Data Processing Addendum
Version 2026-08-27
This DPA forms part of an agreement that incorporates it between The Groundbreakers Inc. ("Groundbreakers") and a customer where Groundbreakers processes Customer Personal Data on the customer's behalf. It does not replace the Privacy Policy for processing where Groundbreakers acts as controller.
1. Roles and instructions
The customer is controller and Groundbreakers is processor for Customer Personal Data processed solely on the customer's behalf, except where applicable law assigns different roles. Groundbreakers will process that data only to provide and secure the Service, on documented instructions in the agreement and the customer's use of the Service, or as required by law. The customer's configured workspace, artifact, session, recipient, analysis, export, and publication permissions are documented instructions within the Service. Groundbreakers will not treat workspace ownership, membership, payment, sponsorship, affiliation, or access to one artifact as an instruction to disclose other source material. If legally permitted, we will notify the customer before processing required by law. We will tell the customer if we believe an instruction violates applicable data-protection law.
The Terms and Privacy Policy describe restricted product-intelligence, research, and benchmarking uses for which Groundbreakers may independently determine purposes and act as controller. The customer authorizes that separate processing of linkable Customer Personal Data only to the extent disclosed, permitted by law, and not excluded by a signed order form or enterprise agreement. The customer is responsible for providing required notices and establishing a lawful basis before submitting personal information about participants or other people for that processing. Without such authorization, Groundbreakers may use processor data for independent purposes only after it has been irreversibly anonymized so it is no longer personal data.
2. Processing details
Subject matter: delivery of Ecosystem Navigator. Duration: the agreement plus return, deletion, backup, and legally required retention periods. Nature and purpose: collection, storage, organization, analysis, generation, retrieval, permission-based sharing at the customer's direction, support, and deletion. Customer-directed sharing may include selected reports, findings, Explore-derived outputs, aggregates, or publication snapshots, including named material where the customer has the required authority and lawful basis. Data subjects may include customer personnel, authorized users, invited participants, stakeholders, report subjects, and people appearing in customer-provided content. Data may include contact and account details, professional roles, locations, diagnostic responses, reports, documents, session activity, communications, and technical identifiers. The customer will not submit sensitive or special-category data unless expressly agreed and lawfully authorized.
3. Confidentiality and security
Personnel authorized to process Customer Personal Data are subject to confidentiality obligations. Groundbreakers will maintain measures appropriate to risk, as described in the Security Schedule, and periodically assess their effectiveness. The customer is responsible for its users, access configuration, lawful instructions, endpoint security, and backups or exports it chooses to retain.
4. Subprocessors
The customer gives general authorization for the providers in the Subprocessor Register. Groundbreakers will impose materially equivalent data-protection obligations on subprocessors and remains responsible for their performance to the extent required by applicable law. Before adding or replacing a subprocessor that processes Customer Personal Data, we will provide reasonable advance notice through the Service, by email, or through an agreed enterprise process. The customer may object during the notice period on reasonable data-protection grounds. We will work in good faith on a reasonable alternative and may suspend the affected feature if no reasonable alternative is available.
5. Assistance
Taking account of the processing and information available to us, we will reasonably assist the customer with data-subject requests, security obligations, breach notifications, impact assessments, and regulator consultations. We will promptly forward a request relating to Customer Personal Data unless authorized to respond. The customer remains responsible for deciding and communicating the response. Extraordinary assistance may be charged at an agreed reasonable rate.
6. Incidents
We will notify the customer without undue delay after confirming a breach of Customer Personal Data and provide available information reasonably needed for the customer's obligations. Notice is not an admission of fault. We will take reasonable steps to contain, investigate, and mitigate the incident.
7. Return and deletion
At the end of the Service, Groundbreakers will delete or return Customer Personal Data processed solely as processor on request, unless law requires retention. Deletion may occur through account controls and established request procedures. Residual encrypted backups are isolated from ordinary use and removed through normal rotation. Separately authorized controller records are handled under the Terms, Privacy Policy, and applicable law. De-identified records remain personal data while reasonably linkable and are not exempt from deletion merely because direct identifiers were removed. Irreversibly anonymous information may be retained.
8. Transfers
The transfer terms in the EU/UK Addendum apply. Where required, the parties will incorporate the applicable EU Standard Contractual Clauses, UK Addendum, UK IDTA, or successor mechanism. The customer authorizes onward transfers needed for approved subprocessors subject to an appropriate mechanism.
9. Information and audits
On reasonable request, we will provide information needed to demonstrate compliance. Audits must first use current documentation and written responses. If that is insufficient, a customer may request a proportionate audit no more than once annually, or after a confirmed material incident, with reasonable notice, confidentiality, no access to other customers' data, and minimal disruption. The requesting customer bears reasonable costs unless the audit identifies a material breach by Groundbreakers.
10. Conflict and contact
This DPA controls over conflicting agreement terms only for its subject matter. It does not expand liability limits unless non-waivable law requires otherwise. Contact ibarker@thegroundbreakers.net to execute an enterprise DPA or request transfer documentation.