Data Processing Addendum (DPA)
Last Updated: March 2026 | Governing Jurisdiction: California, USA
This Data Processing Addendum is entered into between Immerse Inc. ("Immerse" or "Data Processor"), a Delaware corporation with its principal place of business at 2175 Tustin Ave, Costa Mesa, CA 92627, and the Customer identified on the applicable Order Form ("Customer" or "Data Controller").
This DPA is automatically incorporated into and forms part of the Immerse Enterprise Terms of Service upon execution of an Order Form that references the Enterprise Terms of Service. No separate execution of this DPA is required. By executing an Order Form, both parties agree to be bound by this DPA as of the DPA Effective Date. This automatic incorporation satisfies the written contract requirement under GDPR Article 28(3) and equivalent provisions under applicable data protection law.
1. Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person processed by Immerse on behalf of Customer in connection with the Services.
- "Processing"(and its derivatives) means any operation or set of operations performed on Personal Data, whether or not by automated means.
- "Data Controller" means Customer, the entity that determines the purposes and means of Processing Personal Data.
- "Data Processor" means Immerse, which Processes Personal Data on behalf of and under the instructions of the Data Controller.
- "Sub-processor" means any third party engaged by Immerse to Process Personal Data on Customer's behalf in connection with the Services.
- "Data Subject" means the identified or identifiable natural person to whom Personal Data relates.
- "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored, or otherwise processed.
- "Supervisory Authority" means any governmental, regulatory, or supervisory authority responsible for enforcing applicable data protection laws.
- "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses approved by the European Commission for the transfer of Personal Data to third countries.
- "GDPR" means the EU General Data Protection Regulation 2016/679.
- "LGPD" means Brazil's Lei Geral de Proteção de Dados Pessoais (Law No. 13,709/2018).
- "UK GDPR" means the GDPR as retained in UK law by the European Union (Withdrawal) Act 2018.
- "CCPA" means the California Consumer Privacy Act of 2018.
2. Scope and Purpose of Processing
2.1 Categories of Data Subjects
Authorized Users of the Immerse platform, being employees, contractors, or students of Customer who have been granted access to the Services.
2.2 Categories of Personal Data
Immerse may process the following categories of Personal Data on behalf of Customer:
- Identity and contact data: name, email address, job title, department, employee ID.
- Language learning data: proficiency assessments, lesson progress, performance metrics, fluency scores.
- Usage and session data: login timestamps, session duration, features accessed, platform interactions.
- Communication data: chat transcripts, voice recordings made during instructor-led sessions (where recording is enabled).
- Spatial interaction data: where applicable, movement and interaction data within VR environments.
- Neural and biometric data: eye-tracking data, haptic response data, and spatial intent data generated by VR hardware.
2.3 Purposes of Processing
Immerse processes Personal Data solely to:
- Provide the Services described in the applicable Order Form, including delivering language learning content and facilitating live sessions.
- Generate performance analytics and reporting for Customer's administrative users.
- Maintain platform security, prevent fraud, and ensure platform integrity.
- Fulfill legal obligations applicable to Immerse as a data processor.
2.4 Duration of Processing
Immerse will Process Personal Data for the duration of the applicable Order Form term. Upon termination or expiry of the Order Form, Immerse will Process Personal Data only as necessary to facilitate the data retrieval and deletion obligations.
3. Immerse Obligations as Data Processor
3.1 Documented Instructions
Immerse shall Process Personal Data only on documented instructions from Customer, including as set forth in this DPA.
3.2 Confidentiality of Processing
Immerse shall ensure all personnel authorized to Process Personal Data are subject to appropriate confidentiality obligations.
3.3 Security Measures
Immerse shall implement and maintain appropriate technical and organizational measures to protect Personal Data against unauthorized Processing. Measures include:
- Encryption of Personal Data in transit and at rest.
- Access controls limiting Personal Data access to authorized personnel.
3.4 Sub-processor Management
Customer provides general authorization for Immerse to engage Sub-processors. Immerse shall maintain an up-to-date list of Sub-processors at immerse.com/legal/subprocessors.
4. Customer Obligations as Data Controller
Customer represents and warrants that:
- Customer has the legal authority and all necessary consents to provide Personal Data to Immerse.
- Customer will ensure that Authorized Users are informed of the Processing of their Personal Data.
5. Sub-Processors
5.1 Current Sub-processors
As of the date of this DPA, Immerse engages the following:
- OpenAI, L.L.C.— Provides AI language model processing.
- Amazon Web Services, Inc. (AWS)— Provides cloud infrastructure and data storage.
6. International Data Transfers
Where Personal Data is transferred from the EEA, UK, or Switzerland, Immerse shall ensure that such transfers are subject to appropriate safeguards.
10. Term and Termination
This DPA shall remain in effect for as long as Immerse processes Personal Data on behalf of Customer.