Data Processing Addendum
Version 2026-10-03 · Effective October 3, 2026
This Data Processing Addendum ("DPA") is part of the Terms of Service between Gnok, Inc. ("Gnok") and the customer that accepted them ("Customer"). It applies automatically whenever Gnok processes Customer Personal Data in providing the Service; no signature is needed. Capitalized words not defined here have the meaning given in the Terms.
During Limited Availability, Customers must not upload personal, confidential or regulated data. This DPA still applies to any personal data the Service processes for Customer, including the details of its Users.
1. Definitions
- Customer Personal Data: personal data or personal information, as defined by Data Protection Laws, contained in Customer Data, that Gnok processes on Customer's behalf.
- Data Protection Laws: the US federal and state privacy and data-protection laws that apply to the processing of Customer Personal Data under the Terms, including the California Consumer Privacy Act as amended ("CCPA").
- Security Incident: a breach of security that leads to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Customer Personal Data.
- Subprocessor: a third party that Gnok engages to process Customer Personal Data.
2. Roles
Customer is the controller (or "business") of Customer Personal Data, and Gnok is its processor (or "service provider"). Customer is responsible for the lawfulness of the Customer Personal Data it provides, for giving any required notices and obtaining any required consents, and for the instructions it gives. Annex 1 describes the processing.
3. Customer's instructions
Gnok processes Customer Personal Data only on Customer's documented instructions. The Terms, this DPA, and Customer's use and configuration of the Service (including its AI Governance settings) are those instructions. Gnok may also process Customer Personal Data where the law requires it, and will tell Customer first unless the law forbids that. Gnok will tell Customer if it believes an instruction breaks Data Protection Laws.
4. Service provider commitments
Gnok will not:
- sell or share Customer Personal Data, as "sell" and "share" are defined in the CCPA;
- keep, use or disclose it for any purpose other than providing the Service and the other business purposes described in the Terms, or outside the direct business relationship between Gnok and Customer;
- combine it with personal information Gnok receives from others, except as Data Protection Laws permit.
Gnok will comply with the obligations that Data Protection Laws place on service providers, provide the same level of privacy protection those laws require of Customer, and tell Customer if it can no longer meet them. Customer may take reasonable and appropriate steps to stop and remedy unauthorized use of Customer Personal Data. Gnok understands and will comply with these restrictions.
5. Confidentiality
Gnok limits access to Customer Personal Data to personnel who need it to provide, secure or support the Service, and makes sure they are bound by confidentiality obligations.
6. Security
Gnok maintains the technical and organizational measures in Annex 2, appropriate to the risk of the processing. Gnok may update them, but won't reduce the overall level of protection during Customer's use of the Service. Gnok doesn't hold third-party security certifications or audit reports (such as SOC 2 or ISO 27001).
7. Subprocessors
- Customer authorizes Gnok to use the Subprocessors listed on the Subprocessors page.
- Gnok will update that page and email Customer's administrators at least 30 days before a new Subprocessor starts processing Customer Personal Data. Customer may object on reasonable data-protection grounds within that period. If the parties can't resolve the objection, Customer may stop using the affected part of the Service and, for a paid plan, receive a refund of prepaid fees for the unused part of the billing period.
- Gnok will bind each Subprocessor to data-protection obligations at least as protective as this DPA, to the extent they apply to the Subprocessor's services, and remains responsible for its Subprocessors' performance of those obligations.
8. Requests from individuals
The Service lets Customer's administrators find, export, correct and delete Customer Personal Data and manage Users. Gnok will give Customer reasonable further help to respond to requests from individuals exercising their rights under Data Protection Laws. If Gnok receives such a request directly, it will pass it to Customer and won't respond itself, except to direct the individual to Customer, unless the law requires otherwise.
9. Security Incidents
Gnok will notify Customer's administrators by email without undue delay, and within 72 hours, after confirming a Security Incident. The notice will describe, as far as Gnok then knows, the nature of the incident, the categories and approximate amount of data affected, its likely consequences, the measures taken or proposed, and a contact for more information. Gnok will update Customer as it learns more, take reasonable steps to contain and remedy the incident, and reasonably cooperate with Customer's own notifications. Notifying Customer is not an admission of fault.
