Data Processing Agreement - Talkpal
Talkpal logo

Learn languages faster with AI

Talkpal turns AI into your personal language coach

Learn Languages faster with AI
Flag of England Flag of Spain Flag of France Flag of Germany Flag of Italy
130+ languages

Data Processing Agreement

Last updated August 3, 2026

This Data Processing Agreement (“DPA”) forms part of the agreement between the organization subscribing to the Services (“Customer,” “Controller”) and Talkpal, Inc., 2810 N Church St, PMB 54222, Wilmington, DE 19802-4447, United States (“Talkpal,” “Processor”) for the provision of the Services as described in the Terms and Conditions available at https://talkpal.ai/terms-and-conditions (the “Agreement”).

By accepting the Terms and Conditions of the B2B Platform at https://business.talkpal.ai, the Customer enters into this DPA on behalf of itself and, to the extent required under applicable Data Protection Laws, on behalf of its Authorized Users.

This DPA applies where and only to the extent that Talkpal processes Personal Data on behalf of the Customer in the course of providing the Services under the Agreement. This DPA does not apply to Personal Data for which Talkpal is a controller in its own right (such as Account-Level Information and billing data).

1. Definitions

“Authorized User” means any individual granted access to the Services through the Customer’s organizational account, as defined in the Agreement.

“Data Protection Laws” means all applicable laws and regulations relating to the processing of Personal Data, including (where applicable) the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK Data Protection Act 2018 and UK GDPR, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended by the CPRA, and any other applicable data protection or privacy legislation.

“Personal Data” means any information relating to an identified or identifiable natural person that is processed by Talkpal on behalf of the Customer in connection with the Services. The terms “Personal Data” (as used in this DPA), “personal data” (as used in the Terms and Conditions), and “personal information” (as used in the Privacy Policy) refer to the same categories of information; the variation reflects the terminology used by the applicable Data Protection Laws referenced in each document.

“Processing” means any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, or destruction.

“Security Incident” means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data processed by Talkpal on behalf of the Customer. A Security Incident does not include unsuccessful attempts or activities that do not compromise the security of Personal Data, such as unsuccessful login attempts, pings, port scans, or denial-of-service attacks that do not result in access to Personal Data.

“Sub-processor” means any third party engaged by Talkpal to process Personal Data on behalf of the Customer.

“Standard Contractual Clauses” or “SCCs” means the standard contractual clauses approved by the European Commission for the transfer of personal data to third countries (Commission Implementing Decision (EU) 2021/914), as may be amended or replaced from time to time.

Other capitalized terms not defined in this DPA have the meanings given to them in the Agreement.

2. Scope and Roles

2.1 Roles. With respect to the processing of Personal Data of Authorized Users within Organizational Sub-Accounts, the Customer is the Controller and Talkpal is the Processor. The Customer determines the purposes and means of processing; Talkpal processes Personal Data only on behalf of and in accordance with the Customer’s documented instructions.

2.2 Customer as Controller. The Customer is responsible for ensuring that it has a lawful basis under applicable Data Protection Laws for the processing of Personal Data, including obtaining any necessary consents from Authorized Users where required. The Customer warrants that all Authorized Users are at least 18 years old, and acknowledges that the Services are not designed or intended for the processing of children’s personal data.

