Data Processing Addendum

Peach reduces repetitive tasks, increases student satisfaction, and gives your financial aid team time to focus on what matters.

Hero ShapeHero Shape

Last Updated: August 10, 2026

This Data Processing Addendum ("DPA") forms part of the Master Services Agreement, Order Form, or other written agreement (the "Agreement") between Habitual Money, Inc. DBA Peach ("Peach," "Provider," "we," "our," or "us") and the customer identified in the applicable Agreement ("Customer").

This DPA governs Peach's Processing of Personal Data and Customer Data in connection with the Services.

If there is any conflict between this DPA and the Agreement solely with respect to the Processing of Personal Data, this DPA shall control. In all other respects, the Agreement shall remain in full force and effect.

I. Definitions

For purposes of this DPA:

"Applicable Privacy Laws" means all applicable federal, state, and local laws relating to privacy, data protection, information security, education records, or personal information, including, where applicable, the Family Educational Rights and Privacy Act ("FERPA"), state student privacy laws, and applicable U.S. state consumer privacy laws.

"Customer Data" means all information, documents, communications, records, files, prompts, metadata, and other content submitted to, uploaded into, stored within, or otherwise Processed through the Services by or on behalf of Customer.

"Data Subject" means an identified or identifiable individual whose Personal Data is Processed through the Services.

"Personal Data" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked with an identified or identifiable individual, as defined under Applicable Privacy Laws.

"Process" (and "Processing") means any operation performed on Personal Data or Customer Data, including collecting, storing, organizing, structuring, accessing, retrieving, transmitting, using, disclosing, analyzing, deleting, or otherwise handling such information.

"Security Incident" means any confirmed unauthorized access to, acquisition of, disclosure of, alteration of, loss of, or destruction of Customer Data that compromises the confidentiality, integrity, or availability of such information.

"Subprocessor" means any third party engaged by Peach to Process Customer Data on Peach's behalf in connection with providing the Services.

II. Roles of the Parties

Customer determines the purposes and means for which Customer Data is collected and submitted to the Services.

Peach Processes Customer Data solely for the purpose of providing, maintaining, securing, supporting, and improving the Services in accordance with the Agreement and this DPA.

Nothing in this DPA transfers ownership of Customer Data to Peach.

As between the parties, Customer retains all right, title, and interest in and to Customer Data.

III. Scope of Processing

Customer instructs Peach to Process Customer Data solely as reasonably necessary to:

  • provide and operate the Services;
  • authenticate Authorized Users;
  • host Customer Data;
  • ingest Customer Content uploaded by Customer;
  • extract text and other machine-readable information from uploaded documents and designated websites;
  • analyze, parse, segment, index, and otherwise prepare Customer Content for retrieval and search;
  • generate searchable representations of Customer Content to support knowledge retrieval and AI-assisted workflows;
  • retrieve relevant Customer Content in response to Authorized User requests;
  • generate AI-assisted communications, summaries, analyses, and other requested outputs;
  • process email communications and related context for the purpose of generating draft responses and assisting Authorized Users;
  • provide customer support;
  • monitor system performance and security;
  • maintain backups;
  • investigate technical issues;
  • comply with applicable law; and
  • fulfill Peach's obligations under the Agreement.

Peach will not Process Customer Data for any materially different purpose without Customer's authorization unless required by applicable law.

IV. Confidentiality

Peach shall ensure that all employees, contractors, and agents with authorized access to Customer Data:

  • are subject to written confidentiality obligations;
  • receive appropriate privacy and security training;
  • access Customer Data only when reasonably necessary to perform their responsibilities; and
  • remain bound by confidentiality obligations after their employment or engagement ends.

V. Customer Responsibilities

Customer is responsible for:

  • determining the lawfulness of collecting and providing Customer Data to Peach;
  • ensuring it has all rights, permissions, and legal authority necessary to provide Customer Data;
  • configuring user permissions appropriately;
  • maintaining the confidentiality of Authorized User credentials;
  • reviewing AI-generated content before relying upon or communicating it; and
  • complying with Applicable Privacy Laws.

Customer acknowledges that Peach acts only on Customer's instructions with respect to Customer Data except where otherwise required by law.

