This Data Processing Addendum ("DPA") is incorporated into and forms part of the Master Subscription Agreement ("Agreement") between Gruvi Software, Inc., a Delaware corporation (herein referred to as "Gruvi") and the entity identified as the customer in the Agreement ("Customer").
1. Definitions
1.1. The terms "Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach", and "Processing" shall have the meanings given to them in the Data Protection Laws.
1.2. "Data Protection Laws" means all applicable data protection and privacy laws and regulations, including, to the extent applicable, United States federal and state privacy laws (such as the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA")), the EU General Data Protection Regulation ("EU GDPR"), the UK General Data Protection Regulation ("UK GDPR") and the Data Protection Act 2018.
1.3. "Customer Personal Data" means any Personal Data processed by Gruvi on behalf of Customer in the course of providing the Services, specifically including Inputs provided to AI Agents.
1.4. "Sub-processor" means any third party (including AI model providers such as OpenAI, Anthropic, or Microsoft Azure) engaged by Gruvi to process Customer Personal Data.
1.5. "Security Policy" means Gruvi's internal security documentation as updated from time to time, detailing the technical and organisational measures.
2. Scope and Roles
2.1. Role of the Parties. As between Gruvi and Customer, Customer is the Controller of Customer Personal Data, and Gruvi shall process Customer Personal Data only as a Processor on behalf of Customer.
2.2. Gruvi as a Controller. Customer acknowledges that Gruvi shall also process certain Personal Data as a Controller (e.g., billing data, account registration, and service usage logs). This processing is governed by the Gruvi Privacy Policy and is excluded from the scope of this DPA.
2.3. Subject Matter and Duration. The subject matter of the processing is the provision of AI-driven business workflows. The duration of the processing shall be for the Subscription Term plus the period until all Customer Personal Data is deleted per Section 9.
3. Customer Obligations and Warranties
3.1. Lawfulness of Data. Customer represents and warrants that it has provided all necessary notices and obtained all required consents for the processing of Customer Personal Data via the Services.
3.2. Legality of Instructions. Customer is solely responsible for its instructions to Gruvi. Customer warrants that its use of the Services, including the instructions provided to AI Agents, will not cause Gruvi to violate any law. Customer shall indemnify Gruvi against any and all claims, fines, or damages arising from Gruvi following Customer's instructions.
3.3. Prohibited Data. Customer shall not provide any "High-Risk Data" (as defined in the MSA) to the Services. Customer acknowledges that Gruvi's security measures are not designed for PHI, PCI, or biometric data. Submission of such data is at Customer's sole risk.
4. Gruvi Obligations
4.1. Processing Instructions. Gruvi shall process Customer Personal Data only in accordance with Customer's documented instructions, unless required to do otherwise by applicable law.
4.2. Confidentiality. Gruvi shall ensure that its personnel authorized to process Customer Personal Data are under appropriate obligations of confidentiality.
4.3. Security Measures. Gruvi shall implement and maintain commercially reasonable technical and organisational measures designed to protect Customer Personal Data against unauthorized or unlawful processing and against accidental loss, destruction, or damage. Customer acknowledges that Gruvi does not currently maintain SOC 2, ISO 27001, or similar third-party certifications, and Customer accepts Gruvi's implemented measures as sufficient for its requirements.
5. Sub-processors and AI Models
5.1. General Authorisation. Customer provides a general written authorisation for Gruvi to engage Sub-processors (including LLM and cloud infrastructure providers).
5.2. Notification of Changes. Gruvi shall maintain an up-to-date list of Sub-processors. Gruvi will notify Customer of any addition or replacement of Sub-processors via email or the platform.
5.3. Objection Rights. Customer may object to a new Sub-processor on reasonable grounds related to data protection within ten (10) days of notification. In the event of an objection, Gruvi may, at its sole discretion: (a) cease using the Sub-processor for the Customer; or (b) terminate the Agreement without penalty or refund to the Customer.
6. Data Subject Rights and Assistance
6.1. Assistance. Taking into account the nature of the processing, Gruvi shall provide reasonable assistance to Customer, at Customer's expense, for the fulfilment of Customer's obligation to respond to requests for exercising Data Subject rights.
6.2. Direct Requests. If Gruvi receives a request directly from a Data Subject, it shall forward the request to Customer without undue delay.
6.3. Government and Law Enforcement Requests. Where Gruvi receives a request from a public authority for Customer Personal Data, Gruvi reviews the legality of the request, challenges requests it considers unlawful, discloses only the minimum information necessary to comply, and records the request, its response, and the legal reasoning applied. Gruvi notifies the Customer unless legally prohibited from doing so.
7. Data Breach Notification
7.1. Notification. Gruvi shall notify Customer of any Personal Data Breach involving Customer Personal Data without undue delay, and in any event within seventy-two (72) hours of becoming aware of the breach.
7.2. Disclaimer. Notification of a Personal Data Breach shall not be construed as an admission of fault or liability by Gruvi.
8. Compliance Information and Audits
8.1. Information Provision. Gruvi shall make available to Customer all information reasonably necessary to demonstrate compliance with the obligations laid down in this DPA.
8.2. No Audit Rights. To the maximum extent permitted by law, Gruvi does not grant Customer, or any third party acting on behalf of Customer, the right to conduct physical, technical, or onsite audits of Gruvi's premises, systems, or data centres. Customer acknowledges that its sole means of verifying Gruvi's compliance is through the review of the information provided by Gruvi under Section 8.1 and Gruvi's internal Security Policy.
9. Termination and Deletion
9.1. Deletion upon Termination. Upon termination of the Services, Gruvi shall, at Customer's choice, delete or return all Customer Personal Data, unless retention is required by law.
9.2. Account Delinquency. Notwithstanding any other provision, if an account is in a state of non-payment or unaddressed overage for six (6) months, Gruvi will permanently and irreversibly delete all Customer Personal Data and account configurations. Customer waives any claim for damages related to deletion under this provision.
10. International Transfers
10.1. Transfer Mechanism. Gruvi is established in the United States and processes Customer Personal Data there and in other countries where it or its Sub-processors maintain facilities. To the extent that Customer Personal Data originating in the EEA, the UK or Switzerland is transferred to a country that is not recognized as providing an adequate level of protection, such transfer shall be governed by the EU Standard Contractual Clauses (SCCs) and, for UK data, the UK International Data Transfer Addendum to the SCCs, which are hereby incorporated by reference. Where Gruvi certifies to the EU-U.S. Data Privacy Framework, transfers may also rely on that framework.
11. Limitation of Liability
11.1. Liability Cap. The total aggregate liability of Gruvi arising out of or related to this DPA, whether in contract, tort, or otherwise, shall be subject to the limitation of liability provisions set forth in the Agreement. The parties agree that the liability cap in the MSA applies to the entirety of this DPA.
Contact
Email: legal@gruvi.ai
Address: Gruvi Software, Inc., 2810 N Church St STE 90490, Wilmington, DE 19802, United States