Skip to content
helloAISearch

Data Processing Agreement

Effective September 17, 2026

This Data Processing Agreement (“DPA”) forms part of the agreement between PulseSpark.ai LLC, a Pennsylvania limited liability company (“Processor,” “we,” “us”), operator of helloAISearch, and the customer identified in the account registration (“Controller,” “you”).

This DPA applies where we process Personal Data on your behalf in the course of providing the Service, and where that processing is subject to the EU General Data Protection Regulation (Regulation 2016/679), the UK GDPR, or comparable law.

1. Definitions

Terms not defined here carry the meaning given in the GDPR. “Service” means helloAISearch as described at helloaisearch.com. “Personal Data” means personal data we process on your behalf under this DPA. “Subprocessor” means a third party we engage to process Personal Data.

2. Subject Matter, Duration, Nature and Purpose

Subject matter. Provision of the Service: monitoring whether and how your brand is referenced in the responses of third-party AI search engines, and reporting on that.

Duration. For as long as you hold an account or otherwise use the Service, including any free trial, plus the retention periods described in section 8.

Nature and purpose. Storing your configuration; transmitting prompts to AI providers; recording and analysing the responses; producing reports, metrics and recommendations; billing; and service communications.

3. Categories of Data Subject

Individuals you authorise to use the Service, being your personnel and any users you invite.

4. Categories of Personal Data

  • Identity and contact. Name, email address, company or organisation name.
  • Account. Authentication data, plan, preferences, time zone, settings.
  • Project configuration. Brand names, domains, aliases, industry, descriptions, competitor sets, tracked prompts.
  • Service output. Prompts sent to AI providers, provider responses, extracted mentions, rankings, Share of Voice metrics, generated reports.
  • Billing. Payment processor customer and subscription identifiers, invoice history, billing status. Card numbers are transmitted by the data subject's browser directly to Stripe and are never received by us.
  • Technical. IP address, browser and device information, session data, error and security logs.
  • Product analytics. Usage events, feature adoption, and masked session recordings, all conditional on the data subject accepting analytics.

No special categories. We do not require, request, or knowingly process special categories of personal data under Article 9, nor criminal conviction data under Article 10. You must not submit such data through the Service.

Session recordings. Where analytics consent is given, the Service records masked replays of application sessions. All on-screen text and all typed input are masked in the data subject's browser before transmission, and no analytics recording occurs on authentication, billing, or account-settings pages. Separately, when a software error occurs, our error-monitoring tool may capture a masked replay of the session in which it occurred, on any page; it is triggered by errors only, and text and media are masked before the replay leaves the browser.

5. Processor Obligations

We shall:

  • process Personal Data only on your documented instructions, including your use of the Service, unless required otherwise by law, in which case we will inform you before processing unless the law forbids it;
  • ensure that persons authorised to process Personal Data are bound by confidentiality;
  • implement the technical and organisational measures described in section 7;
  • respect the conditions in section 6 for engaging Subprocessors;
  • taking into account the nature of the processing, assist you by appropriate technical and organisational measures in responding to data subject requests under Chapter III of the GDPR;
  • assist you in complying with Articles 32 to 36, taking into account the nature of processing and the information available to us;
  • at your election, delete or return Personal Data at the end of the provision of services, as described in section 8; and
  • make available to you the information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits as set out in section 10.

Aggregated, de-identified and improvement data. Notwithstanding the first paragraph above, we may (i) create and use aggregated or de-identified information of the kind described in section 5 of the Privacy Policy, which no longer reasonably identifies you or any data subject, to operate, secure and improve the Service, measure trends, and create benchmarks; and (ii) use prompts and scan results, kept separate from your account record and never including names, email addresses, billing details or credentials, to train and improve our own models and to develop benchmarks, as described in section 3 of the Privacy Policy. You may withdraw (ii) at any time in Settings → Account → Data use, which excludes your account from that work with immediate effect. Aggregated or de-identified information under (i) is not Personal Data, and our right to retain and use it survives termination of this DPA.

6. Subprocessors

You grant us general authorisation to engage Subprocessors. The current Subprocessors, with the purpose of each and the categories of data it receives, are listed at helloaisearch.com/subprocessors. That page is the authoritative record and is incorporated into this DPA by reference.

We shall impose data protection obligations on each Subprocessor no less protective than those in this DPA, and remain fully liable to you for each Subprocessor's performance.

