Gogins

Data Processing Agreement

v0.1 · Last updated 2026-07-22 · Draft — pending final legal review

Gogins.ai — Nevari International Limited

THIS DATA PROCESSING AGREEMENT (this "DPA") forms part of, and is incorporated into, the Master Subscription Agreement, SaaS Agreement, Order Form, Terms of Service (Part A), or other written or electronic agreement governing Customer's use of the Gogins.ai platform and related Services (the "Agreement") entered into by and between:

  • Nevari International Limited, a private limited company incorporated under the laws of England and Wales (registered office and details as set out in the Agreement) (the "Processor", "Nevari", "we", "us", or "our"); and
  • the customer entity identified in the Agreement, Order Form, or signature block hereto (the "Customer", "Controller", "you", or "your"),

each a "Party" and together the "Parties".

Acceptance and Execution

This DPA does not require a separate ink or electronic signature to be binding. Customer acknowledges and agrees that, by performing any one or more of the following acts, Customer executes, accepts, and is legally bound by this DPA and all of its Schedules, with the same force and effect as if Customer had signed it by hand or electronic signature:

  • signing, electronically accepting, clicking "Accept", "Agree", "Submit", or any equivalent affirmative action on any Gogins.ai proposal, quote, Order Form, Statement of Work, subscription plan, checkout page, or onboarding flow that references, links to, or incorporates this DPA or the Agreement;
  • entering, submitting, authorising, or providing payment or billing details to Nevari or to Nevari's authorised billing processor in connection with Customer's subscription to or use of the Services;
  • paying, or causing to be paid, any invoice, subscription fee, or other amount payable to Nevari for the Services;
  • creating, activating, or accessing a Gogins.ai account, workspace, or tenant; or
  • using, accessing, or permitting any authorised user of Customer to use or access any part of the Services.

The earliest of the foregoing acts shall constitute the "Effective Date" of this DPA. Customer represents and warrants that the natural person performing any such act has full authority to bind Customer. Customer further acknowledges that (i) this DPA, the Agreement, and any related Order Form together constitute a single, integrated contract, (ii) acceptance of any one of them constitutes acceptance of all, and (iii) Customer waives any defence to enforceability of this DPA based on the absence of a signature on this DPA itself.

Recitals

  • Nevari provides the Gogins.ai platform and related Services to Customer pursuant to the Agreement.
  • In the course of providing the Services, Nevari Processes Personal Data on behalf of Customer.
  • The Parties wish to set out their respective rights and obligations in relation to such Processing in accordance with Applicable Data Protection Law, including Article 28 of the UK GDPR and the EU GDPR.
  • This DPA applies to all Processing of Customer Personal Data by Nevari and its Sub-processors in connection with the Gogins.ai platform: AI-agent inventory and cited classification, governance findings and evidence, connected-systems scanning, usage metering, auditor exports, workspace and team administration, support, and any other Services provided under the Agreement.
  • By executing the Agreement or otherwise accepting the Services, Customer agrees to be bound by this DPA.

NOW THEREFORE, the Parties agree as follows:

1. Definitions and Interpretation

1.1 Capitalised terms used but not defined in this DPA shall have the meanings given to them in the Agreement. In this DPA:

"Affiliate" means any entity that directly or indirectly controls, is controlled by, or is under common control with a Party, where "control" means ownership of more than fifty percent (50%) of the voting securities or equivalent interests.

"Applicable Data Protection Law" means all laws, regulations, and binding regulatory guidance applicable to the Processing of Personal Data under the Agreement, including (i) the UK GDPR as incorporated into UK law by the European Union (Withdrawal) Act 2018; (ii) the EU GDPR (Regulation (EU) 2016/679); (iii) the UK Data Protection Act 2018; (iv) the Privacy and Electronic Communications (EC Directive) Regulations 2003; (v) the EU ePrivacy Directive 2002/58/EC and implementing national legislation; (vi) the Swiss Federal Act on Data Protection (FADP); (vii) the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 (the "CCPA"); and (viii) any other applicable national, federal, state, or supranational law relating to the protection of Personal Data, in each case as amended, replaced, or supplemented.

