Free discovery sessionSee which agents would take the admin off your sales team

Data Processing Agreement

Last updated: August 7, 2026

This Data Processing Agreement ("DPA") forms part of the Go Fig App Subscription Agreement or other written agreement between Go Fig, LLC ("Go Fig", "Processor") and the customer ("Customer", "Controller") governing Customer's use of the Go Fig platform (the "Agreement"). It applies to the extent Go Fig processes Personal Data on Customer's behalf.

A counter-signable copy is available from trust.gofig.ai or by emailing [email protected]. Where Customer and Go Fig have executed a negotiated data processing agreement, that agreement governs and supersedes this one.

1. Definitions

1.1 "Applicable Data Protection Law" means all laws relating to the processing of Personal Data applicable to a party, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and the California Consumer Privacy Act as amended by the CPRA ("CCPA").

1.2 "Customer Data" means the data Customer or its Authorized Users connect, upload, submit, or generate in the platform, together with the models, metrics, flows, dashboards, and analyses derived from it.

1.3 "Personal Data" means any Customer Data relating to an identified or identifiable natural person, as defined under Applicable Data Protection Law.

1.4 "Processing", "Controller", "Processor", "Data Subject", and "Personal Data Breach" have the meanings given in the GDPR.

1.5 "Subprocessor" means any third party engaged by Go Fig to process Personal Data on Customer's behalf.

1.6 "Standard Contractual Clauses" or "SCCs" means the clauses annexed to European Commission Implementing Decision (EU) 2021/914, and for UK transfers the UK International Data Transfer Addendum issued by the Information Commissioner.

2. Roles and scope

2.1 Customer is the Controller and Go Fig is the Processor with respect to Personal Data contained in Customer Data. Where Customer is itself a processor for a third-party controller, Go Fig is a subprocessor and Customer warrants it has the authority to engage Go Fig on those terms.

2.2 Go Fig is an independent Controller with respect to account registration data, billing data, and product usage telemetry relating to Authorized Users. That processing is described in the Privacy Policy and is outside the scope of this DPA.

2.3 The subject matter, duration, nature, and purpose of the processing, the categories of Personal Data, and the categories of Data Subjects are set out in Annex I.

3. Customer obligations

3.1 Customer is responsible for the accuracy and legality of Personal Data it makes available to Go Fig, and warrants that it has a lawful basis for the processing, has provided any required notices, and has obtained any required consents.

3.2 Customer determines which integrations to enable and what scope to grant. Customer acknowledges that mail, calendar, and messaging integrations may transmit message content, and that Customer is responsible for assessing whether to enable them.

3.3 Customer will not submit special categories of Personal Data under GDPR Article 9, or data subject to HIPAA, PCI-DSS, or comparable sectoral regimes, unless the parties have agreed additional terms in writing.

3.4 Customer-directed transmissions. Customer may direct Go Fig to transmit Customer Data to a third party, including by connecting its Go Fig organization to an external AI assistant through Go Fig's Model Context Protocol (MCP) server. Where Customer does so, the transmission is made on Customer's instruction and the recipient is not a Subprocessor of Go Fig. Go Fig authenticates the connection and logs the access, but does not control the recipient's processing, which is governed by Customer's own agreement with that recipient. This Section 3.4 does not apply to exports Customer takes into its own possession under Sections 7.1 and 10.1.

3.5 Customer-provided AI credentials. Where an Order Form specifies that Customer supplies its own credentials for an artificial intelligence service, Go Fig transmits Customer Data to that service on Customer's instruction and through Customer's own account with the provider. That provider is not a Subprocessor of Go Fig with respect to that processing, which is governed by Customer's own agreement with the provider, including any commitment concerning model training. Before transmission Go Fig applies the same role-based permission filtering and automated PII redaction described in Annex I, Section 6, and logs the access. Sections 4.3 and 5.3 do not apply to that processing. Go Fig will not substitute its own provider accounts for Customer's without Customer's prior written instruction.

4. Go Fig obligations

4.1 Documented instructions. Go Fig will process Personal Data only on Customer's documented instructions, which comprise the Agreement, this DPA, and Customer's configuration and use of the platform. Go Fig will inform Customer if, in its opinion, an instruction infringes Applicable Data Protection Law.

4.2 No sale, no independent use. Go Fig will not sell or share Personal Data as those terms are defined under the CCPA, will not retain, use, or disclose Personal Data for any purpose other than performing the services, and will not combine Personal Data with data received from other sources except as permitted under the CCPA.