VI. Information Security

Peach shall maintain and implement commercially reasonable administrative, technical, and organizational safeguards designed to protect Customer Data against unauthorized access, acquisition, disclosure, alteration, destruction, loss, or misuse.

Such safeguards are designed to be appropriate to the nature of the Services, the sensitivity of the Customer Data processed, and the risks presented by Processing activities.

At a minimum, Peach will maintain security measures that include, as appropriate:

Access Controls

Peach maintains administrative controls designed to limit access to Customer Data to authorized personnel with a legitimate business need.

Access privileges are granted based on job responsibilities and are reviewed and modified as personnel roles change or access is no longer required.

Authentication

Peach maintains authentication controls designed to protect access to Customer accounts and internal administrative systems.

Customers are responsible for managing Authorized User accounts and safeguarding account credentials within their organizations.

Encryption

Peach uses industry-standard encryption technologies to protect Customer Data during transmission over public networks.

Where appropriate, Customer Data stored within Peach-managed systems is protected using encryption at rest or equivalent safeguards designed to protect against unauthorized access.

Network and Infrastructure Security

Peach maintains security measures designed to protect the infrastructure supporting the Services, including controls intended to:

  • monitor system availability;
  • restrict unauthorized network access;
  • protect against malicious software;
  • detect suspicious activity; and
  • support the integrity and availability of the Services.

Secure Development

Peach incorporates security considerations into the design, development, testing, deployment, and maintenance of the Services.

Security issues identified during development or operation are prioritized and addressed based on the nature and potential impact of the identified risk.

Logging and Monitoring

Peach maintains logs and monitoring capabilities designed to support operational performance, security investigations, troubleshooting, and incident response.

Where appropriate, access to Customer Data and administrative actions may be logged for security and auditing purposes.

Personnel Security

Peach requires personnel with access to Customer Data to be subject to confidentiality obligations and to receive appropriate security and privacy awareness training.

Access to Customer Data is limited to personnel whose responsibilities reasonably require such access.

Business Continuity

Peach maintains procedures designed to support the availability and recovery of the Services in the event of operational disruptions.

Reasonable backup and recovery processes are maintained to reduce the risk of accidental loss of Customer Data.

Vendor Management

Where Peach engages Subprocessors to assist in providing the Services, Peach will conduct reasonable diligence prior to engagement and require such Subprocessors to maintain contractual obligations regarding confidentiality, privacy, and information security that are no less protective than those applicable to Peach under this DPA.

Security Program

Peach may update or modify its security program from time to time to address changes in technology, threats, legal requirements, industry practices, or the Services, provided that such modifications do not materially diminish the overall security of the Services.

Customer acknowledges that information security is an evolving discipline and that no security program can eliminate every possible risk. Peach does not warrant that the Services will be immune from every security incident, cyberattack, or unauthorized access. Peach will, however, maintain and operate a security program designed to protect Customer Data using commercially reasonable safeguards appropriate for the Services.

VII. Artificial Intelligence Processing

To provide the Services, Peach Processes Customer Data through multiple stages of document retrieval, knowledge retrieval, and artificial intelligence processing.

These Processing activities may include:

  • ingesting documents, communications, and other Customer Content;
  • retrieving content from Customer-designated websites;
  • extracting text and other machine-readable information from uploaded documents and websites;
  • parsing, segmenting, indexing, and otherwise preparing Customer Content for retrieval and AI-assisted processing;
  • generating searchable or indexed representations of Customer Content to support knowledge retrieval;
  • retrieving relevant portions of Customer Content in response to Authorized User requests;
  • processing prompts, instructions, and related contextual information submitted by Authorized Users;
  • processing email communications and conversation history for the purpose of generating draft responses;
  • generating AI-assisted summaries, analyses, recommendations, communications, and other requested outputs; and
  • using Customer-approved context to improve the relevance and accuracy of AI-generated responses.

Customer acknowledges that these Processing activities are necessary to provide the functionality of the Services.

Customer further acknowledges and agrees that:

  • AI-generated content is intended solely to assist Authorized Users and is not a substitute for human judgment.
  • AI-generated content may be incomplete, inaccurate, inconsistent, or outdated.
  • Customer remains solely responsible for reviewing, approving, modifying, and verifying AI-generated content before relying upon it or communicating it to any third party.
  • Peach does not independently make decisions regarding admissions, enrollment, financial aid eligibility, financial aid awards, Title IV compliance, institutional policy, or any other academic or administrative determination.

