Legal
Data Processing Agreement
1. Introduction and Scope
This Data Processing Agreement ("DPA") forms part of the Terms of Service between GAIO Tech BV ("we," "our," "us," or "GAIO Tech") and you ("Customer," "you," or "your organisation") regarding the processing of personal data in connection with our AI-powered brand intelligence services.
This DPA applies when GAIO Tech processes personal data on behalf of Customer (acting as Data Processor) or when we process personal data for our own business purposes (acting as Data Controller). This agreement ensures compliance with applicable data protection laws, including the Belgian Data Protection Act and the EU General Data Protection Regulation (GDPR).
Important: This DPA supplements but does not replace our Privacy Policy. Both documents should be read together to understand our complete data protection framework.
2. Definitions
For the purposes of this DPA, the following definitions apply:
- Personal Data
- Any information relating to an identified or identifiable natural person processed through our Service.
- Customer Data
- All data, including personal data, that Customer uploads, submits, or provides to GAIO Tech through the Service.
- Processing
- Any operation performed on personal data, including collection, storage, analysis, transmission, and deletion.
- Data Controller
- The entity that determines the purposes and means of processing personal data.
- Data Processor
- The entity that processes personal data on behalf of and under instructions from a Data Controller.
- Sub-processor
- Any third party engaged by GAIO Tech to process personal data on Customer's behalf.
3. Data Controller and Processor Roles
3.1 GAIO Tech as Data Controller
GAIO Tech acts as Data Controller when processing:
- Account registration and authentication data
- Billing and subscription information
- Platform usage analytics and performance metrics
- Customer support communications
- Marketing communications (with consent)
- Security and fraud prevention data
3.2 GAIO Tech as Data Processor
GAIO Tech acts as Data Processor when processing Customer Data that includes personal data:
- Brand analysis data submitted by Customer
- Website content and brand assets uploaded for analysis
- Knowledge tree data and brand intelligence insights
- Custom content and strategies created for Customer
When acting as Data Processor, we process personal data only in accordance with Customer's documented instructions and applicable law.
3.3 Joint Controller Scenarios
In limited circumstances, we may act as Joint Controllers with Customer:
- Product improvement and AI model enhancement using aggregated data
- Industry benchmarking and research (with anonymization)
- Platform optimisation and feature development
Joint Controller arrangements require explicit agreement and clear allocation of responsibilities. We will notify Customer of any such arrangements.
4. Processing Instructions and Purposes
4.1 Customer Instructions
When acting as Data Processor, GAIO Tech will process personal data only:
- As necessary to provide the contracted services
- In accordance with Customer's documented instructions
- As required by applicable law or regulation
- With Customer's explicit written consent for any other purpose
Permitted Processing Activities
- AI-powered brand analysis and intelligence generation
- Knowledge tree creation and visualization
- Brand book generation and optimisation recommendations
- Performance tracking and reporting
- Data backup and disaster recovery
- Security monitoring and threat detection
4.2 Prohibited Processing
GAIO Tech will not, without explicit Customer authorization:
- Use Customer Data to train third-party AI models
- Share personal data with unauthorized third parties
- Process data for marketing to Customer's customers
- Combine Customer Data across different customer accounts
- Use personal data for competitive analysis against Customer
5. Categories of Data and Data Subjects
5.1 Categories of Personal Data
Customer Account Data
- Names and contact information
- Job titles and company details
- Authentication credentials
- Billing and payment information
Usage and Analytics Data
- Platform interaction data
- Feature usage patterns
- Performance metrics
- Error logs and diagnostics
Customer Data
- Brand and business information
- Website content and assets
- Marketing materials
- Strategic planning documents
Communication Data
- Support ticket content
- Email communications
- Chat and messaging data
- Feedback and surveys
5.2 Categories of Data Subjects
- Customer Representatives: Employees, contractors, and authorized users of Customer's organisation
- End Users: Individuals who interact with Customer's brand through AI-optimised content
- Business Contacts: Individuals mentioned in business information submitted for analysis
- Website Visitors: Individuals whose data may be included in website content analysed by our Service
6. Security of Processing
6.1 Technical Safeguards
Encryption
- AES-256 encryption at rest
- TLS 1.3 for data in transit
- End-to-end encryption for sensitive data
- Encrypted database connections
Access Controls
- Multi-factor authentication
- Role-based access control (RBAC)
- Principle of least privilege
- Regular access reviews
Infrastructure Security
- SOC 2 Type II certified infrastructure
- Network segmentation
- Intrusion detection systems
- Automated security monitoring
Data Protection
- Regular security audits
- Penetration testing
- Vulnerability assessments
- Incident response procedures
6.2 Organizational Measures
- Staff Training: Regular data protection and security awareness training
- Background Checks: Enhanced vetting for personnel with data access
- Confidentiality: Binding confidentiality agreements for all staff
- Data Minimization: Processing only necessary data for specified purposes
- Retention Policies: Automated deletion based on retention schedules
7. Sub-processors
7.1 Authorized Sub-processors
GAIO Tech may engage the following sub-processors to assist in providing our Service:
| Service Provider | Service | Location | Purpose |
|---|---|---|---|
| Neon Database | PostgreSQL Hosting | US/EU | Data storage and management |
| SendGrid | Email Delivery | US | Transactional emails |
| OpenAI | AI Processing | US | Brand analysis (processing only) |