"Controller", "Processor", "Data Subject", and "Processing" have the meanings given under Applicable Data Protection Law.

"Customer Personal Data" means Personal Data Processed by Nevari (or any Sub-processor) on behalf of Customer pursuant to or in connection with the Agreement, as further described in Schedule 1.

"EU SCCs" means the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as amended or replaced.

"IDTA" means the International Data Transfer Agreement issued by the Information Commissioner's Office under section 119A of the UK Data Protection Act 2018, as amended or replaced.

"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.

"Security Incident" means any confirmed Personal Data Breach affecting Customer Personal Data. For the avoidance of doubt, unsuccessful security events (including unsuccessful login attempts, pings, port scans, and denial-of-service attacks that do not result in a breach) shall not constitute Security Incidents.

"Special Category Data" means Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership; genetic or biometric data Processed to uniquely identify a natural person; data concerning health; or data concerning a natural person's sex life or sexual orientation, as defined under Article 9 GDPR, together with Personal Data relating to criminal convictions and offences.

"Sub-processor" means any third party (including any Affiliate of Nevari) engaged by Nevari to Process Customer Personal Data in connection with the Services.

"Supervisory Authority" means a competent regulator under Applicable Data Protection Law, including the UK Information Commissioner's Office ("ICO").

"UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the ICO under section 119A of the UK Data Protection Act 2018, as amended or replaced.

1.2 In this DPA: (a) the singular includes the plural and vice versa; (b) references to a statute include subordinate legislation and any re-enactment or replacement; (c) headings are for convenience only; (d) "including" and "in particular" are illustrative and not limiting; and (e) in the event of conflict between this DPA and the Agreement with respect to the Processing of Personal Data, this DPA prevails.

2. Scope and Role of the Parties

2.1 Roles. With respect to the Processing of Customer Personal Data: (a) Customer is the Controller; (b) Nevari is the Processor; and (c) Nevari may engage Sub-processors in accordance with Section 9.

2.2 Customer Determines Purposes. Customer alone determines the purposes and means of Processing. Nevari shall Process Customer Personal Data solely on documented instructions from Customer and shall not Process it for any other purpose, except where required by applicable law (in which case Nevari shall inform Customer before Processing, unless prohibited on important grounds of public interest).

2.3 Documented Instructions. Customer's documented instructions comprise (a) the Agreement (including this DPA and any Order Form), (b) Customer's use of the Services and the configurations and settings selected by Customer, and (c) any further written instructions consistent with the foregoing that Nevari has reasonably agreed to follow.

2.4 Customer's Affiliates. Customer's permitted Affiliates may submit Customer Personal Data to the Services. Customer is solely responsible for coordinating communications on behalf of its Affiliates and for their acts and omissions as if they were Customer's own.

2.5 No Sale. Nevari does not sell, share, or otherwise transfer Customer Personal Data for valuable consideration and shall not be considered to have "sold" or "shared" Customer Personal Data within the meaning of the CCPA or other Applicable Data Protection Law.

2.6 Subject Matter. The subject matter, duration, nature, purpose, types of Personal Data, and categories of Data Subjects are set out in Schedule 1.

3. Customer Responsibilities, Warranties, and Covenants

3.1 Customer represents, warrants, and covenants that, at all times during the term:

  • it has all necessary rights, permissions, lawful bases, consents, and notices required under Applicable Data Protection Law to (i) collect Customer Personal Data, (ii) make it available to Nevari and its Sub-processors, and (iii) authorise their Processing of it for the purposes of providing the Services;
  • its instructions to Nevari comply with Applicable Data Protection Law;
  • it shall not instruct Nevari to Process Customer Personal Data in any manner that would violate Applicable Data Protection Law, infringe third-party rights, or cause Nevari to breach any obligation owed to a Data Subject or Supervisory Authority;
  • it is solely responsible for the accuracy, quality, integrity, and legality of Customer Personal Data and the manner in which it was acquired;
  • it shall provide all required privacy notices to Data Subjects, including in respect of the engagement of Nevari and its Sub-processors and any international transfers; and
  • it shall not submit Special Category Data, payment card data, government-issued identifiers, children's data, or other regulated categories through the Services (including into free-text fields or the evidence library) except where expressly authorised in writing by Nevari and where Customer has implemented all additional measures required by law.

