Legal

Data Processing Agreement

How Gatana processes personal data on behalf of its customers.

Version 1.1 — Effective 13 August 2026 (adds the AI assistant model provider, Section 5.6)

This Data Processing Agreement (“DPA”) forms part of, and is subject to, the Gatana Terms of Service governing the provision of the Gatana platform and related services (the “Agreement”). It governs the Processing of Personal Data by the Processor on behalf of the Controller. By accepting the Agreement, the Customer and Gatana are bound by this DPA, which is incorporated into the Agreement by reference; a signature on this DPA is not required for it to take effect.

1. The Parties

Controller (“Customer”) — the legal entity that accepted the Agreement.

Processor (“Gatana”)

Legal entity name Accendo Consulting GmbH
Registered address Gatana c/o Accendo Consulting GmbH, Werdstrasse 122, 8003 Zürich, Switzerland
Company registration number CHE-487.652.075
Data protection contact [email protected]

2. Definitions

Terms not defined here have the meaning given in the Agreement or in the EU General Data Protection Regulation 2016/679 (“GDPR”).

  • “Applicable Data Protection Law” means the GDPR and any national laws implementing or supplementing it that apply to the Processing under this DPA, the Swiss Federal Act on Data Protection (“FADP”), and — where relevant under Section 6 — the UK GDPR.

  • “Personal Data”, “Processing”, “Controller”, “Processor”, “Data Subject”, “Supervisory Authority” and “Personal Data Breach” have the meanings given in the GDPR.

  • “Customer Personal Data” means Personal Data that Gatana Processes on behalf of the Controller under the Agreement, as described in Annex 1.

  • “End User” means an individual authorised by the Customer to use the Gatana platform and, where applicable, to delegate credentials to an agent through it.

  • “Sub-processor” means any third party engaged by Gatana to Process Customer Personal Data.

  • “Standard Contractual Clauses” (“SCCs”) means the clauses adopted by the European Commission in Decision (EU) 2021/914 for the transfer of Personal Data to third countries.

  • “UK Addendum” means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner under section 119A of the UK Data Protection Act 2018.

3. Roles and Scope

3.1 For Customer Personal Data, the Customer is the Controller and Gatana is the Processor. The Customer may itself be acting as a processor for a third-party controller; in that case the Customer warrants it has the authority to engage Gatana on those terms.

3.2 Gatana Processes Customer Personal Data only to provide the Gatana platform and the services described in the Agreement, and as further described in Annex 1.

3.3 This DPA does not apply to Personal Data for which Gatana acts as a controller — for example Gatana’s own account administration, billing, and security log data — which is governed by the Privacy Policy.

4. Processor Obligations

Gatana shall:

4.1 Process only on documented instructions. Process Customer Personal Data only on the Controller’s documented instructions, including with regard to international transfers, unless required to act otherwise by applicable law (in which case Gatana will inform the Controller of that requirement before Processing, unless the law prohibits this). The Agreement and this DPA constitute the Controller’s complete initial instructions.

4.2 Notify unlawful instructions. Inform the Controller promptly if, in Gatana’s opinion, an instruction infringes Applicable Data Protection Law.

4.3 Confidentiality. Ensure that persons authorised to Process Customer Personal Data are bound by an appropriate duty of confidentiality.

4.4 Security. Implement and maintain the technical and organisational measures set out in Annex 2, appropriate to the risk.

4.5 Sub-processing. Engage Sub-processors only in accordance with Section 5.

4.6 Assist with Data Subject requests. Assist the Controller by appropriate technical and organisational measures, insofar as possible, in fulfilling the Controller’s obligation to respond to Data Subject requests under Chapter III of the GDPR (Articles 12–23). Gatana responds to Controller assistance requests without undue delay, taking into account the nature of the Processing and the statutory deadline applying to the Controller.

4.7 Assist with compliance. Assist the Controller in ensuring compliance with its obligations under Articles 32–36 of the GDPR, taking into account the nature of Processing and the information available to Gatana.

4.8 Deletion or return. At the Controller’s choice, delete or return all Customer Personal Data after the end of the provision of services, and delete existing copies unless applicable law requires storage (see Section 11).

4.9 Demonstrate compliance. Make available to the Controller the information necessary to demonstrate compliance with Article 28 of the GDPR, and allow for and contribute to audits in accordance with Section 8.

5. Sub-processors

5.1 The Controller provides general written authorisation for Gatana to engage the Sub-processors listed in Section 5.2, subject to this Section.