4.3 No model training. Go Fig will not use Customer Data to train, fine-tune, or otherwise develop any machine learning model made available to any other customer, and will not permit any AI Subprocessor to do so. Go Fig's use of conversation content to evaluate and improve its own service is limited as described in Annex I, Section 6. This Section 4.3 governs Go Fig's own engagement of AI Subprocessors; it does not apply to transmissions Customer directs under Section 3.4, or to processing performed under Customer-provided credentials under Section 3.5, each of which is governed by Customer's own agreement with the recipient or provider.

4.4 Confidentiality. Go Fig will ensure that personnel authorized to process Personal Data are bound by confidentiality obligations and receive appropriate training.

4.5 Security. Go Fig will implement and maintain the technical and organizational measures set out in Annex II, taking into account the state of the art, the costs of implementation, and the risks to Data Subjects.

5. Subprocessors

5.1 General authorization. Customer grants Go Fig general authorization to engage Subprocessors, subject to this Section 5. The current list is published at trust.gofig.ai/subprocessors.

5.2 Notice and objection. Go Fig will give at least 30 days' notice before adding or replacing a Subprocessor, through the subscription mechanism on that page. Customer may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, Customer may terminate the affected subscription and receive a pro-rata refund of prepaid fees for the unused remainder of the term.

5.3 Flow-down and liability. Go Fig will impose data protection obligations on each Subprocessor no less protective than those in this DPA, and remains fully liable to Customer for each Subprocessor's performance, as required by Article 28(4) of the GDPR. That liability is subject to the limitations and exclusions of liability in Section 11.1.

6. International transfers

6.1 Go Fig processes Personal Data in the United States. Where Customer transfers Personal Data subject to GDPR, UK GDPR, or Swiss law to Go Fig, the SCCs are incorporated into this DPA by reference and apply as follows: Module Two (Controller to Processor) where Customer is a controller, and Module Three (Processor to Processor) where Customer is a processor.

6.2 For the purposes of the SCCs: Customer is the data exporter and Go Fig is the data importer; the optional docking clause applies; in Clause 9, Option 2 (general written authorization) applies with the notice period in Section 5.2; in Clause 17, the governing law is that of Ireland; in Clause 18(b), the forum is the courts of Ireland. Annexes I and II to this DPA populate Annexes I and II to the SCCs.

6.3 For UK transfers, the UK Addendum applies with Go Fig as Importer and Customer as Exporter, and neither party may terminate under Section 19 of the Addendum.

7. Data subject requests

7.1 The platform provides Customer with the ability to access, correct, export, and delete Customer Data directly. Customer will use those capabilities to respond to Data Subject requests where it can.

7.2 Where Customer cannot, Go Fig will provide reasonable assistance. If Go Fig receives a request directly from a Data Subject relating to Customer's Personal Data, it will not respond substantively and will refer the request to Customer without undue delay.

8. Personal Data Breach

8.1 Go Fig will notify Customer without undue delay, and in any event within 72 hours, of becoming aware of a Personal Data Breach affecting Customer's Personal Data.

8.2 The notification will describe the nature of the breach, the categories and approximate volume of Personal Data and Data Subjects affected so far as known, the likely consequences, and the measures taken or proposed. Where the full picture is not available at the time, Go Fig will provide information in phases as it is established.

8.3 Go Fig will provide reasonable assistance to Customer in meeting Customer's own notification obligations. Notification is not an acknowledgement of fault or liability.

9. Audit and assistance

9.1 Go Fig will make available the information necessary to demonstrate compliance with this DPA. Where Customer's subscription is designated as Enterprise in an Order Form, that information includes Go Fig's SOC 2 Type II report and supporting documentation, available under NDA from trust.gofig.ai. For all other subscriptions, Go Fig will make available a summary of its security posture, the technical and organizational measures set out in Annex II, and written responses to reasonable security and data protection questions, and will make the report available to the extent required by Applicable Data Protection Law. Customer acknowledges that Go Fig's SOC 2 examination covers the Security trust services category only, and does not cover the Availability, Processing Integrity, Confidentiality, or Privacy categories. Go Fig will respond directly to reasonable written questions on matters the report does not address. Customer's audit rights under Section 9.2 apply regardless of the edition of Customer's subscription.

9.2 Where that documentation is insufficient, Customer may request an audit no more than once in any 12-month period, on 30 days' notice, during business hours, subject to confidentiality, and at Customer's expense unless the audit reveals material non-compliance. Additional audits may be conducted where required by a supervisory authority or following a Personal Data Breach.

9.3 Go Fig will provide reasonable assistance with data protection impact assessments and prior consultations under GDPR Articles 35 and 36, taking into account the nature of the processing and the information available to it.

