Effective: on execution of the MSA Order Form
Last updated: 2026-05-18
Document key: dpa
Plain-English summary
When a GAEZLA customer uses the Service to process personal information about other people (their employees, their IT-asset users, etc.), this Addendum sets out what we can do with it, what protections we apply, which third parties we use, and what happens when things go wrong. The customer decides what to put in; we process it only on the customer’s documented instructions. This Addendum is governed by Delaware law and is written to satisfy California Consumer Privacy Act (CCPA / CPRA) requirements for service-provider contracts. It does not undertake non-US privacy regimes; customers subject to such regimes are responsible for their own compliance and may negotiate separate terms with us.
Order of precedence: This DPA takes precedence over the MSA with respect to Personal Information.
1. Definitions
“Business” and “Service Provider” have the meanings given in the California Consumer Privacy Act (Cal. Civ. Code § 1798.140) as amended by the California Privacy Rights Act.
“Customer” / “Business” means the Customer entity identified in the Order Form, acting as the Business in respect of Personal Information it provides to the Service.
“Company” / “Service Provider” means T1P5M4RK, LLC, the entity that processes Personal Information on the Customer’s behalf as a Service Provider.
“Personal Information” has the meaning in CCPA § 1798.140(v): information that identifies, relates to, describes, or could reasonably be linked with a particular consumer or household, in respect of California residents, plus equivalent terms in other applicable US state privacy laws.
“Customer Data” has the meaning in the MSA and includes any Personal Information processed under this Addendum.
“Sensitive Personal Information” has the meaning in CCPA § 1798.140(ae).
“Sub-processor” means any third party engaged by Company to process Personal Information under this Addendum.
“Security Incident” means a confirmed unauthorised acquisition of, access to, or disclosure of unencrypted Personal Information in Company’s possession.
2. Roles
The Customer is the Business. Company is the Service Provider. Company will process Personal Information only on the Customer’s documented instructions, including as set out in this Addendum, the MSA, and the Order Form. If Company believes an instruction would cause it to violate applicable US privacy law, Company will promptly notify Customer and may suspend the instruction pending resolution.
3. CCPA / CPRA Service Provider commitments
Company will:
(a) Use limitation. Process Personal Information only to perform the Service for Customer or as otherwise permitted by CCPA § 1798.140(ag)(2). Company will not: (i) sell or share Personal Information (as those terms are defined in CCPA); (ii) retain, use, or disclose Personal Information for any purpose other than performing the Service or as expressly permitted by CCPA; (iii) retain, use, or disclose Personal Information outside the direct business relationship between Company and Customer; or (iv) combine Personal Information received from Customer with Personal Information from any other source, except as permitted by 11 CCR § 7050.
(b) Confidentiality. Ensure that personnel authorised to process Personal Information are bound by appropriate confidentiality obligations.
(c) Security. Implement and maintain the technical and organisational security measures set out in Annex II.
(d) Sub-processors. Engage sub-processors only on the terms in Section 5.
(e) Assistance with consumer rights. Assist Customer in responding to verifiable consumer requests under CCPA (access, deletion, correction, opt-out of sale/sharing, limit use of sensitive personal information) to the extent Company can reasonably do so, taking into account the nature of the processing and information available to Company.
(f) Notice of inability to comply. Notify Customer promptly if Company determines that it can no longer meet its obligations under CCPA.
(g) Audit. Make available to Customer, on reasonable written request, information reasonably necessary to demonstrate Company’s compliance with this Addendum. Customer may, no more than once per year and on at least thirty (30) days’ written notice, conduct a reasonable audit (or commission one through an independent third-party auditor) at Customer’s cost, subject to confidentiality and operational-security requirements.
4. Customer obligations
Customer warrants and undertakes that:
(a) it has provided all required notices to, and obtained all required consents from, individuals whose Personal Information is processed via the Service, as required by applicable US privacy law; (b) it has a lawful basis under applicable US privacy law to provide the Personal Information to Company for processing; (c) it will not configure the Service to ingest Sensitive Personal Information without first agreeing additional written safeguards with Company; and (d) it will promptly inform Company of any change to its processing instructions.
5. Sub-processors
5.1 Authorisation
Customer grants Company general authorisation to engage the sub-processors listed in the Sub-processor List at gaezla.com/legal/sub-processors.
5.2 Notification of changes
Company will give Customer at least thirty (30) days’ prior written notice of any addition or replacement of a sub-processor. Customer may object within that notice period. If Customer objects and Company cannot accommodate the objection, Customer may terminate the relevant Order Form without penalty on thirty (30) days’ notice.
5.3 Flow-down
Company will impose on each sub-processor, by written contract, obligations protective of Personal Information that are at least as protective as those Company owes Customer under this Addendum (including the CCPA Service Provider commitments in Section 3). Company remains liable to Customer for the acts and omissions of its sub-processors with respect to Personal Information.
