Version 1.2.0 (Effective: June 25, 2026)
Effective Date: June 25, 2026 Version: 1.2.0
This Data Processing Agreement ("DPA") is entered into by and between the customer identified in the applicable service agreement ("Customer" or "Controller") and GridBoost, Inc., a Delaware corporation ("Provider" or "Processor"), and is incorporated into and forms part of the GridWonk Terms of Service or other written agreement between the parties governing Customer's use of the Service (the "Agreement").
This DPA sets forth the parties' obligations with respect to the processing and security of Personal Data in connection with the Service. In the event of a conflict between this DPA and the Agreement, this DPA shall prevail with respect to the processing of Personal Data.
For the purposes of this DPA, the following terms have the meanings set forth below. Capitalized terms not defined herein have the meanings set forth in the Agreement.
1.1 "Controller" means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. For the purposes of this DPA, Customer is the Controller.
1.2 "Data Protection Laws" means all applicable laws, regulations, and legal requirements relating to (a) privacy, data protection, and data security, and (b) the Processing of Personal Data, including, where applicable, the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), the Virginia Consumer Data Protection Act (VCDPA), the Colorado Privacy Act (CPA), the Connecticut Data Privacy Act (CTDPA), the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK General Data Protection Regulation, and any implementing or successor legislation.
1.3 "Data Subject" means an identified or identifiable natural person to whom Personal Data relates.
1.4 "Personal Data" means any information relating to an identified or identifiable natural person that is Processed by Provider on behalf of Customer in connection with the Service. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
1.5 "Processing" (and its cognates "Process" and "Processed") means any operation or set of operations performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
1.6 "Sub-processor" means any third-party entity engaged by Provider to Process Personal Data on behalf of Customer in connection with the Service.
1.7 "Supervisory Authority" means an independent public authority established by a member state of the European Economic Area, the United Kingdom, or any other jurisdiction pursuant to applicable Data Protection Laws, which is responsible for monitoring the application of Data Protection Laws.
1.8 "Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data transmitted, stored, or otherwise Processed by Provider or its Sub-processors in connection with the Service.
1.9 "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to processors established in third countries, as approved by the European Commission or other competent authority under applicable Data Protection Laws.
1.10 "Operational Backup" means a short-term disaster-recovery copy of Personal Data maintained solely for service continuity, resiliency, restoration testing, and related security operations.
1.11 "Regulatory Archive" means Customer-elected long-term retention of designated records subject to regulatory, audit, contractual, or legal-hold requirements, governed by an Order, retention schedule, or archive addendum separate from Operational Backups.
1.12 "Legal Hold" means a directive to preserve records relevant to pending or reasonably anticipated litigation, audit, regulatory inquiry, governmental proceeding, or similar legal obligation.
1.13 "CEII-Designated Data" means customer-designated sensitive infrastructure data that Customer identifies as Critical Energy Infrastructure Information (CEII) or as requiring CEII-equivalent handling under the Agreement.
Customer is the Controller of Personal Data, and Provider is the Processor of Personal Data. Provider shall Process Personal Data only as a Processor acting on behalf of Customer and in accordance with Customer's documented instructions as described in this DPA and the Agreement.
Provider Processes Personal Data solely to provide, maintain, and improve the Service as described in the Agreement. The details of the Processing are as follows:
Customer shall comply with its obligations under applicable Data Protection Laws with respect to its Processing of Personal Data and its instructions to Provider. Customer is responsible for ensuring that it has obtained all necessary consents, authorizations, and legal bases required under applicable Data Protection Laws for Provider to Process Personal Data as contemplated by this DPA and the Agreement.
Provider shall Process Personal Data only on the basis of Customer's documented instructions, unless Processing is required by applicable law to which Provider is subject. Customer's documented instructions for the Processing of Personal Data are set forth in:
Provider shall promptly inform Customer if, in Provider's reasonable opinion, an instruction from Customer infringes or would cause Provider to infringe applicable Data Protection Laws. Provider shall not be required to carry out any instruction that it reasonably believes would violate applicable law, and Provider may suspend performance of the relevant Processing activity until Customer modifies the instruction or confirms its lawfulness.
To the extent Customer requires Processing activities beyond the scope of the instructions set forth in Section 3.1, such additional instructions must be agreed upon in writing by both parties and may be subject to additional fees.