3.2 Customer acknowledges that Nevari relies on Customer for direction as to the Processing, and that Nevari shall not be liable for any claim arising from an act or omission to the extent it resulted from Customer's instructions or breach of this Section 3.

3.3 Customer Indemnity. Without prejudice to any indemnity in the Agreement, Customer shall indemnify Nevari against losses arising from Customer's breach of Section 3.1 or failure to comply with Applicable Data Protection Law as a Controller.

4. Processor Obligations

Nevari shall, at all times during the term:

  • Process Customer Personal Data solely on documented instructions from Customer (including regarding international transfers), unless required by applicable law (with prior notice unless prohibited);
  • ensure that personnel authorised to Process Customer Personal Data are bound by confidentiality and have received appropriate data-protection training;
  • implement and maintain appropriate technical and organisational measures in accordance with Article 32 GDPR and as described in Schedule 2;
  • respect the conditions in Article 28(2) and (4) GDPR for engaging Sub-processors;
  • taking into account the nature of Processing, assist Customer by appropriate technical and organisational measures, insofar as possible, in responding to Data Subject requests;
  • assist Customer in ensuring compliance with Articles 32 to 36 GDPR (security, breach notification, impact assessments, prior consultation), taking into account the nature of Processing and the information available;
  • at Customer's choice, delete or return Customer Personal Data on termination in accordance with Section 14;
  • make available information reasonably necessary to demonstrate compliance with Article 28 GDPR and allow for and contribute to audits in accordance with Section 13; and
  • inform Customer if, in Nevari's opinion, an instruction infringes Applicable Data Protection Law (provided Nevari is not obliged to perform a legal analysis on Customer's behalf).

5. Confidentiality

5.1 Nevari shall treat all Customer Personal Data as Customer's confidential information and shall not disclose it except (a) to Sub-processors as permitted, (b) to personnel on a need-to-know basis under confidentiality obligations, (c) as required to provide the Services, (d) as authorised by Customer, or (e) as required by law.

5.2 Nevari shall ensure that any person authorised to Process Customer Personal Data is informed of its confidential nature, is bound by enforceable confidentiality obligations surviving the end of their engagement, and has received appropriate data-protection and security training.

5.3 Where compelled by law to disclose Customer Personal Data, Nevari shall (unless legally prohibited) provide reasonable prior notice and cooperate with Customer's efforts to limit disclosure.

6. Security of Processing

6.1 Nevari shall implement and maintain appropriate technical and organisational measures to protect Customer Personal Data (the "Security Measures"), having regard to the state of the art, the costs of implementation, the nature, scope, context, and purposes of Processing, and the risks to Data Subjects.

6.2 A summary of the Security Measures is set out in Schedule 2. Nevari may update the Security Measures from time to time provided that such updates do not materially reduce the overall level of protection.

6.3 Customer is responsible for assessing whether the Security Measures meet its requirements and for implementing and maintaining its own security measures for its systems, devices, accounts, and personnel.

7. Data Subject Rights

7.1 Taking into account the nature of the Processing, Nevari shall provide Customer with reasonable assistance, insofar as possible by appropriate technical and organisational measures, to respond to Data Subject requests under Applicable Data Protection Law, including the rights of access, rectification, erasure, restriction, portability, objection, and rights relating to automated decision-making (Articles 15 to 22 GDPR).

7.2 If Nevari receives a Data Subject request relating to Customer Personal Data, it shall (a) where possible, promptly direct the Data Subject to Customer, and (b) promptly notify Customer and not respond itself except as legally required or as authorised by Customer.

7.3 Data Subject requests and requests for assistance under this Section 7 may be submitted to Nevari at [email protected].

7.4 Where assistance exceeds the standard functionality of the Services, Nevari may charge reasonable fees on a time-and-materials basis.

8. Personal Data Breach Notification

8.1 Nevari shall notify Customer without undue delay and, where feasible, no later than seventy-two (72) hours after becoming aware of a confirmed Security Incident affecting Customer Personal Data.

8.2 Such notification shall include, to the extent then known: (a) the nature of the Security Incident, including where possible the categories and approximate number of Data Subjects and records affected; (b) the likely consequences; (c) the measures taken or proposed to address it; and (d) the contact point for further information.

8.3 Where it is not possible to provide all information at once, it may be provided in phases without further undue delay.

8.4 Nevari's notification of, or response to, a Security Incident is not an acknowledgement of fault or liability.

8.5 Customer is solely responsible for complying with its own notification obligations (including to Supervisory Authorities and Data Subjects).

9. Sub-processors

9.1 General Authorisation. Customer grants Nevari general authorisation to engage Sub-processors to Process Customer Personal Data, subject to this Section 9.

9.2 Sub-processor Obligations. Nevari shall enter into a written agreement with each Sub-processor containing data-protection obligations no less protective of Customer Personal Data than those in this DPA, to the extent applicable.

9.3 Onward Sub-processors. Where a Sub-processor engages its own sub-processors to deliver the relevant service, such onward sub-processors are engaged under the Sub-processor's contract and are covered by this Section 9.

9.4 Nevari Liability. Nevari shall remain liable to Customer for the acts and omissions of its Sub-processors with respect to Customer Personal Data to the same extent Nevari would be liable if performing those services directly, except as otherwise provided in the Agreement.

9.5 Notice of Changes. Nevari shall provide Customer with at least thirty (30) days' prior notice before adding or replacing a Sub-processor that materially affects the Processing. Such notice may be given by email, by updating Nevari's published sub-processor list, by in-Service notification, or by such other means as Nevari may reasonably designate.

9.6 Right to Object. If Customer has a legitimate and reasonable objection on data-protection grounds to a new Sub-processor, Customer shall notify Nevari in writing within fifteen (15) days of receipt of notice. The Parties shall work in good faith to resolve the concern; if unresolved within thirty (30) days, Customer's sole and exclusive remedy is to terminate the affected portion of the Services without liability for unused prepaid fees.

9.7 Approved Sub-processors. As of the Effective Date, Nevari's approved Sub-processors are listed in Schedule 3. The current and authoritative list is published and maintained at https://gogins.ai/legal/sub-processors and is incorporated by reference; in the event of any discrepancy, the published list governs.

10. International Data Transfers

10.1 Customer acknowledges that, in order to provide the Services, Nevari and its Sub-processors may Process Customer Personal Data in countries outside the United Kingdom, the European Economic Area, Switzerland, or such other jurisdiction in which Customer or a Data Subject is located. Nevari's database, storage, and application compute run in the Frankfurt (EU) region; certain Sub-processors are US-incorporated companies whose administrative or support access may constitute a transfer (see Schedule 3).

10.2 Where any Processing constitutes a restricted transfer, the Parties agree that such transfer shall be subject to appropriate safeguards under Applicable Data Protection Law, which may include one or more of the following, as applicable:

  • an adequacy decision by the European Commission, the UK government, or other competent authority (including, where applicable and validly relied upon, the UK Extension to the EU–US Data Privacy Framework for transfers to certified recipients);
  • the EU SCCs (Module 2: Controller-to-Processor; or Module 3: Processor-to-Processor), incorporated by reference and deemed entered into with effect from the Effective Date, completed as follows: (i) Clause 7 (Docking Clause) applies; (ii) under Clause 9, Option 2 (general written authorisation) applies with a thirty (30) day period; (iii) under Clause 11, the optional language is not included; (iv) under Clause 17, the governing law is the law of Ireland; (v) under Clause 18, the competent courts are the courts of Ireland; (vi) Annex I and Annex II are completed with the information in Schedules 1 and 2 respectively; and (vii) Annex III is completed with the list of Sub-processors in Schedule 3;
  • the UK Addendum, executed by reference to the EU SCCs above, with the information in Schedules 1, 2, and 3 forming the relevant tables, the start date being the Effective Date, and neither Party entitled to terminate under Section 19 of the UK Addendum;
  • the IDTA, where required by the ICO or otherwise agreed, with the information in Schedules 1, 2, and 3 forming the relevant tables;
  • for transfers from Switzerland, the EU SCCs as supplemented by the Swiss FADP; or
  • any other transfer mechanism approved under Applicable Data Protection Law.