5.4 Bring-your-own AI integrations
Where Customer configures a bring-your-own AI integration, Company is not a Service Provider in respect of data Customer sends to that AI provider. Customer’s own privacy obligations apply to that transfer.
6. Security
Company will implement and maintain the technical and organisational measures set out in Annex II. Company may update those measures provided the updates do not materially reduce the overall level of protection.
7. Security Incident notification
On becoming aware of a Security Incident affecting Personal Information processed under this Addendum, Company will:
(a) notify Customer without undue delay, and in any event within seventy-two (72) hours of confirmation; (b) provide Customer with information about the nature of the incident, approximate number of consumers and records affected, likely consequences, and measures taken or proposed; and (c) cooperate reasonably with Customer’s incident-response and US state regulatory-notification obligations.
8. Return or deletion
On termination or expiry of the Customer’s Order Form, Company will delete Customer Data from production within thirty (30) days and from backups within ninety (90) days, except as required by US law (for example, tax records). Company will certify deletion in writing on request.
9. International transfers and non-US privacy regimes
Company is an American company and does not undertake compliance with non-US privacy regimes (including the EU General Data Protection Regulation, the UK General Data Protection Regulation, the Swiss FADP, the EU–US Data Privacy Framework, the EU Standard Contractual Clauses, and the UK International Data Transfer Agreement) in this Addendum. Where Customer or its end-users are subject to such regimes, Customer is responsible for assessing whether its use of the Service is consistent with those regimes and for its own compliance. Separate per-deal terms addressing non-US regimes may be negotiated in writing.
10. Governing law
This Addendum is governed by the laws of the State of Delaware, without regard to conflict-of-laws rules. The parties submit to the exclusive jurisdiction of the state and federal courts located in New Castle County, Delaware.
Annex I — Details of processing
| Item | Detail |
|---|---|
| Parties | Business: Customer (as identified in the Order Form). Service Provider: T1P5M4RK, LLC, 1111B S Governors Ave Ste 90229, Dover, DE 19904, USA. |
| Subject matter and duration | Processing Personal Information in the Customer Data — including data the Service ingests from the Customer Estate under Customer’s authorisation — as necessary to provide the Service during the Subscription Term and for 30 days post-termination (production); 90 days (backups). |
| Nature of processing | Observation and ingestion of data from the Customer Estate; storage, retrieval, transmission, analysis, normalisation, and automated processing of that data; execution of Customer-Authorized Actions in the Customer Estate; and presentation of results in formats designed for professional IT consumption. |
| Purpose | Providing the GAEZLA IT operations orchestration Service per the MSA and Order Form. |
| Categories of consumers | Customer’s employees, contractors, IT administrators, IT-asset owners, account-holders in systems within the Customer Estate, and end-users whose data appears in systems the Service is configured to observe or act upon. |
| Categories of Personal Information | Reflecting the IT-orchestration nature of the Service, categories may include: (a) identifiers (user names, email addresses, account IDs); (b) device and asset identifiers (hostnames, serial numbers, MAC and IP addresses, OS and software inventory); (c) network telemetry (source/destination IPs, ports, protocols, connection timestamps); (d) system and application log entries (which may incidentally contain identifiers, usernames, or activity data); (e) configuration data extracted from systems in the Customer Estate; (f) ticketing/work-item metadata; (g) such other categories as Customer elects, by configuration of the Service, to ingest from the Customer Estate. The Service does not require any Sensitive Personal Information; Customer must not configure the Service to ingest such data without agreeing additional written safeguards. |
| Sensitive Personal Information | Not processed by default. Customer bears full responsibility if it configures the Service to ingest such data. |
| Data location | Cloudflare global edge. Company does not commit to specific regional storage. |
| Deletion/return | On termination: production deletion within 30 days; backup deletion within 90 days; Company certifies on written request. |
Annex II — Technical and organisational measures
| Measure | Implementation |
|---|---|
| Encryption in transit | TLS 1.2+ (TLS 1.3 preferred) via Cloudflare |
| Encryption at rest | AES-256 via Cloudflare R2 |
| Secrets management | API credentials stored encrypted; service identities scoped to least privilege |
| Access controls | Production access restricted to founder-engineer with hardware-key MFA |
| Tenant isolation | Application-level tenant identifiers; no shared-runtime customer code execution |
| Network controls | Cloudflare global edge with DDoS protection and bot management |
| Logging | Security-relevant events recorded with timestamp and acting identity |
| Vulnerability management | Automated dependency scanning; expedited patching of critical severity findings |
| Resilience | Cloudflare global edge with automatic failover; automated backups |
| Sub-processor oversight | Sub-processors bound by equivalent written obligations |