Data Processing Agreement
This page describes the data processing practices of InnerWorks for organizations that require formal data processing documentation.
Overview
When an organization deploys InnerWorks, Gigabox Research acts as a data processor on behalf of the organization (the data controller). This means:
- Your organization determines the purposes for which user data is collected (deploying a professional development platform)
- Gigabox Research processes that data according to the organization’s instructions and these documented practices
Data processing activities
| Activity | Data processed | Purpose | Legal basis |
|---|---|---|---|
| User onboarding | Email, profile (values, goals, situation) | Account creation, content personalization | Consent (user accepts invitation) |
| Content generation | Profile context, theme, engagement history | AI-personalized daily content | Legitimate interest (service delivery) |
| Engagement tracking | Practice completion, reflection text | Progress tracking, platform analytics | Consent (user engages with practices) |
| Aggregate analytics | Anonymized engagement metrics | Organizational reporting | Legitimate interest (organizational development) |
| Notifications | Push token, email, preferences | Daily reminders, announcements | Consent (configurable by user) |
Sub-processors
InnerWorks uses the following sub-processors:
| Sub-processor | Purpose | Data shared | Location |
|---|---|---|---|
| Google Cloud Platform | Infrastructure hosting (compute, database, storage) | All service data | United States (us-central1) |
| Anthropic | AI content generation | Profile context (values, goals, situation, theme) — no directly identifying information | United States |
| Clerk | Authentication and identity management | Email, authentication credentials | United States |
| Resend | Transactional email delivery | Email addresses, email content | United States |
Data location
All InnerWorks data is processed and stored in the United States:
- Database: Google Cloud SQL, us-central1 (Iowa)
- Application server: Google Compute Engine, us-central1
- Backups: Google Cloud Storage, us-central1
Security measures
Technical and organizational measures in place:
- Encryption in transit — All data transmitted via TLS/HTTPS
- Access control — Database credentials restricted to application backend; no shared access
- Tenant isolation — Each organization’s data is logically isolated within the multi-tenant architecture
- Authentication — Managed by Clerk, a dedicated identity platform with industry-standard security
- Backup and recovery — Daily automated backups with 14-day retention
- Monitoring — Continuous uptime monitoring with alerting
Data retention and deletion
- Active service — Data retained for the duration of the service agreement
- User deletion requests — Individual user data deleted within 30 days
- Service termination — All organization data deleted within 30 days of written confirmation
- Backups — Subject to the same deletion timelines; backups older than 14 days are automatically purged
Breach notification
In the event of a personal data breach that is likely to result in a risk to user rights and freedoms:
- We will notify the affected organization without undue delay, and no later than 72 hours after becoming aware of the breach
- Notification will include: nature of the breach, categories and approximate number of individuals affected, likely consequences, and measures taken to address the breach
Requesting a formal DPA
Organizations requiring a signed Data Processing Agreement can contact us:
Email: info@gigabox.ai
We will provide a formal DPA document for review and execution. Standard DPA terms align with the practices described on this page.