Data Processing Agreement
Last updated: August 6, 2026
This Data Processing Agreement ("DPA") forms part of the Go Fig App Subscription Agreement or other written agreement between Go Fig, LLC ("Go Fig", "Processor") and the customer ("Customer", "Controller") governing Customer's use of the Go Fig platform (the "Agreement"). It applies to the extent Go Fig processes Personal Data on Customer's behalf.
A counter-signable copy is available from trust.gofig.ai or by emailing [email protected]. Where Customer and Go Fig have executed a negotiated data processing agreement, that agreement governs and supersedes this one.
1. Definitions
1.1 "Applicable Data Protection Law" means all laws relating to the processing of Personal Data applicable to a party, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and the California Consumer Privacy Act as amended by the CPRA ("CCPA").
1.2 "Customer Data" means the data Customer or its Authorized Users connect, upload, submit, or generate in the platform, together with the models, metrics, flows, dashboards, and analyses derived from it.
1.3 "Personal Data" means any Customer Data relating to an identified or identifiable natural person, as defined under Applicable Data Protection Law.
1.4 "Processing", "Controller", "Processor", "Data Subject", and "Personal Data Breach" have the meanings given in the GDPR.
1.5 "Subprocessor" means any third party engaged by Go Fig to process Personal Data on Customer's behalf.
1.6 "Standard Contractual Clauses" or "SCCs" means the clauses annexed to European Commission Implementing Decision (EU) 2021/914, and for UK transfers the UK International Data Transfer Addendum issued by the Information Commissioner.
2. Roles and scope
2.1 Customer is the Controller and Go Fig is the Processor with respect to Personal Data contained in Customer Data. Where Customer is itself a processor for a third-party controller, Go Fig is a subprocessor and Customer warrants it has the authority to engage Go Fig on those terms.
2.2 Go Fig is an independent Controller with respect to account registration data, billing data, and product usage telemetry relating to Authorized Users. That processing is described in the Privacy Policy and is outside the scope of this DPA.
2.3 The subject matter, duration, nature, and purpose of the processing, the categories of Personal Data, and the categories of Data Subjects are set out in Annex I.
3. Customer obligations
3.1 Customer is responsible for the accuracy and legality of Personal Data it makes available to Go Fig, and warrants that it has a lawful basis for the processing, has provided any required notices, and has obtained any required consents.
3.2 Customer determines which integrations to enable and what scope to grant. Customer acknowledges that mail, calendar, and messaging integrations may transmit message content, and that Customer is responsible for assessing whether to enable them.
3.3 Customer will not submit special categories of Personal Data under GDPR Article 9, or data subject to HIPAA, PCI-DSS, or comparable sectoral regimes, unless the parties have agreed additional terms in writing.
4. Go Fig obligations
4.1 Documented instructions. Go Fig will process Personal Data only on Customer's documented instructions, which comprise the Agreement, this DPA, and Customer's configuration and use of the platform. Go Fig will inform Customer if, in its opinion, an instruction infringes Applicable Data Protection Law.
4.2 No sale, no independent use. Go Fig will not sell or share Personal Data as those terms are defined under the CCPA, will not retain, use, or disclose Personal Data for any purpose other than performing the services, and will not combine Personal Data with data received from other sources except as permitted under the CCPA.
4.3 No model training. Go Fig will not use Customer Data to train, fine-tune, or otherwise develop any machine learning model made available to any other customer, and will not permit any AI Subprocessor to do so. Go Fig's use of conversation content to evaluate and improve its own service is limited as described in Annex I, Section 6.
4.4 Confidentiality. Go Fig will ensure that personnel authorized to process Personal Data are bound by confidentiality obligations and receive appropriate training.
4.5 Security. Go Fig will implement and maintain the technical and organizational measures set out in Annex II, taking into account the state of the art, the costs of implementation, and the risks to Data Subjects.
5. Subprocessors
5.1 General authorization. Customer grants Go Fig general authorization to engage Subprocessors, subject to this Section 5. The current list is published at trust.gofig.ai/subprocessors.
5.2 Notice and objection. Go Fig will give at least 30 days' notice before adding or replacing a Subprocessor, through the subscription mechanism on that page. Customer may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, Customer may terminate the affected subscription and receive a pro-rata refund of prepaid fees for the unused remainder of the term.
