Skip to content
GravityAgent

Data Processing Addendum

Version 1.0 — 2026-09-05 (draft — [REVIEW])

This Data Processing Addendum ("DPA") forms part of the Terms of Service between [ENTITY] ("GravityAgent", "we") and the organisation that activates a site with the GravityAgent service ("Customer", "you"). It applies whenever GravityAgent processes personal data on your behalf. It is a standard addendum: it is accepted by activating a site and is not individually negotiated. A signed copy is available on request to [SUPPORT EMAIL].

1. Roles

1.1 You are the controller of the personal data contained in the form submissions your site sends to the Service, and of the verdict records the Plugin stores on your site.

1.2 GravityAgent is your processor for that data, and processes it only as described in this DPA and as instructed through your use of the Plugin (enabling a form, excluding a field, correcting a verdict, requesting a crawl, deactivating a site).

1.3 For the account data you give us or our merchant directly (site domain, licence and billing details, an administrator e-mail you opt in to sharing), we and the merchant act as independent controllers under the Privacy Policy.

2. Subject matter, nature and purpose

2.1 Subject matter. Submissions made through Gravity Forms on your site, together with the context the Plugin attaches to them.

2.2 Nature. Transient, automated processing: each submission is received, sent to a language model with your site's context and any correction examples, the model's verdict is validated, and the response is returned. The submission is then discarded.

2.3 Purpose. To return a spam verdict for that submission, and nothing else.

2.4 Data subjects. People who submit forms on your site.

2.5 Categories of personal data. Whatever your form collects and you have not excluded — typically name, e-mail address, phone number, message text — plus the submitter's IP address, browser user agent, submission time and page URL, and file names of uploads (never file contents or URLs). Special-category data may be present if your form collects it; you are responsible for excluding such fields if that processing is not appropriate.

2.6 Duration. The processing of each submission lasts for the request, normally under two seconds. Non-content operational records are retained as stated in the Privacy Policy (decision records about 90 days; aggregates and account records for the life of the account).

3. Our commitments

3.1 Transient processing — no content is stored. We do not persist the content of any submission: not field values, not file bytes or URLs, not the model's explanation text, not the content of correction examples. Not in a database, not in a log, not in a cache, not in a backup. What we retain is limited to the non-content operational records enumerated in the Privacy Policy. Our automated test suite asserts, on every change to the Service, that a sentinel string placed in a submission appears in no database table and on no log line.

3.2 No training. We do not use your submissions, corrections or context to train, fine-tune or otherwise improve any model, ours or a third party's, and we engage our language-model provider only on terms that prohibit it from doing so (Google Gemini API, Paid Services terms).

3.3 Instructions only. We process personal data only for the purpose in §2.3 and on your documented instructions, unless required by law, in which case we will tell you before processing unless the law forbids it.

3.4 Confidentiality. Personnel with access to the Service's operational data are bound by confidentiality obligations. No person reviews submission content in the ordinary course; the Service is fully automated.

3.5 Security. We maintain appropriate technical and organisational measures, including: TLS on every connection; API tokens stored only as SHA-256 hashes; provider credentials held as platform secrets, never in the database; authentication before any request body is read; rate limiting of unauthenticated requests; a log format with no free-form field; and automated tests that enforce the no-content rule.

3.6 Subprocessors. You authorise the subprocessors listed at https://gravityagent.io/subprocessors — Cloudflare (hosting), Google (language model), Firecrawl (public-page crawl only) and Freemius (paid checkout and licensing; never a submission). We remain responsible for their performance. We will post any addition that would receive submission content at least 30 days before it takes effect; you may object by deactivating your site before that date, and if you do we will refund any prepaid fees for the unused period.

3.7 International transfers. All stored data is held in the United States. In-flight processing takes place at the Cloudflare location nearest your server and at our language-model provider under its own processor terms. We do not offer EU data residency. Where the data you send us is subject to a law that restricts transfers, you are responsible for establishing a lawful basis for the transfer to us and to the subprocessors above; we will provide reasonable assistance, including entering into standard contractual clauses on request. [REVIEW]

3.8 Assistance. Taking into account the nature of the processing, we will assist you with data-subject requests and with your security, breach-notification and impact- assessment obligations, to the extent our non-content records make that possible. In practice: we cannot identify a data subject from what we hold; given decision ids we will delete the associated records.

3.9 Breach notification. We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal-data breach affecting your data, with the information we have at the time and updates as we learn more. Because no content is stored, a breach of our stores cannot expose submission content; the notification duty still applies to the operational records we keep.

3.10 Deletion. Deleting an entry in Gravity Forms deletes the authoritative record; we hold no content copy of it. On deactivation of a site the API token is revoked and that site's profile and notes are deleted immediately, without a request; deactivating one site under a multi-site licence does not affect the others. Decision records contain no content and expire automatically within about 90 days; on written request to [SUPPORT EMAIL] we will delete the ones you identify sooner, within 30 days. Aggregated daily counts contain no personal data and are retained.

3.11 Audit. We will make available the information reasonably necessary to demonstrate compliance with this DPA — this DPA, the Privacy Policy, the Subprocessors page, the relevant sections of our public architecture documentation, and answers to reasonable written questions. We do not offer on-site audits on the Free tier; for paid plans an audit may be arranged at your cost, no more than once a year, on 30 days' notice, and subject to confidentiality.

4. Your commitments

4.1 You warrant that you have a lawful basis to send us the personal data in your submissions, that your own privacy notice discloses the processing, and that you have excluded any field you are not permitted to send.

4.2 You will not send us data you know to be unlawful to process, and you will use the Plugin's field-exclusion setting for any field whose contents should not leave your site.

5. Liability and precedence

The limitations of liability in the Terms of Service apply to this DPA. If this DPA conflicts with the Terms, this DPA prevails for matters of personal-data processing.

6. Term

This DPA applies for as long as we process personal data on your behalf and, for the obligations in §3.10, until deletion is complete.


[ENTITY] · [SUPPORT EMAIL] · Governing law [GOVERNING LAW]