G

GUARDYX AI

AI Agent Control Plane

Legal

Guardyx AI Data Processing Addendum

Version 1.0

Effective May 14, 2026 · Last updated May 14, 2026

This Data Processing Addendum (“DPA”) forms part of the Guardyx AI Terms of Service and any applicable Order Forms (collectively, the “Agreement”) between Code Above Lab, Inc. d/b/a Guardyx AI (“Guardyx”) and the Customer identified in the applicable Agreement (“Customer”).

This DPA applies where Guardyx processes Personal Data on behalf of Customer in connection with the Services.

Contents

  1. Definitions
  2. Scope and Roles
  3. Customer Obligations
  4. Confidentiality
  5. Security Measures
  6. Security Incident Notification
  7. Subprocessors
  8. International Data Transfers
  9. Assistance and Cooperation
  10. Audit Rights
  11. Deletion and Return of Personal Data
  12. AI Model Training Restrictions
  13. Government Access Requests
  14. California Privacy Provisions
  15. Records of Processing
  16. Liability
  17. Sensitive Data
  18. Term and Termination
  19. Order of Precedence
  20. Contact Information

1. Definitions

Capitalized terms not defined in this DPA have the meanings set forth in the Agreement.

1.1 “Applicable Data Protection Laws”

All laws and regulations applicable to the processing of Personal Data under the Agreement, including where applicable:

1.2 “Controller”

The entity that determines the purposes and means of processing Personal Data.

1.3 “Processor”

The entity that processes Personal Data on behalf of a Controller.

1.4 “Personal Data”

Any information relating to an identified or identifiable natural person, as defined under Applicable Data Protection Laws, processed by Guardyx in connection with the Services, including where such information is contained within prompts, tool payloads, responses, approval snapshots, workflow metadata, telemetry, audit logs, or execution events.

1.5 “Security Incident”

Unauthorized access to, acquisition of, disclosure of, destruction of, loss of, alteration of, or inability to access Personal Data.

1.6 “Subprocessor”

Any third party engaged by Guardyx to process Personal Data on Guardyx’s behalf.

2. Scope and Roles

2.1 Roles of the Parties

Customer acts as Controller or Processor, as applicable, with respect to Personal Data processed through the Services.

Guardyx acts as Processor or subprocessor, as applicable, when processing Personal Data on behalf of Customer.

2.2 Customer Instructions

Guardyx will process Personal Data only:

The Agreement and Customer’s use of the Services constitute Customer’s primary documented instructions to Guardyx for purposes of this DPA.

Customer may provide additional written instructions consistent with the Agreement and Applicable Data Protection Laws. Guardyx may refuse instructions that would violate applicable law, create material security risk, or fundamentally alter the nature of the Services.

2.3 Nature of Processing

Processing activities may include:

3. Customer Obligations

Customer represents and warrants that:

Customer is responsible for:

4. Confidentiality

Guardyx will ensure that personnel authorized to process Personal Data are subject to appropriate confidentiality obligations.

Guardyx will limit access to Personal Data to personnel with a legitimate business need to access such data.

5. Security Measures

Guardyx will maintain commercially reasonable administrative, technical, and organizational safeguards designed to protect Personal Data, including at a minimum:

Additional security measures, certifications, and operational information may be described in Guardyx’s Security Addendum or Trust Center documentation for informational purposes and to supplement this DPA.

Guardyx may update or modify security measures from time to time provided that such changes do not materially reduce the overall level of protection.

Guardyx may publish additional security information through its Trust Center, Security Addendum, or related documentation.

6. Security Incident Notification

Guardyx will notify Customer without undue delay, and in any event within seventy-two (72) hours after becoming aware of a confirmed Security Incident involving Personal Data, except where delayed by applicable law or a request from law enforcement or a governmental authority.

To the extent reasonably available, such notice may include:

Guardyx’s notification obligations do not constitute an admission of fault or liability.

7. Subprocessors

7.1 Authorization

Customer authorizes Guardyx to engage Subprocessors in connection with the Services.

7.2 Subprocessor Obligations

Guardyx will impose data protection obligations on Subprocessors that are materially protective of Personal Data to a standard substantially similar to this DPA.

7.3 Subprocessor List

Guardyx will maintain a current list of Subprocessors, including categories of processing activities and locations, through its Trust Center or another publicly accessible mechanism designated by Guardyx.

