Data Processing Addendum

Last updated July 22, 2026.

This Giga Data Processing Addendum (“DPA”) forms part of the agreement between Customer and Giga AI, Inc. (“Giga”) that references or otherwise incorporates this DPA (the “Agreement”). This DPA applies to pilots, proofs of concept, evaluations, and all other Processing of Customer Personal Data that is not governed by a separate data processing agreement executed by the parties or by an amendment to this DPA. To the extent the parties have entered into such a signed or amended data processing agreement covering specific Processing activities, that agreement controls with respect to those activities. This DPA may be updated by Giga from time to time to the extent permitted by applicable law, provided that Giga will not, without Customer's consent, make any update that materially reduces the security measures or Giga's obligations under Section 11 (Data Transfers) or Section 12 (U.S. State Privacy Laws); Giga will provide reasonable notice of material updates by posting the revised DPA at https://trust.giga.ai/ or through the Services.

1. Definitions and Interpretation

Capitalized and undefined terms used in this DPA have the meanings given to them in the Agreement, or if not defined there, under Applicable Data Protection Laws.

  • “Applicable Data Protection Laws” means any privacy or data protection law applicable to a party's Processing of Personal Data under the Agreement, which may include, without limitation, European Data Protection Laws, the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”), and India's Digital Personal Data Protection Act, 2023 (“DPDP Act”).
  • “Controller” means, consistent with Applicable Data Protection Laws, the entity that determines the purposes and means of Processing Personal Data, and includes “business” under the CCPA and “Data Fiduciary” under the DPDP Act, as applicable.
  • “Customer Personal Data” means any Personal Data Processed by Giga as a Processor on behalf of Customer under the Agreement.
  • “Data Subject” means, consistent with Applicable Data Protection Laws, the individual to whom Personal Data relates, and includes “consumer” under the CCPA and “Data Principal” under the DPDP Act, as applicable.
  • “Data Subject Rights” means the rights granted to Data Subjects under Applicable Data Protection Laws, which may include rights to access, rectification, erasure, restriction, portability, objection, and withdrawal of consent.
  • “Data Transfer” means a disclosure of Customer Personal Data by an organization subject to Applicable Data Protection Laws in the EEA, UK, or Switzerland to another organization located outside such jurisdiction.
  • “EEA” means the European Economic Area.
  • “EEA SCCs” means the clauses annexed to European Commission Implementing Decision 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries, as amended or replaced from time to time.
  • “European Data Protection Laws” means the GDPR and the e-Privacy Directive 2002/58/EC (as amended), their national implementations in the EEA, and all other data protection laws of the EEA, the UK, and Switzerland, each as amended or replaced from time to time.
  • “EU-US Data Privacy Framework” means the adequacy decision of the European Commission dated 10 July 2023 regarding the adequate level of protection of personal data transferred under the EU-US Data Privacy Framework, as may be updated from time to time.
  • “Personal Data” shall be interpreted consistent with Applicable Data Protection Laws, and includes “personal data” under European Data Protection Laws, “personal information” under the CCPA, and “personal data” under the DPDP Act, as applicable.
  • “Process” and “Processing” shall be interpreted consistent with Applicable Data Protection Laws.
  • “Processor” shall be interpreted consistent with Applicable Data Protection Laws, and includes a “processor” under European Data Protection Laws, a “service provider” or “contractor” under the CCPA, and a “Data Processor” under the DPDP Act, as applicable.
  • “SCCs” means the EEA SCCs and the UK Addendum, as applicable.
  • “Security Incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data transmitted, stored, or otherwise Processed under the Agreement.
  • “Services” means the Giga Platform and Giga Services provided by Giga to Customer under the Agreement.
  • “Subprocessor” means any entity appointed by Giga to Process Customer Personal Data on behalf of Customer in connection with the Agreement.
  • “Third-Party Controller” means, in relation to Customer Personal Data Processed in connection with the Agreement, a Controller for which Customer is a Processor.
  • “UK Addendum” means the addendum to the EEA SCCs issued by the UK Information Commissioner under Section 119A(1) of the UK Data Protection Act 2018 (version B1.0, in force 21 March 2022).

