Legal

Data Processing Addendum

Standard hosted-service terms · Version July 28, 2026

This Data Processing Addendum (“DPA”) forms part of an agreement under which GaugeWright LLC provides hosted services to a customer. It applies when GaugeWright processes personal data on the customer's behalf. If a signed agreement contains different data-processing terms, those terms control.

1. Roles and instructions

The customer is controller and GaugeWright is processor, except where law assigns different roles. GaugeWright processes personal data only on documented customer instructions—including the agreement, service configuration, and authorized use—unless law requires otherwise.

2. Processing details

Subject matter: providing, securing, supporting, and maintaining the hosted service. Duration: the agreement plus the limited retention needed for deletion and legal obligations. Data subjects may include customer personnel, users, experts, and people represented in customer-supplied content. Data may include identity, contact, account, audit, usage, support, and customer-selected workspace content. The customer determines frequency and scope through its use.

3. Confidentiality and security

GaugeWright limits access to authorized persons bound by confidentiality and maintains technical and organizational safeguards appropriate to risk, including access control, transport encryption, secret management, tenant isolation, logging, vulnerability management, backup and recovery, and incident response. Current control status is disclosed in the security questionnaire.

4. Subprocessors

The customer authorizes the providers on the current subprocessor list. GaugeWright contractually requires subprocessors to protect personal data consistently with applicable obligations and remains responsible for their processing to the extent required by law and contract. Material additions will be posted before use where reasonably practicable; customers may raise a documented data-protection objection.

5. Requests, assessments, and incidents

Taking into account the nature of processing, GaugeWright will reasonably assist with data-subject requests, security and privacy assessments, regulatory consultation, and breach obligations. GaugeWright will notify the customer without undue delay after confirming a personal-data breach affecting customer data and will provide available information needed for the customer's response. Notification is not an admission of fault.

6. Return and deletion

During the service, supported export and erasure controls are available to authorized users. At termination or on valid instruction, GaugeWright will return or delete customer personal data unless law requires retention. Residual encrypted backup copies remain protected and are deleted through the ordinary backup lifecycle.

7. International transfers

When applicable law requires a transfer mechanism, the parties will use the relevant standard contractual clauses or another lawful mechanism. GaugeWright will provide reasonable information about transfer safeguards on request.

8. Audit information

GaugeWright will make available information reasonably necessary to demonstrate compliance, including public control documentation and relevant test evidence. On reasonable notice and subject to confidentiality, the parties may agree to a proportionate audit that avoids exposing other customers or security-sensitive material. GaugeWright has not represented that it currently holds an independent SOC 2 report.

9. Contact and execution

Questions and execution requests may be sent to Jack@GaugeWright.com. This published version describes GaugeWright's standard terms; it becomes binding through incorporation into an agreement or signature by authorized representatives.