1.1. This Data Processing Addendum ("DPA") forms part of the Master Services Agreement or Terms of Service available at https://gmelius.com/legal/terms or such other location as they may be posted from time to time (as applicable, the "Agreement"), entered into between the customer identified in the Agreement ("Company") and Gmelius SA ("Gmelius"). Gmelius and Company are individually a "party" and, collectively, the "parties".
1.2. This DPA applies only to the extent that Gmelius receives, stores or Processes Personal Data in connection with the Services. Schedule 1 describes the Processing activities in scope of this DPA.
1.3. This DPA replaces any data processing addendum the parties may previously have entered into in connection with the Services.
1.4. Except as modified by this DPA, the Agreement remains unchanged and in full force and effect. In the event of a conflict between this DPA and the Agreement, this DPA prevails to the extent of the conflict. In the event of a conflict between this DPA and an International Data Transfer Mechanism, the International Data Transfer Mechanism prevails.
1.5. Any claims brought under or in connection with this DPA are subject to the terms of the Agreement, including its limitations and exclusions of liability. Gmelius' total aggregate liability under this DPA and the Agreement combined shall not exceed the limitations set out in the Agreement.
1.6. Any regulatory penalties incurred by Gmelius in relation to Company Data that arise from Company's failure to comply with its obligations under this DPA or Data Protection Law will count toward and reduce Gmelius' liability under the Agreement as if it were liability to Company.
1.7. No one other than a party to this DPA, its successors and permitted assignees has any right to enforce its terms, except to the extent that Data Subjects may enforce rights under an International Data Transfer Mechanism.
1.8. This DPA is governed by the governing law and jurisdiction provisions of the Agreement, unless an International Data Transfer Mechanism or Data Protection Law requires otherwise.
1.9. If the Agreement is a HIPAA Business Associate Agreement or the parties have executed one, that agreement governs Protected Health Information and prevails over this DPA to the extent of any conflict.
1.10. Changes to this DPA. Gmelius may update this DPA from time to time. Gmelius will notify Company of any update at least thirty (30) days before it takes effect, by email to Company's administrative contact and by posting the updated version at https://gmelius.com/legal/dpa, except that updates required by Data Protection Law, a regulatory or judicial order, or a new or amended International Data Transfer Mechanism may take effect on shorter notice. If an update materially and adversely affects Company's rights as a Controller, Company may object in writing within the notice period; if the parties cannot resolve the objection in good faith, Company may terminate the affected Services on written notice, without refund of prepaid fees. Continued use of the Services after the effective date constitutes acceptance of the updated DPA.
1.11. Language. This DPA is drafted in English. Translations are provided for convenience only; in the event of any discrepancy, the English version prevails.
2.1. Capitalised terms not defined in this DPA have the meanings given in the Agreement.
2.2. The terms "Business", "Sale", "Share", "Service Provider" and "Third Party" have the meanings given in the CCPA.
2.3. "AI Features" means features of the Services that use machine-learning, large-language or generative models to produce inferences, classifications, content or actions from Company Data, including AI Sorting, Dispatching and Reply Assistants and configurable agents ("Meli").
2.4. "Company Data" means Personal Data that Gmelius Processes on behalf of Company as a Processor in the course of providing the Services, including Personal Data contained in email messages, attachments, calendar events, files and data from Connected Applications made available to the Services.
2.5. "Connected Application" means a third-party application or service (such as a CRM, chat, project-management or automation tool) that Company or its Users connect to the Services.
2.6. "Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach" and "Processing" have the meanings given in the GDPR, and include equivalent terms under other Data Protection Law (for example "Business" and "Service Provider" under the CCPA, and "personal data" and "processing" under the FADP) as context requires.
2.7. "Data Protection Law" means all data protection and privacy laws applicable to the Processing of Personal Data under the Agreement, including Regulation (EU) 2016/679 ("GDPR"), the Swiss Federal Act on Data Protection of 25 September 2020 ("FADP"), the UK General Data Protection Regulation and Data Protection Act 2018 ("UK GDPR"), the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA"), and other applicable U.S. state privacy laws.
