This Data Processing Addendum (“DPA”) is incorporated into the Groundwork Software License and Subscription Terms (the “Terms”) by the Order Form and forms part of the Agreement. Capitalized terms not defined here have the meanings given in the Terms.
1. DEFINITIONS AND ROLES#
1.1 Definitions. “Data Protection Laws” means all laws relating to the processing of Personal Data applicable to a party in respect of the Platform, which may include the Texas Data Privacy and Security Act, the California Consumer Privacy Act as amended, other United States state privacy laws, and where applicable the EU and UK General Data Protection Regulation. “Personal Data”, “processing”, “controller”, “processor”, “data subject” and “personal data breach” have the meanings given in the applicable Data Protection Laws. “Customer Personal Data” means Personal Data contained in Customer Data and processed by Groundwork under the Agreement.#
1.2 Roles. Customer is the controller and Groundwork is the processor in respect of Customer Personal Data. Where Customer is itself a processor for a third-party controller, Customer warrants that it has authority to appoint Groundwork as a sub-processor on these terms.#
1.3 Scope. This DPA applies only to the processing of Customer Personal Data. Operational, industrial and telemetry data that does not identify or relate to an identified or identifiable natural person is not Customer Personal Data and is governed by the Terms alone.#
2. PROCESSING
2.1 Documented instructions. Groundwork shall process Customer Personal Data only on Customer’s documented instructions, which comprise the Agreement, the configuration of the Platform by or for Customer, and any further written instruction agreed by the parties. Annex A sets out the subject matter, duration, nature and purpose of processing, the categories of data subject and Personal Data, and the frequency of transfer.#
2.2 Unlawful instruction. Groundwork shall inform Customer if, in its opinion, an instruction infringes Data Protection Laws, and may suspend the affected processing until the instruction is withdrawn or amended.#
2.3 Legal requirement. Where Groundwork is required by law to process Customer Personal Data other than on Customer’s instructions, Groundwork shall inform Customer of that requirement before processing unless the law prohibits it.#
2.4 Confidentiality. Groundwork shall ensure that persons authorized to process Customer Personal Data are subject to an appropriate obligation of confidentiality and are granted access only to the extent necessary.#
2.5 No sale or independent use. Groundwork shall not sell or share Customer Personal Data as those terms are defined in applicable United States state privacy laws, shall not retain, use or disclose it for any purpose other than performing the Agreement, and shall not combine it with Personal Data from another source except as necessary to perform the Agreement. Aggregated or de-identified data used under Section 8.4 of the Terms is not Customer Personal Data, and Groundwork shall not attempt to re-identify it.#
3. SECURITY#
3.1 Measures. Groundwork shall implement and maintain the technical and organizational measures set out in Annex B, having regard to the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing and the risks to data subjects.#
3.2 Changes. Groundwork may update the measures in Annex B provided that no update materially reduces the overall level of protection during a Subscription Term.#
4. SUB-PROCESSORS#
4.1 Authorization. Customer grants Groundwork general written authorization to engage the sub-processors listed in Annex C, and to engage further sub-processors in accordance with this Section.#
4.2 Notice and objection. Groundwork shall give Customer not less than thirty (30) days’ notice before engaging a new sub-processor. Customer may object on reasonable grounds relating to data protection within that period. Where the parties cannot resolve the objection, Customer may terminate the affected Order Form on written notice and receive a pro-rata refund of prepaid fees for the unexpired term, which is Customer’s sole remedy.#
4.3 Terms and responsibility. Groundwork shall impose on each sub-processor data protection obligations no less protective than those in this DPA, and remains fully liable to Customer for the performance of each sub-processor’s obligations.#
5. DATA SUBJECT RIGHTS AND ASSISTANCE#
5.1 Requests. Groundwork shall promptly notify Customer of any request it receives from a data subject relating to Customer Personal Data, and shall not respond except on Customer’s instructions or as required by law.#
5.2 Assistance. Taking into account the nature of the processing, Groundwork shall provide reasonable assistance by appropriate technical and organizational measures to enable Customer to respond to data subject requests, and reasonable assistance with data protection impact assessments and prior consultations, in each case at Customer’s cost where the assistance requires more than de minimis effort.#
6. PERSONAL DATA BREACH#
6.1 Notification. Groundwork shall notify Customer without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a personal data breach affecting Customer Personal Data.#
6.2 Content. The notification shall describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Where the information is not available at the time of notification, Groundwork shall provide it in phases without undue further delay.#
6.3 Cooperation. Groundwork shall take reasonable steps to mitigate and remediate the breach and shall reasonably cooperate with Customer in Customer’s notification obligations. Notification under this Section is not an acknowledgement of fault or liability.#
7. DELETION AND RETURN#
7.1 On expiry or termination, Groundwork shall delete Customer Personal Data in accordance with Section 7.4 of the Terms, save that Groundwork may retain Customer Personal Data to the extent required by law and may retain copies held in routine automated backup systems, which are deleted on their ordinary cycle. Retained data remains subject to this DPA for so long as it is retained. Groundwork shall certify deletion in writing on request.#
8. AUDIT AND INFORMATION#