| OAuth & Analytics | US/Global | Authentication and usage analytics |
7.2 Sub-processor Requirements
All sub-processors must:
- Provide appropriate technical and organisational security measures
- Process personal data only for specified purposes
- Maintain confidentiality of all processed data
- Assist with data subject rights and compliance obligations
- Delete or return data upon termination of services
- Undergo regular security and compliance audits
7.3 Changes to Sub-processors
We will provide 30 days' advance notice of any new sub-processors. If you object to a new sub-processor on reasonable data protection grounds, you may:
- Request alternative processing arrangements
- Terminate the affected services with 30 days' notice
- Receive a pro-rata refund for prepaid but unused services
8. Data Subject Rights
8.1 Rights Under the EU GDPR
We will assist Customer in fulfilling data subject rights requests:
Information Rights
- Right to be informed
- Right of access
- Right to rectification
- Right to erasure
Control Rights
- Right to restrict processing
- Right to data portability
- Right to object
- Rights related to automated decision-making
8.2 Response Procedures
When we receive a data subject rights request:
- Verification: Confirm identity and verify request legitimacy
- Assessment: Determine our role (Controller vs Processor)
- Coordination: Forward Processor requests to Customer within 3 business days
- Assistance: Provide technical assistance to fulfill requests
- Response: Complete responses within statutory timeframes (typically 30 days)
8.3 Customer Obligations
When acting as Data Controller, Customer must:
- Implement appropriate procedures for handling rights requests
- Verify the identity of data subjects making requests
- Respond to requests within legal timeframes
- Coordinate with GAIO Tech for data processed on Customer's behalf
9. International Data Transfers
9.1 Transfer Mechanisms
When personal data is transferred outside the EU/EEA, we ensure adequate protection through:
Legal Safeguards
- Standard Contractual Clauses (SCCs)
- Adequacy decisions
- Binding Corporate Rules (where applicable)
- Certification schemes
Technical Measures
- End-to-end encryption
- Pseudonymization techniques
- Access controls and monitoring
- Data localization options
9.2 Transfer Impact Assessment
We conduct regular assessments to ensure ongoing adequacy of transfer safeguards, including:
- Legal and regulatory environment in destination countries
- Technical and organisational measures of recipients
- Additional safeguards to address identified risks
- Regular monitoring and review procedures
10. Data Retention and Deletion
10.1 Retention Periods
Account Data
- Active account: Duration of service + 30 days
- Billing records: 7 years (legal requirement)
- Support tickets: 3 years
- Marketing communications: Until consent withdrawn
Customer Data
- Analysis results: Duration of service + 90 days
- Backup copies: 30 days after primary deletion
- Anonymized insights: May be retained indefinitely
- Security logs: 2 years
10.2 Deletion Procedures
Upon termination of services or expiry of retention periods:
- Secure Deletion: Cryptographic erasure and overwriting
- Backup Purging: Automated removal from all backup systems
- Sub-processor Notification: Instructions to delete data
- Certification: Written confirmation of deletion (upon request)
10.3 Legal Hold Exceptions
Deletion may be suspended when data is subject to:
- Legal proceedings or investigations
- Regulatory audit or examination
- Dispute resolution processes
- Compliance with legal obligations
11. Data Breach Notification
11.1 Incident Response Process
In the event of a personal data breach, GAIO Tech will:
Immediate Response (0-24 hours)
- Identify and contain the incident
- Assess the scope and severity
- Implement immediate remediation measures
- Document all response activities
Notification Phase (24-72 hours)
- Notify affected customers without undue delay
- Report to ICO if required by law
- Coordinate with sub-processors as needed
- Provide regular updates on remediation progress
Recovery and Review (Ongoing)
- Complete forensic analysis
- Implement additional preventive measures
- Conduct post-incident review
- Update security procedures based on lessons learned
11.2 Customer Notification
Breach notifications to Customer will include:
- Description of the incident and affected data
- Likely consequences and potential impact
- Measures taken to address the breach
- Recommendations for Customer actions
- Contact information for further inquiries
12. Audits and Compliance
12.1 Audit Rights
Customer has the right to audit GAIO Tech's compliance with this DPA through:
- Documentation Review: Access to relevant policies and procedures
- Compliance Reports: Annual SOC 2 Type II and security audit reports
- Questionnaires: Completion of Customer security assessments
- Third-Party Audits: Independent compliance verification (at Customer's expense)
Audit Conditions: On-site audits require 30 days' advance notice, must be conducted by qualified professionals, and are limited to once per year unless triggered by a security incident.
12.2 Compliance Monitoring
GAIO Tech maintains ongoing compliance through:
- Regular internal audits and assessments
- Continuous monitoring of security controls
- Third-party penetration testing
- Staff training and certification programs
- Vendor risk management and due diligence
13. Termination and Data Return
13.1 Upon Termination
Upon termination of services, Customer may choose:
Data Return
- Export in commonly used formats
- Secure transfer via encrypted channels
- Verification of data integrity
- 30-day retention for data retrieval
Data Deletion
- Secure deletion from all systems
- Removal from backup systems
- Notification to sub-processors
- Deletion certificate (upon request)
13.2 Survival Provisions
The following provisions survive termination:
- Data protection and confidentiality obligations
- Limitation of liability clauses
- Audit rights for a period of 2 years
- Dispute resolution procedures
14. Contact Information
Data Protection Officer: [email protected]
Legal Department: [email protected]
Security Team: [email protected]
General Contact: [email protected]
Postal Address:
GAIO Tech BV
SQ Antwerp Tower - Frankrijklei 5, Office 3.08
2000 Antwerp
Belgium