10. Assessments and audits
Gnok will give Customer the information reasonably needed to show that it complies with this DPA and to help with Customer's data-protection assessments. On written request, no more than once a year (or after a Security Incident), Gnok will answer a reasonable security questionnaire. Where Data Protection Laws require Customer to be able to audit Gnok in another way, the parties will agree on its scope, timing and confidentiality in advance, at Customer's cost.
11. Return and deletion
Customer can export Customer Personal Data with the Service at any time while its organization is active. When Customer asks Gnok to delete its organization, or the Terms end, Gnok deletes Customer Personal Data as described in section 7 of the Terms: after a 7-day grace period, data is deleted from the Service, and copies in database backups and earlier versions of files expire within 30 days after that, unless the law requires Gnok to keep it.
12. Where data is processed
Gnok stores and processes Customer Data in the United States: on Amazon Web Services in us-east-1, with backup copies in us-west-2. When Customer's Users use AI features, the data they send is processed by the AI provider listed on the Subprocessors page. The Service is offered to organizations based in the United States. Gnok does not offer Standard Contractual Clauses or other mechanisms for transfers of personal data from the European Economic Area, the United Kingdom or Switzerland; a Customer subject to those laws must not upload personal data covered by them without a separate written agreement with Gnok.
13. General
This DPA lasts as long as Gnok processes Customer Personal Data. Each party's liability under this DPA is subject to the limitation of liability in the Terms. If this DPA conflicts with the Terms about the processing of Customer Personal Data, this DPA prevails. Gnok may update this DPA as described in the Terms, but won't reduce its protections for Customer Personal Data during a paid billing period without Customer's agreement.
Annex 1: The processing
- Subject matter and duration: providing the Service, for as long as Customer uses it and until deletion under section 11.
- Nature and purpose: hosting, storing, querying, transforming and analyzing Customer Data; training and running models Customer defines; sending data to AI providers when Customer's Users use AI features; backups; security and support.
- Individuals: Customer's Users, and any individuals whose information Customer chooses to store in the Service.
- Personal data: Users' names, email addresses and sign-in details, and whatever personal data Customer chooses to store in Customer Data.
- Sensitive data: none is intended. During Limited Availability, Customers must not upload personal or regulated data, and the Acceptable Use Policy restricts data that needs special safeguards.
Annex 2: Security measures
| Area | Measure |
|---|---|
| Encryption in transit | TLS 1.2 or later on every public endpoint; database connections from clients require TLS. Inside the platform, the query engine and the catalog authenticate each other with mutual TLS. |
| Encryption at rest | Table data and files in Amazon S3 (server-side encryption), the catalog database (encrypted storage), and its backups (encrypted backup vaults). |
| Isolation | Each organization’s data, identities and settings are scoped to that organization. Background work runs under an identity of the organization, not a shared superuser. |
| Access control | Roles, grants, row policies and column masking per organization. Administrators must use a second factor (a passkey or an authenticator app). Single sign-on (OIDC, SAML 2.0) and SCIM are available. |
| Sign-in protection | Throttling and lockout of repeated failed sign-ins; a web application firewall with a browser check on sign-up and password reset. |
| Gnok personnel | Access to production systems is limited to authorized Gnok personnel who need it to run the Service, who are bound by confidentiality obligations. |
| Backups | Daily database backups kept 14 days, with a copy in a second US region (us-west-2); earlier versions of files kept 30 days. |
| Logging and monitoring | Application logs kept 30 days; audit records of sign-ins, grants and administrative changes; health checks published on the status page. |
| Vulnerability management | A public vulnerability disclosure policy with safe harbor, at gnok.com/security/disclosure. |
Annex 3: Subprocessors
The current list is on the Subprocessors page.
Contact
Gnok, Inc.. Questions about this DPA: support@gnok.com. Security issues: security@gnok.com.