2.3 Data for which Talkpal is an independent Controller. Notwithstanding the controller-to-processor relationship described in Section 2.1, certain categories of Personal Data are processed by Talkpal as an independent controller and fall outside the scope of this DPA. These include (a) Account-Level Information (such as the Authorized User’s email address, password, display name, and general account preferences, as defined in Section 4A of the Terms and Conditions), which is shared across the Authorized User’s Account and persists with the Authorized User after their Organizational Sub-Account is deactivated; (b) the Authorized User’s Personal Sub-Account and any associated Sub-Account Data; and (c) billing and payment data processed in connection with the Customer’s subscription. Talkpal’s processing of this data is governed by the Privacy Policy at https://talkpal.ai/privacy-policy and not by this DPA. For the avoidance of doubt, the Customer and Talkpal are independent controllers, and not joint controllers within the meaning of Article 26 GDPR, with respect to the Personal Data described in this Section 2.3. Each party independently determines the purposes and means of its own processing of such Personal Data and is separately responsible for complying with its obligations under applicable Data Protection Laws, including its transparency obligations toward data subjects. If and to the extent the parties are nevertheless deemed joint controllers with respect to any specific processing operation, the parties shall, upon either party’s request, enter into an arrangement pursuant to Article 26 GDPR that transparently allocates their respective responsibilities for compliance with applicable Data Protection Laws, and this DPA shall be deemed to reflect the essence of that arrangement in the interim.

3. Details of Processing

3.1 Subject matter and duration. Talkpal processes Personal Data for the purpose of providing the language learning Services to the Customer’s Authorized Users. Processing continues for the duration of the Agreement plus the post-termination deletion periods described in Section 9 of this DPA.

3.2 Nature and purpose of processing. The provision of AI-powered language learning services, including user account management, lesson delivery, speech recognition and language assessment, learning progress tracking, and usage analytics as described in the Agreement and Privacy Policy.

3.3 Categories of data subjects. Authorized Users invited by the Customer to use the Services through an Organizational Sub-Account.

3.4 Types of Personal Data processed. The Personal Data processed includes:

3.5 Special categories of data. Talkpal does not intentionally process special categories of Personal Data (as defined under Article 9 GDPR) on behalf of the Customer. The Customer shall instruct its Authorized Users not to submit special category data through the Services.

3.6 No model training on Organizational Sub-Account data. Talkpal does not use Personal Data processed on behalf of the Customer within an Organizational Sub-Account to train, fine-tune, or otherwise develop or improve any machine-learning model. This includes conversation content, learning interactions, and audio submitted by Authorized Users within an Organizational Sub-Account. For the purposes of Section 3.2 and Schedule 1, “service improvement” means the operation, maintenance, security, monitoring, and defect correction of the Services, and does not include model training or fine-tuning. Section 2.3 identifies data processed by Talkpal as an independent controller, which falls outside the scope of this DPA and of this Section.

4. Customer Instructions

4.1 Talkpal shall process Personal Data only on the Customer’s documented instructions, unless required to do so by applicable law, in which case Talkpal shall (to the extent permitted by law) inform the Customer of that legal requirement before processing.

4.2 The Customer’s instructions for processing are set out in this DPA, the Agreement, and any applicable Order Form. The Customer may issue additional reasonable written instructions consistent with the Agreement, provided that if such instructions fall outside the scope of the Services or require changes to the Services, the parties shall negotiate in good faith any additional fees or terms.

4.3 Talkpal shall promptly inform the Customer if, in Talkpal’s opinion, an instruction infringes applicable Data Protection Laws.

5. Confidentiality

5.1 Talkpal shall ensure that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

5.2 Talkpal shall not disclose Personal Data to any third party except as permitted by this DPA, the Agreement, or as required by applicable law.

6. Security

6.1 Talkpal shall implement and maintain appropriate technical and organizational measures to protect Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, damage, theft, or disclosure. These measures shall include, as appropriate:

6.2 Talkpal shall take reasonable steps to ensure that security measures are appropriate to the risks presented by the processing, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing.

7. Sub-processors

7.1 The Customer provides general authorization for Talkpal to engage Sub-processors to assist in providing the Services. Sub-processors may include cloud infrastructure providers, AI processing vendors, speech recognition services, analytics providers, payment processors, and other service providers necessary for the delivery, maintenance, and improvement of the Services. The Sub-processors currently engaged by Talkpal and authorized by the Customer are listed in Schedule 3 (Approved Sub-processors) to this DPA, which forms Annex III to the Standard Contractual Clauses. Schedule 3 identifies each Sub-processor’s entity name and address, the processing it performs, the categories of Personal Data it processes, the location of processing, and the applicable transfer mechanism. The current version of this DPA, including Schedule 3, is published at https://talkpal.ai/data-processing-agreement (the “DPA Page”). An up-to-date copy of Schedule 3 is also available to the Customer at any time upon request to privacy@talkpal.ai.

