Data Processing Agreement
Effective Date: July 7, 2026
This Data Processing Agreement (this “DPA”) forms part of the agreement governing Customer’s use of Gate AI and related services (the “Agreement”) between Constellation Network, Inc., a Delaware corporation, with its principal address at 2140 S Dupont Hwy, Camden, Delaware 19934 (“Constellation”) and the customer identified in the Agreement (“Customer”).
This DPA applies where Constellation Processes Personal Data on behalf of Customer in connection with the Services.
1. Definitions
For this DPA:
“Applicable Data Protection Law” means all laws and regulations applicable to the Processing of Personal Data under the Agreement, including, where applicable, the GDPR, UK GDPR, Swiss FADP, and any implementing or supplementary legislation.
“Controller,” “Processor,” “Data Subject,” “Personal Data,” “Personal Data Breach,” “Process” and “Processing,” and “Supervisory Authority” have the meanings given in Applicable Data Protection Law.
“Customer Personal Data” means Personal Data Processed by Constellation on behalf of Customer under the Agreement.
“GDPR” means Regulation (EU) 2016/679.
“Restricted Transfer” means any transfer of Personal Data for which Applicable Data Protection Law requires a specific transfer mechanism.
“Sub-processor” means any third party engaged by Constellation to Process Customer Personal Data on behalf of Customer in connection with the Services.
“UK GDPR” means the GDPR as it forms part of the law of England and Wales, Scotland, and Northern Ireland.
2. Roles of the Parties
The parties acknowledge that, for the Processing of Customer Personal Data under the Agreement, Customer is the Controller or Processor, as applicable, and Constellation is a Processor or sub-processor, as applicable.
If Customer is itself a Processor, Customer represents and warrants on an ongoing basis that Customer’s instructions and actions with respect to Customer Personal Data, including its appointment of Constellation as another processor, have been authorized by the relevant Controller.
3. Customer’s Instructions
Constellation will Process Customer Personal Data only on Customer’s documented instructions, including as set out in the Agreement, this DPA, Customer’s configuration of the Services, and Customer’s use of the Services, unless otherwise required by applicable law. In that case, Constellation will inform Customer of that legal requirement before Processing unless the law prohibits such notice.
Customer instructs Constellation to Process Customer Personal Data as necessary to provide, secure, monitor, support, maintain, and improve the Services; to route prompts and related data to Customer-selected or Customer-enabled Third-Party Providers; to generate logs, alerts, and tamper-evident audit records; and to take measures requested or configured by Customer in the Services.
Customer is responsible for ensuring that its instructions comply with Applicable Data Protection Law. Constellation will promptly inform Customer if, in Constellation’s opinion, an instruction infringes Applicable Data Protection Law, but Constellation is not required to monitor Customer’s compliance comprehensively.
4. Confidentiality
Constellation will ensure that persons authorized to Process Customer Personal Data are subject to confidentiality obligations no less protective than those in the Agreement.
5. Security
Constellation will implement and maintain appropriate technical and organizational measures designed to provide a level of security appropriate to the risk, including as described in Annex 2 of this DPA.
In assessing the appropriate level of security, Constellation will take into account the risks presented by Processing, including accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data.
6. Sub-processors
Customer provides general written authorization for Constellation to engage Sub-processors to Process Customer Personal Data. Constellation will maintain a list of its Sub-processors and make it available as described in its Sub-processor Notice and Objection Policy.
Constellation will impose written contractual obligations on Sub-processors that are no less protective, in substance, than the obligations Constellation undertakes in this DPA, to the extent applicable to the services performed by the Sub-processor.
Constellation will give Customer reasonable prior notice of the addition or replacement of a Sub-processor, except where shorter notice is required for urgent legal, security, operational, or service-continuity reasons. Customer may object to a new or replacement Sub-processor in accordance with the Sub-processor Notice and Objection Policy. If Constellation cannot reasonably resolve Customer’s objection, Customer may terminate the affected portion of the Services and receive a refund of prepaid fees for the unused remainder of the terminated term.
Constellation remains responsible for its Sub-processors to the extent required by Applicable Data Protection Law.
7. Data Subject Rights
Taking into account the nature of the Processing, Constellation will provide reasonable assistance to Customer, through appropriate technical and organizational measures where possible, to enable Customer to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Law.
If Constellation receives a request from a Data Subject relating to Customer Personal Data, Constellation will advise the Data Subject to submit the request directly to Customer unless Constellation is legally prohibited from doing so. Constellation may assist Customer in responding to such requests at Customer’s reasonable expense, except to the extent assistance is already included in the Services.
