Skip to content

    Goldilocks AI Data Processing Addendum

    Last Updated: July 10, 2026

    This Data Processing Addendum ("DPA") forms part of the Goldilocks AI Platform Terms of Service or other agreement between Customer and Goldilocks AI, Inc. (or the Goldilocks entity identified in an applicable Order Form) ("Goldilocks") referencing it (the "Agreement"). It is deemed executed by both parties upon acceptance of the Agreement. Capitalized terms not defined here have the meanings in the Agreement. "Data Protection Laws" means all laws applicable to the processing of Personal Information under the Agreement, including UK GDPR, EU GDPR, the UK Data Protection Act 2018, and the CCPA/CPRA. "EU SCCs" means the standard contractual clauses in Commission Implementing Decision (EU) 2021/914. "UK Addendum" means the ICO's International Data Transfer Addendum to the EU SCCs (version B1.0). "Restricted Transfer" means a transfer of Personal Information that would be prohibited by EU GDPR, UK GDPR, or the Swiss FADP absent a valid transfer mechanism.

    1. ROLES

    1.1 Output Data (Part A applies). For Personal Information contained in Output Data and the Goldilocks database, Goldilocks and Customer are each independent controllers of the Personal Information they respectively process. The parties are not joint controllers, and neither processes such data on the other's behalf.

    1.2 Submitted Data (Part B applies). For Personal Information contained in Submitted Data, Customer is the controller (or a processor for its own clients) and Goldilocks is Customer's processor.

    1.3 CCPA. Where CCPA applies: for Output Data, each party is a "business" for its own processing and Goldilocks discloses Personal Information to Customer as a "third party"; for Submitted Data, Goldilocks is Customer's "service provider," does not sell or share Submitted Data, and does not retain, use, or disclose it outside the direct business relationship or for any purpose other than the business purposes in the Agreement, and Goldilocks certifies it understands these restrictions and will not combine Submitted Data with personal information received from other sources except as permitted by the CCPA for the business purposes.

    1.4 Other US state privacy laws. To the extent Submitted Data includes personal data of residents of US states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, New Jersey, New Hampshire, Iowa, and Nebraska), Goldilocks processes such data as Customer's "processor" under those laws, and the obligations in Part B (instructions, confidentiality, security, sub-processing, assistance, deletion, and audit) apply as the contract required by those laws.

    1.5 Jurisdictional coverage. For ease of reference, this DPA addresses the following regimes where they apply to the processing:

    RegimeWhere addressed
    EU GDPRParts A and B; EU SCCs Modules One, Two, and Three (A.4, B.9, B.10)
    UK GDPRUK Addendum (A.4, B.10); UK representative under Article 27 (2.5); ICO as UK authority (Annex 1)
    Swiss FADPSwiss adaptation of the SCCs (A.4, B.10)
    California CCPA/CPRAService-provider and third-party terms, including no sale/share and no combining (1.3)
    Other US state privacy laws (VA, CO, CT, UT, TX, OR, MT, DE, NJ, NH, IA, NE, and successors)Processor-contract terms (1.4)
    Other jurisdictionsGood-faith implementation of additionally required transfer or processing mechanisms (A.4, B.10) and the amendment mechanism (2.3a)

    PART A — CONTROLLER-TO-CONTROLLER (OUTPUT DATA)

    A.1 Compliance. Each party will comply with Data Protection Laws applicable to it as an independent controller, including maintaining its own lawful basis, transparency notices, and records.

    A.2 Customer obligations. Customer will process Output Data only within the Permitted Purpose, comply with Sections 10 and 11 of the Agreement (communications compliance; regulated uses), and implement appropriate technical and organizational security measures for Output Data in its systems.

    A.3 Data subject requests. Each party will handle requests it receives relating to its own processing. Where Goldilocks removes or suppresses an individual (including at a licensor's or regulator's instance), Customer will act per Section 10.4 of the Agreement (prompt deletion absent an independent legal basis; no re-acquisition). Each party will provide the other reasonable assistance with requests where the other's processing is implicated.

    A.4 Transfers. Transfers of Output Data from Goldilocks to Customer that are restricted transfers under EU GDPR are made under the EU SCCs, Module One, incorporated by reference and completed as follows: Clause 7 (docking) excluded; Clause 11 optional language not used; Clause 17: laws of Ireland; Clause 18: courts of Ireland; Annexes populated by Annex 1 and Annex 2 to this DPA; the competent supervisory authority is determined per Clause 13. For restricted transfers under UK GDPR, the UK Addendum is incorporated: Table 1 is populated by the parties' details in the Agreement; Table 2 refers to the Module One EU SCCs as completed above; Table 3 refers to Annexes 1–3; for Table 4, either party may end the UK Addendum as set out in Section 19 of the UK Addendum. For Restricted Transfers subject to the Swiss FADP, the EU SCCs apply as adapted for Switzerland: references to EU GDPR are read as references to the FADP, the competent authority is the Swiss FDPIC, Swiss data subjects may enforce their rights in Switzerland, and references to EU member states include Switzerland. For Restricted Transfers subject to any other jurisdiction's transfer regime, the parties will cooperate in good faith to implement any additionally required mechanism.

