Legal
Guardyx AI Data Processing Addendum
Version 1.0
Effective May 14, 2026 · Last updated May 14, 2026
This Data Processing Addendum (“DPA”) forms part of the Guardyx AI Terms of Service and any applicable Order Forms (collectively, the “Agreement”) between Code Above Lab, Inc. d/b/a Guardyx AI (“Guardyx”) and the Customer identified in the applicable Agreement (“Customer”).
This DPA applies where Guardyx processes Personal Data on behalf of Customer in connection with the Services.
Contents
- Definitions
- Scope and Roles
- Customer Obligations
- Confidentiality
- Security Measures
- Security Incident Notification
- Subprocessors
- International Data Transfers
- Assistance and Cooperation
- Audit Rights
- Deletion and Return of Personal Data
- AI Model Training Restrictions
- Government Access Requests
- California Privacy Provisions
- Records of Processing
- Liability
- Sensitive Data
- Term and Termination
- Order of Precedence
- Contact Information
1. Definitions
Capitalized terms not defined in this DPA have the meanings set forth in the Agreement.
1.1 “Applicable Data Protection Laws”
All laws and regulations applicable to the processing of Personal Data under the Agreement, including where applicable:
- the EU General Data Protection Regulation (GDPR);
- the UK GDPR;
- the California Consumer Privacy Act (CCPA), as amended by the CPRA;
- other applicable privacy, security, or data protection laws.
1.2 “Controller”
The entity that determines the purposes and means of processing Personal Data.
1.3 “Processor”
The entity that processes Personal Data on behalf of a Controller.
1.4 “Personal Data”
Any information relating to an identified or identifiable natural person, as defined under Applicable Data Protection Laws, processed by Guardyx in connection with the Services, including where such information is contained within prompts, tool payloads, responses, approval snapshots, workflow metadata, telemetry, audit logs, or execution events.
1.5 “Security Incident”
Unauthorized access to, acquisition of, disclosure of, destruction of, loss of, alteration of, or inability to access Personal Data.
1.6 “Subprocessor”
Any third party engaged by Guardyx to process Personal Data on Guardyx’s behalf.
2. Scope and Roles
2.1 Roles of the Parties
Customer acts as Controller or Processor, as applicable, with respect to Personal Data processed through the Services.
Guardyx acts as Processor or subprocessor, as applicable, when processing Personal Data on behalf of Customer.
2.2 Customer Instructions
Guardyx will process Personal Data only:
- in accordance with Customer’s documented instructions;
- as necessary to provide the Services;
- as required by applicable law.
The Agreement and Customer’s use of the Services constitute Customer’s primary documented instructions to Guardyx for purposes of this DPA.
Customer may provide additional written instructions consistent with the Agreement and Applicable Data Protection Laws. Guardyx may refuse instructions that would violate applicable law, create material security risk, or fundamentally alter the nature of the Services.
2.3 Nature of Processing
Processing activities may include:
- routing and governance of Tool invocations;
- processing prompts, tool payloads, responses, approvals, workflow metadata, telemetry, audit logs, and execution events;
- policy enforcement and approval workflows;
- storage, transmission, monitoring, and observability functions;
- security, fraud prevention, and operational reliability activities;
- customer support and troubleshooting.
3. Customer Obligations
Customer represents and warrants that:
- it has all rights, permissions, notices, and consents necessary to provide Personal Data to Guardyx;
- its instructions comply with Applicable Data Protection Laws;
- it has independently determined that the Services provide appropriate safeguards for its intended use cases;
- it will not instruct Guardyx to process Personal Data in violation of Applicable Data Protection Laws.
Customer is responsible for:
- configuring retention settings and approval workflows;
- responding to data subject requests unless otherwise agreed;
- determining whether to process regulated or sensitive categories of data through the Services, as further described in Section 17.
4. Confidentiality
Guardyx will ensure that personnel authorized to process Personal Data are subject to appropriate confidentiality obligations.
Guardyx will limit access to Personal Data to personnel with a legitimate business need to access such data.
