Legal
Data Processing Addendum
Last updated: September 30th, 2026
Datagrid Data Processing Addendum
Effective September 30, 2026
This Data Processing Addendum (this “DPA”) supplements and forms part of the services agreement between Customer and Datagrid AI, Inc. about the provision of Services by Datagrid to Customer (“Agreement”) when Data Protection Law applies to Customer's access and use of the Services to Process Customer Personal Data.
1. Data Processing
1.1 Scope and Roles — This DPA applies when Customer Personal Data is processed by Datagrid under applicable Data Protection Law. Customer is the Controller of the Customer Personal Data covered by this DPA, and Datagrid shall be a Processor.
1.2 Details of Data Processing:
- Subject matter: Customer Personal Data
- Duration: Determined by the Agreement; expires when Datagrid deletes or anonymizes all Customer Personal Data
- Purpose: Provision of the Services by Datagrid to Customer
- Nature: Customer Personal data is processed by Datagrid in connection with the Services
- Categories of Data Subjects: Customer's Authorized Users, employees, contractors, suppliers, or other third parties
- Categories of data: Identifiers (name, email, phone, addresses); Employment Data; Internet and Network Activity Data; Geolocation Data; and other Personal Data that Customer or its Authorized Users elect to submit
- Special categories: Datagrid does not intentionally collect or process any special categories of data
1.3 Compliance with the laws — Each party will comply with all laws, rules and regulations applicable to it.
2. Documented Instructions
Customer shall provide documented instructions to Datagrid for the Processing of Customer Personal Data. The DPA and Agreement constitute Customer's documented instructions.
3. Confidentiality of Customer Personal Data
Datagrid will not access or use, or disclose to any third party, any Customer Personal Data, except as necessary to maintain or provide the Services, or as necessary to comply with the law.
4. Authorized Persons
Datagrid shall ensure that all persons authorized to Process Customer Personal Data are aware of the confidential nature of the data and have committed to confidentiality.
5. Authorized Subprocessors
Customer hereby generally authorizes Datagrid to engage Subprocessors. If Customer reasonably objects to a new Subprocessor, Datagrid shall have the right to cure the objection through cancelling use of the Subprocessor, taking corrective steps, ceasing the relevant aspect of Service, or providing alternatives.
6. Security; Audits; Personal Data Breach
Datagrid's provision of the Services will be consistent with the Security Measures and Controls described in Appendix B. In the event of a Personal Data Breach, Datagrid shall notify Customer without undue delay.
7. Datagrid Assistance with Data Subject Requests
Datagrid will inform Customer of requests from Data Subjects exercising their rights and will reasonably assist Customer with handling such requests upon written request.
8. International Transfers of Personal Data
Datagrid may transfer and process Customer Personal Data to and in the United States. The applicable SCC Controller-to-Processor Clauses will apply to Customer Personal Data transferred from Europe and/or the United Kingdom.
9. Effect of Termination
Upon termination, Datagrid shall anonymize or delete all Customer Personal Data in its possession or control.
10. Indemnification by Customer
Customer agrees to defend and indemnify Datagrid from and against any Losses resulting from Customer's violation of this DPA.
11. Limitation of Liability
Each Party's liability arising out of or related to this DPA is subject to the “Limitation of Liability” section of the Agreement.
12–15. Additional Provisions
Survival of the DPA; Severance; Jurisdiction Specific Terms (including U.S./CCPA provisions); Entire Agreement and Order of Precedence.
16. Definitions
Extensive definitions covering: Access Credentials, Action, Affiliates, Alternative Transfer Mechanism, Competent Supervisory Authority, Controller, Customer Personal Data, Data Controller Affiliates, Data Protection Law, Data Subject, Documented Instructions, GDPR, Losses, Personal Data, Personal Data Breach, Processing, Processor, Public Authority Request, SCCs, Subprocessor, UK GDPR.
Appendix A – List of Datagrid Subprocessors
| Name | Nature / Description | Subject of Processing | Country |
|---|---|---|---|
| Amazon Web Services | Cloud infrastructure, RDS, GuardDuty, S3, CloudWatch, Analytics | Authorized User Identifiers, Internet/Network Activity Data | United States |
| Google, LLC | LLM/AI services, Cloud Storage, Kubernetes, BigQuery, Vertex AI | Authorized User Identifiers, Internet/Network Activity Data | United States* |
| Anthropic | Large Language Model and AI services | Authorized User Identifiers, Internet/Network Activity Data | United States |
| OpenAI | Large Language Model and AI services | Authorized User Identifiers, Internet/Network Activity Data | United States |
| Stripe | Billing/subscription/credit card payments | Authorized User Identifiers, Credit Card Processing Data | United States* |
| Sentry | Application Performance and error monitoring | Authorized User Identifiers, Internet/Network Activity Data | United States |
| Github | Codebase & CICD/Pipeline, Dependabot | Authorized User Identifiers, Internet/Network Activity Data | United States* |
| LaunchDarkly | Feature flags | Authorized User Identifiers, Employment Data, Internet/Network Activity Data | United States |
| Mixpanel | Customer activity assessment | Authorized User Identifiers, Internet/Network Activity Data | United States |
| Zilliz | Milvus (Vector store database) | Authorized User Identifiers, Internet/Network Activity Data | United States |
*Country is United States unless services are accessed from outside the applicable region.
