Last Updated: August 10, 2026 | Effective Date: August 10, 2026
Supersedes: March 2026 | Governing Jurisdiction: California, USA
Immerse Inc., a Delaware corporation — 2175 Tustin Ave, Costa Mesa, CA 92627
This Data Processing Addendum (the “DPA”) is entered into between Immerse Inc. (“Immerse” or the “Data Processor”), a Delaware corporation located at 2175 Tustin Ave, Costa Mesa, CA 92627, and the Customer identified on the applicable Order Form (the “Customer” or the “Data Controller”). It is automatically incorporated into the Immerse Enterprise Terms of Service upon the execution of an Order Form referencing the Enterprise Terms, and no separate execution is required. This DPA satisfies the written-contract requirement under Article 28(3) of the GDPR and equivalent law. In the event of a conflict with the Enterprise Terms, this DPA prevails with respect to the Processing of Personal Data. The DPA Effective Date is the date the Order Form is executed or the date the Customer first provides Personal Data, whichever is earlier.
For the purposes of this DPA, the following terms have the meanings set out below. Capitalized terms not defined in this DPA have the meanings given to them in the Enterprise Terms.
“Personal Data” means any information relating to an identified or identifiable natural person that is processed by Immerse on behalf of the Customer under this DPA.
“Processing” (and “Process”) means any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, retrieval, use, disclosure, transmission, restriction, erasure, or destruction.
“Data Controller” (or “Controller”) means the Customer, being the entity that determines the purposes and means of the Processing of Personal Data.
“Data Processor” (or “Processor”) means Immerse, being the entity that Processes Personal Data on behalf of the Data Controller.
“Sub-processor” means any third party engaged by Immerse to Process Personal Data on the Customer’s behalf.
“Data Subject,” “Personal Data Breach,” “Supervisory Authority,” “Standard Contractual Clauses” (or “SCCs”), “GDPR,” “LGPD,” “UK GDPR,” and “CCPA” each have the meaning given to them under applicable data-protection law and are used accordingly in this DPA.
“Capture”is the Immerse feature — available across mobile, desktop, and smart glasses — that turns real-world moments into learning content, as described in the Enterprise Terms.
2.1 Data Subjects.
The Data Subjects whose Personal Data is Processed under this DPA are the Authorized Users of the Immerse platform (namely the employees, contractors, or students of the Customer). For customers whose Authorized Users use Capture (on any device — mobile, desktop, or smart glasses), the additional category of Data Subjects set out in Schedule 1 also applies.
2.2 Categories of Personal Data.
The categories of Personal Data Processed under this DPA include identity and contact data; language-learning data (including assessments, progress, metrics, and fluency scores); usage and session data; communication data (including chat transcripts and instructor-session voice recordings where enabled); spatial-interaction data where applicable (such as headset and controller position and orientation and voice-derived avatar animation); captured still images and their associated transcripts generated by the Capture feature; and biometric data only where a biometric-enabled feature is used and the Data Subject has given opt-in consent. Immerse does not perform eye-tracking and does not collect neural, brain-activity, or nervous-system data. For customers whose Authorized Users use Capture, the additional categories set out in Schedule 1 also apply.
2.3 Purposes.
Immerse Processes Personal Data for the following purposes: to provide the Services; to generate analytics and reporting for the Customer’s administrators; to maintain the security and integrity of the Services; and to fulfill Immerse’s legal obligations in its capacity as processor.
2.4 Duration.
Immerse Processes Personal Data for the term of the applicable Order Form and thereafter only for so long as is necessary to fulfill its obligations under Section 8 (Retention, Return and Deletion of Personal Data).
3.1 Documented Instructions.
Immerse Processes Personal Data only on the Customer’s documented instructions, including with respect to transfers of Personal Data, unless Immerse is required to Process Personal Data by applicable law to which it is subject. In such a case, Immerse will inform the Customer of that legal requirement before Processing, unless the law prohibits it from doing so on important grounds of public interest.
3.2 Confidentiality.
Immerse ensures that all personnel authorized to Process Personal Data are bound by appropriate obligations of confidentiality, whether by contract or by statutory duty, and are made aware of the confidential nature of the Personal Data.
