Data Processing Agreement
Version 1.1 — 11 July 2026. Incorporated into the Terms of Service; by accepting the Terms you accept this DPA.
This Data Processing Agreement (“DPA”) forms part of the agreement for services (the “Agreement”) — comprising the Gigante Tech Terms of Service and the applicable Order or engagement confirmation (the “Order”) — between Gigante Tech Ltd, a company registered in England & Wales, company no. 17239192, whose registered office is at 57 Loxwood Avenue, Worthing, West Sussex, BN14 7RF (“Gigante Tech”, the processor) and the customer that purchases or uses the Services (“Customer”, the controller), each a “party” and together the “parties”.
No signature is required. This DPA is automatically incorporated into the Terms of Service: by accepting the Terms — including by purchasing, renewing or continuing to use the Services — the Customer accepts this DPA. A countersigned copy is available on request to info@gigantetech.com.
It records the parties’ obligations under Article 28 of the UK GDPR in respect of Personal Data that Gigante Tech Processes on the Customer’s behalf when providing the Services.
1. Definitions
1.1 Terms not defined here have the meanings given in the UK GDPR and the Data Protection Act 2018 (together, “Data Protection Law”).
1.2 “UK GDPR” means the retained EU General Data Protection Regulation as it forms part of the law of England and Wales, Scotland and Northern Ireland, as amended (including by the Data (Use and Access) Act 2025). “Personal Data”, “Processing”, “controller”, “processor”, “data subject”, “personal data breach” and “supervisory authority” have the meanings in the UK GDPR.
1.3 “Supervisory Authority” means the Information Commissioner’s Office, the Information Commission upon its assumption of the applicable functions, or any successor UK supervisory authority.
1.4 “Services” means the services Gigante Tech provides under the Agreement, comprising the modules that are enabled for the Customer per Annex 1 Part A.
1.5 “Sub-processor” means any third party engaged by Gigante Tech to Process Personal Data on the Customer’s behalf.
1.6 “Restricted Transfer” means a transfer of Personal Data outside the UK that would be prohibited by Data Protection Law in the absence of a lawful transfer mechanism.
2. Roles and scope
2.1 For the Personal Data described in Annex 1, the Customer is the controller and Gigante Tech is the processor. Where the Customer is itself a processor for a third- party controller, Gigante Tech acts as a sub-processor and the Customer warrants it has authority to appoint it on these terms.
2.2 Precedence. In the event of conflict concerning the Processing of Customer Personal Data, this DPA prevails over the Agreement. The Agreement continues to govern commercial matters, service levels and liability, subject to clause 11.1.
2.3 The Customer is responsible for the lawfulness of the Personal Data and of its instructions, for having a valid lawful basis, and — where the Services involve monitoring of the Customer’s workers or their devices — for meeting its own transparency and lawful-basis obligations to those workers before enabling such monitoring.
2.4 Independent controller carve-out. Notwithstanding clause 2.1, Gigante Tech acts as an independent controller, not as the Customer’s processor, where it Processes personal data for its own purposes: account administration and contract contacts, billing, invoicing and tax records, direct correspondence with the Customer, its own legal compliance, the security and fraud prevention of its own systems and services, and establishing or defending legal claims. Such processing is governed by Gigante Tech’s privacy notice and is outside this DPA.
3. Gigante Tech’s obligations (Article 28(3))
Gigante Tech shall:
(a) Documented instructions. Process the Personal Data only on the Customer’s documented instructions, unless required to do otherwise by law; in which case it will inform the Customer of that legal requirement before Processing, unless the law prohibits it. The Agreement, this DPA and the Customer’s ordinary use of the enabled Services constitute the Customer’s documented instructions. Gigante Tech will immediately inform the Customer if, in its opinion, an instruction infringes Data Protection Law.
(b) Confidentiality. Ensure that persons authorised to Process the Personal Data (including Gigante Tech’s director and any personnel) are subject to an appropriate duty of confidentiality.
(c) Security. Implement the technical and organisational measures in Annex 2 and otherwise as required by Article 32, appropriate to the risk.
(d) Sub-processors. Only engage Sub-processors in accordance with clause 5.
(e) Assistance with data-subject rights. Taking account of the nature of the Processing, assist the Customer by appropriate technical and organisational measures, so far as possible, to respond to requests from data subjects exercising their rights under Chapter III of the UK GDPR (access, rectification, erasure, restriction, portability, objection). Because Gigante Tech holds mainly derived signals and short-lived metadata (clause 6), such assistance is typically limited to locating, exporting and deleting the relevant derived records, which Gigante Tech will do within 10 business days of a written request.