7.2 Talkpal shall enter into a written agreement with each Sub-processor imposing data protection obligations no less protective than those set out in this DPA. Talkpal remains liable to the Customer for the acts and omissions of its Sub-processors.

7.3 Notice of changes. Talkpal maintains an up-to-date list of Sub-processors (Schedule 3). Talkpal shall provide notice of any intended addition or replacement of a Sub-processor by updating Schedule 3 on the DPA Page at least thirty (30) days before the new Sub-processor processes any Personal Data. Talkpal offers a mechanism by which the Customer may subscribe to receive notification of changes to the Sub-processor list; the Customer is responsible for subscribing in order to receive such notifications. Posting the updated Schedule 3 to the DPA Page constitutes notice for the purposes of this DPA and the Standard Contractual Clauses. The updated Schedule 3 shall take effect upon expiry of the notice period and shall thereupon replace the prior version without further formality, subject to Section 7.4.

7.4 Right to object. The Customer may object to an intended change on reasonable, documented data-protection grounds by written notice to privacy@talkpal.ai within thirty (30) days of the date the updated Schedule 3 is posted to the DPA Page. The parties shall cooperate in good faith to resolve the objection, including, where commercially reasonable, offering an alternative configuration of the Services that avoids the new Sub-processor. If no resolution is reached within thirty (30) days of the objection, the Customer may terminate the affected Services upon written notice, and Talkpal shall refund any prepaid fees covering the remainder of the subscription term for the affected Services. If the Customer does not object within the notice period, the change is deemed authorized.

7.5 Emergency replacements. Where a Sub-processor must be replaced urgently to address a security incident or to maintain continuity of the Services, Talkpal may engage the replacement before the notice period expires, provided it notifies the Customer without undue delay and the objection right in Section 7.4 applies from the date of that notice.

8. Data Subject Rights

8.1 Taking into account the nature of the processing, Talkpal shall assist the Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling the Customer’s obligations to respond to requests from data subjects to exercise their rights under applicable Data Protection Laws (“Data Subject Requests”).

8.2 If Talkpal receives a Data Subject Request directly from an Authorized User relating to the Customer’s Organizational Sub-Account, Talkpal shall promptly notify the Customer and shall not respond to the request without the Customer’s prior instructions, unless required by applicable law. This Section 8.2 does not apply where the request relates to Personal Data for which Talkpal acts as an independent controller under Section 2.3. Talkpal will handle such requests directly, in accordance with the Privacy Policy and applicable Data Protection Laws, and will notify the Customer where a request also concerns Personal Data within an Organizational Sub-Account.

8.3 The Customer may use the administrative tools provided through the B2B Platform to access, export, or delete Authorized User data within its Organizational Sub-Account(s) as needed to respond to Data Subject Requests.

9. Data Retention and Deletion

9.1 Upon termination or expiration of the Agreement, or upon deactivation of an Organizational Sub-Account (for any reason), Talkpal shall delete the Personal Data associated with the relevant Organizational Sub-Account(s) from its active systems within thirty (30) days, unless retention is required by applicable law.

9.2 Data contained in automated backups may persist for up to ninety (90) days before being overwritten in the normal course of Talkpal’s backup rotation.

9.3 Upon the Customer’s written request prior to deletion, Talkpal shall make available to the Customer a copy of the Personal Data in a commonly used, machine-readable format, to the extent technically feasible.

9.4 Talkpal shall certify the deletion of Personal Data in writing upon the Customer’s request.

10. Security Incident Notification

10.1 Talkpal shall notify the Customer of a Security Incident without undue delay and in any event within forty-eight (48) hours after becoming aware that a Security Incident affecting Personal Data processed on behalf of the Customer has occurred, to enable the Customer to meet its own notification obligations under applicable Data Protection Laws. Talkpal shall investigate suspected incidents promptly upon detection. Talkpal’s notification is not an acknowledgement of fault or liability.

