Gatavo — Data Processing Agreement
Effective date: 20 September 2026 Last updated: 20 September 2026
This Data Processing Agreement ("DPA") forms part of the Gatavo Terms of Use between Gatavo, LLC, 131 Continental Dr, Suite 305, Newark, DE 19713, United States ("Gatavo", "Processor") and the customer accepting those Terms ("Customer", "Controller").
It applies where Gatavo processes personal data on the Customer's behalf in providing the Service, and satisfies Article 28 of Regulation (EU) 2016/679 ("GDPR").
No signature is required. By accepting the Terms of Use, the Customer accepts this DPA. If your organization requires a countersigned copy, write to info@gatavo.eu.
Where this DPA conflicts with the Terms of Use in relation to the processing of personal data, this DPA prevails.
1. Definitions
Terms defined in the GDPR — including "personal data", "processing", "controller", "processor", "sub-processor", "data subject", "personal data breach", and "supervisory authority" — have the same meaning here.
"Customer Personal Data" means personal data contained in Customer Data that Gatavo processes on the Customer's behalf under the Terms of Use.
2. Roles
The Customer is the controller of Customer Personal Data and Gatavo is the processor. The Customer determines the purposes and means of processing; Gatavo processes only as set out in this DPA.
Gatavo is an independent controller of the account, billing, security, and usage data described in its Privacy Policy. That processing falls outside this DPA.
3. The Customer's obligations
The Customer:
- warrants that it has a valid legal basis for the processing it instructs, and for entering personal data about its clients, prospects, and personnel into the Service;
- is responsible for providing any privacy notice its clients require, and for obtaining any consent required by law before communications are sent through the Service, including review requests and marketing;
- is responsible for the accuracy of Customer Personal Data and for the settings it configures;
- will not enter special categories of personal data (Article 9 GDPR) or criminal conviction data into the Service. The Service is not designed for such data and Gatavo's obligations do not extend to it.
4. Gatavo's obligations
Gatavo will:
4.1. Process only on instructions. Process Customer Personal Data only on the Customer's documented instructions, which comprise the Terms of Use, this DPA, the Customer's configuration of the Service, and any further written instruction the parties agree. Gatavo will inform the Customer if it believes an instruction infringes data protection law, and may suspend that instruction until resolved.
4.2. Comply with legally required processing. Where Gatavo is required by applicable law to process for another purpose, it will inform the Customer before doing so unless that law prohibits it on important grounds of public interest.
4.3. Ensure confidentiality. Ensure that personnel authorized to process Customer Personal Data are bound by confidentiality obligations and receive appropriate training, and limit access to those who need it.
4.4. Maintain security. Implement and maintain the technical and organizational measures described in Annex 2, appropriate to the risk under Article 32 GDPR.
4.5. Assist with data subject rights. Taking into account the nature of the processing, assist the Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling its obligation to respond to data subject requests under Chapter III GDPR. Where a data subject contacts Gatavo directly about Customer Personal Data, Gatavo will not respond substantively but will forward the request to the Customer without undue delay.
4.6. Assist with compliance. Assist the Customer in complying with its obligations under Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments, and prior consultation), taking into account the nature of processing and the information available to Gatavo.
4.7. Notify breaches. Notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records affected so far as known, the likely consequences, the measures taken or proposed, and a contact point. Gatavo will provide further information as it becomes available. Notifying a breach is not an admission of fault or liability.
4.8. Delete or return data. On termination, and at the Customer's choice, delete or return Customer Personal Data, and delete existing copies, within 90 days — unless retention is required by applicable law, in which case Gatavo will inform the Customer and keep only what is required, for as long as required. Customers should export any records they need before terminating.
4.9. Demonstrate compliance. Make available to the Customer the information reasonably necessary to demonstrate compliance with Article 28 GDPR, and allow for and contribute to audits as set out in Section 7.
5. Sub-processors
5.1. General authorization. The Customer gives Gatavo general written authorization to engage sub-processors. Those engaged at the effective date are listed in Annex 3, which is kept current.
5.2. Terms. Gatavo will impose on each sub-processor data protection obligations no less protective than those in this DPA, by written contract, and remains fully liable to the Customer for its sub-processors' performance.
5.3. Changes and objection. Gatavo will give at least 14 days' notice by email to the account's notification address before adding or replacing a sub-processor. The Customer may object on reasonable data protection grounds within that period. The parties will discuss the objection in good faith; if it cannot be resolved, the Customer may terminate the affected Service by written notice, with a pro-rata refund of prepaid fees for the unused period.
6. International transfers
Gatavo is established in the United States and engages sub-processors located there, as set out in Annex 3. Where Customer Personal Data is transferred out of the European Economic Area, the transfer is made under the Standard Contractual Clauses in Commission Implementing Decision (EU) 2021/914 (Module Two, controller to processor, and Module Three where onward transfers to sub-processors apply), which are incorporated into this DPA by reference and completed as follows:
- Clause 7 (docking): included.
- Clause 9 (sub-processors): Option 2, general written authorization, with the 30-day notice period in Section 5.3.
- Clause 11 (redress): the optional independent dispute resolution body is not selected.
- Clause 17 (governing law): the law of Ireland.
- Clause 18(b) (forum): the courts of Ireland.
- Annex I.A (parties): the Customer as data exporter and controller; Gatavo, LLC as data importer and processor, with the addresses in the Terms of Use.
- Annex I.B (description of transfer): as set out in Annex 1 below.
- Annex I.C (competent supervisory authority): the authority of the EEA member state in which the Customer is established, or where the Customer is not established in the EEA, the authority of the member state where its data subjects are located.
