Data Processing
Data Processing Addendum
Last updated February 26, 2026 · Version 2026-07-11
1. Roles
The Controller determines the purposes and means of processing personal data submitted to the Platform. G3 AI processes such personal data as a Processor (Service Provider, under the CCPA/CPRA), on documented instructions from the Controller.
2. Subject matter, duration, and categories
- Subject matter: provision of the G3 AI platform to the Controller.
- Duration: the term of the order form plus the retention period stated below.
- Categories of data subjects: the Controller's employees, contractors, members, and any individuals whose data the Controller uploads.
- Categories of personal data: identifiers, contact information, professional information, content the Controller submits, and any additional categories the Controller chooses to upload.
- Special-category data: the Controller must not submit special categories of personal data (Article 9 GDPR) unless expressly authorized in writing.
3. Processor obligations
- Process personal data only on the Controller's documented instructions, including with regard to transfers.
- Ensure that persons authorized to process personal data are bound by confidentiality.
- Implement the technical and organizational measures described in the Security & Compliance page.
- Assist the Controller in responding to data-subject requests and in meeting its own security, breach-notification, DPIA, and prior-consultation obligations.
- Make available all information reasonably necessary to demonstrate compliance and allow for and contribute to audits, subject to reasonable confidentiality and scoping.
4. Subprocessors
The Controller grants a general authorization for G3 AI to engage subprocessors necessary to provide the Platform (hosting, database, email delivery, error monitoring, payment processing, and AI inference). G3 AI will:
- maintain a current list of subprocessors, available at privacy@g3ai.io;
- impose data-protection terms on each subprocessor that are at least as protective as this DPA; and
- notify the Controller of intended additions or replacements, giving the Controller a reasonable opportunity to object on legitimate grounds.
5. International transfers
Where personal data is transferred from the EEA, UK, or Switzerland to a country not recognized as providing an adequate level of protection, the parties agree that the European Commission's Standard Contractual Clauses (2021/914) apply and are hereby incorporated by reference, with the UK Addendum and Swiss addendum as applicable. G3 AI will implement any supplementary measures required by the transfer impact assessment.
6. Security measures
G3 AI implements and maintains appropriate technical and organizational measures designed to ensure a level of security appropriate to the risk, including encryption in transit and at rest, least-privilege access, multi-factor authentication for administrators, network segmentation, logging and monitoring, regular vulnerability scanning, and a documented incident-response plan.
7. Personal data breach notification
G3 AI will notify the Controller without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a personal data breach affecting the Controller's personal data, and will provide information reasonably needed for the Controller to meet its own notification obligations.
8. Data-subject requests
G3 AI will, taking into account the nature of the processing, assist the Controller by appropriate technical and organizational measures, insofar as this is possible, to fulfill the Controller's obligation to respond to requests from data subjects. G3 AI will forward any such request received directly to the Controller and will not respond except on the Controller's instructions or as required by law.
9. Return or deletion
On termination of the order form, and at the Controller's choice, G3 AI will return or delete all personal data processed on the Controller's behalf within thirty (30) days, and will delete existing copies unless applicable law requires storage. Backup copies are overwritten in the ordinary course.
10. CCPA / CPRA
To the extent G3 AI processes personal information subject to the CCPA/CPRA on the Controller's behalf, G3 AI is a "service provider". G3 AI will not: (a) sell or share personal information; (b) retain, use, or disclose personal information outside the direct business relationship or for any purpose other than the specified business purpose; or (c) combine personal information received from the Controller with personal information received from another source, except as permitted by law.
11. Governing terms
This DPA forms part of the underlying agreement between the parties. In case of conflict, this DPA prevails on data-protection matters. All other terms remain in effect.
Questions about this document? Email legal@g3ai.io.