10.2 The notification shall include, to the extent available:

10.3 Where it is not possible to provide all information at the same time, the information may be provided in phases without undue further delay.

10.4 Talkpal shall take reasonable steps to contain, investigate, and mitigate the Security Incident and shall cooperate with the Customer in the Customer’s compliance with its own notification obligations under applicable Data Protection Laws.

11. Data Protection Impact Assessments

Where required under applicable Data Protection Laws, Talkpal shall provide the Customer with reasonable assistance in conducting data protection impact assessments and, where necessary, prior consultations with supervisory authorities, taking into account the nature of the processing and the information available to Talkpal.

12. Audits

12.1 Talkpal shall make available to the Customer all information reasonably necessary to demonstrate compliance with this DPA.

12.2 The Customer (or its appointed independent third-party auditor, subject to reasonable confidentiality obligations) may conduct an audit of Talkpal’s processing activities relevant to this DPA, subject to the following conditions:

12.3 Where Talkpal holds a current SOC 2 Type II report, ISO 27001 certification, or equivalent third-party audit report, Talkpal may satisfy an audit request by providing the Customer with a copy of such report (subject to confidentiality obligations), unless the Customer can demonstrate that such report is insufficient to address a specific and documented concern.

12.4 Nothing in this Section 12 limits the Customer’s rights under Clause 8.9 of the Standard Contractual Clauses. To the extent permitted, the parties agree that audits and inspections under Clause 8.9 shall be conducted in accordance with the conditions set out in this Section 12.

13. International Data Transfers

13.1 The Customer acknowledges that Talkpal may transfer Personal Data to countries outside the European Economic Area (“EEA”), the United Kingdom, or Switzerland in order to provide the Services. The countries in which Personal Data is processed are identified in Schedule 3 (Approved Sub-processors), which specifies the location of processing and the applicable transfer mechanism for each Sub-processor.

13.2 Where Personal Data originating from the EEA, UK, or Switzerland is transferred to a country that has not received an adequacy decision, Talkpal shall ensure that appropriate safeguards are in place, including:

13.3 Where required under applicable Data Protection Laws, Talkpal will carry out and maintain transfer impact assessments for transfers to countries that have not received an adequacy decision, and will implement supplementary measures where necessary to address identified risks.

13.4 The Standard Contractual Clauses are incorporated into this DPA by reference. Where the SCCs apply:

13A. US State Privacy Laws

To the extent the California Consumer Privacy Act, as amended (“CCPA”), or any similar US state privacy law applies to Personal Data processed under this DPA, Talkpal acts as a “service provider” (or equivalent term) and the Customer acts as the “business” (or equivalent term). Talkpal shall not: (a) sell or share the Personal Data (as those terms are defined in the CCPA); (b) retain, use, or disclose the Personal Data for any purpose other than for the business purposes specified in this DPA and the Agreement, or as otherwise permitted by the CCPA; (c) retain, use, or disclose the Personal Data outside of the direct business relationship between the parties; or (d) combine the Personal Data with personal information that Talkpal receives from or on behalf of another person, or collects from its own interactions with consumers, except as expressly permitted by the CCPA. Talkpal certifies that it understands and will comply with the restrictions in this Section. Talkpal shall notify the Customer without undue delay if it determines that it can no longer meet its obligations under applicable US state privacy laws, in which case the Customer may take reasonable and appropriate steps to stop and remediate any unauthorized use of Personal Data.

14. Liability

The liability of each party under this DPA is subject to the limitations and exclusions of liability set out in the Agreement, except that nothing in the Agreement or this DPA limits or excludes liability to the extent that such limitation or exclusion is not permitted under applicable Data Protection Laws.

