Legal · v1.0 · 2026-09-01
Data Processing Addendum
Standard template — subject to legal review before signing. Contact [email protected] for a redline or a countersigned copy.
This Data Processing Addendum ("DPA") forms part of the agreement between the customer ("Controller") and GTWY AI ("Processor," "we," "us," "our") governing GTWY's processing of personal data on the Controller's behalf through the Services. Where the Standard Contractual Clauses or an equivalent transfer mechanism apply, they are incorporated by reference into Section 7 below.
1. Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person that the Controller submits to, or that is generated by, the Services.
- "Processing" has the meaning given under applicable data protection law (GDPR Art. 4(2), CCPA, or equivalent).
- "Subprocessor" means any third party engaged by GTWY to process Personal Data in providing the Services — see the current list in Section 5.
- "Data Protection Laws" means the GDPR, UK GDPR, the CCPA/CPRA, and any other law applicable to the processing of Personal Data under this DPA.
2. Roles & Scope
The Controller determines the purposes and means of processing its end users' Personal Data. GTWY acts as Processor (or "Service Provider" under the CCPA) and processes Personal Data only as necessary to provide the Services, on the Controller's documented instructions, unless required to do otherwise by law.
Categories of data subjects, data, and processing operations are as described in the Security Whitepaper's Data Security section: authentication credentials and provider API keys, AI prompts/completions/conversation history, and user/organization account metadata.
3. Processor Obligations
- Process Personal Data only on documented instructions from the Controller, including with regard to international transfers.
- Ensure persons authorized to process Personal Data are bound by confidentiality obligations.
- Implement the technical and organizational security measures described in the Security Whitepaper.
- Assist the Controller, insofar as reasonably possible, in responding to data subject requests and in meeting its obligations under Articles 32–36 GDPR (or equivalent).
- Notify the Controller without undue delay after becoming aware of a Personal Data breach affecting the Controller's data.
- At the Controller's choice, delete or return all Personal Data after the end of the provision of Services, and delete existing copies, subject to the retention windows described in Section 6.
4. Confidentiality & Security
GTWY restricts access to Personal Data to personnel who need it to provide the Services, and holds SOC 2 Type II and ISO 27001 certifications covering the controls in place. Full detail is in the Security Whitepaper; audit reports are available under NDA — see the Trust Center.
5. Subprocessors
The Controller provides general authorization for GTWY to engage the Subprocessors listed on the Trust Center. GTWY will give at least 30 days' notice before adding or replacing a Subprocessor, during which the Controller may object on reasonable data protection grounds.
6. Data Retention & Deletion
Retention windows are configurable per account. Soft-deleted records are purged automatically 30 days after deletion. On termination of the underlying agreement, GTWY deletes or returns Personal Data within the documented window described in the Security Whitepaper, except where retention is required by law.
7. International Transfers
GTWY's infrastructure is self-hosted on Google Cloud Platform in a single region located in India. Where Personal Data originating in the EEA, UK, or Switzerland is transferred outside those regions, the transfer is governed by Standard Contractual Clauses (or the UK Addendum, as applicable), incorporated into this DPA by reference. A signed copy is available on request.
8. Audit Rights
GTWY makes available the information reasonably necessary to demonstrate compliance with this DPA, principally through its SOC 2 Type II report and ISO 27001 certificate (available under NDA — see the Trust Center), and permits audits by the Controller or an appointed auditor, subject to reasonable notice and confidentiality terms.
9. Liability & Term
This DPA remains in effect for as long as GTWY processes Personal Data on the Controller's behalf under the underlying agreement. Liability under this DPA is subject to the limitations set out in the Terms of Service.
10. Contact
Data protection contact: [email protected]. To request a redline or a countersigned copy of this DPA, email that address with your company name and the agreement it attaches to.
Last updated 2026-09-01. This is a standard template — the version you sign may include customer-specific terms agreed during legal review.