10. Return and deletion

10.1 On termination or expiry of the Agreement, Customer may export Customer Data in standard formats for 30 days.

10.2 After that period Go Fig will delete Customer Data from its production systems. Encrypted database backups are retained on a rolling schedule of 21 automated daily backups, with a seven-day point-in-time recovery window; backups are not restored to production, and Personal Data within them is overwritten as they age out of that schedule. Go Fig will confirm production deletion in writing on request.

10.3 Go Fig may retain Personal Data to the extent required by law, in which case it will continue to protect it under this DPA and process it only for the purpose requiring retention.

11. General

11.1 Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, except where Applicable Data Protection Law does not permit that limitation.

11.2 In the event of a conflict, this DPA prevails over the Agreement on matters of data protection, and the SCCs prevail over this DPA.

11.3 This DPA takes effect on the effective date of the Agreement and continues for as long as Go Fig processes Personal Data on Customer's behalf.


Annex I: Details of processing

1. Parties

Data exporter: Customer, as identified in the Agreement or Order Form. Role: Controller (or Processor, where Section 2.1 applies). Contact: as stated in the Order Form.

Data importer: Go Fig, LLC, 25 Goldsmith St, PMB 38, Greenville, SC 29609, United States. Role: Processor. Contact: [email protected].

2. Categories of Data Subjects

Customer's Authorized Users; and, depending on which integrations Customer enables, Customer's own customers, prospects, contacts, suppliers, employees, and correspondents.

3. Categories of Personal Data

Identifiers and contact details (name, email, phone, address); employment and role data; commercial and transactional records (invoices, bills, payments, deals, orders); communications content and metadata where mail, calendar, or messaging integrations are enabled; and any other Personal Data Customer chooses to connect or upload.

Special categories of Personal Data are not permitted without a separate written agreement (Section 3.3).

4. Nature and purpose of processing

Ingesting, storing, transforming, querying, analyzing, and displaying Customer Data to provide business analytics; generating AI-assisted analysis in response to Customer's questions; and, where Customer opts in, writing records to and sending messages through Customer's connected systems at Customer's direction.

5. Frequency and duration

Continuous for the duration of the subscription, on the sync schedules Customer configures, plus the retention periods in Section 10.

6. AI processing

Go Fig transmits to AI Subprocessors: the user's question and session history; structural metadata (table names, field names, field types, metric definitions, and user-written table and field descriptions); limited sample values drawn from a field or semantic model dimension to convey the shape of the data; a sample of rows relevant to the question, capped at 100 rows per request; and capped, truncated query results. Row samples and query results are filtered by the requesting user's role-based permissions before transmission. Automated redaction is applied to row samples and to profiled and sampled field values before transmission, and again as a screen on the assembled prompt. That redaction is pattern-based, covering government identification numbers, payment card numbers, email addresses, and telephone numbers, and is not guaranteed to remove all Personal Data. Descriptions and knowledge-base content authored by Customer's users are transmitted as written, without redaction.

Go Fig additionally transmits data to Google Cloud Vertex AI Vector Search, located in the United States (us-central1), which generates and stores embeddings of that data to support retrieval. What is transmitted on this path is broader than the prompt payload described above and comprises: table and field names, types, and descriptions; statistical profiles of fields, including value ranges and frequently occurring values; a small number of sample rows drawn from Customer Data; the definitions of Customer's flows, dashboards, and saved questions, including their names and descriptions; question text submitted by Customer's users; and the contents of any knowledge file Customer uploads. The redaction described above is applied to sample rows and to profiled and sampled values on this path; it is not applied to descriptions or knowledge-file content.

Records derived from Customer Data carry Customer's organization identifier, and retrieval of those records is filtered by that identifier at the provider. Indexed records are not subject to a fixed retention period. They are removed when the underlying table is deleted, when Customer disables AI features for its organization, and on deletion of Customer's organization.

Go Fig does not transmit full table exports, bulk extracts, credentials, or data belonging to another customer. AI Subprocessors are engaged through business API tiers whose terms prohibit training on submitted data.

Where an Order Form specifies that Customer supplies its own credentials for an artificial intelligence service, the transmissions described in this Section 6 are made through Customer's own account with that provider rather than Go Fig's. The categories of data transmitted, the permission filtering, and the PII redaction are unchanged. The provider's treatment of that data, including any commitment concerning model training and retention, is governed by Customer's own agreement with the provider rather than by this DPA. See Section 3.5.

Go Fig reviews conversation content from real usage to evaluate and improve its own service quality. Conversations are screened by an automated filter that excludes those showing indicators of Personal Data; flagged conversations are reviewed by authorized Go Fig personnel before any further use. This activity does not train any third-party model. Customer may request that its organization be excluded from this activity at [email protected].

