Exhibit A — AI & Data Schedule
1. AI Data Processing
Provider will process Customer Data submitted to AI features solely in accordance with the MSPSA, DPA, and applicable Order Form. Provider will not use Customer Data to train generally available models for unrelated customers unless expressly authorized in writing.
2. Model Providers
Provider may use the third-party model providers listed at trivas.ai/trust/subprocessors. Provider will maintain a current list of material AI subprocessors and provide notice of changes as required by the DPA.
3. Retention
AI prompts and Outputs will be retained unless otherwise configured. Security and operational logs may be retained for longer periods as reasonably necessary.
4. Customer Controls
- Role-based access controls.
- Administrative controls for enabling/disabling AI features.
- Configurable retention where supported.
- Audit logs where included in the purchased plan.
- Human-review requirements for high-impact use cases.
- Ability to restrict or disable specified AI models/providers where offered.
5. Regulatory Allocation
Customer remains responsible for determining whether its particular use of the Services is subject to sector-specific or AI-specific regulatory obligations. Provider will reasonably cooperate with Customer’s compliance efforts to the extent required under the applicable DPA, Security Addendum, or Order Form.
.5f521cec.png)