Peach does not use Customer Data to train publicly available artificial intelligence foundation models.

Customer Data may be Processed by third-party artificial intelligence providers and other service providers acting solely on Peach's behalf for the purpose of providing the Services, including document analysis, knowledge retrieval, AI-assisted generation, and related functionality. Such providers are contractually required to protect Customer Data in accordance with applicable agreements and applicable law.

Peach may use aggregated and de-identified information derived from Customer Data to improve the performance, reliability, security, and functionality of the Services, provided such information cannot reasonably identify Customer, its Authorized Users, or individual students.

Peach will not:

  • sell Customer Data;
  • use Customer Data to train publicly available artificial intelligence foundation models;
  • permit third parties to use Customer Data to train publicly available artificial intelligence foundation models for their own benefit;
  • use Customer Data for targeted advertising;
  • disclose Customer Data except as permitted by the Agreement, this DPA, or as required by applicable law; or
  • attempt to re-identify de-identified Customer Data.

Nothing in this Section transfers ownership of Customer Data to Peach. Customer retains ownership of Customer Data, while Peach retains ownership of the Services and the underlying software, workflows, models, algorithms, and other intellectual property used to provide the Services.

VIII. Subprocessors

Peach may engage third-party service providers ("Subprocessors") to Process Customer Data on Peach's behalf in connection with providing the Services.

Peach will engage only Subprocessors that are reasonably capable of maintaining appropriate privacy, confidentiality, and security protections for Customer Data.

Peach shall enter into written agreements with each Subprocessor requiring the Subprocessor to:

  • Process Customer Data only for the purposes authorized by Peach;
  • maintain appropriate confidentiality obligations;
  • implement commercially reasonable administrative, technical, and organizational safeguards designed to protect Customer Data;
  • notify Peach of Security Incidents affecting Customer Data as required under the applicable agreement; and
  • comply with obligations substantially similar to those imposed upon Peach under this DPA.

Peach remains responsible for the performance of its Subprocessors to the extent required by applicable law and the Agreement.

Peach will maintain a current list of its material Subprocessors and, upon Customer's written request, will make that list available to Customer or direct Customer to a publicly available Subprocessor page.

If Peach intends to engage a new material Subprocessor that will Process Customer Data, Peach will provide reasonable notice to Customer where required by applicable law or the Agreement.

IX. Data Subject Requests

Customer acknowledges that it is responsible for responding to requests from Data Subjects relating to Personal Data processed through the Services, including requests to access, correct, delete, restrict, or otherwise exercise rights under Applicable Privacy Laws.

To the extent Peach receives a request directly from a Data Subject regarding Customer Data, Peach will:

  • promptly notify Customer, unless prohibited by applicable law;
  • not respond directly to the request except as instructed by Customer or as required by applicable law; and
  • provide reasonable assistance to Customer in responding to such request, taking into account the nature of the Processing and the functionality of the Services.

Peach may charge Customer for assistance with requests that require substantial additional engineering, legal review, or administrative effort, to the extent permitted under the Agreement.

Nothing in this Section relieves Customer of its responsibility to respond to requests from Data Subjects under Applicable Privacy Laws.

X. Security Incidents

Peach maintains policies and procedures designed to identify, investigate, contain, mitigate, and remediate Security Incidents.

In the event Peach confirms a Security Incident affecting Customer Data, Peach will notify Customer without undue delay and, where feasible, no later than seventy-two (72) hours after confirmation of the Security Incident.

To the extent reasonably available, Peach's notification will include:

  • a general description of the nature of the Security Incident;
  • the categories of Customer Data reasonably believed to be affected;
  • the known or reasonably suspected impact of the Security Incident;
  • the measures Peach has taken or proposes to take to investigate, contain, mitigate, and remediate the Security Incident; and
  • contact information for Peach personnel coordinating the response.

Peach will:

  • promptly investigate confirmed Security Incidents;
  • take commercially reasonable steps to contain and remediate the Security Incident;
  • cooperate reasonably with Customer regarding Customer's investigation and response obligations; and
  • provide supplemental information as it becomes reasonably available.

