InnerWorks Docs

Data Processing Agreement

This page describes the data processing practices of InnerWorks for organizations that require formal data processing documentation.

Overview

When an organization deploys InnerWorks, Gigabox Research acts as a data processor on behalf of the organization (the data controller). This means:

  • Your organization determines the purposes for which user data is collected (deploying a professional development platform)
  • Gigabox Research processes that data according to the organization’s instructions and these documented practices

Data processing activities

ActivityData processedPurposeLegal basis
User onboardingEmail, profile (values, goals, situation)Account creation, content personalizationConsent (user accepts invitation)
Content generationProfile context, theme, engagement historyAI-personalized daily contentLegitimate interest (service delivery)
Engagement trackingPractice completion, reflection textProgress tracking, platform analyticsConsent (user engages with practices)
Aggregate analyticsAnonymized engagement metricsOrganizational reportingLegitimate interest (organizational development)
NotificationsPush token, email, preferencesDaily reminders, announcementsConsent (configurable by user)

Sub-processors

InnerWorks uses the following sub-processors:

Sub-processorPurposeData sharedLocation
Google Cloud PlatformInfrastructure hosting (compute, database, storage)All service dataUnited States (us-central1)
AnthropicAI content generationProfile context (values, goals, situation, theme) — no directly identifying informationUnited States
ClerkAuthentication and identity managementEmail, authentication credentialsUnited States
ResendTransactional email deliveryEmail addresses, email contentUnited States

Data location

All InnerWorks data is processed and stored in the United States:

  • Database: Google Cloud SQL, us-central1 (Iowa)
  • Application server: Google Compute Engine, us-central1
  • Backups: Google Cloud Storage, us-central1

Security measures

Technical and organizational measures in place:

  • Encryption in transit — All data transmitted via TLS/HTTPS
  • Access control — Database credentials restricted to application backend; no shared access
  • Tenant isolation — Each organization’s data is logically isolated within the multi-tenant architecture
  • Authentication — Managed by Clerk, a dedicated identity platform with industry-standard security
  • Backup and recovery — Daily automated backups with 14-day retention
  • Monitoring — Continuous uptime monitoring with alerting

Data retention and deletion

  • Active service — Data retained for the duration of the service agreement
  • User deletion requests — Individual user data deleted within 30 days
  • Service termination — All organization data deleted within 30 days of written confirmation
  • Backups — Subject to the same deletion timelines; backups older than 14 days are automatically purged

Breach notification

In the event of a personal data breach that is likely to result in a risk to user rights and freedoms:

  • We will notify the affected organization without undue delay, and no later than 72 hours after becoming aware of the breach
  • Notification will include: nature of the breach, categories and approximate number of individuals affected, likely consequences, and measures taken to address the breach

Requesting a formal DPA

Organizations requiring a signed Data Processing Agreement can contact us:

Email: info@gigabox.ai

We will provide a formal DPA document for review and execution. Standard DPA terms align with the practices described on this page.