7. Subprocessors

The current list, with the processing purpose and data categories for each, is maintained at trust.gofig.ai/subprocessors and forms part of this Annex.


Annex II: Technical and organizational measures

Encryption

TLS 1.2 or higher enforced for all connections in transit, with TLS 1.3 negotiated by default; TLS 1.0 and 1.1 are disabled. This includes database connections (sslmode=require) and object storage access over HTTPS. Google Cloud managed AES-256 encryption at rest for Cloud SQL and Cloud Storage. Connector credentials encrypted at rest with Fernet symmetric encryption. Platform secrets held in Google Cloud Secret Manager. Storage access keys rotated on a 90-day policy.

Access control

Email and password authentication with configurable verification, plus Google and Microsoft OAuth. TOTP multi-factor authentication with recovery codes available to all users. Password policy enforcing minimum length and rejecting common, numeric-only, and user-similar passwords. Account lockout after 3 failed attempts in 5 minutes; login rate-limited to 5 attempts per minute per IP. Sessions expire after 8 hours.

Role-based access control at three levels: organization roles (Admin, Data Steward, and Analyst, plus a legacy read-only role that is retained for existing assignments and is no longer issued); custom data roles for collection and table access; and field-level restrictions supporting both hiding and redaction. Organization roles apply to every subscription. Custom data roles and field-level restrictions are enabled on Growth and Enterprise subscriptions. API keys are user-owned, organization-scoped, and stored hashed. All external identifiers are obfuscated.

Tenant isolation

Isolation enforced independently at four layers: middleware organization fence validated on every request; organization filtering on every database query; per-organization storage namespacing with scoped access credentials; and role-based access control within each organization. Cross-organization access attempts raise an error and are logged. AI vector search is guarded both in application code and by server-side provider filters.

AI guardrails

Four independent layers: input sanitization with PII redaction before any provider call; SQL security enforcing SELECT-only execution and blocking system tables and file access functions; SQL validation against the live schema with type checking and dry-run execution; and output validation stripping unverified URLs, flagging fabricated figures, and detecting ungrounded claims. Write-back capabilities are disabled by default, enabled only by the Controller's own organization-level and per-connector settings, and recorded in a write audit log.

Logging and monitoring

AI interaction audit logs capturing intent, tables and fields accessed, model used, and results. Each record is reviewable in-product by the user who ran the interaction, and by any user holding the Admin role in that user's organization, both under the individual interaction and in an organization-wide log filterable by user and by date range. That log reports on a window of the Customer's choosing spanning up to 400 days measured end to end; a single request returns at most the 500 most recent interactions within the window, the log states on screen when the window holds more than one request returns, and it reports the total number of interactions in the window in either case. Question text is readable for 90 days measured from the creation of the conversation containing it, so a question put to a conversation opened more than 90 days earlier is withheld even where the question itself is recent; decision trails are readable for 90 days measured from the interaction itself. Beyond those periods the content is withheld at read time, in advance of the scheduled deletion jobs. Where a decision trail is withheld on the conversation measure, the stages executed, their timing and confidence, and the tables reached remain readable and only the written detail and generated SQL are withheld. The interaction's user attribution and timestamp are not subject to the 90-day limit; the models used and credits consumed are held with the usage metering records described next and are retained on the same seven-year basis. Usage metering records (model, token counts, cost, credits, no content) are retained for seven years on a tax and accounting basis, with the user identifier removed after 90 days so that only organization-level metering persists. Application error tracking, uptime monitoring, and structured logging to Google Cloud Logging. Permission audit logging available on Enterprise.

Resilience

Google Cloud Platform. Application compute runs in us-east1. Customer data objects are stored in Google Cloud Storage's US multi-region location, which replicates them across at least two United States regions and holds them only within the United States, with 11 nines durability. Cloud SQL automated daily backups, 21 retained, with point-in-time recovery across a seven-day transaction log window. Auto-scaling compute with multiple instances. Application compute is currently single-region; formal recovery time and recovery point objectives are in development and are disclosed on request.

Secure development and assurance

Code review required on all changes. Continuous integration runs linting, tests, and dependency vulnerability scanning. Staging environment for integration testing. Migrations run before code deployment and a failed migration blocks the deploy. SOC 2 Type II certified, with continuous control monitoring through Vanta. External penetration testing is commissioned periodically; the most recent scope and results are available to Customer on request.

Personnel

Background screening, confidentiality obligations, and security awareness training for personnel with access to Personal Data. Access granted on a least-privilege basis and revoked on role change or departure.