Draft — pending legal review. This DPA is a template, not final legal advice.

Data Processing Agreement

Last updated: [date]. This DPA is a draft template for owner and legal review.

1. Roles

For personal data that customers place into the service (for example, content crawled from a customer's website and the results produced from it), the customer is the controller and gist acts as a processor on the customer's documented instructions. Where the customer is itself a processor for a third party, gist acts as a sub-processor.

2. Processing instructions

We process customer data only to provide and support the service described in the customer's account, and in accordance with the customer's lawful instructions. We do not use customer data for purposes other than those instructed, and we do not sell it.

3. Sub-processors

We may engage the sub-processors listed in docs/legal/subprocessors.md (hosting, AI analysis, email delivery, payment processing and backup storage). We will notify customers of any new or replaced sub-processor and will not engage one without this notice; customers may object by contacting us or terminating their account.

4. Data subject rights

We will assist the customer in fulfilling data-subject requests relating to data processed under this agreement, using the account's export and deletion tools and, on request, by other reasonable means.

5. Security

We apply appropriate technical and organisational measures to protect customer data, including encryption of stored secrets, access controls, and per-tenant isolation. We will notify the customer without undue delay of any confirmed personal-data breach affecting their data.

6. Retention and deletion

Customer data is retained only as long as needed to provide the service, in line with the retention periods in our Privacy Policy, and is deleted when the customer requests erasure or after termination of the account, except where law requires longer retention.

See also: Terms, Privacy Policy, Refunds.