10.3 In the event of conflict between the EU SCCs (or UK Addendum or IDTA) and this DPA or the Agreement, the EU SCCs, UK Addendum, or IDTA (as applicable) shall prevail to the extent of the conflict.

10.4 Where a competent authority adopts new or replacement transfer mechanisms, the Parties agree that restricted transfers shall be subject to such updated mechanisms from the date they enter into force, and shall implement such additional documentation as is reasonably necessary.

10.5 Customer authorises Nevari and its Sub-processors to make restricted transfers necessary to provide the Services in accordance with this Section 10.

11. Data Protection Impact Assessments and Prior Consultation

11.1 Nevari shall, to the extent required by Applicable Data Protection Law and taking into account the nature of the Processing and the information available, provide reasonable assistance to Customer with data-protection impact assessments under Article 35 GDPR and prior consultations under Article 36 GDPR.

11.2 Such assistance may be provided through standard documentation or, where additional assistance is required, on a reasonable, mutually agreed basis at Nevari's then-current professional-services rates.

12. Data Exports and Portability

12.1 Upon Customer's written request, Nevari shall provide a machine-readable export of Customer Personal Data then held within the Services, including, where applicable, available audit-log records.

12.2 Export requests shall be submitted to [email protected] with the subject line "Data export request" and shall identify the affected Customer account and scope.

12.3 Nevari shall respond to validated export requests within thirty (30) days of receipt, unless a longer period is permitted by law or reasonably required due to volume or complexity.

12.4 Export requests exceeding the standard functionality of the Services may be subject to reasonable professional-services fees.

13. Audit Rights

13.1 Nevari shall make available, on reasonable written request, information reasonably necessary to demonstrate compliance with this DPA and Article 28 GDPR, and shall allow for and contribute to audits, subject to this Section 13.

13.2 Customer's audit rights shall: (a) be exercised no more than once in any twelve (12) month period, except where required by a Supervisory Authority or following a confirmed Security Incident materially affecting Customer Personal Data; (b) be conducted during normal business hours on not less than thirty (30) days' prior written notice; (c) not unreasonably interfere with Nevari's operations; (d) be subject to confidentiality obligations; (e) not require Nevari to disclose information that would breach confidentiality owed to others, compromise security, or violate law; and (f) be at Customer's cost, except where the audit reveals a material breach by Nevari.

13.3 Nevari may satisfy its audit obligations by making available (subject to confidentiality): (a) third-party certifications, attestations, or audit reports where and to the extent Nevari holds them; (b) security questionnaires (such as CAIQ or SIG); (c) penetration-testing summaries where available; (d) written responses to reasonable security and compliance questionnaires; and (e) such other information as Nevari may reasonably designate.

13.4 Any auditor mandated by Customer must not be a competitor of Nevari and must enter into a confidentiality agreement with Nevari before any audit.

14. Retention, Deletion, and Return of Customer Personal Data

14.1 Nevari shall Process Customer Personal Data only for the duration of the Agreement and any applicable retention period required by law. Nevari does not currently apply automatic time-based deletion; Customer Personal Data is retained for the life of Customer's account and removed on a validated erasure request or on account closure and offboarding.

14.2 Upon termination or expiry, or upon Customer's earlier written request, Nevari shall (at Customer's choice) delete or return Customer Personal Data, unless retention is required by law or permitted under this Section 14.

14.3 Nevari may retain Customer Personal Data, in whole or in part, where required for: (a) compliance with law; (b) audit, accounting, tax, or financial-reconciliation obligations; (c) establishment, exercise, or defence of legal claims; (d) security monitoring, fraud prevention, or risk management; (e) back-up systems until overwritten in the ordinary course; and (f) aggregated, anonymised, or de-identified data that no longer constitutes Personal Data.

14.4 Audit-trail records. Nevari maintains an immutable audit trail for the integrity of the compliance record the Services provide. On erasure, Nevari redacts the Data Subject's identifiers within the audit trail (replacing them with redacted values) while preserving the record of the actions taken; the redacted records no longer identify the Data Subject. This scrub-not-delete treatment is the sole exception to deletion.

