Skip to content
GBNOX
AboutProductsPrinciplesLegalContact
Home/Legal & Trust/Data Processing Addendum

Legal

Data Processing Addendum

The Article 28 processor terms that apply when GBNOX processes personal data on a customer's behalf. It forms part of the Terms of Service — no signature required, though we will sign a copy if your procurement team needs one.

Last updated August 29, 2026·Effective immediately upon posting

On this page

  1. 01Parties and incorporation
  2. 02Definitions
  3. 03Roles of the parties
  4. 04Subject matter and details of processing
  5. 05GBNOX obligations
  6. 06Customer obligations
  7. 07Security measures
  8. 08Sub-processors
  9. 09International transfers
  10. 10Government and law enforcement requests
  11. 11Personal data breach
  12. 12Data subject requests
  13. 13Audit and demonstrating compliance
  14. 14Deletion and return of data
  15. 15Liability, term and general

01Parties and incorporation

This Data Processing Addendum ("DPA") is entered into between the customer identified in the applicable order form or account ("Customer", "Controller") and GBNOX LLC, registered in the State of Florida, United States of America ("GBNOX", "Processor").

It forms part of, and is governed by, the Terms of Service. Where the DPA and the Terms conflict on the processing of personal data, this DPA prevails.

It takes effect automatically when Customer begins using the Services to process personal data. No signature is required for it to bind us.

If your procurement or legal team requires a countersigned copy, or an alternative form of DPA, use the contact form and we will arrange it.

02Definitions

"Data Protection Laws" means all laws on the processing of personal data applicable to a party, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss FADP, the California Consumer Privacy Act as amended ("CCPA"), Brazil's LGPD, Canada's PIPEDA, and comparable laws elsewhere.

"Controller", "Processor", "Data Subject", "Personal Data", "Processing", "Personal Data Breach" and "Supervisory Authority" have the meanings given in the GDPR. Under the CCPA, GBNOX is a "Service Provider" and Customer is a "Business".

"Customer Personal Data" means personal data contained in Customer Data that GBNOX processes on Customer's behalf.

"SCCs" means the Standard Contractual Clauses annexed to European Commission Implementing Decision (EU) 2021/914.

"UK Addendum" means the International Data Transfer Addendum issued by the UK Information Commissioner under s119A of the Data Protection Act 2018.

03Roles of the parties

Customer is the Controller of Customer Personal Data. GBNOX is the Processor, acting only on Customer's documented instructions.

Where Customer is itself a processor for a third-party controller, Customer warrants it has authority to appoint GBNOX as a sub-processor on these terms.

GBNOX is an independent Controller for its own account, billing, security and business-operations data. That processing is governed by the Privacy Policy, not this DPA.

04Subject matter and details of processing

ItemDetail
Subject matterProvision of the GBNOX Services described in the Terms of Service and the applicable order form
DurationThe term of the subscription, plus the deletion window in Deletion and return
Nature and purposeHosting, storage, retrieval, analysis, aggregation, scoring, transmission to authorised integrations, backup, support and deletion — solely to deliver the Services
Categories of Data SubjectCustomer's personnel and authorised users; Customer's own customers and prospects; contacts at Customer's suppliers and partners — to the extent Customer submits such data
Categories of Personal DataIdentifiers (name, email, user ID); account and role data; business contact details; commercial and transaction data; technical data (IP address, device and log data); and any other personal data Customer chooses to submit
Special category dataNot requested and not required. Customer must not submit special category or criminal-offence data without a prior written agreement with GBNOX.

05GBNOX obligations

GBNOX shall:

  1. Process Customer Personal Data only on Customer's documented instructions, including as to international transfers, unless required otherwise by law — in which case GBNOX will inform Customer first, unless the law forbids it on important grounds of public interest. The Terms, this DPA and Customer's use of the Services constitute those documented instructions.
  2. Immediately inform Customer if, in GBNOX's opinion, an instruction infringes Data Protection Laws.
  3. Ensure that persons authorised to process Customer Personal Data are bound by confidentiality obligations and are trained appropriately.
  4. Implement and maintain the technical and organisational measures in Security measures, taking account of the state of the art, cost, and the risk to Data Subjects.
  5. Respect the conditions in Sub-processors for engaging another processor.
  6. Assist Customer, by appropriate measures, in responding to Data Subject requests under Chapter III GDPR.
  7. Assist Customer in complying with Articles 32 to 36 GDPR — security, breach notification and data protection impact assessments — taking into account the nature of processing and the information available to GBNOX.
  8. At Customer's choice, delete or return all Customer Personal Data at the end of the Services, as set out in Deletion and return.
  9. Make available all information necessary to demonstrate compliance with Article 28 GDPR, and allow for and contribute to audits as set out in Audit.