    PART B — CONTROLLER-TO-PROCESSOR (SUBMITTED DATA)

    B.1 Instructions. Goldilocks will process Submitted Data only on Customer's documented instructions, which comprise the Agreement, this DPA, and Customer's configuration and use of the Service, unless required otherwise by law (in which case Goldilocks will inform Customer unless prohibited). Goldilocks will inform Customer if, in its opinion, an instruction infringes Data Protection Laws.

    B.2 Confidentiality. Persons authorized to process Submitted Data are bound by confidentiality obligations.

    B.3 Security. Goldilocks implements the technical and organizational measures in Annex 2.

    B.4 Sub-processors. Customer grants general written authorization for the sub-processors listed at goldi.ai/subprocessors and for Goldilocks' engagement of new or replacement sub-processors as follows. Goldilocks will give notice of an intended addition or replacement at least ten (10) days in advance by updating the published list, and, for paid subscriptions, by emailing Customer's account contact. Customer may object within ten (10) days of notice on reasonable data-protection grounds; absent objection, the change is deemed accepted. If Customer objects and the parties cannot resolve the objection within thirty (30) days, Customer may terminate the affected subscription and receive a pro-rata refund of prepaid unused fees. Where a replacement is required urgently for security, continuity, or legal reasons, Goldilocks may engage the replacement immediately and will give notice without undue delay, with the same objection right running from that notice. Goldilocks imposes data protection obligations on each sub-processor no less protective than this Part B and remains liable for its sub-processors' performance.

    B.5 Assistance. Taking into account the nature of processing, Goldilocks will assist Customer by appropriate technical and organizational measures with data subject requests concerning Submitted Data, and with Customer's obligations under Articles 32–36 UK/EU GDPR (security, breach notification, DPIAs, consultation), at Customer's reasonable cost where such assistance is material. If Goldilocks receives a data subject request relating to Submitted Data, it will promptly forward the request to Customer and will not respond to it except to acknowledge receipt or as required by law.

    B.6 Personal data breach. Goldilocks will notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Submitted Data, providing the information reasonably required for Customer's own notification obligations as it becomes available. Unsuccessful attempts or activity that do not compromise Submitted Data (such as blocked attacks, port scans, or failed login attempts) are not personal data breaches requiring notice.

    B.7 Deletion and return. On termination of the Agreement, Goldilocks will, at Customer's choice communicated within thirty (30) days, delete or return Submitted Data and delete existing copies, save as retention is required by law; absent an election, Goldilocks will delete. On account deletion, prompts and query history are de-identified as described in the Agreement.

    B.8 Audit. Goldilocks will make available information reasonably necessary to demonstrate compliance with this Part B, including summaries of third-party security reviews and completed security questionnaires. Where Data Protection Laws grant Customer a mandatory audit right that cannot be satisfied by the foregoing, an audit may be conducted not more than once annually, on at least thirty (30) days' notice, during business hours, subject to confidentiality, at Customer's cost, and without access to other customers' data.

    B.9 Customer as processor. Where Customer processes Submitted Data as a processor for its own clients, Goldilocks acts as Customer's sub-processor, this Part B applies mutatis mutandis, and for Restricted Transfers the EU SCCs Module Three apply with the same selections as Module Two below, Customer warranting that its instructions reflect its controller's authorization.

    B.10 Transfers. Where processing of Submitted Data by Goldilocks involves a Restricted Transfer under EU GDPR, the EU SCCs Module Two apply (Clause 7 excluded; Clause 9(a) Option 2 general written authorization, ten (10) days; Clause 11 optional language not used; Clause 17 Ireland; Clause 18 Ireland; Annexes populated by Annexes 1–3). For UK Restricted Transfers, the UK Addendum applies as in A.4, referencing Module Two, and the Swiss adaptation and other-jurisdiction cooperation provisions in A.4 apply equally to transfers under this Part B.

    2. GENERAL

    2.1 Precedence. For its subject matter, this DPA prevails over the Agreement; the EU SCCs and UK Addendum prevail over this DPA in case of conflict.

    2.2 Liability. Liability under this DPA is subject to the limitations and exclusions in the Agreement, to the extent permitted by Data Protection Laws.

    2.3 Term; survival. This DPA applies for as long as Goldilocks processes Personal Information under the Agreement; provisions that by their nature should survive (including deletion, confidentiality, and transfer obligations for retained data) survive termination.

    2.3a Amendments required by law. Goldilocks may amend this DPA where required to comply with Data Protection Laws, a court order, or regulator guidance (including replacement of the EU SCCs or UK Addendum by the issuing authority), provided the change does not materially reduce the protections for Customer or expand either party's rights to process Personal Information; Goldilocks will give at least 30 days' notice of material changes, and continued use of the Service after the effective date constitutes acceptance.

    2.4 Government requests. If Goldilocks receives a law-enforcement or other governmental demand for Submitted Data, it will notify Customer before disclosure unless legally prohibited, will direct the authority to request the data from Customer where possible, and will disclose only the minimum required.