The terms “Commission,” “Member State,” and “Supervisory Authority” have the same meaning as in the GDPR. The terms “Business Purpose,” “Share,” and “Shared” have the meaning given under the CCPA, and “Sell” and “Selling” have the meaning given under Applicable Data Protection Laws in the U.S.

2. Scope

2.1 This DPA applies to the extent Giga Processes Customer Personal Data as a Processor on behalf of Customer, where Customer acts as a Controller or as a Processor for a Third-Party Controller. The subject matter, nature, and purpose of the Processing, the types of Customer Personal Data, and the categories of Data Subjects are set out in Annex I.

2.2 As between the parties, Customer is responsible for its compliance obligations as a Controller, including providing notice to Data Subjects about Giga's Processing described in this DPA and obtaining any consent necessary under Applicable Data Protection Laws. Giga will comply with its obligations as a Processor under Applicable Data Protection Laws in Processing Customer Personal Data.

2.3 If Customer is a Processor on behalf of a Third-Party Controller, Customer: (i) is the single point of contact for Giga; (ii) must obtain all necessary authorizations from the Third-Party Controller in connection with this DPA; (iii) will ensure the Third-Party Controller provides notice and obtains any necessary consents for Giga's Processing; and (iv) undertakes to issue all instructions and exercise all rights on the Third-Party Controller's behalf. Giga is entitled to rely on Customer's instructions as if they were the instructions of the Third-Party Controller, and Customer is responsible for ensuring such instructions are consistent with the Third-Party Controller's requirements.

3. Processing of Customer Personal Data

3.1 Giga will not Process Customer Personal Data other than (i) on Customer's documented instructions, as set forth in the Agreement (including this DPA), or (ii) as expressly permitted by Applicable Data Protection Laws.

3.2 To the extent permitted by Applicable Data Protection Laws, Customer may take reasonable steps to confirm Giga uses Customer Personal Data consistent with Customer's obligations under Applicable Data Protection Laws.

3.3 If Giga becomes subject to a legal obligation requiring it to Process Customer Personal Data contrary to Customer's instructions, Giga will inform Customer to the extent legally permitted.

4. Personnel

Without limiting the confidentiality obligations in the Agreement, Giga will use commercially reasonable efforts to ensure the reliability of personnel with access to Customer Personal Data, and will limit such access to those who need it to carry out rights and obligations under the Agreement.

5. Security

Taking into account the state of the art, implementation costs, and the nature, scope, and risk of the Processing, Giga will implement appropriate technical and organizational measures designed to ensure a level of security appropriate to that risk, as described in Annex II.

6. Subprocessing

6.1 Customer grants Giga a general authorization to engage Subprocessors. A list of Giga's Subprocessors is maintained at https://trust.giga.ai/ (the “Subprocessor List”).

6.2 Giga will enter into a written agreement with each Subprocessor imposing data protection obligations substantially as protective as this DPA.

6.3 Giga will notify Customer at least ten (10) days before appointing a new or replacement Subprocessor (“Notice Period”) by updating the Subprocessor List. Customer may object on reasonable data-privacy or data-security grounds within the Notice Period by contacting privacy@giga.ai. The parties will work together in good faith to address the objection; if unresolved, either party may terminate the affected Services upon written notice.

7. Data Subject Rights

7.1 Taking into account the nature of the Processing, Giga will provide reasonable assistance to help Customer fulfill requests to exercise Data Subject Rights in relation to Customer Personal Data.

7.2 Giga will promptly notify Customer if it receives a Data Subject request under Applicable Data Protection Laws relating to Customer Personal Data, and will not respond except on Customer's instructions or as required by law, other than to confirm the request relates to Customer or to direct the individual to Customer.

8. Personal Data Breach

8.1 Giga will notify Customer without undue delay upon confirming a Security Incident, providing Customer with reasonable information relating to such Security Incident, including information required to be provided by Giga to Customer under Applicable Data Protection Laws.

8.2 Giga will, upon Customer's reasonable request, provide reasonable assistance in connection with Customer's investigation and mitigation of the Security Incident.

9. Deletion or Return of Customer Personal Data

9.1 This DPA terminates automatically upon termination of the Agreement.

9.2 Giga will delete Customer Personal Data from the Services within thirty (30) days of expiration or termination of the Agreement, unless Customer consents to retention beyond that period.