CCPA-specific undertakings

GBNOX will not sell or share Customer Personal Data; will not retain, use or disclose it for any purpose other than performing the Services specified in the Terms, or as otherwise permitted by the CCPA; will not use it outside the direct business relationship between the parties; and will not combine it with personal information from another source except as the CCPA permits. GBNOX certifies that it understands and will comply with these restrictions.

06Customer obligations

Customer shall:

  1. Ensure it has a lawful basis for the processing it instructs, and has given any notice and obtained any consent required;
  2. Ensure its instructions comply with Data Protection Laws;
  3. Be responsible for the accuracy, quality and legality of Customer Personal Data and the means by which it was acquired;
  4. Configure the Services, and manage user access, appropriately for the sensitivity of the data it submits;
  5. Not submit special category data, government identifiers, payment card data, or data subject to sector-specific regimes such as HIPAA, unless separately agreed in writing.

07Security measures

GBNOX maintains the measures described on the Security page, which are incorporated here as Annex II for the purposes of the SCCs. They include, at minimum:

  • Encryption of personal data in transit (TLS 1.2+) and at rest (AES-256 or equivalent);
  • Pseudonymisation and data minimisation where compatible with the purpose;
  • Role-based access control on least-privilege terms, with mandatory multi-factor authentication for production access;
  • Logical tenant isolation enforced at the data-access layer;
  • Logging of administrative access, with retention for security review;
  • Regular backup with encryption and restore testing;
  • Vulnerability and dependency scanning, with prioritised remediation;
  • A documented incident response process with defined severity levels and notification duties;
  • Separation of development, staging and production environments, with no production data in development;
  • Personnel confidentiality undertakings and prompt access revocation on departure.

GBNOX may update these measures provided the level of protection is not materially reduced.

08Sub-processors

Customer gives general written authorisation for GBNOX to engage sub-processors, subject to the conditions below.

  1. GBNOX maintains a current list at Sub-processors.
  2. GBNOX imposes on each sub-processor, by written contract, data protection obligations no less protective than those in this DPA.
  3. GBNOX remains fully liable to Customer for the performance of each sub-processor's obligations.
  4. GBNOX will give Customer at least 30 days' notice before adding or replacing a sub-processor. Customers who ask to be notified receive that notice by email.
  5. Customer may object on reasonable data protection grounds within 30 days. The parties will work in good faith to find an alternative. If none is available, Customer may terminate the affected part of the Services and receive a pro-rata refund of prepaid fees.

09International transfers

Where GBNOX processes Customer Personal Data originating in the EEA, the UK or Switzerland in a country without an adequacy decision, the following apply and are incorporated by reference:

  • The SCCs, Module Two (Controller to Processor), or Module Three (Processor to Processor) where Customer is itself a processor;
  • For the UK, the UK Addendum to the SCCs;
  • For Switzerland, the SCCs as adapted by the Swiss Federal Data Protection and Information Commissioner, with references to the GDPR read as references to the FADP.

Agreed options under the SCCs

  • Clause 7 (docking) — applies.
  • Clause 9 (sub-processors) — Option 2, general written authorisation, with a 30-day notice period.
  • Clause 11 (redress) — the optional independent dispute resolution paragraph does not apply.
  • Clause 17 (governing law) — the law of Ireland.
  • Clause 18 (forum) — the courts of Ireland.
  • Annex I — the parties, the processing description in Subject matter, and the competent supervisory authority determined under Clause 13.
  • Annex II — the technical and organisational measures in Security measures.
  • Annex III — the list at Sub-processors.

GBNOX carries out transfer impact assessments for material sub-processors, applies supplementary measures including encryption and access minimisation, and will notify Customer if it becomes unable to comply with the SCCs.

