Data Processing Addendum

Last updated: March 1, 2026

Scope

This Addendum applies where Gyggle processes personal data on behalf of a customer. Because file content is encrypted client-side, Gyggle processes only account and placement metadata.

Roles

The customer is the controller. Gyggle Labs, Inc. is the processor and acts only on documented instructions.

Sub-processors

Gyggle uses hosting and payment sub-processors. We give 30 days' notice before adding a new one.

Security measures

Encryption in transit and at rest, least-privilege access, audit logging, and annual third-party review.

Breach notification

We notify affected customers without undue delay, and in any case within 72 hours of becoming aware of a personal data breach.

Questions about this document? → Contact us