8.1 Information. Groundwork shall make available to Customer the information reasonably necessary to demonstrate compliance with this DPA, including any current third-party audit report, certification, or completed security questionnaire that Groundwork makes generally available.#
8.2 Audit. Where the information provided under Section 8.1 is not sufficient, Customer may audit Groundwork’s compliance not more than once in any twelve (12) month period, on not less than thirty (30) days’ written notice, during business hours, without unreasonable disruption, and subject to confidentiality obligations. Customer shall bear its own costs and Groundwork’s reasonable costs of supporting the audit. An audit shall not extend to any data, system or premises relating to another customer of Groundwork.#
8.3 Additional audits. Customer may audit more frequently where required by a supervisory authority or following a personal data breach affecting Customer Personal Data.#
9. INTERNATIONAL TRANSFERS#
9.1 Customer Personal Data is processed in the United States. Where Data Protection Laws require a transfer mechanism for any transfer of Customer Personal Data outside its territory of origin, the parties shall enter into the applicable standard contractual clauses or other lawful transfer mechanism, which shall apply in addition to this DPA and shall prevail in the event of conflict with it.#
10. LIABILITY AND PRECEDENCE#
10.1 Liability. Each party’s liability arising out of or in connection with this DPA is subject to the limitations and exclusions in Section 12 of the Terms. This DPA does not create any separate or additional cap.#
10.2 Precedence. In the event of conflict between this DPA and the Terms in relation to the processing of Customer Personal Data, this DPA controls. In all other respects the Terms control.#
10.3 Term. This DPA takes effect on the effective date of the Order Form incorporating it and continues while Groundwork processes Customer Personal Data.#
Annex A. Details of processing
| Subject matter | Provision of the Platform under the Agreement. |
|---|---|
| Duration | The Subscription Term, plus the deletion period in Section 7 of this DPA. |
| Nature and purpose | Authentication and authorization of Authorized Users; recording and displaying attributable governance actions; access and security logging; provision of support; operation, security and maintenance of the Platform. |
| Categories of data subject | Customer’s Authorized Users, comprising its employees and the personnel of its contractors and delivery partners. |
| Categories of Personal Data | Identity and directory attributes (name, business email address, organizational identifier, group and role claims received from Customer’s identity provider); authentication events; access and audit logs including timestamps and network address; and governance action records identifying the individual who approved, signed, changed or published a definition, threshold, mapping or surface, and when. |
| Special categories | None. Customer shall not submit special categories of Personal Data to the Platform. |
| Data not within scope | Operational, industrial, telemetry and derived figures that do not identify or relate to an identified or identifiable natural person. |
| Frequency of transfer | Continuous during the Subscription Term. |
| Location of processing | United States. |
| Controller contact | As stated in the Order Form. |
Annex B. Technical and organizational measures
| Access control | Authentication through Customer’s identity provider using OpenID Connect. Role-based authorization derived from group claims. Least-privilege access for Groundwork personnel, reviewed on a defined cycle and revoked on role change or departure. Multi-factor authentication required for all administrative access. |
|---|---|
| Data in transit | TLS 1.2 or higher for all connections to the Platform and to Customer Sources. |
| Data at rest | Encryption at rest for stored configuration, credentials and logs. Credentials for Customer Sources held server-side in a managed secret store and never exposed to a client. |
| Data minimization | The Platform reads Customer Sources under Customer’s own catalog governance and retains no operational data at rest beyond serving copies necessary to render current state. |
| Logging and monitoring | Access, authentication and administrative actions logged. Governance actions recorded with actor and timestamp. Logs protected against unauthorized alteration and retained for a defined period. |
| Change management | Changes to the Platform pass a validation gate before release. Deterministic assembly from vetted components with reproducible builds. Changes are recorded and attributable. |
| Segregation | Logical separation of each customer’s configuration, credentials and data. |
| Resilience | Backup of configuration and governance records, with restoration tested on a defined cycle. |
| Vulnerability management | Dependency monitoring, patching of the Platform and its runtime on a defined cycle, and prioritized remediation of vulnerabilities by severity. |
| Personnel | Background screening consistent with applicable law, confidentiality obligations, and security awareness training. |
| Incident response | A documented incident response process covering detection, containment, notification under Section 6 of this DPA, remediation and review. |
| Sub-processor management | Diligence before engagement and contractual flow-down of the obligations in this DPA. |
Annex C. Sub-processors
As at the effective date of this DPA, Groundwork engages the following sub-processors in the processing of Customer Personal Data. The current list is published at groundwork4ai.com/legal/subprocessors.
| Sub-processor | Purpose | Location | Data processed |
|---|---|---|---|
| Cloudflare, Inc. | Hosting of the Platform | United States | All categories in Annex A |
| Microsoft, Inc. | Authentication support | United States | Identity and authentication events |
| Supabase Pte. Ltd | Data storage and backup | United States | Categories of Data |
| Linear Orbit, Inc. | Handling of support requests | United States | Identity and contact details of named contacts |