Customer acknowledges that Peach's obligation to notify Customer under this Section does not constitute an admission of fault or liability.

Customer remains solely responsible for determining whether notification to affected individuals, governmental authorities, regulators, or other third parties is required under Applicable Privacy Laws, unless otherwise expressly required by law.

XI. Data Retention and Deletion

Peach will retain Customer Data only for as long as reasonably necessary to:

  • provide the Services;
  • fulfill Customer's instructions;
  • comply with applicable legal obligations;
  • resolve disputes;
  • enforce the Agreement; or
  • maintain appropriate business records.

Upon expiration or termination of the Agreement, Customer may request that Peach:

  • return Customer Data;
  • provide Customer Data in a commercially reasonable export format where technically feasible; or
  • securely delete Customer Data from Peach's production systems.

Unless otherwise agreed in writing or required by applicable law, Peach will complete such return or deletion within sixty (60) days following Customer's written request.

Customer acknowledges that:

  • backup systems may temporarily retain Customer Data until such backups are overwritten or expire in the ordinary course of business;
  • certain records may be retained where required by applicable law or to establish, exercise, or defend legal claims; and
  • de-identified or aggregated information that cannot reasonably identify Customer or any individual may be retained and used in accordance with this DPA and the Agreement.

Upon Customer's written request, Peach will certify that Customer Data has been deleted from Peach's production systems, except to the extent retention is required by law or permitted under this DPA.

XII. Audits and Compliance Information

Upon Customer's reasonable written request, and no more than once during any twelve (12) month period unless required by applicable law or following a confirmed Security Incident affecting Customer Data, Peach will make available information reasonably necessary to demonstrate its compliance with this DPA.

Such information may include, as applicable:

  • security policies and procedures;
  • summaries of security practices;
  • independent audit reports or certifications, if available;
  • responses to reasonable security questionnaires; or
  • other documentation reasonably requested by Customer.

If Customer reasonably determines that additional verification is required, the parties may mutually agree upon a reasonable audit process, subject to:

  • reasonable advance notice;
  • execution of an appropriate confidentiality agreement;
  • reasonable limitations on scope, timing, and duration;
  • protection of Peach's confidential information and the security of other customers; and
  • Customer bearing its own costs associated with the audit.

Nothing in this Section requires Peach to disclose:

  • information relating to other customers;
  • trade secrets;
  • source code;
  • penetration testing reports in their entirety;
  • information that would create a security risk if disclosed; or
  • information restricted by law or contractual confidentiality obligations.

XIII. Cross-Border Data Transfers

Customer acknowledges that Customer Data may be processed in the United States and in other jurisdictions where Peach or its Subprocessors maintain operations, subject to applicable law.

Where Applicable Privacy Laws require specific safeguards for international transfers of Personal Data, Peach will implement commercially reasonable measures designed to satisfy those requirements, including entering into appropriate contractual commitments where required.

Nothing in this Section obligates Peach to store Customer Data in any particular jurisdiction unless expressly agreed in writing between the parties.

XIV. Return or Destruction of Customer Data Upon Request

Upon Customer's written request during the term of the Agreement or following termination of the Services, Peach will use commercially reasonable efforts to provide Customer with access to Customer Data in a commonly used electronic format, where technically feasible.

Following completion of such export, or upon Customer's written instruction, Peach will securely delete Customer Data from its production systems in accordance with the data retention provisions of this DPA.

Peach shall not be required to delete Customer Data that:

  • must be retained to comply with applicable law;
  • is maintained solely within disaster recovery or backup systems until such backups are overwritten through ordinary retention processes;
  • has been de-identified such that it can no longer reasonably identify Customer or any individual; or
  • is retained solely for the establishment, exercise, or defense of legal claims.

Upon reasonable written request, Peach will provide Customer with written confirmation that Customer Data has been deleted in accordance with this Section, except to the extent retention is permitted or required under this DPA.

XV. Subprocessor Changes

Peach may engage new Subprocessors from time to time as necessary to provide, maintain, support, secure, or improve the Services.

Peach will maintain a current list of its material Subprocessors and make such list available to Customers upon request or through a publicly available webpage.

Where required by applicable law or the Agreement, Peach will provide reasonable advance notice before authorizing a new material Subprocessor to Process Customer Data.

