Legal & trust center

Data Processing Addendum

Core controller–processor terms for organizations using TrainerSim.

Effective · Version 1.0

This public document explains our standard operating terms and practices. A signed order, enterprise agreement, or negotiated DPA may contain additional terms.

1. Scope and roles

This Data Processing Addendum (DPA) forms part of the agreement between the customer and Pacific Wave Digital for TrainerSim when we process personal data on the customer’s behalf. The customer is controller and Pacific Wave Digital is processor, except where either party acts independently under applicable law.

2. Documented instructions

We process customer personal data only to provide and secure TrainerSim, follow the agreement and documented configuration, or comply with law. The customer is responsible for lawful instructions, notices, consents, accuracy, and deciding whether the service is appropriate for its data and users.

3. Confidentiality and security

Personnel and subprocessors with access are subject to confidentiality obligations. We maintain measures appropriate to the service, including tenant and role controls, authentication, transport encryption, server-side secrets, private recording storage, short-lived replay links, webhook verification, logging safeguards, and vulnerability remediation processes.

4. Subprocessors and transfers

The customer generally authorizes the subprocessors listed on our Subprocessors page. We remain responsible for their processing to the extent required by the agreement and will impose data-protection obligations appropriate to their function. Processing may occur internationally; the parties will use an applicable transfer mechanism where required.

5. Assistance and incidents

Taking account of the nature of processing and information available to us, we will reasonably assist with data-subject requests, security obligations, impact assessments, and regulator inquiries. We will notify the customer without undue delay after confirming a personal-data breach affecting customer data and provide available information needed for the customer’s response.

6. Return, deletion, and audit

On termination or written request, we will return or delete customer personal data within a reasonable period unless law requires retention. Residual backups are isolated and expire through normal cycles. We will provide information reasonably necessary to demonstrate compliance. Additional audits require advance notice, confidentiality, limited disruption, and reimbursement of reasonable costs unless a material breach is identified.

7. Processing details

  • Subject matter: delivery of AI simulation, coaching, learning, assessment, recording, reporting, administration, and embedded support.
  • Duration: the agreement plus configured retention and lawful backup periods.
  • Data subjects: customer personnel, learners, students, candidates, support visitors, administrators, and other authorized participants.
  • Data types: identity, contact, organization, account, learning, transcript, recording, assessment, support context, device, security, and billing metadata; special-category data only when the customer lawfully chooses to provide it.
  • Purpose: operate, secure, support, and improve the contracted service under customer instructions.

8. Order of precedence and contact

If this DPA conflicts with the service agreement on personal-data processing, this DPA controls. For a signed copy or tailored enterprise schedule, contact support@trainersim.com.

Questions about this document?

Contact Pacific Wave Digital at support@trainersim.com. We are based in Port Vila, Vanuatu.