(f) Assistance with the Customer’s obligations. Assist the Customer in ensuring compliance with its obligations under Articles 32–36 (security, personal data breach notification, data protection impact assessments and prior consultation), taking account of the nature of Processing and the information available to Gigante Tech.
(g) Deletion or return. At the Customer’s choice, delete or return all Customer Personal Data at the end of the provision of the Services, per clause 7.
(h) Audits. Make available to the Customer the information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates, subject to clause 9.
4. Customer instructions
4.1 The Customer instructs Gigante Tech to Process Personal Data as necessary to provide the Services enabled per Annex 1 Part A. Additional instructions must be agreed in writing (email suffices) and may be chargeable if they materially change the Services.
4.2 Authorised Contacts. Instructions are valid only from the contacts the Customer designates in writing (email suffices) or, until designated, from the Customer’s principal business contact for the engagement (“Authorised Contacts”). For high-impact instructions — deletion of all data, disclosure to a third party, or a change to the categories of data Processed — Gigante Tech may first verify the instruction through a second channel (e.g. a phone call to a known number).
4.3 Limits of “ordinary use”. The Customer’s ordinary use of the Services does not constitute an instruction to: access or copy message or file contents; obtain write access to Customer systems (except under the Managed IT Assistance module, clause 4.4); Process new categories of Personal Data; make a Restricted Transfer; or perform automated remediation on Customer systems. Each of those requires a specific written instruction from an Authorised Contact.
4.4 Managed IT Assistance. Where that module is enabled, Gigante Tech performs hands-on support and administration (for example Microsoft 365 administration, device setup, troubleshooting) on the Customer’s specific written or verbal request, under access the Customer grants. Content (for example a user’s mailbox or files) may be incidentally visible during such work; Gigante Tech will not copy or retain content, and will record the work performed in its ticket records.
5. Sub-processors
5.1 The Customer gives general authorisation for Gigante Tech to engage the Sub-processors listed in Annex 3 for the modules enabled for the Customer.
5.2 Gigante Tech will impose on each Sub-processor, by written contract, data-protection obligations no less protective than those in this DPA (in particular under Article 28), and remains fully liable to the Customer for its Sub-processors’ performance.
5.3 Gigante Tech will give the Customer at least 14 days’ prior notice (email suffices) of any intended addition or replacement of a Sub-processor, except that where an urgent replacement is necessary to protect the security or continuity of the Services, Gigante Tech may replace the Sub-processor immediately and notify the Customer without undue delay. The Customer may object within 14 days of notice on reasonable, documented data-protection grounds; if the parties cannot resolve the objection, the Customer may (i) require the affected optional module to be disabled, or (ii) terminate the affected Services without penalty for the unexpired term, with any refund handled per the Agreement.
5.4 Customer platforms. Where the Services involve monitoring or administering the Customer’s own third-party platforms (for example Microsoft 365, Google Workspace, Google Search Console or Postmaster Tools), those providers act as the Customer’s own processors or controllers under the Customer’s separate agreements with them; they are not Gigante Tech’s Sub-processors. Gigante Tech accesses them only under read-only or scoped delegated access granted by the Customer, which the Customer may revoke at any time.
6. Data minimisation architecture
6.1 Gigante Tech’s monitoring Services are designed so that it holds no Customer data of record. It Processes low-content, predominantly read-only metadata and stores derived signals (statuses, counts, classifications and alerts) plus short-lived operational caches, purged on the retention schedule in Annex 2. In particular:
- Message bodies are never read, analysed or retained. Where the enquiry-triage module is enabled, forwarded emails necessarily arrive whole; Gigante Tech’s systems extract header metadata only (sender, subject, date) and delete the source message at the next daily processing run, so a forwarded message resides on Gigante Tech systems for no more than approximately 24–48 hours and its body is never opened.
- Gigante Tech does not hold, and its instructions do not extend to, the contents of mailboxes or files, backup contents, passwords or credential-vault contents, or payment/transaction records.
- Alert notifications sent to Gigante Tech’s operational messaging channel contain counts and service identifiers only — never data subjects’ identities.
6.2 The parties acknowledge this reduces, but does not remove, Gigante Tech’s status as a processor, and this DPA applies to all Personal Data within Annex 1 regardless.
7. Deletion and return at end of Services
7.1 Within 30 days of the end of the Services the Customer may elect, in writing, return or deletion of Customer Personal Data. If no election is made, Gigante Tech will delete.