Notwithstanding the foregoing, each party’s aggregate liability arising out of or in connection with this DPA and the Standard Contractual Clauses shall not exceed the greater of (a) the total fees paid or payable by the Customer under the Agreement in the twelve (12) months preceding the event giving rise to the claim, and (b) USD 50,000. Nothing in the Agreement or this DPA limits or excludes (i) either party’s liability under Clause 12 of the Standard Contractual Clauses to data subjects, (ii) liability for a party’s wilful misconduct or fraud, or (iii) any liability that cannot be limited or excluded under applicable Data Protection Laws.

15. General Provisions

15.1 Conflict. In the event of a conflict between this DPA and the Agreement with respect to data protection obligations, this DPA shall prevail.

15.2 Amendments. Talkpal may update this DPA to reflect changes in Data Protection Laws, regulatory guidance, or Talkpal’s processing practices. Talkpal shall notify the Customer of any material change at least thirty (30) days before its effective date, together with a summary of the change, by email to the Customer’s designated Administrator and by posting the updated DPA. If the Customer does not agree to a material change, the Customer may terminate the affected Services by written notice given before the effective date, and Talkpal shall refund any prepaid fees covering the remainder of the subscription term. If the Customer does not terminate before the effective date, the change takes effect. Non-material changes (such as corrections of typographical errors or updates to contact information) take effect upon notice. For the avoidance of doubt, updates to Schedule 3 (Approved Sub-processors) are governed exclusively by Sections 7.3 to 7.5 and do not constitute amendments under this Section 15.2. Talkpal shall not make any change that reduces the level of protection afforded to Personal Data below that required by applicable Data Protection Laws or the Standard Contractual Clauses.

15.3 Severability. If any provision of this DPA is found to be invalid or unenforceable, the remaining provisions shall continue in full force and effect.

15.4 Governing law. Where the Customer is established in the European Economic Area, this DPA is governed by the laws of Ireland. Where the Customer is established in the United Kingdom, this DPA is governed by the laws of England and Wales. In all other cases, this DPA is governed by the laws of the State of Delaware. The Standard Contractual Clauses shall be governed as specified therein. Nothing in this DPA limits any mandatory statutory rights the Customer may have under the Data Protection Laws of its country of establishment.

15.5 Contact. For questions about this DPA, contact Talkpal at privacy@talkpal.ai. You may also contact Talkpal’s Data Protection Officer: Dr. Kilian Schmidt, Kertos GmbH, Brienner Str. 41, 80333 Munich, Germany, dataprivacy@kertos.io.

Schedule 1 — Details of Processing (Annex I to the SCCs)

A. List of Parties

Data Exporter (Controller): The Customer, as identified in the Agreement. Contact: the Customer’s designated Administrator.

Data Importer (Processor): Talkpal, Inc., 2810 N Church St, PMB 54222, Wilmington, DE 19802-4447, United States. Contact: privacy@talkpal.ai. Data Protection Officer: Dr. Kilian Schmidt, Kertos GmbH, Brienner Str. 41, 80333 Munich, Germany, dataprivacy@kertos.io. EU/UK Privacy Representative: Prighter Group – https://app.prighter.com/portal/talkpal

B. Description of the Transfer

Categories of data subjects: Authorized Users of the Customer who access the Services through an Organizational Sub-Account.

Categories of Personal Data transferred: Name, email address, language selections, learning preferences, learning progress, lesson completion records, proficiency assessments, conversation history (text; audio is processed transiently and is not retained by Talkpal), usage statistics, device and browser information, IP address, and approximate location.

Sensitive data transferred: None intended. The Services involve free-form user content; any special-category data incidentally contained in conversation content is processed only as part of that content, is protected by the measures in Annex II, and is not used to derive special-category insights. The Customer shall instruct Authorized Users not to submit sensitive or special category data.

Frequency of the transfer: Continuous, for the duration of the Agreement.

Nature and purpose of the processing: Provision of AI-powered language learning services, including user account management, lesson delivery, speech recognition and language assessment, learning progress tracking, usage analytics, and service improvement.

