Data Processing Addendum
Standard hosted-service terms · Version July 28, 2026
This Data Processing Addendum (“DPA”) forms part of an agreement under which GaugeWright LLC provides hosted services to a customer. It applies when GaugeWright processes personal data on the customer's behalf. If a signed agreement contains different data-processing terms, those terms control.
1. Roles and instructions
The customer is controller and GaugeWright is processor, except where law assigns different roles. GaugeWright processes personal data only on documented customer instructions—including the agreement, service configuration, and authorized use—unless law requires otherwise.
2. Processing details
Subject matter: providing, securing, supporting, and maintaining the hosted service. Duration: the agreement plus the limited retention needed for deletion and legal obligations. Data subjects may include customer personnel, users, experts, and people represented in customer-supplied content. Data may include identity, contact, account, audit, usage, support, and customer-selected workspace content. The customer determines frequency and scope through its use.
3. Confidentiality and security
GaugeWright limits access to authorized persons bound by confidentiality and maintains technical and organizational safeguards appropriate to risk, including access control, transport encryption, secret management, tenant isolation, logging, vulnerability management, backup and recovery, and incident response. Current control status is disclosed in the security questionnaire.
4. Subprocessors
The customer authorizes the providers on the current subprocessor list. GaugeWright contractually requires subprocessors to protect personal data consistently with applicable obligations and remains responsible for their processing to the extent required by law and contract. Material additions will be posted before use where reasonably practicable; customers may raise a documented data-protection objection.
5. Requests, assessments, and incidents
Taking into account the nature of processing, GaugeWright will reasonably assist with data-subject requests, security and privacy assessments, regulatory consultation, and breach obligations. GaugeWright will notify the customer without undue delay after confirming a personal-data breach affecting customer data and will provide available information needed for the customer's response. Notification is not an admission of fault.
6. Return and deletion
During the service, supported export and erasure controls are available to authorized users. At termination or on valid instruction, GaugeWright will return or delete customer personal data unless law requires retention. Residual encrypted backup copies remain protected and are deleted through the ordinary backup lifecycle.
7. International transfers
When applicable law requires a transfer mechanism, the parties will use the relevant standard contractual clauses or another lawful mechanism. GaugeWright will provide reasonable information about transfer safeguards on request.
8. Audit information
GaugeWright will make available information reasonably necessary to demonstrate compliance, including public control documentation and relevant test evidence. On reasonable notice and subject to confidentiality, the parties may agree to a proportionate audit that avoids exposing other customers or security-sensitive material. GaugeWright has not represented that it currently holds an independent SOC 2 report.
9. Contact and execution
Questions and execution requests may be sent to Jack@GaugeWright.com. This published version describes GaugeWright's standard terms; it becomes binding through incorporation into an agreement or signature by authorized representatives.