DATA PROCESSING ADDENDUM
1. PURPOSE & SCOPE
This Data Processing Addendum ("DPA") forms part of the Subscription Services Agreement between Gaapio, Inc. ("Processor") and the customer entity identified in such agreement ("Controller"). It governs the processing of Personal Data in connection with Controller's use of the Gaapio platform and related services (the "Services").
2. DEFINITIONS
"Personal Data", "Processing", "Controller", "Processor", "Data Subject", and other capitalized terms shall have the meanings given under applicable Data Protection Laws, including the GDPR, CCPA, and similar regulations.
3. ROLES & RESPONSIBILITIES
Controller determines the purposes and means of the Processing of Personal Data. Processor shall process Personal Data only on documented instructions from Controller, including with regard to transfers of Personal Data.
4. CATEGORIES OF PERSONAL DATA
The following categories of Personal Data may be processed: name, email address, job title, employer information, user credentials, usage data, and financial records, contracts, and other business documents uploaded by Controller's users, which may incidentally contain personal data of third parties.
5. DATA SUBJECTS
The Personal Data concerns the following categories of Data Subjects: Controller's employees, contractors, clients, or authorized users.
6. SECURITY MEASURES
Processor implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including encryption, access controls, monitoring, and physical data center protections. Processor maintains a SOC 2 Type 2 certified security program. Current security documentation and certifications are available upon request.
7. SUBPROCESSORS
Processor primarily processes Personal Data in data centers located in the United States. Processor may use subprocessors located in the United States as listed in Appendix 1. Processor will provide Controller with reasonable advance notice before materially changing the geographic location of Personal Data processing.
Controller authorizes the use of subprocessors listed in Appendix 1. Processor shall provide at least thirty (30) days' advance written notice of any intended addition or replacement of subprocessors, and shall allow Controller to object on reasonable grounds within such period prior to the new subprocessor commencing processing. If Controller reasonably objects to a new subprocessor on documented data protection grounds and Processor cannot provide a commercially reasonable alternative, Controller may terminate the affected Services upon written notice.
8. DATA SUBJECT RIGHTS
Processor shall assist Controller in responding to requests from Data Subjects under applicable laws, including access, rectification, erasure, and portability requests.
9. DATA TRANSFERS
If and to the extent Processor processes Personal Data originating from the European Economic Area, United Kingdom, or Switzerland on behalf of Controller, the EU Standard Contractual Clauses for the transfer of personal data to third countries (Module 2: Controller to Processor), as adopted by the European Commission, are hereby incorporated by reference and shall apply automatically. The SCCs shall not apply where no such transfer occurs. In the event of any conflict between the SCCs and this DPA, the SCCs shall prevail with respect to transfers subject to their scope. Processor shall enter into equivalent transfer mechanisms as required by other applicable laws.
10. DELETION OR RETURN OF DATA
Upon termination of the Agreement, Processor shall, at Controller's election, delete or return all Personal Data in its possession within thirty (30) days of the termination date, unless otherwise required by law. Upon request, Processor shall provide written confirmation of deletion.
11. AUDIT RIGHTS
Processor shall make available, upon reasonable written request, information reasonably necessary to demonstrate compliance with this DPA, including relevant third-party audit reports or security documentation, subject to confidentiality obligations. Any audit rights shall be limited to no more than once annually, during normal business hours, upon reasonable advance notice, and in a manner that does not unreasonably interfere with Processor's business operations or compromise the security or confidentiality of other customers' data or systems. In lieu of an on-site audit, Processor shall respond to Controller's reasonable written security questionnaire no more than once per twelve (12) month period. The parties agree that Processor's then-current SOC 2 Type 2 report, together with such questionnaire response, shall satisfy Processor's audit obligations under this DPA, provided no material Security Incident affecting Controller's Personal Data has occurred in the prior twelve (12) months.
12. LIABILITY
Liability under this DPA shall be subject to the limitations of liability in the Subscription Services Agreement.
13. BREACH NOTIFICATION
Processor shall notify Controller without undue delay, and in any event within seventy-two (72) hours of becoming aware, of any confirmed breach of security involving Personal Data ("Security Incident"). Such notice shall include, to the extent then known: (a) a description of the nature of the Security Incident; (b) the categories and approximate number of Data Subjects and Personal Data records affected; (c) likely consequences of the Security Incident; and (d) measures taken or proposed to address the Security Incident. Where full information is not available within 72 hours, Processor shall provide an initial notification and supplement it as additional information becomes available. Notification under this section is provided to satisfy Processor's obligations under this DPA and applicable law and shall not constitute an admission or acknowledgment of fault, liability, or breach by Processor.
14. CONFIDENTIALITY OF PROCESSING PERSONNEL
Processor shall ensure that all personnel authorized to process Personal Data are subject to appropriate confidentiality obligations, whether by contract or applicable law, and that such obligations survive the termination of their engagement.
15. CCPA / U.S. STATE PRIVACY LAWS
To the extent applicable, Processor acknowledges that it acts as a "Service Provider" (as defined under the California Consumer Privacy Act, as amended by the California Privacy Rights Act, and similar U.S. state privacy laws) with respect to Personal Data processed on behalf of Controller. Processor shall not: (a) sell or share Personal Data; (b) retain, use, or disclose Personal Data for any purpose other than providing the Services or as otherwise permitted by applicable law; (c) retain, use, or disclose Personal Data outside the direct business relationship between the parties; or (d) combine Personal Data received from Controller with personal data received from or collected in connection with other persons or sources. Processor certifies that it understands and will comply with the foregoing restrictions.
APPENDIX 1: AUTHORIZED SUBPROCESSORS
- Anthropic, PBC — Large language model inference (Claude) — United States
- OpenAI, L.L.C. — Large language model inference — United States
- Google LLC — Large language model inference (Gemini); cloud storage and serverless function processing (Google Cloud Platform) — United States
- Supabase, Inc. — Database, authentication, and storage — United States
- Vercel Inc. — Application hosting and content delivery — United States
- Resend, Inc. — Transactional email delivery — United States
Note: Each LLM subprocessor is configured under enterprise terms that prohibit use of Customer Content for model training.
IN WITNESS WHEREOF, the parties have executed this Data Processing Addendum as of the Effective Date.
Gaapio, Inc.
By: ___________________________
Name:
Title:
Date: _______________
Customer:
By: ___________________________
Name:
Title:
Date: _______________