5.3 Flow-down and liability. Go Fig will impose data protection obligations on each Subprocessor no less protective than those in this DPA, and remains fully liable to Customer for each Subprocessor's performance.
6. International transfers
6.1 Go Fig processes Personal Data in the United States. Where Customer transfers Personal Data subject to GDPR, UK GDPR, or Swiss law to Go Fig, the SCCs are incorporated into this DPA by reference and apply as follows: Module Two (Controller to Processor) where Customer is a controller, and Module Three (Processor to Processor) where Customer is a processor.
6.2 For the purposes of the SCCs: Customer is the data exporter and Go Fig is the data importer; the optional docking clause applies; in Clause 9, Option 2 (general written authorization) applies with the notice period in Section 5.2; in Clause 17, the governing law is that of Ireland; in Clause 18(b), the forum is the courts of Ireland. Annexes I and II to this DPA populate Annexes I and II to the SCCs.
6.3 For UK transfers, the UK Addendum applies with Go Fig as Importer and Customer as Exporter, and neither party may terminate under Section 19 of the Addendum.
7. Data subject requests
7.1 The platform provides Customer with the ability to access, correct, export, and delete Customer Data directly. Customer will use those capabilities to respond to Data Subject requests where it can.
7.2 Where Customer cannot, Go Fig will provide reasonable assistance. If Go Fig receives a request directly from a Data Subject relating to Customer's Personal Data, it will not respond substantively and will refer the request to Customer without undue delay.
8. Personal Data Breach
8.1 Go Fig will notify Customer without undue delay, and in any event within 72 hours, of becoming aware of a Personal Data Breach affecting Customer's Personal Data.
8.2 The notification will describe the nature of the breach, the categories and approximate volume of Personal Data and Data Subjects affected so far as known, the likely consequences, and the measures taken or proposed. Where the full picture is not available at the time, Go Fig will provide information in phases as it is established.
8.3 Go Fig will provide reasonable assistance to Customer in meeting Customer's own notification obligations. Notification is not an acknowledgement of fault or liability.
9. Audit and assistance
9.1 Go Fig will make available the information necessary to demonstrate compliance with this DPA, including through its SOC 2 Type II report and supporting documentation, available under NDA from trust.gofig.ai. Customer acknowledges that Go Fig's SOC 2 examination covers the Security trust services category only, and does not cover the Availability, Processing Integrity, Confidentiality, or Privacy categories. Go Fig will respond directly to reasonable written questions on matters the report does not address.
9.2 Where that documentation is insufficient, Customer may request an audit no more than once in any 12-month period, on 30 days' notice, during business hours, subject to confidentiality, and at Customer's expense unless the audit reveals material non-compliance. Additional audits may be conducted where required by a supervisory authority or following a Personal Data Breach.
9.3 Go Fig will provide reasonable assistance with data protection impact assessments and prior consultations under GDPR Articles 35 and 36, taking into account the nature of the processing and the information available to it.
10. Return and deletion
10.1 On termination or expiry of the Agreement, Customer may export Customer Data in standard formats for 30 days.
10.2 After that period Go Fig will delete Customer Data from its production systems. Encrypted backups expire on a documented rolling schedule and are not restored to production; Personal Data in expired backups is overwritten in the ordinary course. Go Fig will confirm production deletion in writing on request.
10.3 Go Fig may retain Personal Data to the extent required by law, in which case it will continue to protect it under this DPA and process it only for the purpose requiring retention.
11. General
11.1 Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, except where Applicable Data Protection Law does not permit that limitation.
11.2 In the event of a conflict, this DPA prevails over the Agreement on matters of data protection, and the SCCs prevail over this DPA.
11.3 This DPA takes effect on the effective date of the Agreement and continues for as long as Go Fig processes Personal Data on Customer's behalf.
Annex I: Details of processing
1. Parties
Data exporter: Customer, as identified in the Agreement or Order Form. Role: Controller (or Processor, where Section 2.1 applies). Contact: as stated in the Order Form.
Data importer: Go Fig, LLC, 25 Goldsmith St, PMB 38, Greenville, SC 29609, United States. Role: Processor. Contact: [email protected].
2. Categories of Data Subjects
Customer's Authorized Users; and, depending on which integrations Customer enables, Customer's own customers, prospects, contacts, suppliers, employees, and correspondents.
