Skip to content

Legal

Data Processing Addendum

This addendum applies where Gongong AI processes personal data on your behalf as a processor. It is published in draft; the executable version must be reviewed by counsel before launch.

Draft pending legal review

This document is a draft pending legal review — not an executed agreement.

1. Roles

For content you upload and for the audience data returned by connected networks, you are the controller and Gongong AI is the processor. For account and billing data about your own users, Gongong AI is a controller.

2. Scope and instructions

We process personal data only on your documented instructions, which the configuration of your workspace and the use of the product constitute. We inform you if an instruction appears to breach applicable data protection law.

3. Confidentiality

Personnel with access to personal data are bound by confidentiality obligations and access is granted on a least-privilege basis.

4. Security measures

Technical and organisational measures include, at minimum:

  • Encryption in transit, and envelope encryption of social network tokens at rest.
  • Workspace-scoped data access enforced in the data layer, with cross-tenant isolation covered by automated tests.
  • Role-based access control, mandatory two-factor authentication for staff, and an IP allowlist on administrative surfaces.
  • Audit logging of administrative and destructive actions.
  • Rate limiting per IP, per user, per API key and per connected account.

5. Subprocessors

You authorise the use of subprocessors listed in the maintained register. We give notice before adding one, and you may object on reasonable data protection grounds.

6. Assistance

We assist you with data subject requests, data protection impact assessments and consultations with supervisory authorities, taking into account the nature of the processing and the information available to us.

7. Personal data breach

We notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information needed for your own notification obligations.

8. Transfers

Transfers outside the region of origin rely on the appropriate mechanism for that route, listed with the subprocessor register.

9. Deletion and return

On termination, and at your choice, we delete or return personal data processed on your behalf, except where retention is required by law.

10. Audit

We make available the information needed to demonstrate compliance and accommodate audits on reasonable notice, subject to confidentiality.