5. Security Measures
Guardyx will maintain commercially reasonable administrative, technical, and organizational safeguards designed to protect Personal Data, including at a minimum:
- encryption of Personal Data in transit and at rest;
- logical tenant isolation;
- least-privilege access controls;
- audit logging and telemetry controls;
- monitoring and incident response procedures;
- vulnerability management practices;
- reviewer access controls for approval workflows and approval snapshots containing Customer Data.
Additional security measures, certifications, and operational information may be described in Guardyx’s Security Addendum or Trust Center documentation for informational purposes and to supplement this DPA.
Guardyx may update or modify security measures from time to time provided that such changes do not materially reduce the overall level of protection.
Guardyx may publish additional security information through its Trust Center, Security Addendum, or related documentation.
6. Security Incident Notification
Guardyx will notify Customer without undue delay, and in any event within seventy-two (72) hours after becoming aware of a confirmed Security Incident involving Personal Data, except where delayed by applicable law or a request from law enforcement or a governmental authority.
To the extent reasonably available, such notice may include:
- the nature of the Security Incident;
- categories of affected Personal Data;
- known or likely consequences;
- measures taken or proposed to address the Security Incident.
Guardyx’s notification obligations do not constitute an admission of fault or liability.
7. Subprocessors
7.1 Authorization
Customer authorizes Guardyx to engage Subprocessors in connection with the Services.
7.2 Subprocessor Obligations
Guardyx will impose data protection obligations on Subprocessors that are materially protective of Personal Data to a standard substantially similar to this DPA.
7.3 Subprocessor List
Guardyx will maintain a current list of Subprocessors, including categories of processing activities and locations, through its Trust Center or another publicly accessible mechanism designated by Guardyx.
Subprocessors may include:
- cloud infrastructure providers;
- AI model providers;
- telemetry and observability providers;
- customer support providers;
- security and monitoring vendors.
7.4 Subprocessor Changes
Guardyx will provide at least thirty (30) days’ prior notice of material Subprocessor additions or replacements through the Services, email, or another reasonable mechanism.
Customer may object to a new Subprocessor on reasonable data protection grounds by providing written notice during the notice period. If the parties cannot reasonably resolve the objection, Customer may terminate the affected Services without penalty.
8. International Data Transfers
Where Guardyx transfers Personal Data outside the EEA, UK, or Switzerland, Guardyx will implement appropriate transfer safeguards as required by Applicable Data Protection Laws.
Such safeguards may include:
- Standard Contractual Clauses (SCCs);
- the UK International Data Transfer Addendum;
- other lawful transfer mechanisms.
The SCCs are incorporated by reference where applicable, including Controller-to-Processor Module 2 and Processor-to-Processor Module 3, as applicable to the parties’ relationship.
The parties will complete and maintain applicable SCC annexes describing:
- categories of Personal Data;
- categories of data subjects;
- nature and purpose of processing;
- technical and organizational measures;
- Subprocessors and transfer details.
9. Assistance and Cooperation
Taking into account the nature of processing and information available to Guardyx, Guardyx will provide commercially reasonable assistance to Customer with:
- data subject requests;
- privacy impact assessments;
- consultations with supervisory authorities;
- compliance obligations under Applicable Data Protection Laws.
Guardyx will provide reasonable assistance through self-service functionality and standard support processes without additional charge. Guardyx may charge reasonable fees for assistance requiring substantial additional engineering, legal review, or custom operational effort.
10. Audit Rights
Guardyx will make available information reasonably necessary to demonstrate compliance with this DPA.
Where reasonably required by Applicable Data Protection Laws, Customer may request additional information or documentation regarding Guardyx’s security and privacy controls.
Any audit rights will:
- be exercised no more than once annually unless required by law or following a Security Incident;
- be subject to reasonable confidentiality obligations;
- avoid unreasonable disruption to Guardyx operations;
- be limited to information relevant to the Services.
Guardyx may satisfy audit obligations through third-party certifications, audit reports, or security assessments, including SOC 2 Type II reports.
Guardyx intends to maintain or pursue commercially reasonable independent security assessments and certifications appropriate for the Services.