8. Assistance with Compliance and Impact Assessments
Taking into account the nature of the Processing and the information available to Constellation, Constellation will provide reasonable assistance to Customer with Customer’s obligations under Articles 32 through 36 GDPR and analogous provisions of Applicable Data Protection Law, including security, breach notifications, data protection impact assessments, and prior consultations with Supervisory Authorities, in each case to the extent Customer does not otherwise have access to the relevant information and such assistance is reasonably necessary.
9. Personal Data Breach Notification
Constellation will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data.
Such notice will include, to the extent then available, the nature of the Personal Data Breach, the categories of affected data, the likely consequences, and the measures taken or proposed to address the breach. Constellation may provide information in phases as it becomes available.
Constellation’s notification of or response to a Personal Data Breach will not be construed as an admission of fault or liability.
10. Deletion and Return
Upon termination or expiration of the Agreement, and upon Customer’s written request made within thirty (30) days after termination, Constellation will delete or return Customer Personal Data, unless retention is required by applicable law or reasonably necessary for security, backup, billing, dispute resolution, fraud prevention, or to maintain the integrity of tamper-evident audit processes.
Where the Services anchor cryptographic fingerprints, hashes, or comparable integrity markers to immutable or append-only systems, the parties acknowledge that such markers are intended not to constitute intelligible Personal Data and are retained solely to evidence integrity. Underlying Customer Personal Data held in ordinary storage will remain subject to deletion or return in accordance with this DPA.
11. Information and Audit Rights
Constellation will make available to Customer, upon written request and subject to reasonable confidentiality protections, information reasonably necessary to demonstrate Constellation’s compliance with this DPA and Article 28 of the GDPR or analogous requirements of Applicable Data Protection Law.
Constellation may satisfy its obligations under this Section by providing current third-party audit reports, certifications, summaries of penetration testing, security questionnaires, or other standard compliance documentation that is reasonably sufficient to demonstrate compliance.
Only to the extent required by Applicable Data Protection Law and where the information made available by Constellation is not reasonably sufficient for Customer to verify compliance, Customer may request an audit of Constellation’s relevant processing activities under this DPA.
Any such audit must: (a) be conducted no more than once in any 12-month period, except where required by a competent Supervisory Authority or where a confirmed Personal Data Breach materially affecting Customer Personal Data makes an additional audit reasonably necessary; (b) be conducted on at least thirty (30) days prior written notice; (c) be limited in scope to matters directly relevant to Customer Personal Data Processed by Constellation; (d) be conducted during normal business hours and in a manner that minimizes disruption to Constellation’s business operations; (e) be performed by an independent third-party auditor reasonably acceptable to Constellation and bound by written confidentiality obligations no less protective than those in the Agreement; and (f) comply with Constellation’s reasonable security, access, and confidentiality requirements.
Audits may not unreasonably interfere with Constellation’s operations or compromise the confidentiality, security, or privacy of Constellation’s systems, source code, security architecture, trade secrets, or the data of other customers. Customer will not have direct access to other customers’ data, to raw vulnerability or penetration-test results where summaries are reasonably sufficient, or to any facility or system except to the limited extent strictly necessary to satisfy Applicable Data Protection Law.
Customer will bear its own costs for any audit and will reimburse Constellation for Constellation’s reasonable costs incurred in connection with the audit, except where the audit establishes a material breach of this DPA by Constellation.
Nothing in this Section requires Constellation to disclose information that is legally privileged, would compromise the security of Constellation or its customers, or is otherwise restricted by applicable law or binding confidentiality obligations owed to third parties. Constellation will have no obligation to permit Customer to audit any Sub-processor directly, provided that Constellation will, to the extent required by Applicable Data Protection Law, use commercially reasonable efforts to make available information relating to Sub-processor compliance that Constellation is entitled to share.
12. International Transfers
If Constellation or a Sub-processor makes a Restricted Transfer, the parties will ensure that the transfer is subject to an appropriate transfer mechanism under Applicable Data Protection Law.
Where required, the Standard Contractual Clauses set out in Annex A are incorporated by reference into this DPA. For transfers subject to the UK GDPR, the UK International Data Transfer Addendum set out in Annex B applies to the EU Standard Contractual Clauses. For transfers subject to the Swiss FADP, the EU Standard Contractual Clauses will apply with the modifications necessary to recognize Swiss law and the Swiss Federal Data Protection and Information Commissioner as required.
Customer acknowledges and instructs that Customer Personal Data may be transferred to and Processed in the United States and other jurisdictions where Constellation or its Sub-processors operate, subject to the applicable transfer mechanism.
13. EU Representative and UK Representative
If Constellation is required by Applicable Data Protection Law to appoint an EU representative or UK representative in connection with the Services, Constellation will maintain such appointment and provide the representative’s contact details in its privacy notice or other appropriate public-facing materials.