14.5 Where Customer Personal Data is retained under Section 14.3 or 14.4, Nevari shall continue to protect it in accordance with the Security Measures and limit Processing to the retention purpose.

14.6 Deletion requests shall be submitted to [email protected] with the subject line "Data deletion request" and shall identify the affected Customer account and scope.

14.7 Nevari shall complete validated deletion requests within thirty (30) days of receipt, unless a longer period is reasonably required to give effect to deletion across all systems (including back-ups) or is otherwise permitted by law. Customer acknowledges one honest limit: the contents of files manually uploaded to the evidence library are stored opaquely and are not searchable by individual; erasure removes the record of a person as an uploader, but the file contents themselves are controlled by Customer's administrator.

15. Artificial Intelligence and Automated Processing

15.1 Gogins' authoritative governance function — the classification of Customer's AI agents against regulatory frameworks — is performed by a deterministic, rules-based engine that produces cited outputs. No large language model or generative-AI system is used in the authoritative classification path, and no automated decision produces legal or similarly significant effects concerning a Data Subject within the meaning of Article 22 GDPR.

15.2 Where the Services offer optional advisory or explanatory features that use large-language-model infrastructure provided by a third-party provider (which is not a current Sub-processor — as at the Effective Date no such feature is enabled and none Processes Customer Personal Data, so the provider does not appear on the Schedule 3 list), such features (a) are supplementary to, and never determinative of, the deterministic classification; and (b) as at the Effective Date are not enabled in the production Services and process no Customer Personal Data.

15.3 Nevari shall not use Customer Personal Data to train, fine-tune, or otherwise improve any foundation model, except (a) with Customer's express written consent, or (b) where such data has been irreversibly aggregated, anonymised, or de-identified. Where any advisory feature is enabled in the future, Nevari shall (i) add the AI provider to the Sub-processor list under Section 9 before enablement, and (ii) use commercially reasonable efforts to ensure that provider is contractually prohibited from training its models on data submitted through the Services and to route such Processing through zero-data-retention endpoints where offered.

15.4 Customer remains responsible for ensuring that its use of any advisory feature, if enabled, complies with Applicable Data Protection Law, and shall not submit Special Category or other regulated data into any such feature.

16. CCPA-Specific Provisions

16.1 To the extent Nevari Processes Personal Data subject to the CCPA, this Section 16 applies, and capitalised terms not otherwise defined have the meanings given in the CCPA.

16.2 The Parties acknowledge that Customer is a "business" and Nevari is a "service provider", and that Customer makes Personal Information available to Nevari solely for the limited and specified business purposes set out in the Agreement.

16.3 Nevari shall not: (a) sell or share Personal Information; (b) retain, use, or disclose Personal Information for any purpose other than the specified business purposes; (c) retain, use, or disclose Personal Information outside the direct business relationship; or (d) combine the Personal Information with Personal Information from other sources except as permitted under the CCPA.

16.4 Nevari shall notify Customer if it determines that it can no longer meet its CCPA obligations.

16.5 Nevari grants Customer the right, on reasonable notice, to take reasonable and appropriate steps to ensure Nevari uses the Personal Information in a manner consistent with Customer's CCPA obligations, and to stop and remediate unauthorised use.

17. Liability and Indemnification

17.1 Each Party's liability under this DPA shall be subject to the exclusions and limitations of liability set out in the Agreement.

17.2 Any obligation, claim, or liability arising under this DPA shall be deemed to arise under the Agreement for the purposes of any cap, exclusion, or limitation of liability.

17.3 Nothing in this DPA or the Agreement shall exclude or limit any liability that cannot be excluded or limited under Applicable Data Protection Law, or restrict any Data Subject's rights.

17.4 Where the Parties are jointly and severally liable to a Data Subject, liability shall, as between the Parties, be apportioned in accordance with each Party's respective responsibility.

18. Term and Termination

18.1 This DPA takes effect on the Effective Date and continues for the duration of the Agreement and for so long thereafter as Nevari Processes any Customer Personal Data.