9.3 Notwithstanding Section 9.2, Giga may retain Customer Personal Data to the extent (i) required to comply with applicable law, used only for that purpose, or (ii) contained in Giga's backup systems under an automatic archival process, purged in accordance with Giga's standard retention policies. Any data retained under this Section 9.3 remains subject to the confidentiality obligations in the Agreement for as long as it is retained.

10. Audit Rights and Compliance

10.1 Upon Customer's reasonable written request, Giga will make available a then-current SOC 2 Type II report or comparable industry-standard third-party audit certification covering the Services. The parties agree that provision of this report satisfies any audit rights Customer may have under Applicable Data Protection Laws or the Agreement.

10.2 To the extent Applicable Data Protection Laws require an audit beyond what the report in Section 10.1 can satisfy, or as otherwise expressly agreed in the applicable Order Form, Customer (or its appointed representative) may conduct an additional audit of Giga's policies, procedures, and records relevant to the Processing of Customer Personal Data, provided that any such audit is: (i) conducted during Giga's regular business hours, on reasonable advance notice; (ii) carried out in a manner that avoids unnecessary disruption to Giga's business; (iii) subject to reasonable confidentiality procedures; and (iv) limited to once per year, unless required by a competent government authority.

10.3 Unless an audit under Section 10.2 reveals a material breach by Giga of this DPA, Customer will bear the reasonable costs of that audit.

10.4 To the extent required for Customer to fulfill its obligations under Article 35 or 36 of the GDPR or equivalent provisions of other Applicable Data Protection Laws, Giga will provide reasonable assistance with data protection impact assessments and consultations with Supervisory Authorities relevant to Giga's Processing of Customer Personal Data.

10.5 Information generated in connection with this Section 10, including audit results, will be used by Customer solely to meet its obligations under Applicable Data Protection Laws and is Giga's Confidential Information.

11. Data Transfers

11.1 Customer authorizes Giga to perform Data Transfers (i) to a country deemed adequate by the European Commission, including on the basis of the EU-US Data Privacy Framework, or by the UK or Swiss authorities, as applicable; (ii) pursuant to the SCCs referred to in this Section 11; or (iii) on the basis of another valid transfer mechanism permitted by Applicable Data Protection Laws. The SCCs are deemed executed upon this DPA taking effect, with Giga as “data importer” and Customer as “data exporter,” and Annexes I and II of this DPA serve as Annex I and II of the SCCs.

11.2 The EEA SCCs are completed as follows: the optional docking clause in Clause 7 does not apply; Option 2 of Clause 9(a) applies, with the notice period specified in Section 6.3 above; the optional redress clause in Clause 11(a) is struck; and governing law and courts under Clauses 17 and 18 are those of Ireland.

11.3 For transfers governed by the Swiss Federal Act on Data Protection (“FADP”) rather than the GDPR, the EEA SCCs are deemed modified so that references to the GDPR are read as references to the FADP, and Swiss Data Subjects retain the right to bring claims in Switzerland consistent with Clause 18(c) of the EEA SCCs.

11.4 The UK Addendum is completed with the EEA SCCs referred to in Section 11.2 as the Approved EU SCCs, and Giga is designated as “Importer.”

12. U.S. State Privacy Laws

Giga certifies that it understands the restrictions set out in this Section 12 and will comply with them. 12.1 Giga certifies that it understands the restrictions set out in this Section 12 and will comply with them. To the extent Applicable Data Protection Laws in the U.S. apply to Giga's Processing of Personal Data:

12.1.1 Giga is prohibited from (i) Selling Personal Data, (ii) Sharing Customer Personal Data except as permitted by law, (iii) retaining, using, or disclosing Customer Personal Data for any purpose other than the Business Purposes permitted under the Agreement, and (iv) combining Customer Personal Data with Personal Data from other sources, except as permitted under Applicable Data Protection Laws.

12.1.2 The exchange of Personal Data between the parties is not part of any monetary or other valuable consideration exchanged under the Agreement or this DPA.

12.1.3 Giga will promptly notify Customer if it can no longer meet its obligations under U.S. Applicable Data Protection Laws, and Customer may direct Giga to take reasonable steps to stop and remediate any unauthorized use of Customer Personal Data.

Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set forth in the Agreement, and any reference to the liability of a party under the Agreement includes aggregate liability under the Agreement and this DPA together.

13.1 Limitation. The Parties agree that, for any claim, liability, loss, damage, cost, expense, demand, proceeding, or action (whether in contract, tort, negligence, strict liability, or otherwise) arising out of or relating to this DPA, including any data processing claims, the limitation of liability set out in the Agreement (including any monetary cap and any exclusions/limitations of liability) applies and caps Giga’s aggregate liability in respect of such claims to the maximum extent permitted by applicable law.

13.2 No Separate Cap. There shall be no separate or additional limitation of liability under this DPA other than as expressly stated in the Agreement.

13. Contact

For privacy inquiries relating to this DPA, contact Giga at privacy@giga.ai.

Annex I — Description of the Transfer

A. List of Parties

  • Data exporter: Customer (as defined in the Agreement). Role: Controller, or Processor on behalf of a Third-Party Controller. Customer's legal name, address, and contact person are as set out in the applicable Pilot Order Form or the Agreement.
  • Data importer: Giga AI, Inc. Role: Processor on behalf of Customer, or Subprocessor on behalf of a Third-Party Controller.

B. Description of International Data Transfer

  • Categories of Data Subjects: individuals whose characteristics are present in Customer Materials uploaded by or on behalf of Customer, including Customer's end users.
  • Categories of Personal Data transferred: text, audio, or other content uploaded by or on behalf of Customer through the Services.
  • Sensitive Data transferred and applicable safeguards: If the Services involve voice capture, recording, or synthesis, this may include voice recordings that constitute biometric or sensitive personal information under certain Applicable Data Protection Laws. Applicable safeguards include purpose limitation, access restricted to trained personnel, encryption at rest and in transit, and retention limits.
  • Frequency of transfer: on a continuous basis.
  • Nature and purpose of Processing: provision of the Services, as described in the Agreement.
  • Retention period: as set out in Section 9 above.
  • For transfers to Subprocessors: the subject matter, nature, and duration of Processing are consistent with the terms applicable to Giga as data importer above.

C. Competent Supervisory Authority

For Data Subjects in the EEA: the Supervisory Authority of the EU Member State in which the data exporter is established. For Data Subjects in the UK: the UK Information Commissioner. Where a transfer is governed by the FADP rather than the GDPR: the Swiss Federal Data Protection and Information Commissioner.

Annex II — Technical and Organizational Measures

Giga maintains the following technical and organizational measures to protect Customer Personal Data, consistent with Section 5.

  • Certifications and assurance: ISO 27001:2022, SOC 2, ISO 42001:2023, and PCI DSS 4.0.1, together with HIPAA- and GDPR/CPRA-aligned programs and regular third-party penetration testing.
  • Encryption: Customer Personal Data is encrypted in transit using TLS and at rest using AES-256.
  • Access control: role-based access on a least-privilege basis, multi-factor authentication, and prompt deprovisioning upon personnel changes.
  • Information security management: an ISO 27001-based information security management system, Data Classification Policy, and Acceptable Use Policy.
  • Resilience and recovery: Business Continuity Plan and Business Continuity & Disaster Recovery Policy, with regular backups.
  • Testing and evaluation: vulnerability remediation and centralized flaw-remediation processes, annual penetration testing, and periodic SOC 2 audits.
  • Transmission and storage security: encryption in transit and at rest, controls governing the transfer of personal information, external-system-connection controls, and endpoint anti-malware protection.
  • Physical security: production data is hosted with sub-processors (including AWS, Microsoft Azure, and Google Cloud Platform) that maintain physical and environmental security controls.
  • Logging and monitoring: event logging and anomalous-behavior detection.
  • Change management: documented approval-of-changes process.
  • Governance and personnel: security and privacy awareness training, Code of Business Conduct, and periodic performance review.
  • Incident response: a Personal Data Breach Notification Procedure.
  • Data minimization and retention: data classification and deletion in accordance with Section 9.
  • Sub-processors: all sub-processors are bound to data protection obligations no less protective than those in this DPA, as required by Section 6.

End of Policy.

Data Processing Addendum — Giga