7.2 Return is provided as an export of the derived records held (JSON and/or CSV, plus any report PDFs). Deletion of live copies occurs within 30 days of the election (or of the deadline passing) and Gigante Tech will confirm in writing. OAuth grants and connector credentials are revoked/deleted promptly at termination, and the Customer should also revoke them from its own platform side.
7.3 Backup copies containing deleted records are put beyond ordinary use immediately and expire on the normal backup rotation, which is 30 days (Annex 2), after which they are unrecoverable. Gigante Tech may retain records it is legally required to keep, or that fall within clause 2.4 (e.g. invoices), for the required period only.
8. Personal data breach
8.1 Gigante Tech will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data — all such breaches, not only those likely to result in risk. Notification goes to the Customer’s Authorised Contacts.
8.2 The notification will include, so far as known at the time: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Information may be provided in phases as it becomes available, with continuing updates as material facts emerge.
8.3 Gigante Tech will provide the assistance reasonably available to it to support the Customer’s Article 33/34 obligations. Gigante Tech is not obliged to notify the Supervisory Authority or data subjects on the Customer’s behalf. Gigante Tech’s security contact for breach matters is info@gigantetech.com.
9. Audits
9.1 Gigante Tech operates an evidence-first audit model. On written request it will provide: the current DPA and security measures summary (Annex 2), its record of processing extract for the Customer’s Services, sub-processor list, and available third-party certification or scan evidence. Most audit needs should be met this way within 14 days of request.
9.2 Where remote evidence is demonstrably insufficient, the Customer (or a mandated auditor that is not a competitor of Gigante Tech and has signed reasonable confidentiality terms) may conduct an inspection: on at least 14 days’ notice, no more than once per 12 months, at a mutually agreed time, conducted so as not to compromise other customers’ security or data. The Customer bears its own costs and Gigante Tech’s reasonable costs of exceptional audits, unless the audit reveals material non-compliance by Gigante Tech.
9.3 The frequency and notice limits in clause 9.2 do not apply where an audit is required by Data Protection Law or the Supervisory Authority, or follows a personal data breach or credible evidence of material non-compliance.
10. International transfers
10.1 Gigante Tech shall not make a Restricted Transfer of Customer Personal Data except where the transfer is: (a) to a country or territory covered by applicable UK adequacy regulations; or (b) subject to appropriate safeguards under Article 46 UK GDPR (for example the UK International Data Transfer Agreement, or the EU Standard Contractual Clauses with the UK Addendum), together with any required transfer risk assessment; or (c) otherwise permitted by a lawful exception under Data Protection Law. A Customer instruction does not require or entitle Gigante Tech to make a transfer that would contravene Data Protection Law.
10.2 Current transfers, and their safeguards, are identified in Annex 3. The default posture of the Services is UK processing on Gigante Tech-controlled infrastructure.
11. Liability, term and general
11.1 Liability under this DPA is subject to the limitations and exclusions in the Agreement, save to the extent Data Protection Law prevents limitation. Nothing in this DPA limits a data subject’s rights or either party’s direct statutory liability to the Supervisory Authority or to data subjects.
11.2 This DPA takes effect when the Customer first accepts the Terms of Service (or, if earlier, when Gigante Tech first Processes Personal Data on the Customer’s behalf) and continues while Gigante Tech Processes Personal Data on the Customer’s behalf. Clauses that by their nature should survive (including 3(g), 7, 8 and 11) survive termination.
11.3 Updates. Gigante Tech may update this DPA from time to time, for example to reflect new modules, Sub-processors or changes in law. The current version, with its version date, is always published at gigantetech.com/dpa. Updates will not materially reduce the protections in this DPA. Material changes will be notified to the Customer by email at least 14 days before taking effect (Sub-processor changes follow clause 5.3); continued use of the Services after the effective date constitutes acceptance.
11.4 This DPA is governed by the law of England and Wales and the parties submit to the exclusive jurisdiction of its courts.