18.2 Termination of this DPA shall not relieve either Party of obligations that, by their nature, survive termination, including those relating to confidentiality, indemnification, limitation of liability, governing law, and post-termination Processing.

19. General Provisions

19.1 Order of Precedence. In the event of conflict between this DPA and the Agreement with respect to the Processing of Customer Personal Data, this DPA prevails. In the event of conflict between this DPA and the EU SCCs, UK Addendum, or IDTA, those instruments prevail.

19.2 Variation. Nevari may amend this DPA (a) to reflect changes in Applicable Data Protection Law, (b) to give effect to Supervisory Authority guidance, (c) to incorporate updated transfer mechanisms, or (d) where changes do not materially diminish the protections afforded to Customer. Any other amendment requires written agreement.

19.3 Severability. If any provision is held invalid, the remaining provisions continue in full force, and the Parties shall negotiate in good faith to replace the invalid provision.

19.4 Assignment. Neither Party may assign this DPA without the other's consent, except to an Affiliate or successor in connection with a merger, acquisition, reorganisation, or sale of assets.

19.5 Notices. Notices under this DPA shall be given in accordance with the Agreement; data-protection-specific notices may also be sent by email to [email protected] (to Nevari) or to the primary administrative contact in Customer's account (to Customer).

19.6 Governing Law and Jurisdiction. This DPA is governed by the governing-law and jurisdiction provisions of the Agreement, save that, where the EU SCCs, UK Addendum, or IDTA apply, the governing-law and jurisdiction provisions of those instruments apply to the extent of any conflict.

19.7 Third-Party Rights. Save as expressly provided in this DPA or the EU SCCs, a person who is not a Party has no right under the Contracts (Rights of Third Parties) Act 1999 to enforce any term.

19.8 Counterparts and Acceptance by Conduct. This DPA may be executed by acceptance through conduct (as described above) or by signature, and in counterparts.

19.9 Entire Agreement. This DPA, together with the Agreement and its Schedules, constitutes the entire agreement between the Parties regarding the Processing of Customer Personal Data.

SCHEDULE 1 (DPA) — Details of Processing

A. List of Parties

Data exporter: the Customer entity identified in the Agreement, acting as Controller of Customer Personal Data.

Data importer: Nevari International Limited, a private limited company incorporated under the laws of England and Wales, acting as Processor of Customer Personal Data.

B. Description of Transfer

Subject matter of Processing: The provision of the Gogins.ai platform and related Services in accordance with the Agreement — authentication and workspace/team administration; inventory of Customer's AI agents and their deterministic, cited classification against regulatory frameworks; governance findings and evidence management; connected-systems scanning (structure only); usage metering; and auditor evidence exports.

Duration of Processing: For the duration of the Agreement and any additional period required to fulfil Nevari's obligations and rights, including applicable retention periods specified in Section 14.

Nature of Processing: Collection, recording, organisation, structuring, storage, hosting, retrieval, consultation, use, disclosure by transmission, restriction, erasure (including scrub-in-place of audit records), and other Processing reasonably necessary to provide, secure, support, and maintain the Services.

Categories of Data Subjects: Customer's team members and authorised users of the Gogins workspace (owners, admins, members, viewers); Customer's administrators; and Nevari operators who act on Customer's account in the course of providing and supporting the Services. For the avoidance of doubt, Gogins does not process Personal Data about Customer's downstream data subjects (the individuals whose data Customer's own AI agents may process); scanning reads workflow structure only.

Categories of Personal Data: Identity and account data (business email address, name where provided, sign-in identifier from the identity provider, role, and status); membership and seat records; operational-record attribution (the identity of the person who took an action — creating an API key, generating an auditor export, accepting a risk, requesting an escalation or reclassification, uploading evidence — recorded in the immutable audit trail); free-text content Customer chooses to enter (such as an agent owner label or a note); metadata and the manually-uploaded file objects in the evidence library (stored opaquely; contents not inspected); connector configuration metadata (with credentials encrypted at rest); usage-metering records (counts and hashed references, no message content); and sign-in diagnostic records in the hosting provider's logs (email address and sign-in identifier).