2.8. "Data Privacy Framework" means the EU-U.S. Data Privacy Framework, its UK Extension and the Swiss-U.S. Data Privacy Framework, as administered by the U.S. Department of Commerce.
2.9. "De-identified Data" means data that cannot reasonably be used to identify a Data Subject, including aggregated data.
2.10. "EEA" means the European Economic Area.
2.11. "International Data Transfer Mechanism" means a mechanism recognised under Data Protection Law for transferring Personal Data to a third country, including the Standard Contractual Clauses, the UK Addendum and the Data Privacy Framework.
2.12. "Sensitive Data" means Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership; genetic or biometric data; data concerning health, including Protected Health Information under HIPAA; data concerning sex life or sexual orientation; government identification numbers; payment card and financial account information; account credentials; precise geolocation; and any other category designated as special or sensitive under Data Protection Law.
2.13. "Services" means the products and services provided by Gmelius to Company under the Agreement.
2.14. "Standard Contractual Clauses" means the standard contractual clauses for the transfer of personal data to third countries adopted by Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
2.15. "Subprocessor" means a Processor engaged by Gmelius to Process Company Data.
2.16. "UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (Version B1.0, in force 21 March 2022) issued by the UK Information Commissioner under Section 119A of the Data Protection Act 2018.
2.17. "User" means an individual authorised by Company to use the Services.
3.1. Company is the Controller (or, where Company acts on behalf of another controller, a Processor) of Company Data, and Gmelius is the Processor (or Subprocessor). Schedule 1 describes the subject matter, duration, nature and purposes of the Processing, the categories of Personal Data and Data Subjects, and the parties' respective roles for each Processing activity.
3.2. Where Gmelius Processes Personal Data as a Controller (for example account, billing, support and usage data relating to Company's representatives and Users), such Processing is governed by the Gmelius Privacy Policy and Section 7 does not apply.
4.1. Gmelius is established in Switzerland, a jurisdiction recognised as adequate by the European Commission and the United Kingdom. Company Data is hosted on Google Cloud infrastructure and may be accessed by Subprocessors in the United States as listed in Schedule 1.
4.2. The parties will comply with any International Data Transfer Mechanism required by Data Protection Law. To the extent Company Data of Data Subjects in the EEA, Switzerland or the United Kingdom is transferred to a country without an adequacy decision, the parties agree that by accepting this DPA they also execute the Standard Contractual Clauses (Module 2, or Module 3 where Company acts as a Processor) as completed in Appendix A, together with the Swiss amendments and, for UK data, the UK Addendum. Where a Subprocessor is certified under the Data Privacy Framework, Gmelius may additionally rely on that certification.
4.3. If an International Data Transfer Mechanism on which the parties rely is invalidated or superseded, Gmelius may replace it with a successor or alternative mechanism on notice to Company, and the parties will cooperate in good faith to implement any supplementary measures required.
5.1. Compliance. Each party will comply with its obligations under Data Protection Law.
5.2. Company obligations. Company represents and warrants that it has, and will maintain, all consents, notices and lawful bases required to disclose Company Data to Gmelius and to permit its Processing as contemplated by the Agreement, including for Sensitive Data and for Personal Data of third parties contained in email correspondence. Company is responsible for the accuracy and lawfulness of its instructions, for the configuration of the Services (including User permissions, Connected Applications and AI Features), and for the secure use of the Services by its Users.
5.3. Data Subject requests. The Services provide Company with controls to retrieve, correct, delete and export Company Data. To the extent Company cannot fulfil a Data Subject request through those controls, Gmelius will provide reasonable assistance at Company's expense. If Gmelius receives a request directly from a Data Subject, it will direct the Data Subject to Company and notify Company without undue delay, unless legally prohibited.
5.4. Governmental requests. If a governmental or law-enforcement authority requests Company Data from Gmelius, Gmelius will redirect the authority to Company where possible and, unless legally prohibited, give Company reasonable notice to allow it to seek a protective order before disclosing Company Data.