10Government and law enforcement requests

If GBNOX receives a legally binding request from a public authority for Customer Personal Data, GBNOX will:

  1. Notify Customer promptly, unless legally prohibited — and where prohibited, use reasonable efforts to obtain a waiver and to challenge the prohibition;
  2. Review the request for validity, and challenge it where there are reasonable grounds to consider it unlawful under the law of the requesting country or under international law;
  3. Disclose only the minimum amount of data lawfully required;
  4. Document each request and make that record available to Customer on request, to the extent permitted.

GBNOX has not, to date, received a national security order or government request compelling disclosure of Customer Personal Data.

11Personal data breach

GBNOX will notify Customer without undue delay, and in any event within 72 hours, of becoming aware of a Personal Data Breach affecting Customer Personal Data.

The notification will describe, to the extent known: the nature of the breach and the categories and approximate number of Data Subjects and records affected; the likely consequences; the measures taken or proposed; and a contact point for further information. Where the full picture is not yet available, GBNOX will provide information in phases.

GBNOX will cooperate with Customer, and take the reasonable steps Customer directs, to assist in Customer's own investigation, mitigation and regulatory notification.

Notification is not, and will not be construed as, an acknowledgement of fault or liability.

12Data subject requests

The Services give Customer the ability to access, correct, export and delete Customer Personal Data directly. Customer uses those functions to respond to Data Subject requests in the first instance.

Where Customer cannot do so through the Services, GBNOX will provide reasonable assistance, at Customer's cost where the request is unusually burdensome.

If GBNOX receives a request directly from a Data Subject relating to Customer Personal Data, it will not respond substantively — beyond acknowledging receipt and directing the individual to Customer — and will notify Customer promptly.

13Audit and demonstrating compliance

GBNOX will make available the information reasonably necessary to demonstrate compliance with this DPA — including its security documentation and a completed security questionnaire — on request, no more than once in any 12-month period unless a Personal Data Breach or a supervisory authority requires otherwise.

Where that information is insufficient, Customer may conduct an audit, subject to:

  • At least 30 days' written notice;
  • Conduct during business hours, without unreasonably disrupting GBNOX's operations;
  • A written confidentiality undertaking from Customer and any third-party auditor, who must not be a GBNOX competitor;
  • Scope limited to systems and records relevant to Customer Personal Data;
  • Customer bearing its own costs, and GBNOX's reasonable costs where the audit exceeds one working day.

14Deletion and return of data

On termination or expiry of the Services, GBNOX will, at Customer's election:

  • Make Customer Personal Data available for export for 30 days; and thereafter
  • Delete all Customer Personal Data from live systems, with backups ageing out on a rolling window of up to 35 days.

GBNOX may retain Customer Personal Data where required by law, and in that case will continue to protect it under this DPA and process it only for the purpose requiring retention.

GBNOX will certify deletion in writing on request.

15Liability, term and general

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except where Data Protection Laws prohibit such limitation — in particular, nothing here limits a Data Subject's rights or remedies under the SCCs.

This DPA continues for as long as GBNOX processes Customer Personal Data. Provisions that by their nature should survive, including confidentiality and deletion obligations, survive termination.

If a provision of this DPA is held invalid, the rest remains in force. Where the SCCs conflict with this DPA, the SCCs prevail.

Contact

Data protection matters under this DPA: the contact form. Contract matters: the contact form.

GBNOX LLC5005 W Laurel StTampa, FL 33607United States

Questions about this document?

Send them through the contact form and a real person will answer. Pick the topic that fits — privacy requests, security reports and legal questions each reach the right place.

Contact us
GBNOX

The intelligence layer for modern commerce.

Building deliberately · Two products in the lab

Products

  • GBNOX Radar
  • BeaconPulsar
  • Beaconfrom $19
  • Pulsarfrom $15

Company

  • About
  • Principles
  • Contact

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Acceptable Use

Trust

  • Security
  • Data Processing
  • Sub-processors
  • Accessibility
GBNOX

© 2026 GBNOX LLC. All rights reserved.

Registered in Florida, USA · Built API-first, worldwide.

Legal & TrustPrivacyTermsCookies