Legal

Data Processing Addendum

Effective July 21, 2026

This is Pitch Box's standard Data Processing Addendum (DPA), offered to customers who process personal data through the platform. To execute a counter-signed copy for your organization, contact hello@pitch-box.ai. The current subprocessor list (Annex III) is maintained at pitch-box.ai/subprocessors.

This Data Processing Addendum ("DPA") forms part of the agreement between the customer ("Customer") and Sandbox Group LLC, which operates under the assumed business name Pitch Box ("Pitch Box"), for use of the Pitch Box platform (the "Service") and reflects the parties' agreement on the processing of personal data under the EU General Data Protection Regulation (GDPR), UK GDPR, and applicable US state privacy laws.

1. Definitions

"Controller", "Processor", "Data Subject", "Personal Data", "Processing", and "Personal Data Breach" have the meanings given in the GDPR. "Sub-processor" means any processor engaged by Pitch Box to process Customer Personal Data. "Customer Personal Data" means personal data Pitch Box processes on Customer's behalf under the Service.

2. Roles of the Parties

For Customer Personal Data, Customer is the Controller and Pitch Box is the Processor. Pitch Box processes Customer Personal Data only to provide the Service and only on Customer's documented instructions, including as set out in this DPA and the agreement.

3. Scope and Details of Processing

The subject matter, duration, nature, and purpose of processing, the types of personal data, and categories of data subjects are described in Annex I.

4. Processor Obligations

5. Security

Pitch Box maintains the technical and organizational measures described in Annex II, including encryption in transit, tenant isolation enforced at the authentication, ownership-verification, and database (a dedicated database per workspace) layers, and an access audit log.

6. Sub-processors

Customer provides a general authorization for Pitch Box to engage the sub-processors listed at pitch-box.ai/subprocessors (incorporated as Annex III). Pitch Box imposes data-protection obligations on each sub-processor no less protective than those in this DPA and remains responsible for their performance. Pitch Box will update the list before engaging a new sub-processor and, on request, provide a mechanism for advance notice so Customer may object on reasonable data-protection grounds.

7. Data Subject Rights

Taking into account the nature of the processing, Pitch Box assists Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling Customer's obligation to respond to requests to exercise data-subject rights (access, rectification, erasure, restriction, portability, objection). Pitch Box provides operator tooling to locate, export, and erase a data subject's personal data across the Service.

8. Personal Data Breach

Pitch Box notifies Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and provides information reasonably available to assist Customer in meeting its breach-notification obligations.

9. Audit

Pitch Box makes available information necessary to demonstrate compliance with this DPA and allows for and contributes to audits, including inspections, conducted by Customer or an auditor mandated by Customer, subject to reasonable confidentiality and frequency limits.

10. Deletion or Return

Upon termination of the Service, Pitch Box will, at Customer's election, delete or return Customer Personal Data, and delete existing copies unless retention is required by law.

11. International Transfers

Where Pitch Box processes Customer Personal Data originating in the EEA, UK, or Switzerland outside those territories, the parties rely on an appropriate transfer mechanism, including the Standard Contractual Clauses, which are incorporated by reference where applicable.

12. Annexes

Annex I — Details of Processing

Subject matter: provision of the Pitch Box RFP-response platform for agencies. Duration: the term of the agreement. Nature/purpose: RFP parsing, response drafting, knowledge-base and case-study management, scoring, and compiling branded proposals and decks. Categories of data subjects: Customer's personnel and authorized users; named authors/SMEs and reviewers on the workspace; buying-committee members and CRM contacts the Customer imports into a pursuit; and individuals referenced in Customer-provided or publicly sourced brand material. Types of personal data: names, business email addresses, job titles, professional biographies, professional profile links, and buying-committee contact details and priorities.

Annex II — Technical and Organizational Measures

Encryption in transit (TLS); tenant isolation at three layers — authentication (shared-password workspaces or per-user sign-in via Clerk, using single-use email sign-in links and JWT sessions), per-request ownership verification, and physical database isolation (each customer workspace runs as its own deployment with its own dedicated Postgres database, so content is never commingled with another customer's); least-privilege operator access limited to Sandbox Group operators; SSRF-guarded outbound fetching for URL importers; an access/audit log of privileged and data-access events; and automated purge of orphaned data.

Annex III — Sub-processors

The current list at pitch-box.ai/subprocessors.

13. Contact

Sandbox Group LLC, operating as Pitch Box · hello@pitch-box.ai