3.3 Security Measures.
Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the Processing, Immerse implements and maintains appropriate technical and organizational measures to ensure a level of security appropriate to the risk. Such measures include encryption of Personal Data in transit (TLS 1.2 or higher) and at rest (AES-256); access controls granted on a need-to-know basis; regular security assessments and penetration testing; incident detection and response capabilities; and business-continuity and disaster-recovery planning. These measures are reviewed and updated on a regular basis.
3.4 Sub-processor Management.
The Customer provides Immerse with a general authorization to engage Sub-processors, subject to this Section. Immerse maintains an up-to-date list of its Sub-processors at immerse.com/legal/subprocessors and gives the Customer at least thirty (30) days’ prior notice of the addition or replacement of any Sub-processor, provided both by email to the Customer’s designated administrator contact and by updating the list at immerse.com/legal/subprocessors. Immerse imposes on each Sub-processor, by written contract, data-protection obligations no less protective than those set out in this DPA, and Immerse remains fully liable to the Customer for the performance of each Sub-processor’s obligations.
3.5 Data Subject Rights.
Taking into account the nature of the Processing, Immerse assists the Customer, by appropriate technical and organizational measures and insofar as this is possible, in fulfilling the Customer’s obligation to respond to requests by Data Subjects to exercise their rights of access, rectification, erasure, restriction of Processing, data portability, and objection.
3.6 Data Breach Notification.
Immerse notifies the Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting the Customer’s Personal Data. Such notification includes, to the extent then known, the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach. Immerse cooperates with the Customer and takes reasonable steps to assist the Customer in meeting the Customer’s own breach-notification obligations.
3.7 Data Protection Impact Assessments.
Immerse provides reasonable assistance to the Customer with any data-protection impact assessments and any prior consultations with Supervisory Authorities that the Customer is required to carry out under applicable data-protection law, in each case solely in relation to the Processing of Personal Data by Immerse and taking into account the information available to Immerse.
3.8 Records of Processing.
Immerse maintains records of its Processing activities carried out on behalf of the Customer in accordance with Article 30(2) of the GDPR and equivalent laws, and makes those records available to the relevant Supervisory Authority on request.
The Customer represents and warrants that it has the authority and all necessary rights and consents to provide the Personal Data to Immerse for Processing; that its instructions to Immerse comply with applicable data-protection law; that it has provided, and will continue to provide, all notices and obtain all consents required to enable the lawful Processing contemplated by this DPA (including appropriate privacy notices to Authorized Users); and that it will promptly notify Immerse of any change to its instructions that affects the Processing. The Customer is solely responsible for the accuracy, quality, and legality of the Personal Data and of the means by which it acquired that Personal Data.
5.1 Current Sub-processors.
As of the DPA Effective Date, Immerse engages the following Sub-processors to Process Personal Data. The Processing location is the United States unless otherwise noted.
The complete and current list of Sub-processors is maintained at immerse.com/legal/subprocessors and is updated in accordance with Section 3.4.
6.1 Any transfer of Personal Data from the European Economic Area, the United Kingdom, or Switzerland to a country that has not been recognized as providing an adequate level of data protection is subject to appropriate safeguards, including the Standard Contractual Clauses (Module 2: Controller-to-Processor) for the EEA, the UK International Data Transfer Agreement or Addendum for the United Kingdom, and equivalent mechanisms for Switzerland. By executing the Order Form, the Customer agrees to enter into the applicable SCCs with Immerse as data importer, which are incorporated into this DPA by reference.
6.2 Any transfer of Personal Data from Brazil is carried out in compliance with Chapter V of the LGPD.
6.3 Any onward transfer of Personal Data by a Sub-processor is subject to equivalent safeguards to those set out in this Section. The safeguards in this Section apply to every Sub-processor listed in Section 5.1 and in Schedule 1, and Immerse ensures that appropriate transfer mechanisms (the Standard Contractual Clauses, the UK IDTA or Addendum, or a recognized adequacy decision) are in place for each such Sub-processor before any restricted transfer occurs.
7.1 This DPA constitutes the written contract required by Article 28(3) of the GDPR. For the purposes of the GDPR, Immerse is the processor and the Customer is the controller.
