of this DPA.

Sub-processor Processing Activities Data Storage Location
Cloud infrastructure provider Server hosting, data storage, compute resources Data centres in China
Email delivery service Email sending and delivery monitoring Within China
Security monitoring service Log collection, anomaly detection, security analysis Within China
Customer support platform Support ticket management and communication records Within China

Note: Institutional edition customers with private deployments may not use the above sub-processors; the specific terms shall be governed by the deployment agreement signed by the parties.