14. Liability
Each party’s liability under this DPA is subject to the exclusions and limitations of liability in the Agreement, except to the extent prohibited by Applicable Data Protection Law.
15. Governing Law
This DPA is governed by the governing law provisions of the Agreement, unless and to the extent the Standard Contractual Clauses or other mandatory transfer terms require otherwise for the relevant transfer.
16. Order of Precedence
If there is a conflict between this DPA and the Agreement, this DPA controls with respect to the Processing of Customer Personal Data. If there is a conflict between this DPA and the Standard Contractual Clauses or UK Addendum, the Standard Contractual Clauses or UK Addendum control to the extent of that conflict.
Annex 1 — Details of Processing
Subject matter: Provision of the Services, including AI gateway routing, prompt and response handling, security filtering, abuse detection, logging, and audit-trail functionality.
Duration: The term of the Agreement, plus any period during which Constellation retains Customer Personal Data in accordance with the Agreement and this DPA.
Nature and purpose of Processing: Hosting, storage, organization, transmission, routing, filtering, scanning, logging, analysis, security review, abuse prevention, support, troubleshooting, and other Processing necessary to provide the Services and related support.
Categories of Data Subjects: Customer personnel, end users, contractors, prospects, customers, and other individuals whose Personal Data is included in Customer Content.
Categories of Personal Data: Prompts, responses, account information, contact data, identifiers, online identifiers, device and usage data, support communications, and any other Personal Data submitted by Customer through the Services.
Sensitive data: Customer may choose to submit special categories of data or other sensitive data. Customer is responsible for determining whether such use is permitted and for implementing appropriate safeguards.
Frequency: Continuous, as initiated by Customer and its users.
Annex 2 — Technical and Organizational Measures
Constellation will maintain technical and organizational measures appropriate to the risk, which may include as applicable:
- policies governing information security, access management, and incident response;
- logical access controls, role-based access, credential protection, and least-privilege practices;
- encryption in transit and at rest where appropriate;
- network monitoring, logging, and security review processes;
- vulnerability management and patching practices;
- backup and disaster recovery practices;
- personnel confidentiality obligations and security awareness measures; and
- vendor and sub-processor due diligence and contractual controls.
Annex A — EU Standard Contractual Clauses Incorporation Terms
For any Restricted Transfer of Customer Personal Data from the European Economic Area to Constellation or a relevant Sub-processor in a third country not recognized as providing adequate protection, the European Commission Standard Contractual Clauses for the transfer of personal data to third countries adopted by Commission Implementing Decision (EU) 2021/914 (“EU SCCs”) are incorporated as follows:
- Module Selection. Module Two (Controller to Processor) applies where Customer is a Controller and Constellation is a Processor. Module Three (Processor to Processor) applies where Customer is a Processor and Constellation is a sub-processor.
- Clause 7 (Docking Clause). Optional Clause 7 applies.
- Clause 9 (Use of Sub-processors). Option 2 applies, and the time period for prior notice of Sub-processor changes is the notice period set out in Section 6 of this DPA.
- Clause 11 (Redress). Optional language is not included.
- Clause 17 (Governing Law). The governing law is the law of the Republic of Ireland.
- Clause 18 (Choice of Forum and Jurisdiction). The courts of the Republic of Ireland have jurisdiction.
- Annex I and II. Annex 1 and Annex 2 of this DPA complete Annex I and Annex II of the EU SCCs.
- Annex III. The list of Sub-processors maintained by Constellation completes Annex III of the EU SCCs.
- Conflicts. In the event of any conflict between the EU SCCs and the Agreement or this DPA, the EU SCCs prevail with respect to the relevant Restricted Transfer.
Annex B — UK International Data Transfer Addendum Incorporation Terms
For Restricted Transfers subject to the UK GDPR, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued under section 119A of the UK Data Protection Act 2018 (“UK Addendum”) is incorporated into this DPA, with the following completed details:
- The EU SCCs incorporated by Annex A form the Approved EU SCCs.
- The exporter, importer, transfer details, and technical and organizational measures are as set out in this DPA and the Agreement.
- The start date is the effective date of this DPA.
- The parties select the version of the UK Addendum that permits the tables to be completed by reference to the Agreement and this DPA.
- If the UK Addendum permits either party to end the UK Addendum in accordance with its terms, that right applies only to the extent required by the UK Addendum.
Annex C — Swiss Transfer Terms
For Restricted Transfers subject to the Swiss FADP, the EU SCCs incorporated by Annex A apply with the following modifications to the extent required:
- references to the GDPR include the Swiss FADP to the extent applicable;
- references to Member State law are interpreted as references to Swiss law where required;
- the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner where required; and
- Data Subjects in Switzerland may enforce rights under the EU SCCs in Switzerland to the extent required by Swiss law.