Special Categories of Personal Data: Customer shall not intentionally submit Special Category Data through the Services unless expressly authorised in writing by Nevari and subject to additional safeguards. Nevari does not require or solicit Special Category Data, children's data, or criminal-conviction data.

Frequency of transfer: Continuous, for the duration of the Agreement, in accordance with Customer's use of the Services.

Competent Supervisory Authority: Where the EU SCCs apply, the supervisory authority of the EU Member State determined under Clause 13 of the EU SCCs. Where the UK Addendum or IDTA applies, the Information Commissioner's Office of the United Kingdom.

SCHEDULE 2 (DPA) — Technical and Organisational Security Measures

Nevari implements and maintains technical and organisational measures appropriate to the risks presented by the Processing of Customer Personal Data, including, where applicable, the following:

1. Encryption and Pseudonymisation. Encryption of Customer Personal Data in transit using industry-standard TLS; encryption at rest where supported by the underlying infrastructure; encryption of connector credentials at rest; pseudonymisation/hashing where appropriate (including hashed references in usage metering and the one-way hash used for erasure suppression); secure key-management practices.

2. Access Controls. Role-based, least-privilege access limited on a need-to-know basis; multi-factor authentication enforced at sign-in (passwordless, via the identity provider); server-side-only access to stored data, with customer sessions restricted by row-level security to their own workspace's data; periodic access reviews and prompt revocation on termination or role change.

3. Network and Infrastructure Security. Use of reputable EU-region cloud infrastructure; logical segregation of production, staging, and development environments; network segmentation and edge protections; regular vulnerability scanning and patch management; hardened configurations.

4. Application Security. Secure software-development-lifecycle practices, including code review and dependency management; static analysis and dependency vulnerability scanning (with a build-gating dependency-advisory check); security testing as the Services mature; use of maintained frameworks and libraries.

5. Logging, Monitoring, and Incident Response. An immutable audit trail of security-relevant and administrative actions; monitoring for security and availability anomalies; a documented incident-response process with escalation and customer-notification procedures; post-incident review and remediation tracking.

6. Business Continuity and Resilience. Resilient managed cloud infrastructure; regular back-ups with restoration procedures; documented, periodically reviewed continuity and recovery procedures.

7. Personnel Security and Awareness. Binding confidentiality and data-protection obligations on all personnel with access to Customer Personal Data; data-protection and security awareness; clear acceptable-use and data-handling policies.

8. Vendor and Sub-processor Management. Risk-based due diligence before engagement; contractual obligations requiring substantially equivalent protections; periodic review of Sub-processor security posture.

9. Governance and Policies. Documented information-security policies; designated personnel responsible for data protection and security; periodic review of controls; records of Processing activities where required by Applicable Data Protection Law.

Nevari may update these Security Measures from time to time provided that any such update does not materially reduce the overall level of protection.

SCHEDULE 3 (DPA) — Approved Sub-processors

As of the Effective Date, Nevari engages the Sub-processors set out in the register linked below in connection with the provision of the Services. Customer hereby authorises Nevari's engagement of each Sub-processor listed there. The current and authoritative list — including each provider's role, location, and applicable transfer mechanism — is published and maintained at https://gogins.ai/legal/sub-processors, is incorporated by reference into this Schedule, and governs. This list may be updated from time to time in accordance with Section 9.

As at the Effective Date, the Sub-processors are: Supabase (database + file/evidence storage + authentication token verification; EU, Frankfurt), Vercel (application hosting; EU, Frankfurt), WorkOS (authentication — magic-link sign-in and invitations; EU region), and Inngest (background job orchestration; EU region; receives internal identifiers only, no Personal Data in event payloads).

Onward sub-processors: certain Sub-processors engage their own sub-processors to deliver the relevant service (for example, the hosting provider's underlying infrastructure vendor). Such onward sub-processors are engaged under, and covered by, the relevant Sub-processor's contract in accordance with Section 9.3.


Nevari International Limited · Company No. 16018299 · Nevari HQ, The Summit, Church Lane, Guiting Power, Cheltenham, GL54 5TX, England · [email protected]