This Data Processing Addendum (“DPA”) is part of the Terms of service between The Overton Window Company, Inc. (“Overton”, “we”) and the customer that has agreed to them (“Customer”). It applies automatically whenever we process Customer Personal Data, with no signature needed. A countersigned copy is available on request at support@gbrain.io.
1. Definitions
“Controller”, “processor”, “personal data”, “processing”, “data subject”, “personal data breach” and “supervisory authority” have the meanings given in the GDPR. In addition:
- “Data Protection Laws” means the EU General Data Protection Regulation 2016/679 (“GDPR”); the GDPR as it forms part of UK law and the UK Data Protection Act 2018; the Swiss Federal Act on Data Protection (“FADP”); and any other data protection law that applies to the processing under the Terms.
- “Customer Personal Data” means personal data within Customer Data, as defined in Privacy section 1, that we process on Customer’s behalf to provide the service.
- “Subprocessor” means a third party we engage to process Customer Personal Data.
- “SCCs” means the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914.
2. Roles
For Customer Personal Data, Customer is the controller (or a processor acting for its own customers) and Overton is the processor (or subprocessor). Each party will comply with the Data Protection Laws that apply to it.
Overton is a controller, not a processor, for the account, billing and security data it needs to run its business, such as who signed in and payment records. Privacy describes that processing.
3. Instructions
We process Customer Personal Data only on Customer’s documented instructions, unless the law requires otherwise, in which case we will tell Customer before processing unless the law forbids it.
The Terms, this DPA, and Customer’s use and configuration of the service are Customer’s complete instructions. They authorize us to process Customer Personal Data to provide, maintain, monitor, debug, secure and support the service, including automated review of conversations to detect failures. We do not use Customer Personal Data for marketing, we do not sell it, and we do not use it to train AI models.
If we believe an instruction infringes Data Protection Laws, we will tell Customer. Annex 1 describes the processing.
4. Confidentiality
Everyone we authorize to process Customer Personal Data is bound by a duty of confidentiality, and access is limited to the people who need it to run or support the service.
5. Security
We maintain the technical and organizational measures described in Security (Annex 2), taking into account the nature of the processing and the risks to data subjects. We may change those measures, provided a change does not materially lower the overall level of protection.
6. Subprocessors
Customer gives general authorization for us to engage Subprocessors. The current list is in Privacy section 6 (Annex 3).
We will give at least 30 days’ notice before adding or replacing a Subprocessor, by email to workspace admins and by updating that list. Customer may object on reasonable data protection grounds within that period. If we cannot resolve the objection, Customer may terminate the affected service and receive a refund of prepaid fees for the unused term.
We bind each Subprocessor to data protection obligations no less protective than this DPA, and we remain responsible for its performance of them.
Optional features that run on our accounts with their vendors process Customer Personal Data only when Customer turns them on. They are listed with the other Subprocessors, and turning one on authorizes its vendor.
Applications, accounts and AI clients that Customer connects to the service, such as Gmail, Slack, GitHub or an application from the directory, are chosen and directed by Customer. They are not our Subprocessors, and Customer’s own terms with them govern their processing.
7. Data subject requests
Taking into account the nature of the processing, we will help Customer respond to requests from data subjects to exercise their rights under Data Protection Laws. Customer can delete brains and workspaces in the service, and we will provide exports and carry out deletions on request at support@gbrain.io. If a data subject contacts us directly about Customer Personal Data, we will refer them to Customer and will not otherwise respond, unless the law requires us to.
8. Personal data breaches
We will notify Customer without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice will describe, as far as the information is available, the nature of the breach, its likely consequences and the measures taken or proposed, and we will add to it as we learn more. A notification is not an acknowledgment of fault or liability.
9. Impact assessments and consultations
We will give Customer reasonable assistance with data protection impact assessments and prior consultations with supervisory authorities that relate to the service. Where a request goes beyond the information we publish, the assistance is at Customer’s cost.
10. Deletion and return
Until the Terms end, Customer can export its data as described in Move your GBrain out of a workspace and delete it in the service. When the Terms end, we delete Customer Personal Data, unless the law requires us to keep it. Copies in backups are deleted on the backups’ normal rotation and are not processed in the meantime except to maintain the backups.
11. Audits
This DPA, Security and Privacy are the information we make available to demonstrate compliance with this DPA. If that information is not sufficient, if a supervisory authority requires it, or after a personal data breach affecting Customer, Customer may audit our compliance with this DPA once in any 12 months, on at least 30 days’ written notice, at Customer’s cost, by review of documents, and subject to confidentiality. Security questionnaires and other custom reviews are available under an enterprise agreement.
12. International transfers
We process Customer Personal Data in the United States, and our Subprocessors process it in the locations listed in Annex 3.
Where Customer Personal Data is transferred from the European Economic Area to a country without an adequacy decision, the SCCs are incorporated into this DPA by reference, with Customer as data exporter and Overton as data importer, and apply as follows:
- Module Two (controller to processor) applies where Customer is a controller, and Module Three (processor to processor) where Customer is a processor.
- Clause 7 (docking clause) applies.
- Clause 9(a): Option 2, general written authorization, with the notice period in section 6.
- Clause 11(a): the optional wording does not apply.
- Clause 13: the competent supervisory authority is determined under Clause 13(a).
- Clauses 17 and 18: the law and courts of Ireland.
- Annexes I, II and III of the SCCs are completed by Annexes 1, 2 and 3 of this DPA.
For transfers from the United Kingdom, the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner applies, completed with the information in this DPA. For transfers from Switzerland, the SCCs apply with references to the GDPR read as references to the FADP where relevant, and the Swiss Federal Data Protection and Information Commissioner as the competent supervisory authority.
If the SCCs conflict with this DPA, the SCCs prevail.
13. Liability and precedence
Each party’s liability under this DPA is subject to the limitations in the Terms, except where Data Protection Laws or the SCCs do not allow it. If this DPA conflicts with the Terms, this DPA prevails for the processing of personal data.
14. Changes
We may update this DPA to reflect changes in Data Protection Laws or in the service, with notice under the change policy in Privacy section 14. No update will lower the protection this DPA gives Customer Personal Data.
Annex 1: Details of the processing
| Data exporter | Customer, as identified in its account. Role: controller, or processor for its own customers |
| Data importer | The Overton Window Company, Inc., San Francisco, California, USA. Contact: support@gbrain.io. Role: processor |
| Data subjects | Customer’s users, and people whose data Customer, its users or its connected accounts put into the service, such as correspondents in connected mail, attendees in connected calendars and people named in notes |
| Categories of data | What Customer chooses to put into the service, which may include names, contact details, messages, documents and notes, and the metadata of using the service |
| Special categories | Not intended. The service applies no safeguards to special category data beyond those in Annex 2 |
| Frequency | Continuous, for as long as Customer uses the service |
| Nature and purpose | Hosting AI workspaces: storing, indexing and searching Customer’s data; sending prompts to AI models; acting on connected accounts on Customer’s instructions; and maintaining, monitoring, debugging, securing and supporting the service |
| Duration | The term of the Terms, until deletion under section 10 |
| Transfers to Subprocessors | As listed in Annex 3, for the same nature, purpose and duration |
Annex 2: Technical and organizational measures
The measures described in Security: a dedicated machine and encrypted storage volume for each brain; encryption in transit and at rest, with application-layer encryption of credentials; authentication and authorization controls; restricted operator access; logging and monitoring; backups; vulnerability handling; and incident response.
Annex 3: Subprocessors
The list in Privacy section 6, with what each Subprocessor does and where it processes data.