5.2 Current Sub-processors.

Sub-processor Service Customer Personal Data processed Processing location
Hetzner Bare-metal hosting of the Kubernetes cluster All Customer Personal Data at rest, encrypted Germany
Google Cloud (KMS) Encryption key management Wrapped per-tenant encryption keys; key operation audit logs EU region
Amazon Web Services (SES) Transactional email delivery Email addresses and email content EU region
Cloudflare Authoritative DNS, reverse proxy, CDN, TLS termination and bot protection for inbound traffic IP addresses, request metadata and traffic in transit Global edge network
OVHcloud Encrypted database backup storage Encrypted database backups France
OpenRouter Model inference for the in-app AI assistant, only where the Customer has enabled it Assistant conversation content: End User prompts and the organization data the assistant retrieves to answer them United States (zero data retention — see Section 5.6)

Customer Personal Data at rest is stored in the European Union. Cloudflare processes traffic in transit at its global edge network before it reaches Gatana’s infrastructure; transfers to Cloudflare are addressed in Section 6.3. OpenRouter processes assistant conversation content only for the duration of a request and retains none of it (Section 5.6); transfers to OpenRouter are likewise addressed in Section 6.3. Each Sub-processor’s contracting entity is as identified in that Sub-processor’s own data processing terms.

5.3 Gatana imposes on each Sub-processor, by written contract, data protection obligations no less protective than those in this DPA, in particular regarding security and the requirements of Article 28(3) of the GDPR. Gatana remains fully liable to the Controller for the performance of each Sub-processor’s obligations.

5.4 Changes. Gatana will give the Controller prior notice of any intended addition or replacement of a Sub-processor, by email to the Controller’s registered contact address, and will update the table in Section 5.2. The notice will allow the Controller a reasonable period to object on reasonable data protection grounds before the new Sub-processor begins Processing. If the parties cannot resolve the objection, the Controller may terminate the affected services.

5.5 Customer-connected third-party services. The Gatana platform exists to let agents act on third-party services on behalf of End Users. Where the Customer or an End User connects such a service — for example an email provider, an issue tracker, or any other application reachable through the MCP Gateway — the provider of that service is not a Sub-processor under this DPA. The Customer acts as controller of the data it directs to and from those services and is responsible for its own agreements with those providers.

Where Gatana stores data on its own infrastructure in order to provide the service — including credentials issued for a connected service, service configuration, and agent activity metadata — that data is Customer Personal Data, is Processed under this DPA, and is secured by the Sub-processors named in Section 5.2.

5.6 AI assistant. The in-app AI assistant is disabled by default and Processes no Customer Personal Data until the Customer enables it for its organization. Enabling it — a step reserved to an organization owner in the dashboard — constitutes the Controller’s documented instruction under Section 4.1 for the Processing described in this Section. When the assistant is used, conversation content — End User prompts and the organization data the assistant retrieves to answer them — is sent to OpenRouter, which routes each request to a model provider for inference. Gatana uses OpenRouter under its Zero Data Retention terms: requests are routed only to model endpoints whose providers commit not to store prompts or outputs and not to use them for training, and neither OpenRouter nor the model provider serving a request retains conversation content after the reply is served. OpenRouter retains technical request metadata, such as token counts and timestamps, for billing and abuse prevention. Conversation transcripts are stored by Gatana on the infrastructure described in Section 5.2, not by OpenRouter. The Customer may instead configure its own model endpoint for the assistant; conversations are then sent to that endpoint under the Customer’s own agreement with its provider — a customer-connected third-party service under Section 5.5 — and OpenRouter is not engaged for that Customer.

6. International Transfers

6.1 Gatana is established in Switzerland. Live Customer Personal Data is stored in Germany and encrypted backups are stored in France.

6.2 Transfers to Gatana. The European Commission has determined that Switzerland ensures an adequate level of protection for Personal Data. A transfer of Customer Personal Data from the EEA to Gatana therefore relies on that adequacy decision and does not require additional safeguards. The equivalent United Kingdom adequacy regulations apply to transfers from the United Kingdom. Transfers from Switzerland are domestic and governed by the FADP.

6.3 Onward transfers to Sub-processors. Hosting, key management, email delivery and backup storage are configured to Process Customer Personal Data within the European Union. Cloudflare, which proxies inbound traffic, operates a global edge network, so IP addresses and request metadata may be Processed outside the EEA. OpenRouter, which serves the AI assistant where the Customer has enabled it, Processes assistant conversation content in the United States (Section 5.6). Where a transfer outside the EEA occurs — including at Cloudflare’s edge, at OpenRouter, or for vendor support access by a Sub-processor whose parent undertaking is established outside the EEA — Gatana relies on one or more of the following:

(a) a European Commission adequacy decision applicable to the recipient, including where applicable and valid the recipient’s self-certification under the EU–U.S. Data Privacy Framework; or

(b) the Standard Contractual Clauses concluded between Gatana and that Sub-processor, together with any supplementary measures required following a transfer impact assessment.

