This Data Processing Addendum (“DPA”) forms part of the agreement between Gapless and customers whose use of the service involves the processing of personal data contained in customer content. Capitalized terms not defined here have the meanings given in the agreement.
Roles of the parties
For personal data contained in customer content, the customer acts as the controller and Gapless acts as the processor. Gapless processes such data only on the customer’s documented instructions, including the instructions embodied in the agreement and the customer’s use of the service.
Scope and purpose of processing
Processing is limited to what is necessary to provide, secure, and support the service, including generating and maintaining learning paths for the customer’s users. The categories of data and data subjects are determined by the customer’s configuration and use of the service.
Confidentiality and personnel
Personnel authorized to process personal data are bound by confidentiality obligations and receive access only to the extent needed to perform their role.
Security measures
Gapless maintains technical and organizational measures appropriate to the risk, including encryption in transit, access controls, logging, and secure development practices. Measures are reviewed and updated as the product and threat landscape evolve.
Subprocessors
Gapless uses vetted subprocessors for infrastructure, AI processing, and support, and remains responsible for their performance. Customers receive notice of new subprocessors and may object on reasonable data protection grounds.
Data subject requests
Taking into account the nature of the processing, Gapless assists the customer in responding to requests from data subjects exercising their rights, and forwards to the customer any such requests it receives directly.
Personal data breaches
Gapless notifies the customer without undue delay after becoming aware of a personal data breach affecting customer personal data, and provides the information reasonably needed to meet the customer’s notification obligations.
International transfers
Where processing involves transfers of personal data out of the EEA, UK, or Switzerland, the parties rely on lawful transfer mechanisms such as standard contractual clauses or an applicable adequacy decision.
Deletion and return
Upon termination of the service, Gapless deletes or returns customer personal data at the customer’s choice, subject to limited retention required by law, and deletes remaining copies once retention obligations expire.
Audits and signed copies
Gapless makes available the information reasonably necessary to demonstrate compliance with this DPA. Enterprise customers can request a countersigned copy of the full addendum during procurement.