Constellation Gate AI / DPA
Legal

Data Processing Agreement

Effective Date: July 7, 2026

This Data Processing Agreement (this “DPA”) forms part of the agreement governing Customer’s use of Gate AI and related services (the “Agreement”) between Constellation Network, Inc., a Delaware corporation, with its principal address at 2140 S Dupont Hwy, Camden, Delaware 19934 (“Constellation”) and the customer identified in the Agreement (“Customer”).

This DPA applies where Constellation Processes Personal Data on behalf of Customer in connection with the Services.

1. Definitions

For this DPA:

“Applicable Data Protection Law” means all laws and regulations applicable to the Processing of Personal Data under the Agreement, including, where applicable, the GDPR, UK GDPR, Swiss FADP, and any implementing or supplementary legislation.

“Controller,” “Processor,” “Data Subject,” “Personal Data,” “Personal Data Breach,” “Process” and “Processing,” and “Supervisory Authority” have the meanings given in Applicable Data Protection Law.

“Customer Personal Data” means Personal Data Processed by Constellation on behalf of Customer under the Agreement.

“GDPR” means Regulation (EU) 2016/679.

“Restricted Transfer” means any transfer of Personal Data for which Applicable Data Protection Law requires a specific transfer mechanism.

“Sub-processor” means any third party engaged by Constellation to Process Customer Personal Data on behalf of Customer in connection with the Services.

“UK GDPR” means the GDPR as it forms part of the law of England and Wales, Scotland, and Northern Ireland.

2. Roles of the Parties

The parties acknowledge that, for the Processing of Customer Personal Data under the Agreement, Customer is the Controller or Processor, as applicable, and Constellation is a Processor or sub-processor, as applicable.

If Customer is itself a Processor, Customer represents and warrants on an ongoing basis that Customer’s instructions and actions with respect to Customer Personal Data, including its appointment of Constellation as another processor, have been authorized by the relevant Controller.

3. Customer’s Instructions

Constellation will Process Customer Personal Data only on Customer’s documented instructions, including as set out in the Agreement, this DPA, Customer’s configuration of the Services, and Customer’s use of the Services, unless otherwise required by applicable law. In that case, Constellation will inform Customer of that legal requirement before Processing unless the law prohibits such notice.

Customer instructs Constellation to Process Customer Personal Data as necessary to provide, secure, monitor, support, maintain, and improve the Services; to route prompts and related data to Customer-selected or Customer-enabled Third-Party Providers; to generate logs, alerts, and tamper-evident audit records; and to take measures requested or configured by Customer in the Services.

Customer is responsible for ensuring that its instructions comply with Applicable Data Protection Law. Constellation will promptly inform Customer if, in Constellation’s opinion, an instruction infringes Applicable Data Protection Law, but Constellation is not required to monitor Customer’s compliance comprehensively.

4. Confidentiality

Constellation will ensure that persons authorized to Process Customer Personal Data are subject to confidentiality obligations no less protective than those in the Agreement.

5. Security

Constellation will implement and maintain appropriate technical and organizational measures designed to provide a level of security appropriate to the risk, including as described in Annex 2 of this DPA.

In assessing the appropriate level of security, Constellation will take into account the risks presented by Processing, including accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data.

6. Sub-processors

Customer provides general written authorization for Constellation to engage Sub-processors to Process Customer Personal Data. Constellation will maintain a list of its Sub-processors and make it available as described in its Sub-processor Notice and Objection Policy.

Constellation will impose written contractual obligations on Sub-processors that are no less protective, in substance, than the obligations Constellation undertakes in this DPA, to the extent applicable to the services performed by the Sub-processor.

Constellation will give Customer reasonable prior notice of the addition or replacement of a Sub-processor, except where shorter notice is required for urgent legal, security, operational, or service-continuity reasons. Customer may object to a new or replacement Sub-processor in accordance with the Sub-processor Notice and Objection Policy. If Constellation cannot reasonably resolve Customer’s objection, Customer may terminate the affected portion of the Services and receive a refund of prepaid fees for the unused remainder of the terminated term.