7.2 For the purposes of the LGPD, this DPA satisfies the requirements of Article 37, and Immerse assists the Customer with the exercise of data-subject rights under the LGPD.
7.3 For the purposes of the UK GDPR, this DPA applies with such modifications as are appropriate to reflect the requirements of the UK GDPR and the UK Data Protection Act 2018.
7.4 CCPA. Where the Customer is a “Business” and Immerse is a “Service Provider” within the meaning of the CCPA/CPRA, Immerse will not sell or share Personal Data; will not retain, use, or disclose Personal Data for any purpose other than performing the Services or as otherwise permitted by the CCPA; will not retain, use, or disclose Personal Data outside the direct business relationship between the parties; and will notify the Customer if it determines that it can no longer meet its obligations under the CCPA.
7.5 Regulatory Fines and Enforcement. Notwithstanding any limitation of liability in the Enterprise Terms, any fines, penalties, or sanctions imposed on Immerse in its capacity as Data Processor and arising from Immerse’s own failure to comply with its obligations under this DPA or under applicable data-protection law are the sole financial responsibility of Immerse (including any such fines, penalties, or sanctions under Article 83 of the GDPR, §1798.155 of the CCPA/CPRA, and Articles 52–54 of the LGPD). The Customer is not required to indemnify Immerse for any processor-failure penalties assessed against Immerse.
8.1 Post-Termination Retention.Upon the expiry or termination of the applicable Order Form, Immerse retains the Customer’s Personal Data in a limited, access-restricted state for a period of two (2) years (the “Retention Window”) to enable renewal, reactivation, or return of the data and to preserve Authorized Users’ learning history. During the Retention Window, Immerse does not Process the Personal Data except as necessary to store it securely, to make it available for return, or as instructed by the Customer. Immerse is not required to provide notice prior to deletion at the end of the Retention Window. If the Customer renews or reactivates the Services during the Retention Window, the Retention Window restarts.
8.2 Deletion After the Window.At the end of the Retention Window, Immerse securely deletes or de-identifies the Customer’s Personal Data (including copies held by Sub-processors), unless the Customer has (a) renewed or reactivated the Services, or (b) instructed Immerse in writing to return or to continue retaining the data.
8.3 Return or Deletion on Request.At any time, upon the Customer’s written request, Immerse will, at the Customer’s election, either return the Personal Data in a machine-readable format (.CSV or .JSON) or securely delete and destroy it (including copies held by Sub-processors), and confirm completion in writing within thirty (30) days of the request. Where a Customer or applicable law requires return or deletion within a shorter period following termination, Immerse will honor that requirement.
8.4 Legally Required Retention.Immerse may retain Personal Data only to the extent, and for so long as, required by applicable law, in which case Immerse maintains the confidentiality of the Personal Data and Processes it only as required by that law.
The Customer may audit Immerse’s compliance with this DPA upon thirty (30) days’ prior written notice, no more than once per calendar year (except where a Personal Data Breach or a regulatory investigation reasonably requires more frequent audits), during Immerse’s normal business hours, and provided that any third-party auditor is bound by obligations of confidentiality. Immerse may satisfy the Customer’s audit rights by making available a current SOC 2 Type II report, an ISO 27001 certification, or an equivalent independent report or certification. Any audit beyond such reports is scoped and costed by written agreement between the parties.
This DPA remains in effect for so long as Immerse Processes Personal Data on the Customer’s behalf, and it terminates automatically on the later of (a) the expiry or termination of all Order Forms and (b) the completion of Immerse’s obligations under Section 8 (Retention, Return and Deletion of Personal Data). Sections 1 (Definitions), 3.6 (Data Breach Notification), 6 (International Data Transfers), 7 (Compliance), and 9 (Audit Rights) survive the termination of this DPA to the extent required to give effect to their terms.
11.1 Order of Precedence.
This DPA prevails over the Enterprise Terms with respect to the Processing of Personal Data.
11.2 Governing Law.
This DPA is governed by the laws of the State of California, except where applicable data-protection law requires otherwise (for example, the law of the European Union or the United Kingdom for the purposes of the SCCs or the UK IDTA).