Retention period: For the duration of the Agreement, plus 30 days after termination or deactivation for deletion from active systems (up to 90 days in automated backups).

C. Competent Supervisory Authority

The competent supervisory authority shall be determined in accordance with Clause 13 of the SCCs. Where the data exporter is established in the EEA, the supervisory authority of the EEA Member State in which the data exporter is established. Where the data exporter is not established in the EEA but falls within the territorial scope of the GDPR, the supervisory authority of the EEA Member State designated by the data exporter under Article 27(4) GDPR. For transfers of Personal Data subject to the Swiss FADP, the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner (FDPIC). For transfers subject to the UK GDPR, the competent authority is the Information Commissioner’s Office, as provided in the UK Addendum (Schedule 4).

Schedule 2 — Technical and Organizational Measures (Annex II to the SCCs)

Talkpal implements and maintains the following categories of technical and organizational security measures:

Access Control

Network Security

Data Storage and Backup

Incident Management

Business Continuity

Physical Security

Data Minimization and Retention

Schedule 3 — Approved Sub-processors (Annex III to the SCCs)

The Customer provides general written authorization for the engagement of the Sub-processors listed below in connection with the provision of the Services. This Schedule constitutes Annex III to the Standard Contractual Clauses incorporated under Section 13. Changes to this Schedule are made in accordance with Sections 7.3 to 7.5 of this DPA.

