Data Processing Addendum

Version 1.0 · September 7, 2026

This Addendum forms part of the agreement between you and SIA "GoProst" (trading as Nuggetz) whenever we process personal data on your behalf. It applies automatically from the moment you start using Nuggetz — including during a free trial or evaluation — so you do not need to negotiate or countersign it before running a pilot.

If your organisation requires a signed copy, or needs its own paper used instead, write to privacy@nuggetz.ai and we will sign and return it.

1. Parties and roles

"Processor" means Sabiedrība ar ierobežotu atbildību "GoProst", registration number 44103112931, Valmieras iela 24, Smiltene, Smiltenes novads, LV-4729, Latvia, trading as Nuggetz. "Customer" means the organisation that has created a Nuggetz team and agreed to our Terms of Service.

In respect of Customer Personal Data, the Customer is the controller and Nuggetz is the processor. The Customer decides which interviews are run, what is asked, who is invited to answer, who may read the responses, and how long the data is kept. Nuggetz has no independent purpose of its own for that data.

Nuggetz acts as a controller only for a narrow set of data it needs to operate the service safely — account records, security and audit logs, error diagnostics and billing records. That processing is described in our Privacy Policy and is outside this Addendum.

2. Definitions

"Customer Personal Data" means personal data contained in interviews, responses, transcripts, nuggets and handbooks within the Customer's Nuggetz team, and in the Customer's own account records.

"Data Protection Law" means, as applicable: Regulation (EU) 2016/679 (the GDPR); the GDPR as retained in United Kingdom law together with the Data Protection Act 2018 (the UK GDPR); the Swiss Federal Act on Data Protection; and the US State Privacy Laws addressed in section 13.

"Respondent" means an individual who answers an interview through a share link. "SCCs" means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914. Terms such as controller, processor, data subject, personal data breach and processing carry the meanings given in the GDPR.

3. Processing on documented instructions

Nuggetz processes Customer Personal Data only on the Customer's documented instructions. The Terms of Service, this Addendum, and the Customer's use of the product's own controls together constitute those instructions, and no separate written instruction is required for ordinary use of the service.

Nuggetz will inform the Customer if it believes an instruction infringes Data Protection Law, and may suspend performance of that instruction until it is withdrawn or amended. Where Nuggetz is required by EU or Member State law to process data beyond the Customer's instructions, it will inform the Customer of that requirement before processing unless the law forbids it.

4. No use for artificial intelligence training

Nuggetz does not use Customer Personal Data to train, fine-tune, or otherwise develop or improve any machine learning or artificial intelligence model, whether its own or a third party's. Nuggetz engages AI providers only under terms that prohibit them from using Customer Personal Data to train or improve their models.

Nuggetz does not sell Customer Personal Data, share it for cross-context behavioural advertising, or use it for any purpose other than providing the service to the Customer.

5. Confidentiality

Nuggetz ensures that every person authorised to process Customer Personal Data is bound by an appropriate obligation of confidentiality, whether contractual or statutory, and that this obligation survives the end of their engagement. Access to Customer Personal Data by Nuggetz personnel is limited to what is necessary to operate the service or to support the Customer, and is granted on a least-privilege basis.

6. Security

Nuggetz implements and maintains the technical and organisational measures set out in Annex II, having regard to the state of the art, the costs of implementation, and the nature, scope, context and purposes of the processing. Nuggetz may update those measures over time provided the level of protection is not reduced.

7. Sub-processors

The Customer gives general authorisation for Nuggetz to engage the sub-processors listed in Annex III. Nuggetz imposes on each sub-processor data protection obligations no less protective than those in this Addendum, and remains fully liable to the Customer for their performance.

Nuggetz will give the Customer at least thirty (30) days' notice before adding or replacing a sub-processor, by email to the Customer's administrators. The Customer may object on reasonable data protection grounds within that period. If the objection cannot be resolved, the Customer may terminate the affected service without penalty and receive a pro-rata refund of any prepaid fees.

8. Personal data breach

Nuggetz will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notification will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point for further information — providing that information in phases where it is not all available at once.

Nuggetz will not notify any supervisory authority or data subject on the Customer's behalf without the Customer's prior instruction, unless required to do so by law.

9. Assistance to the Customer

Taking into account the nature of the processing, Nuggetz assists the Customer by appropriate technical and organisational measures in fulfilling its obligation to respond to requests to exercise data subject rights. The product's own controls are the primary means: an administrator can read, export and delete an individual response, and can delete an interview together with everything derived from it.

Where a data subject contacts Nuggetz directly about Customer Personal Data, Nuggetz will not respond substantively but will refer them to the Customer and inform the Customer without undue delay.

Nuggetz provides the Customer with reasonable assistance for data protection impact assessments and prior consultations with supervisory authorities under Articles 35 and 36 GDPR, including by supplying the information in the Annexes to this Addendum.

10. Return and deletion — including at the end of a trial

This section is written for organisations evaluating Nuggetz, because the fair question before a pilot is what happens to employees' answers if the pilot does not proceed.

During the term, the Customer controls deletion directly. An administrator can delete a single response, or delete an entire interview — which permanently deletes its questions, every response and transcript, every nugget extracted from those transcripts, and the handbook written from them. Deletion is immediate and is not reversible. Before deleting, the Customer can export the handbook as Markdown, so the knowledge can be kept without the personal data behind it.

At the end of a trial or on termination, Nuggetz will, at the Customer's choice, return Customer Personal Data in a machine-readable format or delete it. To exercise that choice, write to privacy@nuggetz.ai: Nuggetz will action the request and delete all Customer Personal Data within thirty (30) days of receiving it, confirming in writing. Nuggetz will also delete all Customer Personal Data within thirty (30) days of the Customer closing its account.

Nuggetz does not delete on a timer. Absent a deletion request or account closure, Customer Personal Data is retained so that it remains available to the Customer. Deciding how long that should be is the Customer's call as controller, and the product's own delete controls are always available.

Backups. Deleted data may persist in encrypted database backups after deletion from the live service. Those backups are on a rolling 35-day retention and are overwritten in the ordinary course; they are never restored selectively to recover deleted customer data, and remain subject to this Addendum until they expire.

Nuggetz may retain Customer Personal Data where required by EU or Member State law, in which case it will retain only what the law requires, for only as long as required, and will continue to protect it under this Addendum.

11. Audit and information

Nuggetz makes available to the Customer all information necessary to demonstrate compliance with Article 28 GDPR, including this Addendum's Annexes and the description of its security measures in Annex II. Nuggetz will complete the Customer's own security questionnaire on reasonable request.

Where that information is not sufficient, the Customer may audit Nuggetz's compliance no more than once in any twelve-month period, on thirty days' written notice, during business hours, subject to confidentiality, and in a manner that does not disrupt the service or compromise other customers' data. The Customer bears its own costs. An audit may be conducted more frequently where required by a supervisory authority or following a personal data breach affecting the Customer.

12. International transfers

Customer content stays in the European Union. Interviews, responses, transcripts, nuggets and handbooks are stored and processed entirely within the EU: the Nuggetz application runs in Microsoft Azure West Europe, its database in Azure North Europe, and the Azure resource that transcribes spoken answers and reads questions aloud is likewise located in the EU. No interview content is transferred outside the EEA.

Some account and analytics data reaches sub-processors established outside the EEA. Authentication records are held by Clerk, and product analytics within the signed-in workspace use Microsoft Clarity and Google Analytics. Each is identified in Annex III. Those transfers are made under the safeguards below.

Where a transfer to a third country does occur, the SCCs are incorporated into this Addendum by reference and apply as follows. Module Two (controller to processor) applies where the Customer is a controller established in the EEA. Module Three (processor to processor) applies where the Customer is itself a processor. The optional docking clause applies; the Clause 17 governing law is that of Latvia; the Clause 18 forum is the courts of Latvia; and the Annexes to this Addendum serve as the Annexes to the SCCs.

For transfers subject to UK law, the UK International Data Transfer Addendum (version B1.0) is incorporated and amends the SCCs accordingly, with the Information Commissioner as the relevant supervisory authority. For transfers subject to Swiss law, references to the GDPR are read as references to the Swiss Federal Act on Data Protection and the Federal Data Protection and Information Commissioner is the relevant authority.

13. United States state privacy laws

This section applies where the Customer is subject to the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA) or to a comparable US state privacy law. In those terms, the Customer is a business and Nuggetz is a service provider or processor.

Nuggetz is prohibited from, and will not: sell or share Customer Personal Data; retain, use or disclose it for any purpose other than performing the services specified in the agreement, including outside the direct business relationship between the parties; or combine it with personal information received from another source, except as permitted for a service provider.

Nuggetz certifies that it understands these restrictions and will comply with them. Nuggetz will notify the Customer if it determines it can no longer meet its obligations, and the Customer may on notice take reasonable steps to stop and remediate unauthorised use. The Customer may take these commitments as the certification a US enterprise vendor review generally requires.

14. General

This Addendum forms part of, and is subject to, the Terms of Service. Where this Addendum and the Terms of Service conflict on the processing of personal data, this Addendum prevails. Where this Addendum and the SCCs conflict, the SCCs prevail. This Addendum is governed by the law of the Republic of Latvia, without prejudice to the SCCs.

Liability. Each party's liability under or in connection with this Addendum is subject to the limitations and exclusions of liability in Section 9 of the Terms of Service — the Evaluation Cap where no fees are payable, and otherwise the Enhanced Cap that Section applies to claims arising under this Addendum. The obligations in this Addendum are the same whether or not the Customer is paying; only the financial cap differs. For the avoidance of doubt, Section 9 does not limit a data subject's rights against either party under Article 82 GDPR or under the SCCs, nor any liability that cannot be limited under applicable law.

Nuggetz may update this Addendum where required by a change in law or in its processing, provided the change does not reduce the protection of Customer Personal Data. Material changes will be notified to the Customer's administrators at least thirty days in advance.


Annex I — Description of the processing

Subject matter and duration. Provision of the Nuggetz knowledge interview and handbook service, for the duration of the Customer's use of it, including any trial, and until deletion under section 10.

Nature and purpose. Collection, recording, organisation, storage, transcription, AI-assisted analysis and structuring, retrieval, disclosure to the Customer's authorised users, and erasure — for the purpose of capturing operational knowledge and producing handbooks.

Categories of data subject. The Customer's authorised users (employees and contractors with a Nuggetz account) and Respondents (individuals invited to answer an interview, typically the Customer's own employees or contractors).

Categories of personal data. For users: name, email address, and authentication and activity records. For Respondents: name, optional email address, the content of their answers as transcribed text, and technical data including IP address and browser information. Voice recordings are not retained — see Annex II.

Special categories of data. None are requested, and the service is not designed to elicit them. Because interviews are open-ended, a Respondent may volunteer such data unprompted; the Customer is responsible for designing interviews that do not invite it.

Frequency. Continuous for the duration of the agreement.

Competent supervisory authority. The Data State Inspectorate of Latvia (Datu valsts inspekcija), Elijas iela 17, Riga, LV-1050, Latvia.

Annex II — Technical and organisational measures

  • Encryption in transit: TLS on all connections. HTTP Strict Transport Security is enforced on both nuggetz.ai and app.nuggetz.ai. The application enforces HTTPS-only and FTP access is disabled.
  • Encryption at rest: Azure platform encryption on the database, storage and backups.
  • Voice recordings are never stored. Where a Respondent answers by speaking, the audio is streamed to the transcription service within a single request, held only in memory for the duration of that request, and never written to disk or database. Only the resulting text is retained.
  • Access control: authentication is provided by Clerk. Application data is scoped to the Customer's team on every query; a Respondent's ability to write to a transcript is bound to a per-interview HttpOnly, SameSite cookie enforced as a query condition rather than a post-hoc check.
  • Network isolation: the application runs inside a virtual network. The rate-limit store is reachable only through a private endpoint, requires TLS 1.2 or above, and has public network access disabled. Secrets are held in Azure Key Vault with purge protection enabled.
  • Application hardening: a nonce-based Content Security Policy with strict-dynamic, frame-ancestors 'none', a restrictive permissions policy, cross-origin opener policy, and CSRF protection on every state-changing request including unauthenticated respondent endpoints.
  • Input validation and error handling: schema validation on every API route, request size limits, per-endpoint rate limiting, and centralised error handling that scrubs personal data from logs.
  • Search engine exclusion: interview links and shared handbooks carry instructions preventing indexing, so customer content does not enter public search results.
  • Backup and recovery: automated database backups on a 35-day rolling retention.
  • Monitoring: Azure Application Insights, hosted in the EU, with a 30-day log retention and personal data scrubbed from log output.
  • Personnel: confidentiality obligations, least-privilege access, and access removal on the end of engagement.
  • Certifications: Nuggetz does not currently hold SOC 2 or ISO/IEC 27001 certification. Its cloud infrastructure providers hold ISO/IEC 27001 and SOC 2 certifications for the services used.

Annex III — Sub-processors

Sub-processorPurposeLocation
Microsoft AzureApplication and database hostingEU (West Europe, North Europe)
Microsoft Azure AI FoundryAI processing of interview contentEU
Microsoft Azure SpeechTranscription of spoken answers and read-aloud. Transient processing only — no audio is stored.EU
ClerkAuthentication and account managementUnited States — SCCs
Azure Application InsightsApplication performance and error monitoring, with personal data scrubbed from logsEU (West Europe)
Microsoft ClarityProduct analytics in the signed-in workspace only, page content masked, consent-gated. Does not run on interview pages.United States — SCCs
Google AnalyticsProduct analytics in the signed-in workspace only, consent-gatedUnited States — SCCs

Each sub-processor engages its own onward sub-processors under its own data processing terms — Clerk, for example, uses third-party services for monitoring and bot protection. Those are listed by the sub-processor concerned and are covered by the obligations Nuggetz imposes under section 7.

Changes to this list are notified under section 7. To be notified by email, write to privacy@nuggetz.ai.