Provider shall ensure that all personnel authorized to Process Personal Data on its behalf are bound by appropriate confidentiality obligations, whether by contract or statutory duty. Such obligations shall survive the termination of the individual's engagement with Provider.
Provider shall limit access to Personal Data to those personnel who require access to perform Provider's obligations under the Agreement and this DPA. Provider shall ensure that such personnel Process Personal Data only in accordance with Customer's documented instructions, except where otherwise required by applicable law.
Provider shall implement and maintain appropriate technical and organizational measures designed to protect Personal Data against unauthorized or unlawful Processing and against accidental loss, destruction, damage, theft, or alteration. These measures shall be appropriate to the risk and shall include, at a minimum, the measures described in Annex A (Technical and Organizational Measures) attached to this DPA.
Provider's security measures include, but are not limited to:
Provider shall not materially decrease the overall level of security provided for Personal Data during the term of this DPA. Provider may update or modify specific security measures from time to time, provided that such updates do not result in a material reduction of the overall security posture.
Customer provides general written authorization for Provider to engage Sub-processors to Process Personal Data in connection with the Service, subject to the requirements of this Section 6.
As of the Effective Date, Provider engages the following Sub-processors:
| Sub-processor | Purpose | Location | |---|---|---| | Anthropic | AI model processing and inference | United States | | Google Cloud / Gemini | AI model processing and document digitization | United States | | Google Cloud Platform | Backup storage and operational infrastructure | United States | | Supabase | Database hosting, authentication, and storage | United States | | Vercel | Application hosting and edge network | United States | | PostHog | Product analytics and usage telemetry | United States |
An up-to-date list of Sub-processors is maintained at Provider's website and may be updated from time to time in accordance with this Section 6.
Provider shall notify Customer at least thirty (30) days before engaging any new Sub-processor or materially changing the scope of an existing Sub-processor's Processing activities. Notification shall be provided via email to the address associated with Customer's account and/or through a notification mechanism within the Service.
Customer may object to a new Sub-processor within fifteen (15) days of receiving notice pursuant to Section 6.3, provided that Customer's objection is based on reasonable grounds relating to the protection of Personal Data. Customer's objection must be submitted in writing and must specify the reasonable grounds for the objection.
Upon receiving a timely objection, Provider shall use commercially reasonable efforts to make available to Customer a change in the Service or recommend a commercially reasonable alternative Sub-processor. If Provider is unable to resolve Customer's objection within thirty (30) days of receiving it, Customer may terminate the portion of the Agreement relating to the Service that cannot be provided without the objected-to Sub-processor, without penalty, by providing written notice to Provider.
Provider shall:
Provider shall assist Customer, by appropriate technical and organizational measures and to the extent reasonably possible, in fulfilling Customer's obligations to respond to requests from Data Subjects exercising their rights under applicable Data Protection Laws, including rights of access, rectification, erasure, restriction of Processing, data portability, and objection.
If Provider receives a request directly from a Data Subject regarding Personal Data Processed on behalf of Customer, Provider shall promptly notify Customer and shall not respond to the request directly unless authorized by Customer or required by applicable law. Provider shall provide Customer with commercially reasonable cooperation and assistance in relation to the handling of such requests.
Provider shall make available to Customer, through the Service's functionality or upon reasonable request, the technical capabilities necessary to assist Customer in responding to Data Subject requests, including the ability to access, export, correct, and delete Personal Data associated with individual Data Subjects.
In the event of a Security Incident, Provider shall notify Customer without undue delay and in any event within seventy-two (72) hours after becoming aware of the Security Incident. Notification shall be provided to the email address associated with Customer's account and, where available, through the Service's notification mechanisms.
Provider's notification shall include, to the extent reasonably available at the time of notification:
Where it is not possible to provide all of the information specified in Section 8.2 at the time of the initial notification, Provider shall provide the information in phases without further undue delay as it becomes available.
Provider shall cooperate with Customer and take commercially reasonable steps to assist Customer in investigating, mitigating, and remediating the Security Incident. Provider shall preserve and provide to Customer relevant evidence and logs relating to the Security Incident to the extent within Provider's possession or control.
Provider's notification of a Security Incident to Customer shall not be construed as an acknowledgment of fault or liability by Provider. Customer retains sole responsibility for determining whether a Security Incident triggers notification obligations to Data Subjects, Supervisory Authorities, or other parties under applicable Data Protection Laws.