- Annex II (technical and organizational measures): as set out in Annex 2 below.
Where the UK GDPR applies, the UK International Data Transfer Addendum to the Standard Contractual Clauses applies. Where Swiss law applies, references are read as references to the Swiss FADP and the Swiss Federal Data Protection and Information Commissioner.
If Gatavo becomes certified under the EU–US Data Privacy Framework, transfers may instead rely on that adequacy decision.
7. Audits
Gatavo will make available documentation of its security measures, and will respond to reasonable written questions about its processing, including security questionnaires, within 30 days.
Where documentation and written responses are not sufficient to demonstrate compliance, the Customer may conduct an on-site or remote audit no more than once in any 12-month period, on at least 30 days' written notice, during business hours, without unreasonably disrupting Gatavo's operations, and subject to confidentiality. More frequent audits may be conducted where required by a supervisory authority or following a confirmed personal data breach. The Customer bears its own costs; Gatavo may charge reasonable fees for time spent beyond the first working day.
8. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Use, to the extent permitted by applicable law. Nothing in this DPA limits any data subject's rights under the GDPR or under the Standard Contractual Clauses.
9. Term and general
This DPA takes effect when the Customer accepts the Terms of Use and continues while Gatavo processes Customer Personal Data. Sections that by nature survive termination do so.
Gatavo may update this DPA where necessary to reflect changes in law, guidance from supervisory authorities, or changes to the Service, provided the update does not materially reduce protection for Customer Personal Data. Material changes are notified at least 30 days in advance.
Except where stated otherwise here, the Terms of Use govern, including their provisions on governing law — save that the Standard Contractual Clauses are governed as stated in Section 6.
Annex 1 — Description of the processing
Subject matter. Provision of the Gatavo field service management Service.
Duration. For the term of the Customer's subscription, plus the deletion period in Section 4.8.
Nature and purpose. Hosting, storage, structuring, retrieval, display, and deletion of Customer Personal Data; generation of business documents (quotes, invoices, work certificates, settlement statements); transmission of client-facing email on the Customer's behalf; delivery of webhook payloads to endpoints the Customer configures; production of analytics for the Customer; and technical support.
Categories of data subjects
- The Customer's clients, prospects, and their contact persons
- Individuals who submit the Customer's public lead capture form
- Individuals who submit the Customer's public review form
- The Customer's managers, agents, and other personnel
Categories of personal data
- Identity and contact data: name, company name, email address, phone number
- Location data: service addresses, property addresses, city
- Job and service data: descriptions, visit history, internal notes, photographs and file attachments (which may incidentally contain personal data), time entries
- Financial data: quotes, invoices, work certificates, payment status, amounts, expenses; and for income-split agents, legal name, activity or company code, VAT registration and code, IBAN, and bank name
- Feedback data: star ratings, written review comments
- Communications metadata: email delivery, bounce, and open events
Special categories. None. The Service is not intended for special category or criminal conviction data, and the Customer undertakes not to enter it (Section 3).
Frequency. Continuous, for as long as the Customer uses the Service.
Recipients. The sub-processors in Annex 3, and any endpoint the Customer configures.
Retention. As set out in Section 4.8 and the Privacy Policy.
Annex 2 — Technical and organizational measures
Encryption. TLS for all data in transit; encryption at rest for the database and object storage. Passwords stored using a strong one-way hashing algorithm.
Access control. Role-based permissions enforced server-side, not merely in the user interface. Strict logical separation of each Customer's data, enforced at the data access layer. Internal access limited to personnel who need it, under confidentiality obligations.
Application security. Invisible spam and bot protection on public forms; rate limiting; input validation; signed webhooks with one-time secret display, explicit secret rotation, and a configurable replay and idempotency window.
Availability and resilience. Managed hosting within the European Union with automated backups. Database and object storage are provided by established infrastructure providers with their own resilience measures.
Logging and monitoring. Application and access logging with defined retention; monitoring for anomalous activity.
Vulnerability management. Regular dependency updates and security patching; prompt remediation of identified vulnerabilities according to severity.
Data minimization and deletion. Retention periods as published in the Privacy Policy; deletion or anonymization within 90 days of termination.
Personnel. Confidentiality obligations for all personnel with access to Customer Personal Data.
Sub-processor management. Written data protection terms with every sub-processor, and a published, maintained sub-processor list.
Gatavo is a small company and does not currently hold ISO 27001 or SOC 2 certification. This Annex describes the measures actually in place. Measures may be updated over time provided the level of security is not reduced.
Annex 3 — Sub-processors
Current as of the effective date. Changes are notified in advance under Section 5.3.
| Sub-processor | Purpose | Processing location | Transfer mechanism |
|---|---|---|---|
| Railway Corp. | Application hosting and PostgreSQL database | European Union | Not applicable — EU |
| Cloudflare, Inc. (R2) | Object storage for photographs, receipts, and attachments | European Union (EU-jurisdiction bucket) | Standard Contractual Clauses |
| ActiveCampaign, LLC (Postmark) | Transactional and client-facing email delivery | United States | Standard Contractual Clauses |
| Stripe, Inc. / Stripe Payments Europe, Ltd. | Subscription billing and payment processing | United States, Ireland | Standard Contractual Clauses |
| Vercel, Inc. | Marketing website hosting and page analytics | United States and global edge | Standard Contractual Clauses |
| Google LLC | Optional sign-in authentication | United States | Standard Contractual Clauses / EU–US Data Privacy Framework |
Contact
Questions about this DPA: info@gatavo.eu
Gatavo, LLC, 131 Continental Dr, Suite 305, Newark, DE 19713, United States