Constellation remains responsible for its Sub-processors to the extent required by Applicable Data Protection Law.

7. Data Subject Rights

Taking into account the nature of the Processing, Constellation will provide reasonable assistance to Customer, through appropriate technical and organizational measures where possible, to enable Customer to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Law.

If Constellation receives a request from a Data Subject relating to Customer Personal Data, Constellation will advise the Data Subject to submit the request directly to Customer unless Constellation is legally prohibited from doing so. Constellation may assist Customer in responding to such requests at Customer’s reasonable expense, except to the extent assistance is already included in the Services.

8. Assistance with Compliance and Impact Assessments

Taking into account the nature of the Processing and the information available to Constellation, Constellation will provide reasonable assistance to Customer with Customer’s obligations under Articles 32 through 36 GDPR and analogous provisions of Applicable Data Protection Law, including security, breach notifications, data protection impact assessments, and prior consultations with Supervisory Authorities, in each case to the extent Customer does not otherwise have access to the relevant information and such assistance is reasonably necessary.

9. Personal Data Breach Notification

Constellation will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data.

Such notice will include, to the extent then available, the nature of the Personal Data Breach, the categories of affected data, the likely consequences, and the measures taken or proposed to address the breach. Constellation may provide information in phases as it becomes available.

Constellation’s notification of or response to a Personal Data Breach will not be construed as an admission of fault or liability.

10. Deletion and Return

Upon termination or expiration of the Agreement, and upon Customer’s written request made within thirty (30) days after termination, Constellation will delete or return Customer Personal Data, unless retention is required by applicable law or reasonably necessary for security, backup, billing, dispute resolution, fraud prevention, or to maintain the integrity of tamper-evident audit processes.

Where the Services anchor cryptographic fingerprints, hashes, or comparable integrity markers to immutable or append-only systems, the parties acknowledge that such markers are intended not to constitute intelligible Personal Data and are retained solely to evidence integrity. Underlying Customer Personal Data held in ordinary storage will remain subject to deletion or return in accordance with this DPA.

11. Information and Audit Rights

Constellation will make available to Customer, upon written request and subject to reasonable confidentiality protections, information reasonably necessary to demonstrate Constellation’s compliance with this DPA and Article 28 of the GDPR or analogous requirements of Applicable Data Protection Law.

Constellation may satisfy its obligations under this Section by providing current third-party audit reports, certifications, summaries of penetration testing, security questionnaires, or other standard compliance documentation that is reasonably sufficient to demonstrate compliance.

Only to the extent required by Applicable Data Protection Law and where the information made available by Constellation is not reasonably sufficient for Customer to verify compliance, Customer may request an audit of Constellation’s relevant processing activities under this DPA.

Any such audit must: (a) be conducted no more than once in any 12-month period, except where required by a competent Supervisory Authority or where a confirmed Personal Data Breach materially affecting Customer Personal Data makes an additional audit reasonably necessary; (b) be conducted on at least thirty (30) days prior written notice; (c) be limited in scope to matters directly relevant to Customer Personal Data Processed by Constellation; (d) be conducted during normal business hours and in a manner that minimizes disruption to Constellation’s business operations; (e) be performed by an independent third-party auditor reasonably acceptable to Constellation and bound by written confidentiality obligations no less protective than those in the Agreement; and (f) comply with Constellation’s reasonable security, access, and confidentiality requirements.

Audits may not unreasonably interfere with Constellation’s operations or compromise the confidentiality, security, or privacy of Constellation’s systems, source code, security architecture, trade secrets, or the data of other customers. Customer will not have direct access to other customers’ data, to raw vulnerability or penetration-test results where summaries are reasonably sufficient, or to any facility or system except to the limited extent strictly necessary to satisfy Applicable Data Protection Law.

Customer will bear its own costs for any audit and will reimburse Constellation for Constellation’s reasonable costs incurred in connection with the audit, except where the audit establishes a material breach of this DPA by Constellation.

