Data Processing Agreement
Effective Date: August 29, 2026
This Data Processing Agreement is a template that Unwrapped Solutions Inc. executes with a business customer that requires one. The customer and signatory fields below are completed at the time of signing. To request an executed copy, contact support@cognik.ai.
This Data Processing Agreement ("DPA") forms part of the applicable agreement between Unwrapped Solutions Inc., a British Columbia corporation and operator of the Cognik platform ("Company" or "Processor"), and the customer identified in that agreement or Annex 1 ("Customer"). It applies only where the Company processes Customer Personal Data on Customer's behalf. If there is a conflict concerning that processing, this DPA controls.
Customer uses the Services provided by Cognik and, in doing so, may submit or make available Personal Data that Cognik processes on Customer's behalf.
The parties enter into this DPA to reflect their agreement regarding the processing of such Personal Data in accordance with applicable Data Protection Laws.
1. Definitions
"Applicable Data Protection Laws" means privacy and data-protection laws applicable to the processing covered by this DPA, including, as applicable, British Columbia's Personal Information Protection Act, Canada's Personal Information Protection and Electronic Documents Act, applicable US state privacy laws, and other laws expressly agreed for the Services.
"Customer Personal Data" means personal information the Company processes on Customer's behalf as described in Annex 1. "Controller" includes an organization or business that determines processing purposes; "Processor" includes a service provider processing on its behalf. "Subprocessor" means a provider engaged to process Customer Personal Data. "Security Incident" means confirmed unauthorized access to, disclosure of, alteration of, loss of, or destruction of Customer Personal Data.
2. Roles and Scope of Processing
Customer is the organization, controller, business, or processor responsible for Customer Personal Data and its documented instructions. The Company acts as Customer's processor or service provider only when processing that data to provide the contracted Services.
The Company acts independently for Cognik account administration, subscription and payout operations, fraud prevention, platform security, legal compliance, and other processing it determines and describes in the Privacy Policy. That independent processing is outside this DPA.
Customer is responsible for lawful instructions, notices, permissions, and consents, including any required voice, likeness, biometric, or third-party-content authorization.
3. Processing Instructions
Documented Instructions. Cognik will process Customer Personal Data only on Customer's documented instructions, including as set out in the Agreement, this DPA, and Customer's configuration and use of the Services, unless required to process by law, in which case Cognik will inform Customer of that legal requirement before processing unless the law prohibits it.
Unlawful Instructions. Cognik will inform Customer if, in its opinion, an instruction infringes Applicable Data Protection Laws, without any obligation to conduct a legal review of the lawfulness of instructions.
4. Confidentiality and Personnel
The Company will limit Customer Personal Data access to personnel and contractors who need it for their role and are subject to confidentiality obligations. Access controls depend on the relevant system. This DPA does not promise universal administrative audit logging or a particular authentication control unless identified in Annex 2.
5. Security Measures
Technical and Organizational Measures. Cognik will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against Security Incidents, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing. A summary of current measures is set out in Annex 2.
Updates. Cognik may update its security measures from time to time, provided the updates do not materially reduce the overall level of protection.
6. Subprocessors
Customer generally authorizes the subprocessors identified in Annex 3. The Company will use written or provider terms appropriate to the processing and will remain responsible for subprocessor performance to the extent required by Applicable Data Protection Laws.
The Company will provide information about material changes on request or through another reasonable notice mechanism where required. Customer may object on reasonable data-protection grounds. The parties will seek a commercially reasonable solution; if none exists, Customer may discontinue the affected feature or terminate the affected Services.
7. Data Subject Requests
Assistance. Taking into account the nature of the processing, Cognik will provide reasonable assistance, including appropriate technical and organizational measures and the self-service functionality of the Services, to enable Customer to respond to requests from Data Subjects to exercise their rights under Applicable Data Protection Laws.
Forwarding. If Cognik receives a request from a Data Subject relating to Customer Personal Data, Cognik will, where legally permitted, direct the Data Subject to Customer or forward the request to Customer rather than responding directly, unless otherwise required by law.
8. Assistance to Customer
Compliance Support. Taking into account the nature of processing and the information available to Cognik, Cognik will provide reasonable assistance to Customer with data protection impact assessments, prior consultations with supervisory authorities, and Customer's obligations regarding the security of processing and Security Incident notification.
9. Security Incident Notification
The Company will notify Customer without undue delay after confirming a Security Incident affecting Customer Personal Data and will provide available information reasonably needed for Customer's legal obligations. Information may be provided in phases. Notification is not an admission of fault or liability.
10. International Data Transfers
Customer authorizes processing in Canada, the United States, and other locations used by authorized providers. The Company will use contractual or other measures required by Applicable Data Protection Laws.
This DPA does not itself incorporate incomplete European Standard Contractual Clauses or a UK Addendum. If a restricted transfer requires a specific mechanism, the parties will execute the applicable completed clauses, addendum, or other recognized mechanism before relying on it.
11. Retention, Return, and Deletion of Personal Data
Upon termination or a valid written request, the Company will take reasonable steps to return, delete, or de-identify Customer Personal Data from active Cognik systems, unless retention is required or permitted for legal, financial, security, fraud-prevention, dispute, or operational reasons.
Deletion is subject to technical dependencies, backups, authentication systems, security and retrieval logs, and provider processes. Current database deletion does not by itself erase provider-held copies, and deletion of a source does not yet guarantee simultaneous deletion of every related chunk or embedding. The Company does not promise a fixed deletion deadline unless separately agreed in writing.
