1. Definitions
1.1 “Applicable Data Protection Law” means all data protection and privacy laws applicable to the Processing of Personal Data under this DPA, including, where applicable, the EU/UK General Data Protection Regulation (“GDPR”) and the California Consumer Privacy Act as amended (“CCPA”), together with any successor or equivalent legislation. 1.2 “Controller,” “Processor,” “Data Subject,” “Personal Data,” and “Processing” (and their variants) have the meanings given in Applicable Data Protection Law. Where CCPA applies, “Controller” corresponds to “Business” and “Processor” corresponds to “Service Provider,” and this DPA should be read accordingly. 1.3 “Sub-processor” means any third party engaged by Gravity GTM to Process Personal Data on Gravity GTM’s behalf in connection with providing the Service. 1.4 “Customer Data” means the Personal Data submitted to, looked up through, or accessed via a connected Google account by or at the direction of Controller in the course of using Helium.2. Subject Matter and Duration
2.1 This DPA governs Gravity GTM’s Processing of Personal Data on behalf of Controller in connection with Controller’s use of the Service. 2.2 Processing under this DPA will take place for as long as Controller maintains an active Helium account, plus any additional period during which Gravity GTM retains Customer Data in accordance with Section 9 (Deletion and Return of Data) or applicable law.3. Nature and Purpose of Processing
3.1 Gravity GTM Processes Personal Data solely to provide the Service as directed by Controller — namely, to research, score, and return third-party investor/LP/company data in response to queries submitted by Controller, and to store Controller’s own fundraising profile and uploaded network data to power that research, each performed via the specific Sub-processors identified in Section 5. 3.2 Where Controller connects the Helium Slack app, Gravity GTM additionally Processes the conversational messages Controller’s workspace users send to the Helium Slack bot, for the purpose of interpreting the request and executing the corresponding research. 3.3 Where Controller connects a Google account, Gravity GTM Processes Gmail and Calendar data solely to send outreach Controller has approved, detect inbound replies to pause a sequence, and check calendar availability, as described in Section 5 (Google) and in the Helium Privacy Policy. 3.4 Gravity GTM Processes Personal Data only on Controller’s documented instructions, as reflected in Controller’s configuration and use of the Service, except where otherwise required by law.4. Categories of Data Subjects and Personal Data
4.1 Categories of Data Subjects. (a) The investors, LPs, family offices, and company personnel researched through the Service — typically not Controller’s own employees, customers, or end users. (b) Individuals in Controller’s own connected Gmail account and calendar (e.g., prior correspondents, calendar attendees), to the extent incidentally Processed while sending outreach, detecting replies, or checking availability. 4.2 Categories of Personal Data. Depending on the feature used, Processing may include: full name; job title; firm/fund affiliation; LinkedIn profile data (headline, profile URL, investment history, education); business email address; and, where the Gmail/Calendar connection is used, the content of outreach email sent through that connection, inbox metadata needed to detect a reply on a given thread, and calendar free/busy data. Where the Slack app is used, Processing also includes the content of messages sent to the Helium bot.5. Sub-processors
5.1 Controller authorizes Gravity GTM to engage the following Sub-processors as of the effective date of this DPA. This table is maintained in lockstep with the equivalent table in Section 4 of the Helium Privacy Policy — the two are kept identical and updated together:
5.2 General authorization. Gravity GTM may engage additional or replacement Sub-processors from time to time. Gravity GTM will provide notice of any new Sub-processor by updating this Section and the corresponding table in the Privacy Policy, and by email to Controller’s registered account contact, in either case at least ten (10) days before the new Sub-processor begins Processing Customer Data. Controller may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection, Controller’s sole remedy is to terminate the affected portion of the Service.
5.3 Gravity GTM remains responsible for each Sub-processor’s compliance with obligations materially equivalent to those in this DPA.
6. Security Measures
Gravity GTM implements and maintains the following technical and organizational measures:- API key protection: Customer API keys are stored only as a one-way SHA-256 hash; the plaintext key is displayed once at issuance and cannot be retrieved thereafter, only rotated or revoked.
- Credential encryption: Slack bot tokens, workspace API keys, and Gmail OAuth refresh tokens are encrypted at rest using AES-256-GCM, each with a distinct encryption context, as they must be used to make live calls on Controller’s behalf.
- Encryption in transit: All connections to the Service use TLS.
- Log minimization: Operational logs contain only metadata (request ID, tenant/account ID, API key ID, endpoint called, credits charged, cache hit/miss status, and timestamps). Logs never contain lookup content, message content, or connected-Gmail content. Logs are retained no longer than 30 days.
- Access controls limiting internal access to Customer Data to personnel who require it to operate the Service.