Notice of change. We will give at least fourteen (14) days' notice before adding or replacing a Subprocessor, by updating the page above and notifying you by email to your account's registered address, or, where we offer a subscription to change notifications on that page and you have subscribed, by that notification. You may object on reasonable data protection grounds within that period; if the objection cannot be resolved, you may terminate the affected part of the Service without penalty.

Emergency replacement. Where a Subprocessor must be replaced without delay for reasons of security, legal compliance, or continuity of the Service, we may do so immediately and will give notice as above as soon as practicable afterwards. Your right to object runs from the date of that notice.

7. Security

We maintain technical and organisational measures appropriate to the risk, including:

  • encryption of Personal Data in transit;
  • row-level security on the primary datastore, isolating each account's data;
  • role-based access control and least-privilege service credentials;
  • masking of all text and input in session recordings, applied in the browser before transmission; exclusion of authentication and billing pages from analytics recording entirely; and error-triggered replays limited to software failures and masked in the same way;
  • exclusion of authentication credentials and payment data from error monitoring;
  • consent gating for all non-essential analytics;
  • routine dependency and vulnerability management;
  • backup and recovery procedures;
  • documented incident response.

We may update these measures provided the level of protection is not reduced.

8. Retention, Return and Deletion

Retention periods for each category of data are set out in sections 10 and 11 of the Privacy Policy, which are incorporated into this DPA by reference. We may update those periods from time to time, provided that no retention period is lengthened without prior notice to you.

On termination you may export all data through the in-product export, available on every plan in CSV and JSON. Deletion may be requested at any time, self-serve, from account settings, or by writing to privacy@helloaisearch.com if a shorter timeframe than the standard deletion window is required.

9. International Transfers

We are established in the United States and Personal Data is processed there. Where a transfer from the EEA, UK or Switzerland requires a safeguard under Chapter V of the GDPR, the parties rely on the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor), incorporated by reference, with the UK International Data Transfer Addendum where applicable.

Completion of the Standard Contractual Clauses. Clause 7 (docking clause) does not apply. Clause 9 applies with Option 2 (general written authorisation), with the notice period stated in section 6. The optional language in Clause 11 does not apply. For Clause 13, the competent supervisory authority is that of the EEA member state in which you are established, as identified in Annex I.C. For Clause 17, the Clauses are governed by the law of Ireland. For Clause 18, disputes shall be resolved before the courts of Ireland. Annex I (list of parties and description of the transfer) is completed by sections 2, 3 and 4 of this DPA together with the parties' details in your account registration; Annex II (technical and organisational measures) by section 7; and Annex III (list of subprocessors) by the page referenced in section 6.

UK transfers. The UK International Data Transfer Addendum (version B1.0, in force 21 March 2022) applies, with Table 1 completed by the parties' details in your account registration, Table 2 by the Standard Contractual Clauses as completed above, Table 3 by the Annexes as completed above, and Table 4 permitting either party to end the Addendum as set out in section 19 of it.

10. Audit

We shall make available information reasonably necessary to demonstrate compliance with Article 28. We may satisfy an audit request by providing written responses to your reasonable questions and copies of any third-party assessments or reports we hold. Where you can show that such documentation is reasonably insufficient, you may require an inspection, conducted no more than once per year, on thirty (30) days' written notice, during business hours, subject to confidentiality, and at your cost, except where the inspection reveals material non-compliance.

11. Personal Data Breach

We shall notify you without undue delay after becoming aware of a Personal Data Breach affecting your Personal Data, and in any event within seventy-two (72) hours of becoming aware. The notification will include the information reasonably available to us at that time to assist your own notification obligations, and we will provide further information as it becomes available.

12. Liability

Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service.

13. Order of Precedence

In the event of conflict between this DPA and the Terms of Service, this DPA prevails in respect of the processing of Personal Data.

14. Incorporation and Updates

This DPA is incorporated into and forms part of the Terms of Service. By accepting the Terms of Service, you accept this DPA, and no separate signature is required. If you need a countersigned copy for your records, contact privacy@helloaisearch.com.

We may update this DPA in the same manner and with the same notice as changes to the Terms of Service, provided that no update reduces the level of protection afforded to Personal Data.

15. Contact

PulseSpark.ai LLC
Pittsburgh, Pennsylvania, United States
Privacy: privacy@helloaisearch.com
Website: https://helloaisearch.com