6.4 Where the SCCs apply and there is a conflict between them and this DPA, the SCCs prevail in respect of the relevant transfer.

6.5 United Kingdom and Switzerland. Where the Customer is subject to the UK GDPR or to the FADP, the following apply to transfers of Customer Personal Data to which those laws apply:

(a) for transfers subject to UK GDPR, the UK Addendum is incorporated into this DPA and completed as set out in Annex 3, and references in the SCCs to the GDPR are read as references to the UK GDPR;

(b) for transfers subject to the FADP, the SCCs apply with the adaptations described in Annex 3, including that the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority and that the term “Member State” does not prevent Swiss data subjects from exercising their rights in their place of habitual residence;

(c) all other terms of this DPA apply equally to such transfers, and the protections of this DPA are extended to the relevant data subjects accordingly.

7. Personal Data Breach

7.1 Gatana will notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.

7.2 The notification will, to the extent known, describe the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed to address it. Where the information cannot all be provided at once, it may be provided in phases without undue further delay.

7.3 Gatana will reasonably assist the Controller in meeting its own breach notification obligations to Supervisory Authorities and Data Subjects.

7.4 Suspected incidents may be reported to Gatana at [email protected]. Gatana acknowledges such reports within one business day.

8. Audit

8.1 Gatana will make available to the Controller the information reasonably necessary to demonstrate compliance with Article 28 of the GDPR.

8.2 The Controller may satisfy its audit rights primarily through Gatana’s available compliance reports and security documentation. A SOC 2 examination is currently in progress. Once issued, the report will be made available to the Controller on request under confidentiality. Until then, Gatana makes available its security documentation, including the measures described in Annex 2.

8.3 Where those materials are not sufficient, the Controller, or a mutually agreed independent auditor bound by confidentiality, may conduct an audit on at least 30 days’ prior written notice, no more than once per twelve-month period except where required by a Supervisory Authority or following a Personal Data Breach. Audits are conducted during business hours, with minimal disruption, and at the Controller’s cost.

9. Special Categories of Personal Data

9.1 The Gatana platform is not intended to Process special categories of Personal Data (Article 9 GDPR) or data relating to criminal convictions and offences (Article 10 GDPR).

9.2 The Customer shall not submit such data to the platform unless separately agreed in writing with Gatana. The Customer is responsible for ensuring that the data it and its End Users direct through the platform is limited to what is necessary for the purposes of the service.

10. Liability

The liability of each party under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Agreement.

11. Term, Deletion and Return

11.1 This DPA takes effect on the Effective Date and continues for as long as Gatana Processes Customer Personal Data under the Agreement.

11.2 On termination or expiry of the services, Gatana will, at the Controller’s choice, delete or return all Customer Personal Data and delete existing copies within 60 days of the Controller’s instruction, unless applicable law requires continued storage.

11.3 Deletion method. Records are deleted from the production database. The tenant’s unique encryption key is destroyed in Google Cloud KMS, which renders all remaining encrypted copies of that tenant’s data — including those held in backups — permanently unreadable. Backups then expire in the ordinary course of the backup rotation cycle. Gatana will confirm deletion in writing on request.

12. General

12.1 In the event of a conflict between this DPA and the Agreement on data protection matters, this DPA prevails.

12.2 This DPA is governed by the laws of Zurich, Switzerland, without prejudice to any mandatory provisions of Applicable Data Protection Law. The courts referred to in the Agreement have jurisdiction. This is subject to Annex 3, which governs the law applicable to the SCCs themselves where they apply.

12.3 If any provision is found invalid, the remainder of this DPA remains in effect.

12.4 Gatana may update this DPA from time to time. Where a change materially reduces the protections afforded to Customer Personal Data, Gatana will give the Controller at least 30 days’ notice by email to its registered contact address before the change takes effect.

13. Acceptance

This DPA is incorporated into the Agreement by reference and takes effect when the Customer accepts the Agreement. No signature is required for it to be binding on either party.

A Customer that requires a counter-signed record may request one at [email protected]. Doing so does not change the effective date or the binding nature of this DPA.


Annex 1 — Description of Processing

Subject matter Provision of the Gatana MCP Gateway and credential management platform.
Duration The term of the Agreement, plus any deletion or return period under Section 11.
Nature and purpose Storing and using delegated credentials so that agents can act on third-party services on behalf of End Users; storing service configuration; generating and retaining audit records of credential use and agent activity; creating encrypted backups; where the Customer has enabled it, operating the in-app AI assistant — sending conversation content to the model provider described in Section 5.6 and storing conversation transcripts.
Categories of Data Subjects The Customer’s personnel and authorised End Users; individuals whose Personal Data is incidentally Processed when an agent interacts with a connected third-party service on an End User’s behalf, such as email recipients.
Categories of Personal Data Names; email addresses; hashed passwords for native accounts; federated identity provider identifiers; access credentials and tokens issued for connected services; service configuration data; agent activity logs and metadata; AI assistant conversation content, where the Customer has enabled the assistant.
Special categories None (see Section 9).
Frequency Continuous, for the duration of the services.

