Legal

Data Processing Agreement

Last updated: July 16, 2026
This DPA forms part of our Terms of Service and applies where GroupBox AI processes personal data on your behalf.

1. Roles of the parties

For personal data contained in your workspace, you are the data controller (or a processor acting for another controller) and GroupBox AI is the data processor. We process such data only on your documented instructions, which are given through your use of the service.

2. Scope and purpose of processing

Processing is limited to what is necessary to provide the GroupBox service: hosting your Project Memory, powering AI agent tasks with your project context, enabling team collaboration, and providing support. The duration of processing is the term of your agreement with us.

3. Confidentiality

All personnel authorized to process customer data are bound by confidentiality obligations and receive regular privacy and security training.

4. Sub-processors

You authorize us to engage sub-processors for hosting, AI model inference, and support tooling. We maintain a current list of sub-processors, ensure each is bound by data protection obligations no less protective than this DPA, and will notify you of additions with an opportunity to object. We remain liable for our sub-processors' performance.

5. Security measures

We implement appropriate technical and organizational measures, including encryption in transit and at rest, workspace isolation, role-based access controls, logging, and continuous backup. Details are described on our Security page.

6. Data subject requests

Taking into account the nature of processing, we assist you in responding to data subject requests (access, correction, deletion, portability). If a data subject contacts us directly, we will redirect them to you.

7. Personal data breach

We will notify you without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting your data, and will provide information reasonably required for you to meet your own notification obligations.

8. International transfers

Where personal data is transferred across borders, we rely on appropriate safeguards such as standard contractual clauses and process data only in jurisdictions with adequate protections.

9. Deletion and return

Upon termination of the service, you may export your Project Memory for 30 days, after which we delete all customer data from our systems, except where retention is required by law.

10. Audit

We make available information necessary to demonstrate compliance with this DPA, including our security documentation and third-party audit reports as they become available. Enterprise customers may request a security review once per year.

Questions?

If you have any questions about this document, contact us at sales@groupbox.co or write to us at GroupBox AI, Hyderabad, India.