Spec AI Data Processing Addendum
Effective: September 18, 2026
Document version: 2026-09-18-r02
This Data Processing Addendum (DPA) forms part of the Terms of Service or other agreement (Agreement) between Spec AI, the California-based business operating app.spec-ai.co (Spec AI), and the customer identified in the Agreement (Customer). It applies when Spec AI processes Customer Personal Data on Customer's behalf.
This online DPA supports United States processing. It does not itself incorporate the European Commission Standard Contractual Clauses, the UK Addendum, or another restricted-transfer mechanism. Customers requiring those terms must execute an applicable written transfer addendum before submitting covered personal data.
1. Definitions
Applicable Data Protection Law means privacy and data-protection law applicable to the Processing, including the CCPA/CPRA and other applicable United States privacy laws. GDPR, UK GDPR, Swiss, or other restricted-transfer obligations apply only when legally applicable and after any required transfer arrangement is completed.
Customer Personal Data means Personal Data contained in Customer Content that Spec AI Processes on Customer's behalf under the Agreement.
Controller, Data Subject, Personal Data, Personal Data Breach, Process/Processing, Processor, Sale, Share, Service Provider, and Supervisory Authority have the meanings given by Applicable Data Protection Law.
Subprocessor means a third party engaged by Spec AI to Process Customer Personal Data.
2. Roles and instructions
Customer is Controller or Processor of Customer Personal Data. Spec AI is Customer's Processor or Subprocessor. Customer instructs Spec AI to Process Customer Personal Data to provide, secure, support, and maintain the Service; follow documented feature and support instructions; and comply with law. The Agreement and Customer's authorized use constitute documented instructions.
Customer is responsible for the lawfulness, accuracy, and quality of Customer Personal Data; notices and consents; Data Subject requests directed to Customer; and ensuring its instructions comply with law. Spec AI will notify Customer if it believes an instruction violates Applicable Data Protection Law, unless prohibited by law, and may suspend the affected Processing while the parties resolve the issue.
Spec AI may Process account, billing, security, usage, legal, and relationship information as an independent Controller as described in the Privacy Policy. Such information is not Customer Personal Data under this DPA.
3. Processing obligations
Spec AI will:
- Process Customer Personal Data only on documented instructions, unless law requires otherwise;
- ensure personnel authorized to Process it are bound by confidentiality;
- maintain the safeguards described in Annex II;
- assist Customer, considering the nature of Processing, with Data Subject requests, security, breach response, impact assessments, and regulator consultations as reasonably required;
- make information reasonably necessary to demonstrate compliance available to Customer; and
- notify Customer if Spec AI can no longer meet applicable obligations.
Spec AI will not sell or share Customer Personal Data, combine it with personal information received from another person or from Spec AI's own consumer interactions except as permitted for a service provider by the CCPA, or retain, use, or disclose it outside the direct business relationship or purposes specified in the Agreement. Spec AI certifies that it understands and will comply with those restrictions.
Customer may take reasonable steps to stop and remediate unauthorized use, including by contacting privacy@spec-ai.co.
4. Confidentiality and access
Spec AI will limit Customer Personal Data access to personnel and Subprocessors who need it to provide or secure the Service. Platform-administrator access must be role-restricted, authenticated, logged where appropriate, and used for support, security, legal compliance, or authorized operations.
5. Security and Personal Data Breach
Spec AI will maintain measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Annex II describes the measures verified for the executed version. Measures may change based on risk, technology, Service changes, and Applicable Data Protection Law.
After becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data, Spec AI will notify Customer without undue delay and provide available information reasonably needed for Customer's obligations, including the nature of the breach, likely consequences, affected data and people where known, mitigation, and a contact. Notification is not an admission of fault. Spec AI may provide information in phases and will take reasonable steps to contain, investigate, and remediate.
No shorter contractual notification deadline applies unless a signed Order Form expressly states one.
6. Subprocessors
Customer generally authorizes the Subprocessors listed on the Subprocessor page. Spec AI will impose data-protection obligations as required by Applicable Data Protection Law and remains responsible for their performance to the extent required by that law.
When Applicable Data Protection Law requires notice of an intended new Subprocessor, Spec AI will provide notice before that Subprocessor begins the applicable Processing and allow Customer to object on reasonable data-protection grounds. If an objection cannot be resolved, either party may discontinue the affected Processing as permitted by the Agreement and applicable law. No fixed notice period, substitute provider, migration assistance, refund, or penalty-free termination right applies unless required by law or a signed Order Form.