Version 2.9

Sub-processorEntity & addressProcessing purposePersonal data categoriesLocationTransfer mechanismEffective date
Amazon Web Services, Inc.410 Terry Ave N, Seattle, WA, USACloud infrastructure, hosting, storage, backupsAll categories in Annex I.BEU (Germany, Sweden, Ireland); USAEU-U.S. DPFIn effect
MongoDB, Inc. (Atlas)1633 Broadway, New York, NY, USAManaged database servicesAccount data, learning progress, conversation historyEU region clusters; US support accessEU-U.S. DPFIn effect
Cloudflare, Inc.101 Townsend St, San Francisco, CA, USACDN, DDoS protection, bot managementIP address, technical/connection dataGlobal edge network; USAEU-U.S. DPFIn effect
Microsoft Corporation (Azure AI)One Microsoft Way, Redmond, WA, USASpeech recognition, text-to-speech, AI processingConversation text and audio (transient); language assessmentsEU regions; USAEU-U.S. DPFIn effect
OpenAI, L.L.C.1455 3rd St, San Francisco, CA, USALLM conversation generation and language feedbackConversation text (transient; limited abuse-monitoring retention per DPA)USASCCsIn effect
Google LLC1600 Amphitheatre Parkway, Mountain View, CA 94043, USA(a) Cloud infrastructure, hosting and storage; (b) Authorized User authentication and identity management (Cloud Identity Platform / Firebase Authentication); (c) push notification delivery (Firebase Cloud Messaging); (d) AI processing (Gemini) for conversation generation and language feedback; (e) analytics data warehousing and reporting (BigQuery, Looker); (f) business productivity and collaboration services (Google Workspace) used for customer correspondence, data exports provided under Section 9.3, and internal handling of support and account recordsAccount identifiers and authentication data; device and push tokens; conversation text (transient, for AI processing under (d)); learning progress, lesson records and usage/event data (stored under (e)); support communications and any Personal Data contained in exported records (under (f)); technical and connection dataEU regions; USAEU-U.S. DPFAugust 29, 2026
Google Ireland LimitedGordon House, Barrow Street, Dublin 4, IrelandAndroid app distribution and delivery, and app integrity / anti-abuse (Google Play), for EEA usersDevice and technical identifiers (no conversation content)Ireland (EEA)None required (EEA processing)In effect
Inworld AI, Inc.1975 W El Camino Real, Mountain View, CA, USAAI character conversation engineConversation text (transient)USASCCsIn effect
Anthropic, PBC548 Market Street, PMB 90375, San Francisco, CA 94104, USAAI processing — large language model (Claude) analysis, generation, and language feedback on user-submitted content and learning interactionsConversation text and user-submitted content (transient); learning assessmentsUSASCCsIn effect
Twilio Inc. (SendGrid)101 Spear St, San Francisco, CA, USATransactional email deliveryName, email addressEU; USAEU-U.S. DPFIn effect
RevenueCat, Inc.633 Taraval Street #1021, San Francisco, CA 94116, USASubscription management and in-app purchase entitlement processing (receipt validation, managing subscription status across app stores)App user ID, subscription status, device identifiersUSASCCsIn effect
Zendesk, Inc.989 Market St, San Francisco, CA, USACustomer support ticketingContact data, support communicationsEEA (EU data locality deployment); limited US support accessEEA; EU-U.S. DPFIn effect
Atlassian, Inc. (Atlassian Pty Ltd as affiliate/co-party)350 Bush Street, Level 13, San Francisco, CA 94104, USA (Atlassian Pty Ltd, 341 George Street, Sydney NSW 2000, Australia)Issue tracking, project management, and internal documentation (e.g., support/bug tickets and engineering records logged in Jira/Confluence)Contact data, support communications, and any Personal Data contained in submitted ticketsUSA; Australia; EUEU-U.S. DPF (transfers to Atlassian, Inc., USA)In effect
Datadog, Inc.620 8th Ave, New York, NY, USAPerformance and availability monitoringTechnical metadata, timestamps, error codes (no conversation content)EEA (Datadog EU site); limited US support accessEEA; EU-U.S. DPFIn effect
MaxMind, Inc.51 Pleasant Street #1020, Malden, MA 02148, USAIP-based geolocation lookup to determine approximate user location (country and region) for content localization, pricing, and compliance purposesIP address only (transmitted for real-time lookup; no other Personal Data is shared)USAEU-U.S. DPFIn effect
Usercentrics A/S (Cookiebot)Havnegade 39, 1058 Copenhagen, DenmarkCookie consent management and consent record-keeping across talkpal.ai, app.talkpal.ai and business.talkpal.aiTruncated IP address, consent ID, consent state and timestamp, user agentDenmark (EEA)None required (EEA processing)In effect
AppsFlyer Inc.100 1st Street, 25th Floor, San Francisco, CA 94105, USAApp install and in-app event measurement supporting the usage analytics described in Section 3.2 (no advertising targeting of Authorized Users within Organizational Sub-Accounts)Device identifiers, IP address, technical and usage/event data (no conversation content)USAEU-U.S. DPFIn effect
Contracted individual service providersEngaged by Talkpal, Inc.; located in GeorgiaCustomer support, content and language review, quality assurance, and operational/engineering support, under Talkpal’s instructions and written confidentiality obligations(i) Account data: name, email address, country, language preference, account identifiers, authentication metadata; (ii) Usage and product data: in-app interactions, learning progress, session metadata, device/app identifiers, IP address and approximate location; (iii) User-generated content: text messages, written exercise content, and conversation history (text only; contractors do not have access to voice or audio content); (iv) Billing metadata: subscription status, plan, transaction identifiers (no payment-card data); (v) Support correspondence.GeorgiaSCCs + TIAIn effect
Salesforce, Inc. (Slack) — Slack Technologies Limited as EEA co-party415 Mission Street, 3rd Floor, San Francisco, CA 94105, USA (Slack Technologies Ltd., One Park Place, Hatch Street Upper, Dublin 2, Ireland)Internal communications and support/engineering escalation channels in which support tickets and bug reports containing Personal Data are discussedContact data, support communications, and any Personal Data contained in escalated ticketsEU; USAEU-U.S. DPFAugust 29, 2026
HubSpot, Inc. (HubSpot Ireland Limited as EEA co-party)2 Canal Park, Cambridge, MA 02141, USA (Ground Floor, One Dockland Central, Guild Street, Dublin 1, Ireland)B2B customer relationship management, onboarding and lifecycle communications with Customer administrators and Authorized UsersName, email address, job role, communication history, subscription/account statusEU; USAEU-U.S. DPFAugust 29, 2026
Apple Inc. (Apple Distribution International Ltd. as EEA co-party)One Apple Park Way, Cupertino, CA 95014, USA (Hollyhill Industrial Estate, Hollyhill, Cork, Ireland)iOS app distribution and delivery, and app integrity / anti-abuse (App Store), for EEA usersDevice and technical identifiers (no conversation content)Ireland (EEA); USANone required for EEA processing; EU-U.S. DPF for residual US accessAugust 29, 2026

