Data Processing Addendum
Effective: May 3, 2026 · Last updated: May 23, 2026
This Data Processing Addendum (“DPA”) supplements the PolicyHQ Terms of Service (“Agreement”) between Gemini Group K.K. (“Processor”) and the customer organization identified in the Agreement (“Controller”). It governs Processor’s processing of Personal Data on Controller’s behalf in connection with the PolicyHQ service. Capitalized terms not defined here have the meanings given in the Agreement or, where applicable, in GDPR Article 4 or equivalent Japanese APPI terminology.
1. Subject matter and duration
1.1 Subject matter
Processor processes Personal Data on Controller’s behalf for the sole purpose of providing the Service as described in the Agreement.
1.2 Duration
This DPA takes effect on the Effective Date and remains in force for the term of the Agreement, plus any post-termination period during which Processor retains Personal Data (see § 9 — Return and deletion).
2. Nature and purpose of processing
- Hosting Customer Content within the Service;
- Authenticating users, enforcing access control, and routing notifications;
- Generating AI-powered summaries, classifications, translations, embeddings for semantic search, and answers for the “Ask the corpus” chat feature through subprocessors (see § 6);
- Sending transactional and digest emails to Controller’s authorized users;
- Producing audit logs and operational telemetry for security and support purposes.
3. Categories of Personal Data
- User identifiers: name, email address, role, organization affiliation;
- Authentication data: hashed credentials, session tokens, OAuth identifiers;
- Usage data: features used, search history, monitor definitions, comments, mentions;
- Customer Content: any personal data Controller chooses to include in notes, tags, watchlists, or AI prompts.
Processor does not process special-category data (race, health, biometric, etc.) unless Controller voluntarily includes it in Customer Content. Processing of special-category data outside Controller’s explicit instruction is prohibited.
4. Categories of data subjects
- Controller’s employees, contractors, and agents;
- Third-party stakeholders Controller chooses to track within the Service.
5. Processor obligations
Processor will:
- 5.1 Process Personal Data only on Controller’s documented instructions, including with regard to international transfers, unless required by applicable law;
- 5.2 Ensure persons authorized to process Personal Data are bound by confidentiality obligations;
- 5.3 Implement appropriate technical and organizational measures (see § 7);
- 5.4 Assist Controller in responding to data subject requests (access, deletion, portability) within 30 days of receipt;
- 5.5 Notify Controller without undue delay (and in any event within 72 hours) after becoming aware of a Personal Data breach, with sufficient information for Controller to meet its own notification obligations.
6. Subprocessors
6.1 Authorization
Controller grants general authorization for Processor to engage the subprocessors listed at policyhq.ai/security/subprocessors. Each subprocessor is bound by data protection terms no less protective than those in this DPA. The published list also identifies the country in which each subprocessor is located.
6.2 Changes
Processor will publish material changes to the subprocessor list at least 30 days before they take effect. Controller may object in writing within that window; if the parties cannot resolve the objection, Controller may terminate the affected portion of the Agreement on 30 days’ notice without penalty.
6.3 Liability
Processor remains liable to Controller for the acts and omissions of its subprocessors as if performed by Processor.
7. Security measures
Processor implements:
- TLS 1.3 in transit; AES-256 at-rest encryption;
- Role-based access control with least-privilege principles, enforced both at the application layer and through tenant-isolation tests covering every customer-data read and write path;
- Multi-factor authentication on the identity provider used for all administrative access. Application-level MFA for end users is on the roadmap;
- Audit logging of administrative + customer actions;
- Background-checked, contractually-bound employees with ongoing security training;
- Incident response procedures with documented escalation paths;
- Annual review of security controls. SOC 2 Type 1 audit is planned after the first paid-customer cohort; Processor will notify Controller of the start of the audit window and share the report on completion.
Detailed technical and organizational measures are documented at policyhq.ai/security.
8. International transfers
Personal Data is primarily stored in the Tokyo region (Japan). Where subprocessors located outside Japan or the EEA receive Personal Data (e.g., AI providers operating in the United States), Processor relies on:
- Standard Contractual Clauses (Commission Decision 2021/914) for transfers from the EEA;
- Equivalent contractual safeguards meeting APPI Article 28 requirements for transfers from Japan. Processor shall, to a reasonable extent and upon Controller's request, provide information regarding the status of the security control measures implemented by the subprocessors and the systems of the countries where they are located, so that Controller can fulfill its obligations under the Act on the Protection of Personal Information (APPI) (such as periodic obligations regarding provision to third parties in foreign countries);
- Vendor agreements that prohibit retention of Personal Data for model training or other secondary purposes.
9. Return and deletion
On termination of the Agreement, Controller may request an export of Customer Content within 30 days by emailing privacy@policyhq.ai; Processor will deliver the export within 30 days of receipt at no charge. (Self-serve in-product export is on the roadmap.) After the export window closes, Processor will:
- Delete or anonymize Customer Content from production systems within 30 days;
- Purge Customer Content from backups within 90 days, subject to backup rotation cycles;
- Retain only data legally required to be kept (e.g., billing records under Japanese tax law) for the minimum period required.
Processor will provide written confirmation of deletion on request.
10. Audits
Controller may, on 30 days’ written notice and no more than once per year (except in case of a material security incident), audit Processor’s compliance with this DPA. Audits will be conducted during business hours and not unreasonably interfere with Processor’s operations. Processor may satisfy audit requests by providing recent third-party audit reports (e.g., SOC 2 once available). However, until such third-party audit reports become available, Processor shall, upon Controller's request, provide responses in writing regarding the implementation status of its security control measures (such as security check sheets) once per year.
11. Liability
Each party’s liability under this DPA is subject to the liability limits in the Agreement. Nothing in this DPA limits either party’s liability to data subjects under applicable data protection law.
12. Order of precedence
In case of conflict between this DPA and the Agreement, this DPA prevails to the extent of the conflict, but only with respect to the processing of Personal Data.
13. Contact
DPA inquiries and signature requests: privacy@policyhq.ai.