11.3 Amendments.
Immerse may update this DPA to reflect changes in applicable law or in its Processing operations, upon at least thirty (30) days’ prior notice to the Customer of any material change. If the Customer objects to a material change on reasonable data-protection grounds, it may terminate the affected Order Form without penalty within thirty (30) days of such notice.
11.4 Severability.
If any provision of this DPA is held to be invalid or unenforceable, that provision is severed and the remaining provisions continue in full force and effect.
11.5 Entire Agreement.
This DPA, together with the Enterprise Terms and the applicable Order Form, constitutes the entire agreement between the parties with respect to the Processing of Personal Data and supersedes all prior agreements and understandings on that subject. Countersigned copies of this DPA are available from support@immerse.online.
11.6 Contact. Questions regarding this DPA, and requests for countersigned copies, may be directed to support@immerse.online. The current version of this DPA is published at immerse.com/legal/dpa, and the current list of Sub-processors at immerse.com/legal/subprocessors.
Effective: August 10, 2026
This Schedule 1 supplements this DPA and applies to any Customer whose Authorized Users use the Capture feature (on any device — mobile, desktop, or smart glasses). In the event of a conflict between this Schedule and the body of the DPA as to Capture Processing, this Schedule controls.
S1.1 Additional Sub-Processors (Capture)
S1.2 Additional Categories of Personal Data
In addition to the categories set out in Section 2.2 of the DPA, the following categories of Personal Data are Processed for Capture customers. The Capture feature is user-initiated only; there is no background listening, and no video is ever stored. For each captured moment, the feature always creates a transcript and may also create a single still image. The categories accordingly comprise: the transcripts associated with captured moments; any still image created for a captured moment; the camera and audio streams made available live by the device for real-time processing; the interaction content derived from that capture; facial and voice characteristics to the extent that they constitute Biometric Data; and, where enabled, approximate location metadata. Any still image, where created, is used only for the user’s own review and is not transmitted to third-party AI providers; only transcripts are sent to the AI providers that generate coaching and lessons.
S1.3 Additional Categories of Data Subjects
In addition to the Authorized Users identified in Section 2.1 of the DPA, the Data Subjects include Third-Party Individuals who are incidentally captured. The user is responsible for the privacy of other people and for obtaining any consent required from them. Immerse does not run facial recognition and does not generate biometric identifiers from captured content, and any incidental references to non-users in derived content are minimized and de-identified.
S1.4 Purpose, Storage & Retention
Captured content (a transcript and, where created, a still image for each captured moment) is stored locally on the user’s device by default. Immerse Processes such content server-side only where the user turns on cross-device sync or where a captured moment is turned into a lesson. No video is stored at any point.
Real-time transcription for the Capture feature is performed by Google (Gemini), which may retain inputs briefly for abuse monitoring; that content is not used to train AI models. The interaction content derived from Capture is Processed solely to provide the learning Services and is retained no longer than is necessary for that purpose or as required by applicable law, and subject to Section 8.
Asynchronous lesson voice is transcribed and the resulting transcripts are retained, including through the Langfuse observability tooling Processed in the European Union (Germany), for no longer than is necessary to provide the Services or as required by applicable law. Pronunciation audio Processed by Microsoft Azure Speech is not retained by default. Biometric Data, to the extent Processed, is handled per a written retention-and-destruction policy and is destroyed on the earlier of satisfaction of the purpose or termination, and no later than the period required by applicable law.
S1.5 Data Residency, Access & International Transfers
Primary storage is on AWS US-East-2 (United States). Administrative and support access is limited to personnel located in the United States and Mexico, is subject to multi-factor authentication, and takes place over encrypted channels. The Standard Contractual Clauses (Module 2) and the UK IDTA or Addendum referenced in Section 6 of the DPA extend to the Sub-processors set out in Section S1.1 of this Schedule, and any onward transfer is subject to equivalent safeguards.
S1.6 Security
The technical and organizational measures set out in Section 3.3 of the DPA apply to Capture Data and to the data derived from it, including TLS 1.2 or higher in transit, AES-256 at rest, private-subnet isolation, ephemeral-token authentication for real-time sessions, and the absence of any long-lived provider credentials in any client.