Annex 2 — Technical and Organisational Measures

Gatana maintains the following measures, appropriate to the risk (Article 32 GDPR).

  • Per-tenant encryption at rest. Each tenant has a unique AES-256-GCM data encryption key, wrapped by a key encryption key held in Google Cloud KMS. The plaintext key exists only in application memory for the duration of a cryptographic operation and is never written to disk. Access to the database alone does not reveal Customer Personal Data.

  • Encryption in transit. TLS 1.2 or higher for all external traffic. Encrypted connections between application components and the database.

  • Independent key access logging. Every encryption and decryption operation is recorded in Google Cloud Audit Logs, which are held by the Sub-processor and cannot be altered by Gatana. An unexplained decryption is treated as a critical security incident.

  • Access control. Access to production systems and Customer Personal Data is limited to personnel with a documented business need, granted on a least-privilege basis, protected by multi-factor authentication, and reviewed quarterly. Emergency access follows a separate controlled path that is logged and reviewed after every use.

  • Tenant isolation. Every application query is scoped to a single tenant. Customer workloads run in dedicated namespaces with network policy preventing communication between tenants.

  • Network security. Production infrastructure is reachable only from an explicit IP allowlist. Cluster nodes run an immutable operating system with no interactive shell access.

  • Change management. All infrastructure and application changes are deployed from signed Git commits through an automated pipeline. There is no manual deployment path into production. Every change is traceable to a specific commit and can be reverted.

  • Logging and monitoring. Security-relevant events across the application, infrastructure and third-party services are logged, retained to a defined schedule, and monitored with alerting.

  • Backups and recovery. Daily full database backups with continuous write-ahead log archiving, encrypted and stored with object locking. Restores are tested automatically every night.

  • Vulnerability management. Dependencies are scanned continuously; identified vulnerabilities are remediated to defined timelines based on severity.

  • Personnel. Confidentiality obligations, documented standards of conduct, and security awareness requirements apply to all personnel, with acknowledgement recorded before production access is granted and renewed annually.

  • Sub-processor management. Contractual data protection obligations are imposed on all Sub-processors, whose security posture is assessed before engagement and reviewed annually.

These measures are reviewed periodically and may be updated provided the overall level of security is not reduced.

Annex 3 — Standard Contractual Clauses: Elections and Completion

This Annex records the elections that complete the SCCs where they apply under Section 6, and the equivalent completion of the UK Addendum and Swiss adaptations under Section 6.5.

  • When the SCCs apply. Transfers from the EEA or the United Kingdom to Gatana rely on the adequacy decisions described in Section 6.2 and do not require the SCCs. The SCCs operate between Gatana and any Sub-processor to the extent an onward transfer outside the EEA occurs under Section 6.3.

  • Module in operation. Module Three (processor-to-processor) applies to onward transfers from Gatana to a Sub-processor. Where a Customer requires the SCCs to be concluded directly with Gatana notwithstanding Section 6.2, Module Two (controller-to-processor) applies.

  • Clause 7 — Docking clause. The optional docking clause applies.

  • Clause 9 — Use of sub-processors. Option 2 (general written authorisation) applies. The period for prior notice of Sub-processor changes is as stated in Section 5.4.

  • Clause 11 — Redress. The optional independent dispute resolution body language does not apply.

  • Clause 17 — Governing law. The SCCs are governed by the law of Ireland.

  • Clause 18 — Choice of forum and jurisdiction. Disputes arising from the SCCs are resolved before the courts of Ireland. This applies to the SCCs only; Section 12.2 continues to govern the remainder of this DPA.

  • Annexes to the SCCs. Annex I.A (List of Parties) is completed by Section 1. Annex I.B (Description of Transfer) is as set out in Annex 1. Annex I.C (Competent Supervisory Authority) is the supervisory authority of the EEA state in which the Customer as data exporter is established. Annex II (Technical and Organisational Measures) is as set out in Annex 2. Annex III (List of Sub-processors) is as set out in Section 5.2.

  • UK Addendum completion. For UK transfers, Tables 1, 2 and 3 of the UK Addendum are populated by Sections 1 and 6 and Annexes 1, 2 and 3 of this DPA. In Table 4, neither party may end the Addendum when the Approved Addendum changes, save as required by law.

  • Precedence. Where there is a conflict, the order of precedence is: (1) the SCCs and UK Addendum; (2) this Annex 3; (3) the remainder of this DPA.