Nothing in this Section requires Constellation to disclose information that is legally privileged, would compromise the security of Constellation or its customers, or is otherwise restricted by applicable law or binding confidentiality obligations owed to third parties. Constellation will have no obligation to permit Customer to audit any Sub-processor directly, provided that Constellation will, to the extent required by Applicable Data Protection Law, use commercially reasonable efforts to make available information relating to Sub-processor compliance that Constellation is entitled to share.

12. International Transfers

If Constellation or a Sub-processor makes a Restricted Transfer, the parties will ensure that the transfer is subject to an appropriate transfer mechanism under Applicable Data Protection Law.

Where required, the Standard Contractual Clauses set out in Annex A are incorporated by reference into this DPA. For transfers subject to the UK GDPR, the UK International Data Transfer Addendum set out in Annex B applies to the EU Standard Contractual Clauses. For transfers subject to the Swiss FADP, the EU Standard Contractual Clauses will apply with the modifications necessary to recognize Swiss law and the Swiss Federal Data Protection and Information Commissioner as required.

Customer acknowledges and instructs that Customer Personal Data may be transferred to and Processed in the United States and other jurisdictions where Constellation or its Sub-processors operate, subject to the applicable transfer mechanism.

13. EU Representative and UK Representative

If Constellation is required by Applicable Data Protection Law to appoint an EU representative or UK representative in connection with the Services, Constellation will maintain such appointment and provide the representative’s contact details in its privacy notice or other appropriate public-facing materials.

14. Liability

Each party’s liability under this DPA is subject to the exclusions and limitations of liability in the Agreement, except to the extent prohibited by Applicable Data Protection Law.

15. Governing Law

This DPA is governed by the governing law provisions of the Agreement, unless and to the extent the Standard Contractual Clauses or other mandatory transfer terms require otherwise for the relevant transfer.

16. Order of Precedence

If there is a conflict between this DPA and the Agreement, this DPA controls with respect to the Processing of Customer Personal Data. If there is a conflict between this DPA and the Standard Contractual Clauses or UK Addendum, the Standard Contractual Clauses or UK Addendum control to the extent of that conflict.


Annex 1 — Details of Processing

Subject matter: Provision of the Services, including AI gateway routing, prompt and response handling, security filtering, abuse detection, logging, and audit-trail functionality.

Duration: The term of the Agreement, plus any period during which Constellation retains Customer Personal Data in accordance with the Agreement and this DPA.

Nature and purpose of Processing: Hosting, storage, organization, transmission, routing, filtering, scanning, logging, analysis, security review, abuse prevention, support, troubleshooting, and other Processing necessary to provide the Services and related support.

Categories of Data Subjects: Customer personnel, end users, contractors, prospects, customers, and other individuals whose Personal Data is included in Customer Content.

Categories of Personal Data: Prompts, responses, account information, contact data, identifiers, online identifiers, device and usage data, support communications, and any other Personal Data submitted by Customer through the Services.

Sensitive data: Customer may choose to submit special categories of data or other sensitive data. Customer is responsible for determining whether such use is permitted and for implementing appropriate safeguards.

Frequency: Continuous, as initiated by Customer and its users.

Annex 2 — Technical and Organizational Measures

Constellation will maintain technical and organizational measures appropriate to the risk, which may include as applicable:

Annex A — EU Standard Contractual Clauses Incorporation Terms

For any Restricted Transfer of Customer Personal Data from the European Economic Area to Constellation or a relevant Sub-processor in a third country not recognized as providing adequate protection, the European Commission Standard Contractual Clauses for the transfer of personal data to third countries adopted by Commission Implementing Decision (EU) 2021/914 (“EU SCCs”) are incorporated as follows:

Annex B — UK International Data Transfer Addendum Incorporation Terms

For Restricted Transfers subject to the UK GDPR, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued under section 119A of the UK Data Protection Act 2018 (“UK Addendum”) is incorporated into this DPA, with the following completed details:

Annex C — Swiss Transfer Terms

For Restricted Transfers subject to the Swiss FADP, the EU SCCs incorporated by Annex A apply with the following modifications to the extent required: