Data Processing Agreement
Last updated: August 31, 2026
This Data Processing Agreement (“DPA”) forms part of the Agreement between the Customer and Sheetgo. The Sheetgo products and services provided under the Agreement are the “Service.” This DPA applies when Sheetgo processes Customer Personal Data on the Customer’s behalf in providing the Service.
1. Parties and contracting entity
This DPA is between the Customer and the Sheetgo entity with which the Customer contracts: Sheetgo Europe S.L., a company incorporated in Spain, or Sheetgo, Inc., a Delaware corporation in the United States. The contracting entity is identified in the self checkout, on an invoice issued by Sheetgo, or in an Order Form. If none of those identifies the contracting entity, including for a free plan or a marketplace purchase invoiced by the marketplace, the contracting entity is Sheetgo Europe S.L. unless the self checkout or an Order Form states otherwise. The applicable contracting entity is referred to in this DPA as “Sheetgo.”
2. Definitions
“Agreement” means the agreement governing the Customer’s use of the Service, consisting of Sheetgo’s Terms of Service published at sheetgo.com/legal/terms, this DPA, any applicable Order Form, and the policies or notices that the Terms of Service incorporate.
“Customer” means the organization or business that accepts the Agreement or signs an Order Form. The term does not determine the Customer’s role under Data Protection Law. The Customer may act as a controller or as a processor on behalf of a third-party controller.
“Customer Personal Data” means all personal data that Sheetgo processes on the Customer’s behalf in providing the Service. It includes personal data in the data, files, messages, records, and other content that the Customer or its users connect to, submit to, or process through the Service, and in application programming interface and webhook payloads, email messages and attachments processed by configured workflows, file names and identifiers, configuration and connection data, logs, and artificial intelligence inputs and outputs. It excludes personal data that Sheetgo processes as a controller for its own purposes, including account administration, billing, support administration and communications, and marketing, as described in Sheetgo’s Privacy Policy published at sheetgo.com/legal/privacy.
“Data Protection Law” means all data protection and privacy laws that apply to the processing of Customer Personal Data under this DPA, including Regulation (EU) 2016/679 (“GDPR”), the GDPR as incorporated into the laws of the United Kingdom and amended from time to time (“UK GDPR”), and applicable United States state privacy laws.
“EU SCCs” means the standard contractual clauses for transfers of personal data to third countries adopted by the European Commission in Commission Implementing Decision (EU) 2021/914 of June 4, 2021.
“Order Form” means an order, quote, or statement of work signed with the Sheetgo sales team.
“Subprocessor” means a processor engaged by Sheetgo to process Customer Personal Data on the Customer’s behalf.
“UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the United Kingdom Information Commissioner’s Office, version B1.0 in force from March 21, 2022, as revised in accordance with its terms.
The terms “controller,” “processor,” “personal data,” “processing,” “data subject,” “personal data breach,” and “supervisory authority” have the meanings given by the GDPR or, where another Data Protection Law applies, the corresponding meanings under that law.
3. Roles and scope of processing
When the Customer determines the purposes and means of processing Customer Personal Data, the Customer is the controller and Sheetgo is its processor. When the Customer processes Customer Personal Data on behalf of a third-party controller, the Customer is a processor and Sheetgo is its Subprocessor. In the latter case, the Customer warrants that it has the authority and documented instructions necessary from the third-party controller to engage Sheetgo and instruct the processing described in this DPA.
Annex 1 describes the subject matter and duration of the processing, its nature and purpose, the types of personal data, and the categories of data subjects. Each party will comply with the obligations that apply directly to it under Data Protection Law.
For the optional Service feature that facilitates governed data exchange and may, where agreed for a deployment, include a dataset hosted by Sheetgo on the Customer’s behalf (a “Data Space”), this DPA applies only to the extent Sheetgo processes personal data on the Customer’s behalf, including when it facilitates technical data exchange or hosts a dataset for the deployment. It does not apply to participation administration, governance metadata, security monitoring, or other Data Space activities for which Sheetgo acts as a controller, as described in the Privacy Policy.
4. Processing on documented instructions
Sheetgo will process Customer Personal Data only on the Customer’s documented instructions, including with regard to international transfers. The Agreement, this DPA, and the Customer’s configuration and use of the Service constitute the Customer’s documented instructions.
If applicable law requires Sheetgo to process Customer Personal Data other than on the Customer’s documented instructions, Sheetgo will inform the Customer of that legal requirement before processing unless the law prohibits that information on important grounds of public interest.
Sheetgo will immediately inform the Customer if, in Sheetgo’s opinion, an instruction infringes Data Protection Law. Sheetgo may suspend the affected processing while the parties address the instruction.
Sheetgo does not sell Customer Personal Data. Neither Sheetgo nor its artificial intelligence providers use Customer Personal Data to train general artificial intelligence models.
5. Customer obligations and rights
The Customer is responsible for the lawfulness of its instructions and its use of the Service, including having an applicable legal basis for the processing and providing any notices required to data subjects. The Customer is also responsible for the accuracy and relevance of the Customer Personal Data it chooses to process through the Service and for obtaining all permissions and authorizations necessary for Sheetgo to process it.
When the Customer acts for a third-party controller, the Customer is responsible for ensuring that its instructions to Sheetgo are authorized by and consistent with the instructions of that controller and with the agreement between them.
Subject to the Agreement and Data Protection Law, the Customer has the right to instruct Sheetgo’s processing, receive the assistance described in this DPA, exercise the audit rights in section 13, and choose return or deletion of Customer Personal Data at termination as described in section 12.
6. Confidentiality and security
Sheetgo will ensure that each person it authorizes to process Customer Personal Data is subject to a contractual or statutory duty of confidentiality and receives appropriate data protection and security training.
Taking into account the state of the art, implementation costs, the nature, scope, context, and purposes of the processing, and the risks to data subjects, Sheetgo will implement and maintain appropriate technical and organizational measures designed to provide a level of security appropriate to the risk. Annex 2 describes those measures.
7. Subprocessors
The Customer gives Sheetgo general authorization to engage Subprocessors. The current list of Subprocessors, including their purposes, processing locations, and applicable transfer safeguards, is maintained on the Subprocessors page published at sheetgo.com/legal/subprocessors.
Sheetgo will publish any intended addition or replacement of a Subprocessor on the Subprocessors page at sheetgo.com/legal/subprocessors before that Subprocessor begins processing Customer Personal Data. Publication on that page constitutes notice of the intended change. The Customer may object by contacting [email protected] within 30 days after publication, but only on reasonable data-protection grounds.
The parties will work in good faith to resolve a timely objection. If they cannot resolve it, the Customer may terminate the affected part of the Service by giving written notice to Sheetgo.
Sheetgo will enter into a written contract with each Subprocessor that imposes data protection obligations equivalent to those imposed on Sheetgo by this DPA, taking into account the nature of the services the Subprocessor provides. Sheetgo remains responsible to the Customer for its Subprocessors’ performance of those obligations.
Sheetgo group companies may act as Subprocessors under written intra-group agreements that impose equivalent data protection obligations. In particular, Sheetgo Europe S.L. and its group operate the platform when Sheetgo, Inc. is the contracting entity. Group companies acting as Subprocessors are identified on the Subprocessors page.
The Subprocessors page distinguishes Subprocessors that process Customer Personal Data from service providers that process personal data for which Sheetgo acts as a controller.
8. Assistance with data subject rights
Taking into account the nature of the processing, Sheetgo will assist the Customer through appropriate technical and organizational measures, insofar as possible, to respond to requests by data subjects to exercise their rights under Data Protection Law, including rights of access, correction, deletion, restriction, portability, and objection.
If Sheetgo receives a request from a data subject concerning Customer Personal Data, Sheetgo will, where permitted by law, direct the data subject to the Customer and will not respond on the Customer’s behalf unless the Customer instructs it to do so or applicable law requires it.
9. Assistance with compliance
Taking into account the nature of the processing and the information available to Sheetgo, Sheetgo will reasonably assist the Customer with compliance obligations concerning security of processing, personal data breach notification and communication, data protection impact assessments, and prior consultation with supervisory authorities, including obligations under Articles 32 through 36 of the GDPR where applicable.
10. Personal data breach notification
Sheetgo will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. The notice will include the information reasonably available to Sheetgo, including the nature of the breach, the categories of affected data and data subjects, likely consequences, measures taken or proposed, and a contact for further information. Sheetgo may provide information in phases as it becomes available.
Sheetgo will reasonably assist the Customer in investigating the personal data breach and meeting the Customer’s notification and communication obligations under Data Protection Law.
11. International transfers
Sheetgo’s processing infrastructure runs in the United States with its cloud infrastructure provider identified on the Subprocessors page. Identification data, including names, email addresses, file names and identifiers, configuration data, and logs, is stored there. Customer Personal Data in file content is processed in transit when workflows and artificial intelligence features run but is not stored in that infrastructure, except where the Customer has agreed to a Sheetgo-hosted Data Space dataset or another storage feature in an Order Form. Customer files otherwise remain in the storage environment chosen by the Customer’s organization.
The United States is the default processing region. For deployments purchased under an Order Form as an Enterprise offering (each an “Enterprise deployment”) and deployments of a “Virtual Employee,” meaning an artificial intelligence agent that works through the Customer’s team chat tools and runs workflows on the Sheetgo platform, the parties may agree in the Order Form to another available processing region solely for the AI processing environment, any Data Space dataset Sheetgo hosts for the deployment, and the AI model served through that environment. For a deployment purchased through a cloud marketplace, which has no Order Form, the parties may agree to another available processing region for those three items in a separate written agreement. The core platform infrastructure and the identification data stored with it remain in the United States and cannot be regionalized. If the applicable Order Form or separate written agreement does not specify another region, the United States remains the processing region.
For transfers to the cloud infrastructure provider in the United States, Sheetgo relies, where applicable, on the provider’s certification under the EU-U.S. Data Privacy Framework and on the EU SCCs incorporated into the provider’s data processing terms. Transfers to other Subprocessors are subject to the safeguards identified on the Subprocessors page and the written contracts required by section 7.
For a transfer of Customer Personal Data from the European Economic Area (EEA) to Sheetgo, Inc., the Customer and Sheetgo, Inc. enter into and incorporate the EU SCCs by reference. Module Two applies when the Customer is a controller, and Module Three applies when the Customer is a processor. For purposes of the EU SCCs, Clause 7 applies; in Clause 9(a), Option 2 applies and the notice period is as stated in section 7 of this DPA; the optional language in Clause 11(a) does not apply; in Clause 17, Option 1 applies and the governing law is the law of Spain; and the courts of Spain have jurisdiction under Clause 18(b). Annex 1 to this DPA serves as Annex I to the EU SCCs, Annex 2 serves as Annex II, and, for Module Three, Annex 3 serves as Annex III.
For a restricted transfer of Customer Personal Data from the United Kingdom to Sheetgo, Inc., the UK Addendum is incorporated into this DPA and applies to the applicable Module Two or Module Three EU SCCs described above. For purposes of the UK Addendum, Table 1 is completed with the party and contact information in Annex 1; Table 2 is completed with the selected EU SCC module and clause elections stated in the preceding paragraph; Table 3 is completed with Annexes 1, 2, and 3 of this DPA; and Table 4 permits both the data exporter and the data importer to end the UK Addendum in accordance with section 19 of the UK Addendum.
If the EU SCCs or UK Addendum incorporated into this DPA conflict with another provision of this DPA, the EU SCCs or UK Addendum prevail for the transfer to which they apply. The parties will cooperate in good faith to implement another lawful transfer mechanism or supplementary measure if Data Protection Law requires one.
12. Return and deletion
At termination of the Service, the Customer may choose return or deletion of Customer Personal Data. If the Customer chooses return, it may request an export of Customer Personal Data that Sheetgo holds within 30 days after termination. Sheetgo will provide the export in a format reasonably available through the Service or otherwise reasonably selected by Sheetgo. If the Customer requests deletion, including by deleting its account, Sheetgo will begin deletion without waiting for the export period.
If the Customer requests an export, Sheetgo will delete its remaining copies after making the export available. Whether or not the Customer requests return or deletion, Sheetgo will delete the Customer Personal Data it holds after the 30-day period, except that it may retain data for the time reasonably necessary to complete a timely export request or where applicable law requires retention. Customer Personal Data retained by law will be isolated from further processing except as the law requires and deleted when the retention requirement ends.
Data in routine backups will be put beyond use when the corresponding production data is deleted and will be purged through Sheetgo’s normal backup cycle no later than 90 days after production deletion. If a backup is restored during that period, Sheetgo will apply the deletion again before returning the restored data to ordinary use.
Because customer files generally remain in the Customer’s chosen storage environment, return and deletion primarily concern data held by Sheetgo, such as stored metadata, configuration data, connection credentials and tokens, logs, and any Data Space dataset hosted by Sheetgo for the deployment. Sheetgo will confirm deletion in writing on the Customer’s request.
13. Audits and compliance information
Sheetgo will make available the information reasonably necessary to demonstrate compliance with this DPA, including relevant independent audit reports and certifications, such as SOC 2 Type II, through the Trust Center at https://trust.sheetgo.com/ and subject to its reasonable access, security, and confidentiality procedures.
The parties will ordinarily use that information first. If it is insufficient to demonstrate compliance, if a personal data breach affecting Customer Personal Data has occurred, or if a supervisory authority requires an audit, the Customer or an independent auditor it mandates may conduct an audit, including an inspection, of Sheetgo’s relevant processing and controls.
An audit must be conducted on reasonable advance notice, during normal business hours, under appropriate confidentiality obligations, and in a manner that minimizes disruption and does not expose another customer’s data. Its scope must be limited to processing and controls relevant to this DPA. Unless a personal data breach affecting Customer Personal Data has occurred and justifies additional audits, a supervisory authority requires additional audits, or another statutory audit right justifies additional audits, the Customer may conduct no more than one audit in any 12-month period.
Sheetgo will allow for and reasonably contribute to an audit that meets these conditions. Nothing in this section limits the Customer’s statutory rights under Article 28(3)(h) of the GDPR.
14. United States state privacy laws
To the extent applicable United States state privacy laws apply to Customer Personal Data, Sheetgo acts as a service provider or processor. Sheetgo will not sell or share Customer Personal Data and will retain, use, and disclose it only for the specific business purposes of providing the Service as described in this DPA and Annex 1. Sheetgo will provide the same level of privacy protection required of the Customer by those laws and will notify the Customer if Sheetgo determines that it can no longer meet its obligations. The Customer may take reasonable and appropriate steps through section 13 to help ensure that Sheetgo’s processing is consistent with those obligations and to stop and remediate unauthorized use.
15. Liability
Each party’s liability arising out of or relating to this DPA is subject to the limitations and exclusions of liability in the Agreement. This DPA does not relieve either party of any obligation or liability imposed directly on it by Data Protection Law.
16. Term and acceptance
This DPA takes effect when the Customer accepts the Agreement by agreeing to the Terms of Service, including by creating an account, using the Service, or completing a purchase in the self checkout, or when the Customer signs an Order Form that incorporates this DPA. It remains in effect for as long as Sheetgo processes Customer Personal Data, regardless of the termination or expiration of other parts of the Agreement.
Acceptance of the Agreement or signature of an incorporating Order Form constitutes execution of this DPA, including the EU SCCs and UK Addendum where they apply. At the Customer’s request, Sheetgo will countersign an execution copy of this DPA.
17. Notices and contact
Sheetgo will send a personal data breach notice under section 10 to the Customer’s administrative account email address, the contact identified in the Order Form, or another privacy contact the Customer has designated in writing. The Customer is responsible for keeping that contact information current.
The Customer may send data protection notices, Subprocessor objections, and requests under this DPA to [email protected]. Notice of an intended Subprocessor change is given by publication as stated in section 7.
18. Governing law and precedence
This DPA is governed by the law that governs the Agreement, including any governing-law choice made in an Order Form as permitted by the Terms of Service, except where Data Protection Law, the EU SCCs, or the UK Addendum requires otherwise.
If this DPA conflicts with another part of the Agreement on a data protection matter, this DPA prevails for that matter. Section 11 governs any conflict involving the incorporated EU SCCs or UK Addendum.
Annex 1: details of processing
A. Parties to transfers under the EU SCCs and UK Addendum
- Data exporter: the Customer. Its name, address, and contact details are those stated in the Agreement, the applicable Order Form, or its Sheetgo account. Its activities relevant to the transfer are its use of the Service as described in this Annex. It is a controller for Module Two and a processor for Module Three. Its acceptance or signature, and the applicable date, are determined under section 16.
- Data importer: Sheetgo, Inc., 131 Continental Drive, Suite 305, Newark, Delaware 19713, United States; privacy contact: [email protected]. Its activities relevant to the transfer are providing the Service and performing the operations described in this Annex. It is a processor for Module Two and a Subprocessor for Module Three. Its acceptance or signature, and the applicable date, are determined under section 16.
- Competent supervisory authority: the authority determined under Clause 13 of the EU SCCs based on the Customer’s establishment, appointed representative, or the location of affected data subjects, as applicable.
B. Description of processing and transfer
- Subject matter: providing the Service, including workflow automation, data transfer and integration, artificial intelligence-assisted features, Virtual Employee deployments, Data Space functionality where included, and support.
- Nature and operations: reading and writing the files, spreadsheets, email messages, and attachments defined by a configured workflow; receiving and sending application programming interface and webhook payloads; transiently processing data during workflow runs and artificial intelligence features; generating and returning artificial intelligence outputs; storing identification data, file names and identifiers, configuration and connection data, credentials and tokens, and logs; hosting a Data Space dataset where the deployment includes one; and accessing Customer Personal Data for support at the Customer’s request.
- Purposes: operating, securing, maintaining, and supporting the Service; executing the workflows and integrations the Customer configures; providing requested artificial intelligence functionality; and providing any hosted Data Space functionality included in the deployment.
- Duration and retention: processing continues for the duration of the Agreement and until Customer Personal Data is returned or deleted in accordance with section 12. Legally required retention may continue for the period required by law.