    2.5 UK representative. Goldilocks AI Ltd, 124 City Road, London EC1V 2NX, United Kingdom, is Goldilocks AI, Inc.'s UK representative under Article 27 UK GDPR. Contact for data protection matters: chris@goldi.ai.

    ANNEX 1 — DESCRIPTION OF PROCESSING AND TRANSFERS

    Data exporter (Part A): Goldilocks AI, Inc. (controller). Data importer (Part A): Customer (independent controller). Part B: Customer (controller/exporter as applicable); Goldilocks (processor).

    Categories of data subjects (Output Data): professionals and business people worldwide, including employees, officers, founders, investors, experts, academics, and other individuals with a public professional presence.

    Categories of Personal Information (Output Data): identity data (name); professional data (current and past employers, job titles, employment history, education history, skills); professional achievements (patents, publications, awards); business contact details (business email, phone numbers); public web presence (social and professional profile links); location (country, city); derived data (AI-generated profile summaries, topic-authority assessments, research notes compiled from public sources, contact-verification results).

    Special categories: none intentionally processed; extraction controls discard special-category content.

    Categories of Personal Information (Submitted Data): determined by Customer; typically Account Information of Authorized Users, and names, contact details, and professional details of individuals in Customer's queries, prompts, and uploads. Customer will not submit special-category or children's data.

    Frequency: continuous during the Agreement. Nature and purpose: hosting, storage, retrieval, matching, enrichment, AI-based summarization and assessment, display, export, and support, to provide the Service for the Permitted Purpose. Processing locations: database storage in the United Kingdom; application processing in the United States; support and engineering access from the United Kingdom and the United States. Retention: per the Agreement and Goldilocks' published retention policy (profile data deleted or anonymized if not verified or refreshed within 36 months; suppression list retained to keep removals effective). Competent supervisory authority (Module One/Two, Clause 13): the Irish Data Protection Commission for EU transfers; the ICO for UK transfers under the UK Addendum.

    ANNEX 2 — TECHNICAL AND ORGANIZATIONAL MEASURES

    • Security governance. Goldilocks maintains documented security and data-protection procedures (data subject requests, breach response, retention and deletion), owned at executive level and reviewed at least annually.
    • Personnel security. Personnel and contractors with access to Personal Information are bound by confidentiality obligations; access is limited to what their role requires; access is revoked promptly, and in any event within 24 hours, on termination or role change.
    • Logical access controls. Login-gated access with unique per-user credentials; authentication managed by Supabase Auth, with password credentials held by the auth provider and never by Goldilocks; the application stores only session tokens; least-privilege access to production systems; programmatic access via scoped, revocable API keys.
    • Product-level controls. Per-account rate limits; export limited to results displayed in response to queries; tiered access with contact details restricted to paid and trial plans; capped free tier; monitoring for abusive usage patterns.
    • Encryption. All data encrypted in transit (TLS 1.2 or higher) and at rest (AES-256, provider-managed keys).
    • Infrastructure and physical security. The service database is hosted in the United Kingdom (Supabase); application and processing infrastructure runs on Google Cloud in the United States, with transfers protected as described in this DPA; managed infrastructure with automatic patching; physical and environmental security of data centers is provided by cloud providers operating under independent certifications (including ISO 27001 and SOC 2).
    • Change management. Version-controlled code with review before production deployment; managed platform updates and security patching by infrastructure providers.
    • Backups and resilience. Daily automated database backups with 7-day point-in-time recovery; provider-managed restore procedures.
    • Logging and monitoring. Infrastructure and database activity logging and anomaly monitoring via cloud and database providers.
    • Incident response. Documented breach-response procedure supporting the notification commitments in Section B.6.
    • Vendor management. Service providers and sub-processors are assessed for security posture and data-protection terms before engagement (Annex 3) and bound to obligations no less protective than this DPA where they process Submitted Data.
    • Data minimization and lifecycle. Public-web research limited to professional facts; special-category content discarded on detection; account deletion de-identifies prompts and query history; retention per the published retention policy.
    • Certifications. Goldilocks relies on the certified infrastructure of its cloud providers (including ISO 27001 and SOC 2 certified data centers and managed services).

    ANNEX 3 — SUB-PROCESSORS

    Goldilocks engages sub-processors to provide the Service. The authorized sub-processors, with their locations and a description of their processing, are listed at goldi.ai/subprocessors, together with the applicable transfer safeguards, which is the authoritative list and is incorporated into this DPA by reference. That page completes Annex III of the EU SCCs for the purposes of this DPA. Notice of changes is given per Section B.4. Additions and replacements are governed by Section B.4 (10 days' notice with deemed acceptance; reasonable-grounds objection; termination with pro-rata refund if unresolved; urgent-replacement carve-out).

    Service providers that process only Goldilocks-controlled Profile data (for example contact verification and public-web search retrieval) act for Goldilocks in its controller capacity and are not sub-processors of Submitted Data; those provider categories are described in the Privacy Policy, and Goldilocks' data licensors are disclosed under NDA only.