Skip to content

Data Processing Addendum (GDPR)

Last updated 2026-07-03

Scope and roles of the parties

This Data Processing Addendum ('DPA') forms part of the agreement between the customer ('Controller') and Pathwize ('Processor') and applies where Pathwize processes personal data on the Controller's behalf under the Service. Where the parties determine purposes and means jointly or independently, they act as separate or joint controllers to that extent. This DPA implements Article 28 GDPR.

Details of processing

Subject matter and duration: processing for the term of the agreement. Nature and purpose: sourcing, producing and evaluating data for AI training and evaluation, and operating the platform. Types of personal data: as submitted by the Controller or generated in the Service (for example contact, profile and content data). Categories of data subjects: the Controller's personnel, its end users, and Experts, as applicable.

Processor obligations

Pathwize processes personal data only on the documented instructions of the Controller, including for transfers, unless required by EU or member-state law (in which case it informs the Controller unless prohibited). Pathwize ensures persons authorised to process personal data are bound by confidentiality, and assists the Controller in meeting its GDPR obligations taking into account the nature of processing and the information available.

Security measures

Pathwize implements appropriate technical and organisational measures under Article 32 GDPR, including encryption in transit, access controls and least-privilege access, logging and monitoring, and regular review of its safeguards, taking into account the state of the art, costs, and the risks to data subjects.

Sub-processors

The Controller provides general authorisation for Pathwize to engage sub-processors (for example hosting, authentication, payments and analytics providers) under written terms imposing data protection obligations equivalent to this DPA. A current list of sub-processors is available on request, and Pathwize will give notice of intended changes so the Controller can object on reasonable grounds.

Data subject requests and breach notification

Taking into account the nature of processing, Pathwize assists the Controller with responding to data subject requests and, where applicable, with data protection impact assessments and consultations. Pathwize notifies the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data and provides information reasonably needed to meet the Controller's own obligations.

International transfers

Processing is EU-resident by default. Any transfer of personal data outside the EEA is made only where there is an adequacy decision or appropriate safeguards such as the EU Standard Contractual Clauses, together with supplementary measures where required.

Deletion, return and audits

On termination or expiry, and at the Controller's choice, Pathwize deletes or returns the personal data and deletes existing copies, unless EU or member-state law requires storage. Pathwize makes available information necessary to demonstrate compliance with Article 28 and allows for and contributes to audits, including inspections, conducted by the Controller or an appointed auditor on reasonable notice.

Contact

Data protection queries can be sent to privacy@gopathwize.com.

This document is a structural placeholder pending review by counsel.