- Frequency: continuous or intermittent according to the Customer’s configuration and use of the Service, including scheduled and event-triggered workflow runs.
- Types of personal data: as determined by the Customer, including names, email addresses, contact details, job titles, organization and account identifiers, user and connection identifiers, authentication and authorization data, file names and identifiers, workflow configurations, logs and usage data, and personal data contained in files, spreadsheets, datasets, email messages and attachments, application programming interface and webhook payloads, and artificial intelligence inputs and outputs. Depending on the Customer’s use, Customer Personal Data may also include business, financial, transactional, human-resources, or communications data.
- Categories of data subjects: as determined by the Customer, including the Customer’s users, personnel, contractors, applicants, customers, prospective customers, contacts, suppliers, business partners, and any other individuals whose personal data the Customer chooses to process through the Service.
- Special categories and criminal-conviction data: the Customer must not submit personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data used for unique identification, health data, data concerning a person’s sex life or sexual orientation, or personal data relating to criminal convictions and offenses unless the Customer and Sheetgo expressly agree in writing to that processing and to appropriate safeguards before it begins.
- Transfer frequency and destination: transfers may occur on a continuous or intermittent basis according to the Customer’s use of the Service. The default destination for transfers described in section 11 is the United States, unless an Order Form establishes another processing region.
- Further transfers: the subject matter, nature, and duration of processing by each Subprocessor are limited to what is necessary for that Subprocessor’s purpose as identified on the Subprocessors page. The frequency depends on the Customer’s configuration and use of the relevant Service feature.
Annex 2: technical and organizational measures
Sheetgo will maintain the following technical and organizational measures, as appropriate to the processing and risk:
- Access management and role-based permissions: Sheetgo uses unique user identities, least-privilege access, role-based permissions, strong authentication for privileged access, periodic access reviews, and prompt revocation or adjustment of access when roles change or access is no longer required.
- Encryption: Sheetgo encrypts Customer Personal Data in transit over public networks and at rest in systems managed by Sheetgo or its infrastructure providers using current, industry-accepted protocols and cryptographic methods. Encryption keys and secrets are subject to access controls and lifecycle management.
- Logging and traceability: Sheetgo logs relevant administrative, security, and system activity; restricts access to logs; protects them against unauthorized alteration; and uses them to support monitoring, investigation, and accountability.
- Segregation of environments: Sheetgo separates production from development and testing environments through technical and organizational controls and uses logical controls to segregate customer environments and data. Production Customer Personal Data is not used in non-production environments unless necessary, authorized, and protected by controls appropriate to the risk.
- Backups, availability, and restoration: Sheetgo maintains protected backups and business-continuity and recovery procedures designed to preserve the availability and resilience of systems and to restore access to data after an incident. Sheetgo restricts backup access and periodically tests restoration procedures.
- Vulnerability management: Sheetgo uses vulnerability scanning, risk-based remediation and patching, security monitoring, and periodic penetration testing to identify and address material vulnerabilities in a timely manner according to their severity and risk.
- Secure development: Sheetgo applies secure development and change-management practices, including security requirements, code review, testing, dependency management, controlled deployment, and security training appropriate to personnel responsibilities.
- Incident response: Sheetgo maintains a documented incident-response program with defined responsibilities and procedures for detection, investigation, containment, remediation, recovery, internal escalation, and required notifications. Sheetgo reviews and periodically exercises these procedures.
- Vendor management: Sheetgo conducts risk-based due diligence before engaging Subprocessors, imposes written security and data protection requirements, and periodically reviews Subprocessor risk and performance as appropriate to the services provided.
- Regular testing and review: Sheetgo regularly assesses and tests the effectiveness of its technical and organizational measures, reviews risks and controls, and updates its security program to address material changes in threats, technology, processing, or legal requirements.
Sheetgo’s security and compliance controls are independently assessed against standards that include SOC 2 Type II. Relevant reports and information are available through the Trust Center subject to reasonable access and confidentiality procedures.
Sheetgo may update these measures to reflect changes in technology, threats, and the Service, but will not materially reduce the overall level of protection for Customer Personal Data during the term of the DPA.
Annex 3: subprocessors
The current list of Subprocessors is maintained on the Subprocessors page at sheetgo.com/legal/subprocessors. The list identifies each Subprocessor’s purpose, processing location, and applicable international-transfer safeguards and is incorporated into this DPA. The list in effect when this DPA takes effect constitutes the Customer’s initially authorized Subprocessors.
The Subprocessors page separately identifies providers that process Customer Personal Data on Sheetgo’s behalf and providers that process personal data for which Sheetgo acts as a controller. Only the former are Subprocessors under this DPA.