Entries marked “In effect” are currently authorized. Entries marked with a future effective date take effect on that date, upon expiry of the notice period under Section 7.3. Where a dated entry updates the listing of a Sub-processor already included in the prior version of this Schedule (for example, to reflect an expanded or clarified processing purpose), the engagement of that Sub-processor remains authorized and its prior entry continues to apply until the new entry takes effect. Where a dated entry adds a new Sub-processor, that Sub-processor will not process Personal Data on behalf of the Customer before its effective date.

Payment processing (Stripe, Apple, Google, PayPal) is excluded from this Schedule because Talkpal processes billing and payment data as an independent controller pursuant to Section 2.3(c). For clarity, RevenueCat is listed above as a Sub-processor solely to the extent it processes subscription entitlement status required to provision and maintain Authorized Users’ access to the Services; billing and payment data remains subject to Section 2.3(c) and the Privacy Policy. Advertising and measurement partners that act as independent or joint controllers — including Google, Meta, Microsoft Advertising, TikTok, OpenAI Ads, Taboola, Reddit and Spotify — are likewise not Sub-processors under this DPA. AppsFlyer is listed above as a Sub-processor solely to the extent it processes app install and in-app event data of Authorized Users as part of the usage analytics described in Section 3.2; where AppsFlyer processes data for Talkpal’s own advertising attribution and campaign measurement, Talkpal acts as an independent controller and such processing is described in the Privacy Policy. Any processing by such partners on Talkpal’s websites is carried out on the basis of consent collected through Talkpal’s cookie consent tool, or another lawful basis where applicable, and is described in the Privacy Policy and Cookie Policy.

Where the transfer mechanism for a Sub-processor is stated as “EU-U.S. DPF,” that Sub-processor holds a current certification under the EU-U.S. Data Privacy Framework and, where indicated on the official Data Privacy Framework list at https://www.dataprivacyframework.gov, the UK Extension to the EU-U.S. DPF and the Swiss-U.S. Data Privacy Framework. For Personal Data originating from the United Kingdom or Switzerland transferred to a Sub-processor whose certification does not extend to the UK Extension or the Swiss-U.S. DPF respectively, the transfer mechanism is instead the SCCs, as supplemented by Schedule 4 (for UK-origin data) and the Swiss adaptations in Section 13.4 (for Swiss-origin data).

Schedule 4 — UK International Data Transfer Addendum

Where Personal Data originating from the United Kingdom is transferred under this DPA, the parties enter into the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the Information Commissioner under s.119A(1) of the Data Protection Act 2018 (version B1.0, in force 21 March 2022) (the “UK Addendum”), incorporated by reference and completed as follows:

Download talkpal app

Learn anywhere anytime

Talkpal is an AI-powered language tutor available on web and mobile platforms. Accelerate your language fluency, chat about interesting topics by writing or speaking, and receive realistic voice messages wherever and whenever you want.

Learning section image (en)

Scan with your device to download on iOS or Android

Learning section image (en)

Get in touch with us

We are always here if you have any questions or require assistance. Contact our customer support anytime at support@talkpal.ai

Languages

Learning

Partnerships

Company


Talkpal, Inc., 2810 N Church St, Wilmington, Delaware 19802, US

© 2026 All Rights Reserved.


Trustpilot