Appendix B – Security Measures and Controls
Datagrid will implement and maintain technical and organizational measures designed to secure Customer Data (including Customer Personal Data). Datagrid will maintain and follow a written information security program (including the adoption and enforcement of internal policies and procedures) designed to (i) help Customer secure Customer Data against accidental or unlawful loss, access or disclosure, (ii) identify reasonably foreseeable risks to Customer Data and unauthorized access to the Services, (iii) minimize Customer Data risks, including through risk assessment and regular testing and (iv) monitor, detect, and mitigate attacks or intrusions into Customer Data. Datagrid will designate one or more employees to coordinate and be accountable for the information security program. The information security program will include the following Security Measures (as updated from time to time):
1. Physical Access Controls: Datagrid takes measures, such as security personnel and secured buildings, designed to (i) prevent unauthorized persons from gaining access to Customer Data, (ii) manage, monitor and log movement of persons into and out of Datagrid facilities, and (iii) guard against environmental hazards such as heat, fire, and water damage.
2. System Access Controls: Datagrid takes measures designed to prevent unauthorized use of Customer Data. These controls may vary based on the nature of the Processing undertaken and may include, among other controls, authentication via passwords and two-factor authentication, documented authorization processes, documented change management processes, logging of access on several levels, system audit or event logging, and related monitoring procedures to proactively record user access and system activity for routine review.
3. Data Access Controls: Datagrid takes measures designed to ensure that Customer Data is accessible and manageable only by properly authorized staff, direct database query access is restricted, and application access rights are established and enforced to ensure that persons entitled to use a data processing system only have access to the Customer Data to which they have privilege of access, and that Customer Data cannot be read, copied, modified, or removed without authorization in the course of Processing.
4. Access Policy: In addition to the access control rules set forth in Subsections 1-3 above, Datagrid implements an access policy under which access to its system environment, to Personal Data, and to other Customer Data is restricted to authorized personnel only.
5. Input Controls: Datagrid takes measures to ensure that: (i) the Customer Data source is under the control of Customer; and (ii) Customer Data integrated into Datagrid's systems is managed by secured file transfer from Customer and the Authorized User subject.
6. Data Backup: Datagrid ensures that backups are made on a regular basis, are secured, and are encrypted when storing data to protect against accidental destruction or loss when hosted by Datagrid.
7. Organizational Management: Datagrid maintains a dedicated staff responsible for the development, implementation, and maintenance of Datagrid's data privacy and information security programs.
8. Audit: Datagrid maintains audit and risk assessment procedures for the purposes of periodic review and assessment of risks to the organization, monitoring and maintaining compliance, and reporting the condition of its information security and compliance to senior internal management.
9. Policies: Datagrid maintains data protection and information security policies and makes sure that policies and measures are regularly reviewed and where necessary, improve them.
10. Integration: Datagrid communicates with Customer applications utilizing cryptographic protocols such as TLS 1.2 or above to protect information in transit over public networks. At the network edge, stateful firewalls, web application firewalls, and DDoS protection are used to filter attacks. Within the internal network, applications follow a multi-tiered model which provides the ability to apply security controls between each layer.
11. Operations: Datagrid maintains operational procedures and controls to provide for configuration, monitoring, and maintenance of technology and information systems according to prescribed internal and adopted industry standards, including secure disposal of systems and media to render all information or data contained therein as undecipherable or unrecoverable prior to final disposal or release from Controller possession.
12. Incident Response: Datagrid maintains incident procedures designed to investigate, respond to, mitigate and notify of events related to Customer's data or information assets. A dedicated network operations and security operations staff performs rapid monitoring and response capabilities to address alerts.
13. Network Security: Datagrid engages in network security controls such as providing for the use of enterprise firewalls and layered DMZ architectures, and intrusion detection systems and other traffic and event correlation procedures designed to protect systems from intrusion and limit the scope of any successful attack.
14. Risk Management: Datagrid utilizes vulnerability assessment, patch management, and threat protection technologies and scheduled monitoring procedures designed to identify, assess, mitigate and protect against identified security threats, viruses and other malicious code.
15. Business Continuity: Datagrid maintains business resiliency/continuity and disaster recovery procedures, as appropriate, designed to maintain service and/or recovery from foreseeable emergency situations or disasters. Testing is performed to evaluate the plans and recovery capabilities.
Additional information: For additional information on Datagrid's security measures and compliance please refer to the information made available and updated periodically at the following link: https://datagrid.com/data-security-standards.
Appendix C – Annexes to the Standard Contractual Clauses
ANNEX I – List of Parties
Data exporter: Customer (as identified in the Agreement)
Data importer: Datagrid AI, Inc., 6309 Carpinteria Ave., Carpinteria, CA 93013, United States; Contact: Chief Legal Officer, legalnotice@procore.com; Role: Processor
ANNEX II – Technical and Organizational Measures
See Appendix B to the DPA.
ANNEX III – Subprocessors
See Appendix A in DPA.