5.5. Assessments and consultations. Taking into account the nature of the Processing and the information available to Gmelius, Gmelius will provide reasonable assistance to Company in conducting data protection impact assessments and prior consultations with supervisory authorities required by Data Protection Law. Gmelius may charge for assistance that exceeds the provision of standard documentation.
5.6. Confidentiality. Gmelius will ensure that personnel authorised to Process Company Data are bound by confidentiality obligations and receive appropriate data protection training.
5.7. Tracking Technologies. Company acknowledges that the Services use cookies, unique identifiers and similar technologies as described in the Cookie Policy, and will maintain any notices and consents required by Data Protection Law for their deployment on Users' devices.
6.1. Security Measures. Gmelius will implement and maintain appropriate technical and organisational measures to protect Company Data against Personal Data Breaches, as described in Schedule 2 and at https://gmelius.com/legal/security ("Security Measures"). Gmelius maintains a SOC 2 Type II attestation.
6.2. Updates. Gmelius may update the Security Measures from time to time provided that updates do not materially reduce the overall security of the Services. Company is responsible for reviewing the Security Measures and determining whether they meet its requirements.
6.3. Company responsibilities. Company is responsible for the secure use of the Services, including securing account credentials, configuring User permissions, agent permissions and human-approval settings appropriately, protecting Company Data in transit to and from the Services, and backing up Company Data where appropriate.
7.1. Instructions. Gmelius will Process Company Data only on Company's documented instructions, which consist of: (a) the Agreement and this DPA; (b) Company's and its Users' configuration and use of the Services, including automation rules, Connected Applications and AI Features; and (c) other written instructions agreed by the parties. Gmelius will inform Company if, in its opinion, an instruction infringes Data Protection Law, unless prohibited from doing so.
7.2. Restrictions. Gmelius will not: (a) Sell or Share Company Data; (b) retain, use or disclose Company Data for any purpose other than providing the Services under the Agreement, including for any commercial purpose outside the direct business relationship with Company; (c) combine Company Data with Personal Data obtained from other sources, except as instructed by Company or as necessary to provide the Services; or (d) use Company Data to train, fine-tune or otherwise develop or improve any generalised artificial intelligence or machine-learning model, whether operated by Gmelius or a third party. Gmelius may Process Company Data as necessary to detect and prevent security incidents, fraud or illegal activity, and may create and use De-identified Data for service analytics, provided Gmelius does not attempt to re-identify it. Gmelius certifies that it understands and will comply with these restrictions.
7.3. Personnel. Gmelius restricts access to Company Data to personnel who need it to provide the Services, support or security, and only to the extent necessary.
7.4. Subprocessors.
7.5. Personal Data Breach. Gmelius will notify Company without undue delay, and in any event within seventy-two (72) hours after confirming a Personal Data Breach affecting Company Data. The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed. Gmelius may provide information in phases as it becomes available and may redact confidential or competitively sensitive information. Email notification to Company's administrative contact is sufficient; Company is responsible for keeping its contact details current. Gmelius' notification is not an acknowledgement of fault or liability. Gmelius is not required to notify Company of unsuccessful security events that do not result in a Personal Data Breach.
7.6. Deletion and return. During the term, Company may export Company Data through the Services. Within thirty (30) days after termination or expiry of the Agreement, Gmelius will, at Company's election made in writing before that date, return Company Data in a commonly used format or delete it, and will in any case delete Company Data (including AI personalisation data, agent memory and audit trails) within ninety (90) days after termination, except to the extent retention is required by applicable law, in which case Gmelius will isolate and protect the retained data from further Processing. Data may persist in encrypted backups for up to ninety (90) days before being overwritten.
7.7. Audits. Gmelius will make available to Company, on request and subject to confidentiality, its most recent SOC 2 Type II report, penetration test summary and other documentation reasonably necessary to demonstrate compliance with this DPA. Where such documentation is insufficient to satisfy a requirement of Data Protection Law or a supervisory authority, or following a Personal Data Breach affecting Company Data, Company (or an independent auditor bound by confidentiality and not a competitor of Gmelius) may conduct an audit of Gmelius' relevant facilities and records, no more than once in any twelve-month period, on at least thirty (30) days' written notice, during business hours, in a manner that does not disrupt Gmelius' operations or compromise other customers' data, and at Company's expense. Company will promptly provide Gmelius with any audit findings.