Annex 1 — Details of Processing
Part A — Modules and how they become enabled
The Services comprise the modules below. A module is enabled for a Customer when it is included in the Customer’s plan or Order, or when the Customer activates it by the step shown. Only enabled modules define the operative instructions, data categories, Sub-processors and retention for that Customer.
| # | Processing module | What it does | Enabled by |
|---|---|---|---|
| 1 | External website, domain & email-surface monitoring | Automated read-only checks of the Customer’s public websites, DNS, TLS, mail configuration, blacklists, lookalike domains and page health | Included in every Watch & Care and Business IT Care plan |
| 2 | Email authentication (DMARC) reporting | Receipt and analysis of DMARC aggregate (RUA) reports; policy coaching | The Customer (or Gigante Tech at its request) directing the domain’s DMARC rua record to Gigante Tech’s reporting mailbox |
| 3 | Search & reputation monitoring | Read-only Google Search Console / Postmaster data via the Customer’s own OAuth grant; search-ranking checks for agreed keywords | The Customer granting the read-only Google connection and/or agreeing keywords in the Order |
| 4 | Real-user web-performance telemetry (RUM) | A JavaScript beacon on the Customer’s website reporting Core Web Vitals from real visits | The Customer installing the beacon snippet on its site |
| 5 | Enquiry-metadata triage | Daily classification of enquiry email metadata (sender, subject, date); bodies never read; sources deleted after processing | The Customer setting up forwarding to its dedicated triage address |
| 6 | Managed IT Assistance (human-delivered) | Hands-on support and administration (e.g. Microsoft 365 administration, devices, email) performed by Gigante Tech personnel on request, under Customer-granted access (clause 4.4) | Included in Business IT Care plans; each piece of work is performed on the Customer’s request |
AI classification for module 5 is used only where stated in the Order or agreed with the Customer in writing (see Annex 3 — Anthropic); otherwise classification runs locally on Gigante Tech infrastructure and no data leaves it.
Automated read-only Microsoft 365 / Google Workspace configuration assurance (“Safety Watch”) is not currently offered; it will be added only by a published update to this DPA (including its data categories and any sub-processors, per clause 11.3) before first enablement.
Part B — Duration
For the term of the Agreement plus the retention periods in Annex 2.
Part C — Categories of data subjects (per enabled module)
- Modules 1–3, 6: the Customer’s staff, contractors and administrators; individuals whose personal data appears on the Customer’s public web pages or in email-routing metadata.
- Module 2: senders and recipients reflected in DMARC aggregate report metadata (source IPs and sending domains; no message content).
- Module 4: visitors to the Customer’s website.
- Module 5: individuals who email the Customer (prospects, customers, suppliers).
Part D — Types of Personal Data (per enabled module)
- Module 1: personal data incidentally present on the Customer’s public pages (e.g. published contact details); domain registration contact metadata; findings about publicly exposed email addresses or credentials on the Customer’s site (reported to the Customer as alerts).
- Module 2: email-authentication report data — sending server IP addresses, sending domains, message counts and pass/fail results from DMARC aggregate (RUA) reports. No message contents.
- Module 3: search-query and page-performance statistics associated with the Customer’s web properties; sender-reputation statistics; encrypted OAuth refresh tokens (security-sensitive authentication data). Agreed search keywords must not include the names of natural persons.
- Module 4: page path (query strings stripped), browser user-agent string, truncated/pseudonymised IP prefix (IPv4 /24, IPv6 /48) and performance timings per page view. Raw events are deleted after 24 hours; only aggregates persist in reports.
- Module 5: enquiry email header metadata — sender name and address, subject line, date — and derived lead classifications. Message bodies are not read and source messages are deleted after processing (clause 6.1).
- Module 6: business contact details of Customer staff; account and configuration metadata of the Customer’s platforms and devices as needed for the requested work; content incidentally visible during hands-on support (not copied or retained); ticket/work records describing the work done.
Part E — Special category / criminal-offence data
None is intentionally requested or required by the Services, and the Customer must not instruct Processing of special-category or criminal-offence data through the Services. Such data may nonetheless appear incidentally in user-supplied material Gigante Tech does not control (e.g. an enquiry subject line, a URL path, or a page on the Customer’s own website). The Services are configured to minimise this (bodies unread, sources deleted, query strings stripped, alerts de-identified); Gigante Tech will not use such data for any further purpose and will delete or restrict it when identified, unless the parties document a lawful instruction and appropriate safeguards.
Annex 2 — Technical and organisational security measures (Article 32)
Measures in effect as at the version date of this DPA. Planned improvements are tracked separately and do not form part of this DPA until implemented and added by update.
Access and privilege
- Access to Customer platforms uses read-only or narrowly scoped delegated permissions; no write-capable scopes are requested where a read-only scope exists (write access arises only under module 6, on request, under Customer-granted credentials).
- Systems are operated solely by Gigante Tech’s director. Administrative interfaces are bound to loopback/LAN/VPN and reached over authenticated SSH; MFA is enabled on third-party administrative accounts.
- Internal scanner services read tenant configuration through a restricted internal API that strips credentials; privileged datastore access is limited to two internal services (the OAuth broker and the Google data collector) on an isolated internal container network.