If Customer reasonably believes that a proposed Subprocessor presents a material privacy or security concern, Customer may notify Peach in writing within fifteen (15) days after receiving notice.

The parties will work together in good faith to address Customer's concerns. If the parties are unable to reach a reasonable resolution and the proposed Subprocessor would materially and adversely affect Customer's use of the Services, Customer may terminate the affected Services upon written notice, without penalty, within thirty (30) days after the parties determine that no mutually acceptable resolution can be reached.

Nothing in this Section limits Peach's ability to replace Subprocessors for administrative, operational, or emergency reasons where reasonably necessary to maintain the Services.

XVI. Order of Precedence

This DPA supplements the Agreement and applies solely with respect to the Processing of Personal Data and Customer Data.

In the event of a conflict:

  1. this DPA controls with respect to the Processing of Personal Data;
  2. the Agreement controls with respect to all other commercial matters; and
  3. the Terms of Use and Privacy Policy apply except to the extent inconsistent with this DPA or the Agreement.

Nothing in this DPA reduces or limits any privacy, confidentiality, or security obligations expressly agreed upon in the Agreement.

XVII. Term and Termination

This DPA becomes effective on the Effective Date of the Agreement and remains in effect for so long as Peach Processes Customer Data on behalf of Customer.

Termination or expiration of the Agreement automatically terminates this DPA, except that those provisions which by their nature are intended to survive termination shall remain in effect, including provisions relating to confidentiality, limitation of liability, indemnification, return or deletion of Customer Data, and any other obligations that reasonably require continued effect.

XVIII. Miscellaneous

Amendments

No amendment to this DPA shall be effective unless in writing and signed by authorized representatives of both parties, except that Peach may update Exhibit C (Subprocessors) in accordance with this DPA.

Severability

If any provision of this DPA is determined to be invalid or unenforceable, the remaining provisions shall remain in full force and effect.

Waiver

No failure or delay by either party in exercising any right under this DPA shall constitute a waiver of that right.

Assignment

Neither party may assign this DPA except in connection with a merger, acquisition, corporate reorganization, or sale of substantially all of its assets, provided that the assigning party ensures the successor assumes its obligations under this DPA.

Governing Law

This DPA shall be governed by the governing law specified in the Agreement unless otherwise required by Applicable Privacy Laws.

Notices

Any notices required under this DPA shall be delivered in accordance with the notice provisions of the Agreement.

Entire Agreement

This DPA, together with the Agreement and any incorporated exhibits, constitutes the entire agreement of the parties regarding the Processing of Customer Data and supersedes all prior discussions or understandings relating solely to that subject matter.

Exhibit A – Description of Processing

Category
Description
Purpose of Processing
To provide Peach's AI-powered communications, knowledge management, document analysis, search, retrieval, analytics, and workflow platform for higher education institutions.
Categories of Data Subjects
Customer personnel, applicants, students, prospective students, parents or guardians (where applicable), and other individuals whose information Customer uploads to the Services.
Categories of Personal Data
Names, email addresses, communications, uploaded documents, institutional policies, website content, prompts, metadata, and other information Customer elects to Process through the Services.
Nature of Processing
Collection, hosting, storage, document ingestion, website retrieval, text extraction, document analysis, parsing, segmentation, indexing, generation of searchable representations, knowledge retrieval, AI-assisted drafting, summarization, analytics, transmission, support, backup, deletion, and other Processing reasonably necessary to provide the Services.
Duration of Processing
For the duration of the Agreement and any applicable retention period described in this DPA.

Exhibit B – Security Measures

Peach maintains a security program designed to protect Customer Data through administrative, technical, and organizational safeguards, including as appropriate:

  • role-based access controls;
  • authentication and account management;
  • encryption of data in transit;
  • encryption at rest where appropriate;
  • system logging and monitoring;
  • secure software development practices;
  • vulnerability management;
  • backup and recovery procedures;
  • employee confidentiality and security training;
  • incident response procedures;
  • vendor risk management; and
  • periodic review of security practices.

Peach may modify these measures over time provided that the overall level of protection is not materially diminished.

Exhibit C – Subprocessors

Subprocessor
Purpose
Location
Material subprocessors maintained by Peach
Hosting, AI processing, authentication, communications, analytics, and other operational services
Available through Peach's Subprocessor List