Subprocessors may include:

7.4 Subprocessor Changes

Guardyx will provide at least thirty (30) days’ prior notice of material Subprocessor additions or replacements through the Services, email, or another reasonable mechanism.

Customer may object to a new Subprocessor on reasonable data protection grounds by providing written notice during the notice period. If the parties cannot reasonably resolve the objection, Customer may terminate the affected Services without penalty.

8. International Data Transfers

Where Guardyx transfers Personal Data outside the EEA, UK, or Switzerland, Guardyx will implement appropriate transfer safeguards as required by Applicable Data Protection Laws.

Such safeguards may include:

The SCCs are incorporated by reference where applicable, including Controller-to-Processor Module 2 and Processor-to-Processor Module 3, as applicable to the parties’ relationship.

The parties will complete and maintain applicable SCC annexes describing:

9. Assistance and Cooperation

Taking into account the nature of processing and information available to Guardyx, Guardyx will provide commercially reasonable assistance to Customer with:

Guardyx will provide reasonable assistance through self-service functionality and standard support processes without additional charge. Guardyx may charge reasonable fees for assistance requiring substantial additional engineering, legal review, or custom operational effort.

10. Audit Rights

Guardyx will make available information reasonably necessary to demonstrate compliance with this DPA.

Where reasonably required by Applicable Data Protection Laws, Customer may request additional information or documentation regarding Guardyx’s security and privacy controls.

Any audit rights will:

Guardyx may satisfy audit obligations through third-party certifications, audit reports, or security assessments, including SOC 2 Type II reports.

Guardyx intends to maintain or pursue commercially reasonable independent security assessments and certifications appropriate for the Services.

11. Deletion and Return of Personal Data

Upon termination or expiration of the Agreement:

Residual copies maintained in backups will remain protected under this DPA until deleted in the ordinary course of backup rotation procedures, which are generally completed within ninety (90) days.

12. AI Model Training Restrictions

Unless otherwise expressly agreed in writing:

Guardyx may generate and use aggregated and de-identified data that does not identify Customer or individuals for lawful operational analytics, security, reliability, and product improvement purposes.

Aggregated or de-identified data will not be used to train AI or machine learning models derived from Customer prompts, tool payloads, approval snapshots, or workflow content.

The foregoing does not restrict Guardyx’s use of aggregated or de-identified signals for operational security, abuse prevention, reliability, or anomaly-detection purposes, provided such signals do not identify Customer or individuals.

Guardyx will use commercially reasonable measures designed to prevent re-identification of aggregated or de-identified data.

13. Government Access Requests

If Guardyx receives a legally binding request from a governmental authority for access to Personal Data, Guardyx will:

Guardyx may publish transparency reporting regarding governmental requests where legally permitted.

14. California Privacy Provisions

To the extent the CCPA or CPRA applies:

15. Records of Processing

Guardyx will maintain records of processing activities as required under Applicable Data Protection Laws.

Upon reasonable request and subject to confidentiality obligations, Guardyx may make relevant records available to Customer where required by Applicable Data Protection Laws.

16. Liability

Liability arising under this DPA is subject to the limitations and exclusions of liability set forth in the Agreement unless otherwise prohibited by Applicable Data Protection Laws.

17. Sensitive Data

Customer acknowledges that prompts, tool payloads, responses, approval snapshots, audit logs, telemetry, and workflow content processed through the Services may contain sensitive or regulated information.

Customer is responsible for determining whether the Services are appropriate for Customer’s intended use cases involving regulated or sensitive data.

Unless otherwise expressly agreed in writing:

Customer and Guardyx may agree in an applicable Order Form or separate written agreement to additional contractual or technical safeguards enabling specific regulated-data use cases.

18. Term and Termination

This DPA remains effective for so long as Guardyx processes Personal Data on behalf of Customer.

19. Order of Precedence

In the event of conflict:

  1. the SCCs or other applicable transfer mechanism control with respect to international transfer obligations;
  2. this DPA controls with respect to data protection obligations;
  3. the Agreement controls for all other matters.

20. Contact Information

Privacy inquiries relating to this DPA may be directed to:

Data subject privacy requests may also be submitted through mechanisms identified in Guardyx’s Privacy Policy.

Code Above Lab, Inc.

Operator of Guardyx AI

See also: Terms of Service · Acceptable Use Policy · Privacy Policy · Cookie Policy.