8.1. Activation and instructions. AI Features are enabled by Company's administrators or Users. Company's configuration of an AI Feature or agent, including the data sources it may access, the actions it may take, its level of autonomy and any human-approval requirement, constitutes Company's documented instruction to Gmelius for the Processing performed by that AI Feature. Company may disable AI Features at any time.
8.2. Model providers. AI Features are powered by foundation models operated by the AI model providers listed as Subprocessors in Schedule 1. Gmelius will engage only providers that contractually commit to (a) zero data retention, meaning Company Data is not stored or logged beyond immediate processing, and (b) not using Company Data to train or improve their models. Gmelius will not itself use Company Data to train, fine-tune or improve generalised models, as provided in Section 7.2(d). Personalisation derived from Company Data is specific to Company's account.
8.3. Automated decisions and human oversight. AI Features assist Users and do not make decisions producing legal or similarly significant effects on Data Subjects within the meaning of GDPR Article 22 or FADP Article 21. Company is responsible for determining whether its use of AI Features requires human review, for configuring human-approval steps accordingly, and for any decision it takes on the basis of AI-generated output. Gmelius provides an audit trail of agent actions to support Company's oversight obligations.
8.4. Regulatory allocation. As between the parties, Company is the deployer of AI Features within the meaning of the EU Artificial Intelligence Act and comparable laws, and Gmelius is the provider of the Services. Each party will comply with the transparency, oversight and record-keeping obligations applicable to its role.
8.5. Output. AI-generated content may be inaccurate or incomplete. Company acknowledges that AI output is provided to assist its Users and must be reviewed before being relied upon or communicated to third parties.
8.6. Opt-out. Where Company requires that no AI Feature Process Company Data, Company may disable AI Features at the workspace level, and Gmelius will not enable them for Company without Company's prior written consent, which may be given by an administrator through the Services.
9.1. Where Company or its Users connect a Connected Application to the Services, Company instructs Gmelius to transmit Company Data to and receive Company Data from that Connected Application as configured by Company, including where an agent is given access to it.
9.2. Connected Applications are engaged by Company, not by Gmelius, and are not Subprocessors. Company is responsible for its agreements with the providers of Connected Applications and for the lawfulness of transfers to them. Gmelius is not responsible for the Processing of Company Data by a Connected Application after transmission at Company's direction.
9.3. Transfers of data obtained through Google Workspace APIs to a Connected Application occur only where Company has explicitly configured that flow, consistent with the Google API Services User Data Policy.
Duration: the term of the Agreement plus the deletion period in Section 7.6. Nature and purpose: provision of the Services as described in the Agreement and the Gmelius documentation.
Company authorises Gmelius to use the Subprocessors listed below in accordance with Section 7.4. The current list is maintained at this page.
Gmelius maintains administrative, physical and technical safeguards designed to protect the security, confidentiality and integrity of Company Data, including: encryption of data in transit (TLS) and at rest; logical tenant separation; role-based access control with least-privilege and multi-factor authentication for personnel; logging and monitoring of production access; secure software development lifecycle with code review and dependency scanning; annual independent penetration testing; vulnerability management and responsible disclosure programme; business continuity and backup procedures; incident response procedures; personnel confidentiality obligations and security training; Subprocessor due diligence; and, for AI Features, permission-scoped agent access, egress controls, configurable human-approval steps and audit logging of agent actions. Further detail is available at https://gmelius.com/legal/security and in the SOC 2 Type II report available through the Trust Center.
The Standard Contractual Clauses are incorporated by reference with the following selections:
For transfers of Personal Data subject to the UK GDPR, the UK Addendum applies with the following selections: Table 1: parties as in Annex I(A); Table 2: the Standard Contractual Clauses as completed in this Appendix A; Table 3: Annex information as set out in Schedules 1 and 2; Table 4: either party may end the UK Addendum in accordance with its Section 19. The competent supervisory authority is the Information Commissioner's Office.