Customer must maintain its own copies of important data. Reasonable assistance beyond standard functionality may be subject to fees unless required because of the Company's breach.
12. Audits and Records
The Company will provide information reasonably necessary to demonstrate compliance. Customer will first use available questionnaires, security summaries, provider materials, or third-party reports. An audit may occur where required by law and those materials are insufficient, no more than annually absent a Security Incident or regulatory requirement, subject to reasonable confidentiality, scope, timing, security, and cost conditions.
13. U.S. State Privacy Law Terms
Service Provider Status. To the extent Cognik processes personal information subject to the CCPA on behalf of Customer, Cognik acts as a "service provider" or "processor" under the state law, and processes such personal information only for the business purpose of providing the Services and as permitted for service providers.
Restrictions. Cognik will not sell or share Customer Personal Data, will not retain, use, or disclose it for any purpose other than providing the Services or as otherwise permitted by law, will not combine it with personal information from other sources except as permitted for a service provider, and will not use it for cross-context behavioral advertising.
Certification. Cognik certifies that it understands and will comply with these restrictions.
14. AI and Voice Processing
The Company uses third-party AI, transcription, voice, and related providers described in Annex 3. Uploaded audio or video ingest currently uses OpenAI gpt-4o-mini-transcribe. The live Subscriber speech provider or model is not confirmed in this DPA. Anthropic API services process prompts and outputs, and Fish Audio provides voice synthesis and voice-model functions.
The Company does not use one Customer's content to operate another Creator's Digital Mind and does not intentionally train a general-purpose model on Customer Personal Data. Provider practices depend on the applicable provider terms, account, configuration, and settings. The Company does not represent that it has Enterprise, zero-data-retention, or signed DPA terms with every provider.
15. Liability
Limitation. Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement, and any reference in the Agreement to a party's aggregate liability applies to the combined liability under the Agreement and this DPA.
16. Term and Termination
Term. This DPA takes effect on the Effective Date and remains in effect for as long as Cognik processes Customer Personal Data under the Agreement.
Survival. Provisions that by their nature should survive termination, including those regarding retention, deletion, confidentiality, and liability, will survive.
17. General Provisions
This DPA is governed by the laws of British Columbia and the federal laws of Canada applicable there, except where Applicable Data Protection Laws or a properly executed transfer mechanism requires otherwise. This DPA supplements the Agreement; the Agreement otherwise remains in effect.
The parties execute this DPA as of the Effective Date.
UNWRAPPED SOLUTIONS INC.
By: __________________________________
Name: ________________________________
Title: ________________________________
Date: ________________________________
[CUSTOMER LEGAL NAME]
By: __________________________________
Name: ________________________________
Title: ________________________________
Date: ________________________________
Annex 1 — Details of Processing
| Item | Description |
|---|---|
| Data exporter / Controller | [Customer legal name and contact] |
| Data importer / Processor | Unwrapped Solutions Inc.; 4873 Delta St, Delta, BC V4K 2T9, Canada; support@cognik.ai |
| Subject matter | Processing of Personal Data in connection with the provision of the Cognik Services, including the operation of the Customer's Digital Mind and subscriber dashboard |
| Duration | For the term of the Agreement and until deletion or return of Customer Personal Data in accordance with Section 11 |
| Nature and purpose | Hosting, storage, retrieval, analysis, transcription, voice processing, and AI-assisted generation of responses; account management; support; billing; analytics necessary to deliver the Services |
| Categories of Data Subjects | Customer's subscribers, end users, personnel, Source Individuals, and other individuals whose Personal Data Customer submits to the Services |
| Categories of Personal Data | Name, email address, account identifiers, profile information, payment-related metadata, device and usage data, and the content of interactions with the Services, including conversation inputs and outputs, notes, saved items, and workspace content |
| Special category data | Voice recordings and persistent voice models where authorized; sensitive information that Customer or users place in files or interactions. Customer must not submit regulated health information, payment-card data, government IDs, children's data, or other specially regulated data unless expressly permitted in writing. |
| Frequency of transfer | Continuous, for the duration of the Services |
| Retention | For the Agreement term and then under Section 11, subject to legal records, technical dependencies, logs, backups, and provider processes; no fixed deletion period unless separately agreed. |
Annex 2 — Technical and Organizational Security Measures
The Company maintains safeguards appropriate to the nature, sensitivity, and risk of Customer Personal Data. Measures may include provider-managed encryption in transit and at rest, role-based access, authentication controls, environment separation, logging and monitoring where implemented, personnel confidentiality, dependency management, and incident-response procedures. The scope of each measure depends on the applicable system. The Company does not represent that every administrative or support action is logged.
Annex 3 — Subprocessors
Material providers currently include: Anthropic (AI model processing); OpenAI (uploaded audio/video transcription and other configured AI functions); Fish Audio (voice models, speech synthesis, and generated audio); Supabase (database, authentication, and vector storage); Vercel and Railway (hosting and infrastructure); Whop (payments, subscriptions, refunds, and payouts); Google (authentication and operational services); Cloudflare (security and delivery); and Tally (Creator application forms).
Provider locations, retention, and contractual terms vary. Fish Audio offers a technical voice-deletion API, but Cognik does not currently promise a provider-wide backup deletion deadline. Contact support@cognik.ai for current information.