3. Categories of Personal Data
Identifiers and contact details (name, email, phone, address); employment and role data; commercial and transactional records (invoices, bills, payments, deals, orders); communications content and metadata where mail, calendar, or messaging integrations are enabled; and any other Personal Data Customer chooses to connect or upload.
Special categories of Personal Data are not permitted without a separate written agreement (Section 3.3).
4. Nature and purpose of processing
Ingesting, storing, transforming, querying, analyzing, and displaying Customer Data to provide business analytics; generating AI-assisted analysis in response to Customer's questions; and, where Customer opts in, writing records to and sending messages through Customer's connected systems at Customer's direction.
5. Frequency and duration
Continuous for the duration of the subscription, on the sync schedules Customer configures, plus the retention periods in Section 10.
6. AI processing
Go Fig transmits to AI Subprocessors: the user's question and session history; structural metadata (table names, field names, field types, metric definitions); a sample of rows relevant to the question, capped at 100 rows per request, filtered by the requesting user's role-based permissions, and passed through automated PII redaction; and capped, truncated query results.
Go Fig does not transmit full table exports, bulk extracts, credentials, or data belonging to another customer. AI Subprocessors are engaged through business API tiers whose terms prohibit training on submitted data.
Go Fig reviews conversation content from real usage to evaluate and improve its own service quality. Conversations are screened by an automated filter that excludes those showing indicators of Personal Data; flagged conversations are reviewed by authorized Go Fig personnel before any further use. This activity does not train any third-party model. Customer may request that its organization be excluded from this activity at [email protected].
7. Subprocessors
The current list, with the processing purpose and data categories for each, is maintained at trust.gofig.ai/subprocessors and forms part of this Annex.
Annex II: Technical and organizational measures
Encryption
TLS enforced for all connections in transit, including database connections (sslmode=require) and object storage access over HTTPS. Google Cloud managed AES-256 encryption at rest for Cloud SQL and Cloud Storage. Connector credentials encrypted at rest with Fernet symmetric encryption. Platform secrets held in Google Cloud Secret Manager. Storage access keys rotated on a 90-day policy.
Access control
Email and password authentication with configurable verification, plus Google and Microsoft OAuth. TOTP multi-factor authentication with recovery codes available to all users. Password policy enforcing minimum length and rejecting common, numeric-only, and user-similar passwords. Account lockout after 3 failed attempts in 5 minutes; login rate-limited to 5 attempts per minute per IP. Sessions expire after 8 hours.
Role-based access control at three levels: organization roles (Admin, Data Steward, Analyst, Viewer), custom data roles for collection and table access, and field-level restrictions supporting both hiding and redaction. API keys are user-owned, organization-scoped, and stored hashed. All external identifiers are obfuscated.
Tenant isolation
Isolation enforced independently at four layers: middleware organization fence validated on every request; organization filtering on every database query; per-organization storage namespacing with scoped access credentials; and role-based access control within each organization. Cross-organization access attempts raise an error and are logged. AI vector search is guarded both in application code and by server-side provider filters.
AI guardrails
Four independent layers: input sanitization with PII redaction before any provider call; SQL security enforcing SELECT-only execution and blocking system tables and file access functions; SQL validation against the live schema with type checking and dry-run execution; and output validation stripping unverified URLs, flagging fabricated figures, and detecting ungrounded claims. Write-back capabilities are disabled by default, gated by plan entitlement, and recorded in a write audit log.
Logging and monitoring
AI interaction audit logs capturing intent, tables and fields accessed, model used, and results, retained 90 days and reviewable by organization admins. Application error tracking, uptime monitoring, and structured logging to Google Cloud Logging. Permission audit logging available on Enterprise.
Resilience
Google Cloud Platform, us-east1. Cloud SQL automated backups with point-in-time recovery. Object storage with 11 nines durability. Auto-scaling compute with multiple instances. Deployment is currently single-region; formal recovery time and recovery point objectives are in development and are disclosed on request.
Secure development and assurance
Code review required on all changes. Continuous integration runs linting, tests, and dependency vulnerability scanning. Staging environment for integration testing. Migrations run before code deployment and a failed migration blocks the deploy. Annual external penetration testing. SOC 2 Type II certified, with continuous control monitoring through Vanta.
Personnel
Background screening, confidentiality obligations, and security awareness training for personnel with access to Personal Data. Access granted on a least-privilege basis and revoked on role change or departure.