1. Roles and instructions
This Data Processing Addendum supplements an agreement between the business customer in an order and GC Total Software LLC when GC Total processes personal data for that customer. It becomes effective only when executed or incorporated into an accepted order.
For personal data processed solely under documented customer instructions, the customer is the controller or business and GC Total the processor or service provider, as applicable. Each party remains responsible for processing for which it determines purposes and means.
Customer Personal Data means personal information contained in Customer Content that GC Total processes for the customer under this DPA. A Security Incident means confirmed unauthorized access to, acquisition of, or disclosure, alteration, loss, or destruction of Customer Personal Data in GC Total’s custody or control, excluding unsuccessful attempts that do not compromise its security.
The agreement, order, DPA, and signed Data Handling Profile are the customer’s documented instructions. GC Total will process Customer Personal Data to provide, secure, debug, support, and legally operate the service; perform internal improvement only where the customer’s documented instruction and applicable law permit it and no exclusion or opt-out applies; comply with instructions; or comply with law. GC Total will notify the customer if it reasonably believes an instruction violates applicable privacy law and may suspend the affected processing.
2. Confidentiality and personnel
Personnel authorized to process Customer Personal Data will be bound by confidentiality duties and receive access only as needed. GC Total remains responsible for personnel compliance with this DPA.
3. Security
GC Total will maintain reasonable administrative, technical, and organizational safeguards appropriate to the data and risk, including the controls described in Schedule 2.
4. Security incidents
GC Total will notify the customer without undue delay after becoming aware of a Security Incident involving Customer Personal Data, using the customer’s designated account or security contact. GC Total will take reasonable steps to contain and investigate the incident, preserve relevant records, cooperate with the customer, and provide available facts needed for applicable notice duties, subject to lawful restrictions. Notice is not an admission of fault.
5. Rights requests, assessments, and cooperation
Taking account of the processing, GC Total will reasonably assist with authenticated rights requests, required assessments, and regulator inquiries concerning Customer Personal Data. Customer-controlled project requests are promptly referred to the customer unless law requires otherwise. The customer decides the response.
The customer is responsible for its instructions, notices, permissions, lawful basis, and responses to individuals, and for determining whether the service is appropriate for the data it submits.
6. Subprocessors
The customer gives general authorization for subprocessors in the versioned provider appendix to the Privacy and Data Notice. GC Total will bind each to appropriate confidentiality, security, use, deletion or return, and assistance duties and remains responsible to the extent required by this DPA and law.
GC Total will give at least 15 days’ advance notice of a material new project-processing subprocessor. The customer may object on reasonable data-protection grounds within 10 days after notice. The parties will work in good faith on a reasonable alternative. If none is available, the customer may terminate the affected service without penalty before the change takes effect.
No project-processing subprocessor may use customer-uploaded project documents, extracted project data, generated project outputs, corrections, accept/reject feedback, or GC Total improvement-corpus material to train or improve general-purpose or provider-owned models. Restricted and no-retention projects fail closed when a provider cannot honor the profile.
Payment providers are not authorized to receive project or improvement-corpus material. Stripe may separately process payment-method, billing, transaction, device, and fraud-prevention personal data under its applicable role and terms and states that some such data supports fraud- and loss-prevention model training. Those payment uses are separate from project-document processing and GC Total’s improvement program.
7. Return, deletion, retention, and Legal Holds
At documented direction or after service termination, GC Total will return or delete Customer Personal Data under the order, Privacy and Data Notice, and Data Handling Profile, except for an approved schedule, mandatory law, dispute preservation, security investigation, or Legal Hold.
A no-retention profile disables training at intake and deletes customer files, material prompts/responses, derived data, and server-side deliverables within 30 days after final delivery or sooner if signed terms require. Deleted content expires from rolling backups within 35 days. Minimal deletion proof and legally required account, billing, consent, security, and legal records may remain.
8. Audit information
GC Total will make reasonably necessary compliance information available and cooperate with one reasonable assessment per year on at least 30 days’ notice. The assessment will use documentation and independent reports first, protect other customers and security information, avoid unreasonable disruption, and be paid for by the customer unless it identifies material noncompliance by GC Total. These limits do not restrict a regulator or reasonable investigation following a Security Incident.
9. Location and transfers
U.S.-business-only launch does not establish U.S.-only data residency. Provider facilities and routed AI services may involve other locations. An order and provider appendix must state any promised restriction. Applicable EEA, UK, Swiss, or other cross-border processing requires an approved transfer mechanism before it begins.
10. Liability, precedence, and term
This DPA controls conflicting agreement terms only for its subject matter and remains effective while GC Total processes Customer Personal Data under it. The liability limits and exclusions in the Terms or applicable order apply to this DPA except where law does not permit them. Texas law and the exclusive state and federal courts serving Travis County, Texas govern. This DPA creates no third-party-beneficiary rights and survives termination while GC Total retains Customer Personal Data.
Schedule 1 — Processing details
| Item | Description |
|---|---|
| Subject matter | Authentication, secure intake, storage, automated and AI-assisted Bid-Scope Analysis, work-product generation and delivery, billing, support, audit, and authorized improvement |
| Duration | Service term plus applicable retention, subject to Data Handling Profile and Legal Hold |
| Nature | Collecting, receiving, validating, quarantining, scanning, storing, retrieving, structuring, extracting, analyzing, generating, comparing, transmitting, delivering, correcting, auditing, eligible improvement, returning, and deleting |
| Purposes | Provide, secure, debug, support, audit, improve where authorized, and legally operate the customer’s service |
| Data subjects | Business users, administrators, senders, recipients, contacts, project participants, and people appearing in submitted material |
| Data categories | Business identifiers and contacts; account, role, authorization, device, IP, and usage; communications; project documents; prompts/responses; derived findings; work products; corrections and feedback; billing and transaction metadata; audit and security records |
| Sensitive or restricted data | Not accepted through the ordinary route; suspected restricted material is quarantined and processing stops until an authorized profile supports it or GC Total returns or deletes it |
Schedule 2 — Security controls
- authenticated access limited by organization, project, role, and user scope;
- personnel and provider access limited to what is needed for assigned duties;
- reasonable encryption in transit and provider-supported protection at rest;
- file validation, quarantine, malware screening, and sensitive-document routing;
- logging and audit records for material processing, access, direction, correction, and delivery events;
- credential and secret management, software-change review, backup and recovery practices;
- retention, deletion, no-retention, and Legal Hold procedures; and
- incident response, provider review, and workforce confidentiality obligations.
These controls describe GC Total’s obligations and do not claim a certification. Customer responsibilities include account administration, authorized instructions, recipient accuracy, credential protection, and identifying restricted data before submission.
Schedule 3 — Approved subprocessors
The provider appendix in the Privacy and Data Notice, as dated when this DPA is incorporated, is Schedule 3. Only providers needed for the customer’s enabled route receive Customer Personal Data. Clerk provides identity services; Railway and PostgreSQL hosting and databases; Backblaze B2 object storage; Postmark transactional email; Modal compute; and OpenRouter and routed model providers AI processing. Stripe processes billing separately and is not authorized to receive project documents. GC Total will identify any materially different subprocessor in the notice described in Section 6.
Schedule 4 — Data Handling Profile
A signed profile may select ordinary or no retention; improvement permitted or disabled; approved storage and model routes; location and logging requirements; deletion deadline; restricted-data classification and authority; recipients; and customer-specific security or audit requirements. The route fails closed when a provider cannot satisfy the profile.