Personal Data is Processed primarily within the United States. Provider shall not transfer Personal Data to a country or territory outside the United States without Customer's prior knowledge, except as necessary to engage Sub-processors listed in Section 6.2 or otherwise approved by Customer.
To the extent that the Processing of Personal Data involves a transfer of Personal Data from the European Economic Area, the United Kingdom, or Switzerland to a jurisdiction that has not been recognized as providing an adequate level of data protection:
Provider certifies that it is not aware of any laws or practices in the jurisdictions where Personal Data is Processed that would prevent it from fulfilling its obligations under this DPA and any applicable Standard Contractual Clauses. Provider shall notify Customer promptly if it becomes aware of any change in applicable law that may materially affect its ability to comply with this DPA.
Customer may audit Provider's compliance with this DPA up to one (1) time per twelve (12) month period. Customer shall provide Provider with at least thirty (30) days' prior written notice of any audit, including the proposed scope and duration.
Audits shall be conducted during Provider's normal business hours, in a manner that minimizes disruption to Provider's operations, and subject to reasonable confidentiality obligations. Customer may engage a qualified independent third-party auditor to conduct the audit on Customer's behalf, provided that such auditor enters into appropriate confidentiality agreements.
Provider may satisfy Customer's audit request by providing Customer with a copy of Provider's most recent SOC 2 Type II report (or equivalent independent third-party audit report or certification) that covers the Service. If such report does not reasonably address Customer's audit concerns, Customer retains the right to conduct an on-site audit in accordance with Sections 10.1 and 10.2.
Customer shall bear the costs associated with any audit initiated by Customer, including Customer's internal costs and the fees of any third-party auditor engaged by Customer. Provider shall bear its own costs in facilitating the audit, including making personnel and documentation reasonably available.
If an audit reveals a material non-compliance with this DPA, Provider shall promptly develop and implement a remediation plan to address the identified issues. Provider shall inform Customer of the remediation plan and its progress within a reasonable timeframe.
Upon termination or expiration of the Agreement, Provider shall make Customer's Personal Data available for export through the Service's standard export functionality for a period of sixty (60) days following the effective date of termination or expiration (the "Export Period").
Unless the Agreement, a Regulatory Archive schedule, or applicable law states otherwise, Provider shall delete Personal Data from active systems within ninety (90) days after the Export Period ends and shall remove Personal Data from Operational Backups within an additional commercially reasonable period not to exceed ninety (90) days after active-system deletion. During that period, Provider will continue to protect Personal Data in accordance with this DPA and the Agreement.
Upon Customer's written request following the completion of deletion, Provider shall provide Customer with written certification confirming that all Personal Data has been deleted in accordance with this Section 11.
To the extent that applicable law, a Legal Hold, or a customer-elected Regulatory Archive requires Provider to retain copies of Personal Data beyond the periods specified in this Section 11, Provider shall (a) isolate and protect such Personal Data from further Processing except as required by the applicable obligation, (b) continue to apply the security measures specified in this DPA, and (c) delete such Personal Data promptly when the applicable legal requirement, Legal Hold, or Regulatory Archive schedule expires.
This DPA shall become effective on the Effective Date and shall remain in effect for the duration of the Agreement.
The obligations of Provider under this DPA with respect to the Processing and security of Personal Data shall survive the termination or expiration of the Agreement and this DPA until all Personal Data has been deleted or returned in accordance with Section 11. Sections 1 (Definitions), 8 (Data Breach), 10 (Audits), 11 (Deletion and Return of Personal Data), 12 (Term), and 13 (Liability) shall survive termination or expiration of this DPA.
Each party's liability under or in connection with this DPA shall be subject to the limitations and exclusions of liability set forth in the Agreement.
To the extent permitted by applicable Data Protection Laws, where a party is held liable for damage caused by Processing that infringes applicable Data Protection Laws, the parties shall be liable only to the extent of their respective responsibility for the Processing that caused the damage, subject to the terms of the Agreement.
The following technical and organizational measures are implemented by Provider to protect Personal Data Processed in connection with the Service. These measures are subject to periodic review and update to reflect changes in technology, threats, and best practices.
For questions about this Data Processing Agreement, please contact:
GridBoost, Inc. Email: contact@gridwonk.com