Data protection
- Derived signals only: monitoring stores statuses, counts and classifications; source content is not retained (clause 6.1).
- Encryption in transit: HTTPS/TLS for all web traffic and APIs. Gigante Tech’s mail domains publish MTA-STS (enforce) and DANE, requiring authenticated TLS for mail delivery to Gigante Tech.
- Encryption of secrets at rest: stored OAuth tokens are encrypted (libsodium secretbox); the decryption key is held in service configuration separate from the datastore. All reside on Gigante Tech-controlled UK infrastructure.
- Hosting: self-hosted on Gigante Tech-controlled hardware in the UK, plus a UK (London) cloud probe node for external vantage checks.
- Segregation: per-tenant configuration and per-tenant data directories; per-tenant mailboxes for enquiry-triage forwarding.
Resilience and monitoring
- Edge protection (WAF-style request filtering and automated IP banning) on public endpoints; geo-restriction of administrative surfaces.
- Change and failure alerting across the monitoring fleet; service and system activity logging; work performed for Customers recorded in ticket records.
- Warm-standby replication to a second host, with promotion and failback proven in a live incident.
- Backups: daily encrypted (AES-256) backups to a physically separate disk on Gigante Tech-controlled UK premises; 30-day rotation, after which expired backup data is unrecoverable.
Retention schedule (enforced in code)
| Data | Maximum retention |
|---|---|
| RUM raw events (module 4) | 24 hours |
| Forwarded enquiry source emails (module 5) | Deleted at next daily processing run (≤ ~48 hours) |
| Derived enquiry metadata & classifications (module 5) | 90 days |
| Raw DMARC aggregate reports — files and source emails (module 2) | 30 days |
| Derived DMARC summaries (module 2) | 12 months |
| Monitoring status caches (current/previous scan snapshots) | Rolling; superseded each scan cycle |
| Dark-web/breach caches (where a relevant module is enabled) | Derived identifiers/counts only; 30 days |
| OAuth refresh tokens (module 3) | Until module disabled or termination; then deleted promptly |
| Alerts, tickets and reports | Term of the engagement + 12 months |
| Backup copies of any of the above | Expire on 30-day backup rotation; beyond ordinary use pending expiry (clause 7.3) |
Annex 3 — Sub-processors and international transfers
Sub-processors engaged as at the version date of this DPA, per enabled module. Gigante Tech maintains the current list here and gives notice of changes per clause 5.3.
| Sub-processor | Engaged when | Purpose | Personal data involved | Location / safeguard |
|---|---|---|---|---|
| Oracle Corporation (Oracle Cloud Infrastructure) | Module 1 | Hosting of one external monitoring probe (uptime/availability vantage) | Customer website URLs/paths probed; no data-subject records stored | UK (London region) — no Restricted Transfer |
| Anthropic, PBC | Module 5 only where AI classification is agreed (Annex 1 Part A) | Classification of enquiry metadata via the Anthropic API under Anthropic’s Commercial Terms and Data Processing Addendum | Enquiry subject lines and sender domains (full addresses and bodies are not sent); API inputs/outputs not used for model training per Anthropic’s Commercial Terms | USA — Anthropic DPA incorporating UK-recognised safeguards (EU SCCs + UK Addendum) |
If AI classification is not agreed, module 5 runs entirely on Gigante Tech infrastructure and no Sub-processor is engaged for it.
Not Sub-processors (for clarity):
- Microsoft and Google — the Customer’s own platform providers, accessed under the Customer’s authority (clause 5.4).
- AI report narratives — weekly/monthly report narrative text is generated from derived, non-personal service-status data only (statuses and counts); no Customer Personal Data is involved in that generation.
- Alert messaging (WhatsApp) — Gigante Tech’s internal operational alerts contain counts and service identifiers only, never Customer Personal Data (clause 6.1).
- IP-geolocation data — a locally downloaded database is used on Gigante Tech infrastructure; no data is sent to the database vendor.
- Cloudflare Turnstile — used on Gigante Tech’s own website forms, where Gigante Tech is controller; not part of the Services.
- Search-ranking data vendor (DataForSEO) — receives only the Customer’s domain name and agreed non-personal search keywords (see Annex 1 Part D, module 3).
- Breach/dark-web monitoring vendors — not engaged for Customer domains at current service tiers; if offered in future, this Annex will be updated first per clause 5.3.
Gigante Tech Ltd — company no. 17239192 — info@gigantetech.com. Questions about this DPA are welcome at any time.