11. Deletion and Return of Personal Data
Upon termination or expiration of the Agreement:
- Customer may export Customer Data during the Retrieval Period described in the Agreement;
- Guardyx will delete or irreversibly anonymize Personal Data within ninety (90) days following the Retrieval Period unless retention is required by law, legal process, regulatory obligations, security incident investigation, Customer-configured audit retention requirements, or retention within backup systems subject to standard deletion cycles.
Residual copies maintained in backups will remain protected under this DPA until deleted in the ordinary course of backup rotation procedures, which are generally completed within ninety (90) days.
12. AI Model Training Restrictions
Unless otherwise expressly agreed in writing:
- Guardyx will not use Customer Data to train foundation models or general-purpose AI models;
- Guardyx will not sell Customer Data;
- Guardyx will not disclose Customer Data except as permitted by the Agreement, this DPA, or applicable law.
Guardyx may generate and use aggregated and de-identified data that does not identify Customer or individuals for lawful operational analytics, security, reliability, and product improvement purposes.
Aggregated or de-identified data will not be used to train AI or machine learning models derived from Customer prompts, tool payloads, approval snapshots, or workflow content.
The foregoing does not restrict Guardyx’s use of aggregated or de-identified signals for operational security, abuse prevention, reliability, or anomaly-detection purposes, provided such signals do not identify Customer or individuals.
Guardyx will use commercially reasonable measures designed to prevent re-identification of aggregated or de-identified data.
13. Government Access Requests
If Guardyx receives a legally binding request from a governmental authority for access to Personal Data, Guardyx will:
- review the request for legal validity;
- seek to narrow or challenge overbroad requests through available legal process where reasonably appropriate;
- notify Customer unless legally prohibited from doing so.
Guardyx may publish transparency reporting regarding governmental requests where legally permitted.
14. California Privacy Provisions
To the extent the CCPA or CPRA applies:
- Guardyx acts as a “service provider” or “contractor,” as applicable;
- Guardyx will not retain, use, or disclose Personal Data except as permitted by the Agreement or Applicable Data Protection Laws;
- Guardyx will not sell or share Personal Data;
- Guardyx will not combine Personal Data with data obtained from other sources except as permitted by law.
15. Records of Processing
Guardyx will maintain records of processing activities as required under Applicable Data Protection Laws.
Upon reasonable request and subject to confidentiality obligations, Guardyx may make relevant records available to Customer where required by Applicable Data Protection Laws.
16. Liability
Liability arising under this DPA is subject to the limitations and exclusions of liability set forth in the Agreement unless otherwise prohibited by Applicable Data Protection Laws.
17. Sensitive Data
Customer acknowledges that prompts, tool payloads, responses, approval snapshots, audit logs, telemetry, and workflow content processed through the Services may contain sensitive or regulated information.
Customer is responsible for determining whether the Services are appropriate for Customer’s intended use cases involving regulated or sensitive data.
Unless otherwise expressly agreed in writing:
- the Services are not intended for processing regulated data subject to HIPAA, PCI DSS, or similar sector-specific regimes requiring separate contractual or technical safeguards;
- Customer is responsible for configuring any available data minimization, redaction, retention, or access-control settings appropriate for Customer’s compliance obligations.
Customer and Guardyx may agree in an applicable Order Form or separate written agreement to additional contractual or technical safeguards enabling specific regulated-data use cases.
18. Term and Termination
This DPA remains effective for so long as Guardyx processes Personal Data on behalf of Customer.
19. Order of Precedence
In the event of conflict:
- the SCCs or other applicable transfer mechanism control with respect to international transfer obligations;
- this DPA controls with respect to data protection obligations;
- the Agreement controls for all other matters.
20. Contact Information
Privacy inquiries relating to this DPA may be directed to:
Data subject privacy requests may also be submitted through mechanisms identified in Guardyx’s Privacy Policy.
Code Above Lab, Inc.
Operator of Guardyx AI
See also: Terms of Service · Acceptable Use Policy · Privacy Policy · Cookie Policy.