Data Processing Addendum | Elicit Help Center
Data Processing Addendum
Last updated: April 1, 2025
This Data Processing Addendum, including its Annexes and the Standard Contractual Clauses (" DPA "), forms an integral part of the Elicit Master Services Agreement (" MSA "), or any other written agreement that governs Customer's use of the Elicit Services, entered into between the entity identified as the "Customer" in such Agreement (" Customer ") and Elicit Research, PBC (" Elicit "). This DPA applies solely to the extent that Elicit processes any Customer Personal Data in connection with the Elicit Services.
1. DEFINITIONS
1.1. "Applicable Data Protection Laws" means all data protection and privacy laws and regulations applicable to the respective party in its role in the processing of Customer Personal Data under the Agreement.
1.2. "Authorized Affiliate" means a Customer Affiliate who is authorized to use the Elicit Services under the Agreement and who has not signed their own separate "Agreement" with Elicit.
1.3. "CCPA" means the California Consumer Privacy Act of 2018, as may be amended, superseded or replaced from time to time.
1.4. "Customer Content" means, if not defined within the Agreement, all data processed by Elicit on your behalf in the course of providing the Elicit Services.
1.5. "Customer Personal Data" means any 'personal data' or 'personal information' contained within Customer Content.
1.6. "Elicit Services" means the Platform Services and/or any other services provided directly by Elicit to the Customer under the Agreement.
1.7. "European Data Protection Laws" means Regulation 2016/679 (General Data Protection Regulation), the UK GDPR, and the Swiss Federal Data Protection Act.
1.8. "Restricted Transfer" means a transfer of personal data that is subject to European Data Protection Laws to a third country outside the European Economic Area without an adequacy determination.
1.9. "Security Addendum" means all additional controls and documents that support the protection of data.
1.10. "Security Breach" means a breach of security leading to an accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
1.11. "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses annexed to the European Commission's Implementing Decision 2021/914.
1.12. "Subprocessor" means any other processor engaged by Elicit to process Customer Personal Data.
1.13. "UK Addendum" means the International Data Transfer Addendum issued by the Information Commissioners Office under applicable UK Data Protection laws.
1.14. The terms "controller", "data subject", "supervisory authority", "processor", "process", "processing", "personal data", and "personal information" shall have the meanings given to them in Applicable Data Protection Laws.
2. PROCESSING OF PERSONAL DATA
2.1. Scope and Roles of the Parties. This DPA applies when Customer Personal Data is processed by Elicit as a processor in its provision of the Elicit Services.
2.2. Customer Processing. Customer agrees to comply with its obligations under Applicable Data Protection Laws in its processing of Customer Personal Data and any processing instructions it issues to Elicit.
2.3. Elicit Processing. Elicit agrees to comply with Applicable Data Protection Laws when processing Customer Personal Data.
2.4. Details of Processing. The details of the processing of Customer Personal Data by Elicit are set out in Annex A to the DPA.
3. CONFIDENTIALITY
3.1. Personnel. Elicit shall ensure that any employees or personnel it authorizes to process Customer Personal Data is subject to an appropriate duty of confidentiality.
4. SUBPROCESSING
4.1. Authorization. Customer provides a general authorization to Elicit use of Subprocessors to process Customer Personal Data.
4.2. Subprocessor Obligations. Elicit shall enter into a written agreement with its Subprocessors.
4.3. Subprocessor Changes. Elicit will notify you of subprocessor changes via updates to the Subprocessor List.
5. ASSISTANCE
5.1. Data Subject Requests. Customer is responsible for responding to and complying with data subject requests.
5.2. Data Protection Impact Assessments. Elicit will provide information regarding the Elicit Services to Customer for data protection impact assessments.
5.3. Legal Requests. If Elicit receives a legal demand for Customer Personal Data, Elicit will redirect the request to Customer.
6. SECURITY
6.1. Security Measures. Elicit has implemented and will maintain appropriate technical and organizational security measures.
6.2. Security Breach Notification. Elicit will notify Customer in writing without undue delay in the event of a Security Breach.
7. AUDITS AND RECORDS
7.1. Audit Program. Upon written request, Elicit shall provide Customer access to documentation evidencing Elicit's compliance with its obligations under this DPA.
7.2. Audit. Customer may send a written request to conduct an audit of Elicit's applicable controls on an annual basis.
8. TRANSFER OF PERSONAL DATA
8.1. Restricted Transfers. Transfers of Customer Personal Data that are Restricted Transfers will be governed by the Standard Contractual Clauses.
8.2. Alternative Transfer Mechanisms. The parties shall cooperate to agree and implement any additional measures or alternative transfer mechanisms if required by a supervisory authority.
9. DATA TERMINATION
9.1. No Backups. The Elicit Services do not include backup services for Customer Personal Data.
9.2. Termination. Upon termination of the Agreement, Elicit will assist Customer in deleting any Customer Personal Data within its possession or control.
10. CCPA COMPLIANCE
10.1. Elicit shall not process, retain, use, or disclose Customer Personal Data for any purpose other than as set out in the Agreement and DPA.
11. GENERAL
11.1. The parties agree that this DPA shall replace existing data processing agreements. Elicit may update this DPA periodically.
11.2. If any part of this DPA is held unenforceable, the validity of all remaining parts will not be affected.
11.3. Elicit's obligations extend to Authorized Affiliates, subject to conditions.
11.4. In the event of any conflict between this DPA and any data privacy provisions in agreements between the parties, the terms of this DPA shall prevail.
11.5. Each party's liability arising out of or related to this DPA shall remain subject to the limitation of liability of the Agreement.
11.6. This DPA will be governed by the governing law provisions in the Agreement.
11.7. The obligations under this DPA and the Standard Contractual Clauses shall survive as long as Elicit processes Customer Personal Data on behalf of Customer.
ANNEX A — DESCRIPTION OF THE PROCESSING / TRANSFER
Data exporter: The entity identified as the "Customer" in the Agreement.
Data importer: Elicit Research, PBC, 1904 Franklin St, Oakland, California, 94612, USA.
Categories of data subjects: Individuals about whom data is provided to Elicit via the Elicit Services.
Categories of personal data transferred: The types of Customer Personal Data may include name, address, title, contact details, and any other personal data processed in the course of the Services.
Frequency of the Transfer: Continuous or one-off depending on the services provided by Elicit.
Nature and subject matter of processing: Customer Personal Data is processed for the term of the Agreement and any period after termination during which Elicit processes Customer Personal Data.
Competent supervisory authority: The data exporter's competent supervisory authority will be determined in accordance with the EU GDPR.
ANNEX B — STANDARD CONTRACTUAL CLAUSES
Where the transfer of Customer Personal Data to Elicit is a Restricted Transfer, such transfer shall be governed by the Standard Contractual Clauses (EU Commission Implementing Decision 2021/914).
- Module Two terms apply where Customer is the controller.
- In Clause 9, general authorization (option 2) is selected.
- In Clause 17, option 1 applies and the SCCs shall be governed by Irish law.