7. Data Subject requests
If Spec AI receives a request concerning Customer Personal Data, it will direct the requester to Customer where feasible and will not independently respond except on Customer's instructions or as legally required. Spec AI will provide reasonable self-service tools or assistance. Additional work beyond standard functionality may be charged at agreed rates when law permits.
8. Return and deletion
During the term, Customer may use then-available export features. At the end of the applicable Services, Spec AI will, at Customer's choice, delete or return Customer Personal Data and delete existing copies as required by Applicable Data Protection Law, unless law requires retention. Encrypted, access-restricted recovery snapshots maintained by Spec AI and residual copies held by its providers may contain Customer Personal Data after deletion from active systems. While retained, these copies are restricted from ordinary use and remain subject to applicable retention, lifecycle, provider soft-delete, legal-hold, and legal requirements. Before any restored copy enters ordinary service, Spec AI will reconcile applicable deletion and access-revocation instructions received after the selected recovery point. Any delay in removing recovery copies remains subject to Applicable Data Protection Law. No fixed export, deletion, recovery-copy, or restoration period applies unless required by law or a signed Order Form.
9. Audits
Spec AI will make information available to the extent required by Applicable Data Protection Law to demonstrate compliance with this DPA. Spec AI may satisfy an audit request with available documentation, third-party reports, or written responses. Any inspection must be legally required, reasonably scoped, subject to confidentiality, avoid access to other customers' information, and avoid unreasonable disruption. Customer bears its audit costs unless applicable law requires otherwise.
10. International transfers
The Service and its listed Subprocessors may process Customer Personal Data in the United States and other provider locations. Customer must not submit personal data requiring an EEA, UK, Swiss, or other restricted-transfer mechanism until the parties have completed the legally required transfer arrangement. If the parties execute a transfer addendum, that signed addendum controls for its subject matter. This DPA makes no representation that an unexecuted transfer mechanism applies automatically.
11. Liability and order of precedence
The Agreement's liability limits apply to this DPA to the maximum extent permitted by law. If documents conflict, an executed transfer addendum controls for its subject matter, then this DPA, then the Agreement.
12. Term
This DPA begins when Customer accepts the Agreement or the parties sign it and continues while Spec AI Processes Customer Personal Data.
Annex I - Details of Processing
Parties
- Data exporter: Customer identified in the Agreement; contact and role as provided in its account or order.
- Data importer: Spec AI, reachable at
privacy@spec-ai.co; role: Processor/Subprocessor.
Subject matter and purpose
Providing a B2B product-intelligence and specification platform, including authentication, collaboration, project briefs, optional plan analysis, product search and extraction, recommendations, specifications and cut sheets, reviews, approvals, email, support, security, restricted recovery copies, and administration.
Duration
The applicable Service term and any additional period during which Spec AI lawfully Processes Customer Personal Data.
Data Subjects
Customer personnel and contractors; studio members; clients; project collaborators; reviewers and approvers; manufacturer or supplier representatives; and other people whose business information Customer submits.
Personal Data
Names, business emails, profile images, roles, authentication identifiers, project/client association, project addresses, plans and visible plan information, comments, decisions, product feedback, support content and optional screenshots, activity/audit metadata, IP/device information, and billing contact metadata.
Sensitive data
The Service is not intended for special-category data, protected health information, full card data, government identifiers, biometric identifiers, or data about children. Incidental information visible in uploaded plans may be processed only under Customer's lawful instructions. Customer must not intentionally submit restricted data without a signed addendum.
Frequency
Continuous or user-triggered during Customer's use, including plan analysis and product extraction only when initiated by a user or authorized workflow.
Retention
As described in Section 8 and as reasonably necessary for the Processing purposes or applicable legal obligations.
Annex II - Technical and Organizational Measures
The standard Service uses the following controls as of the effective date:
- unique Google-authenticated accounts and application role controls;
- restricted studio, project, and platform-administrator access;
- TLS in transit and provider-managed encryption at rest;
- private object storage for uploaded plans;
- secret management outside source control;
- upload size, declared-file-type, and file-signature controls;
- expiring, revocable, hashed public review and approval tokens with request throttling;
- studio-scoped access to customer product feedback;
- versioned legal acceptance records and platform-administrator action logs; and
- provider platform and network safeguards included in the listed hosting services.
This annex does not promise backups, restoration, availability monitoring, RPO, RTO, malware detection, penetration testing, a particular certification, or any control not expressly listed in the executed version.
Annex III - Subprocessors
The current list is published on the Subprocessor page and incorporated by reference.