Last updated 29 August 2026
Data processing addendum
The terms required by Article 28 of the GDPR, under which we process personal data on your instructions. It forms part of the terms of service, so accepting those accepts this — no separate signature is needed unless your procurement process requires one.
Draft, pending legal review. This describes what Glass Box actually does, written from the code rather than from a template — which is the part a lawyer cannot do for you. Some of the wording is the market-standard answer, included so a review starts from a position rather than a gap. None of it has been read by a lawyer, and it is not legal advice.
1. Roles
You are the controller of the personal data in your workspace. We are your processor. Where UK or EU law applies to you it applies to this addendum. Where California law applies, we are a service provider as defined by the CCPA/CPRA: we do not sell or share personal information, we do not retain, use or disclose it for any purpose other than performing the service, and we do not combine it with data from other sources except as permitted.
2. What we process, and why
| Subject matter | Detail |
|---|---|
| Purpose | Providing the Glass Box service to you |
| Duration | The term of the subscription, plus the deletion window in section 9 |
| Categories of data subject | Your employees, contractors and anyone else you give access to |
| Categories of personal data | Name, work email, job title, team, role; content the person writes, including its original form; weekly check-in scores against a name; proposals, votes, situation records and readings; session and sign-in security records |
| Special category data | Not requested, and prohibited by the acceptable use terms — but a person writing freely about their working life may disclose it about themselves, and the service must be assumed to contain some. Treat your deployment accordingly |
3. Our obligations
- We process personal data only on your documented instructions, which these terms and your use of the service constitute. If we believe an instruction breaches data protection law we will tell you.
- Everyone with access is bound by confidentiality obligations.
- We apply the technical and organizational measures described in the security overview, which is incorporated into this addendum by reference. We may improve them; we will not materially reduce them.
- We assist you, taking account of the nature of processing, with data subject requests, security, breach notification, impact assessments and prior consultation.
- We make available the information needed to demonstrate compliance and allow audits — see section 8.
4. Your obligations
- You have a lawful basis for putting your people's data into Glass Box, and you have told them about it. In most jurisdictions the basis is legitimate interests, which requires a balancing assessment you should document.
- You are responsible for the accuracy of what you enter and for who you grant access to.
- Consultation. In several European jurisdictions, deploying a tool that collects employee feedback or wellbeing scores requires consulting a works council or employee representative body before launch — Germany's Betriebsrat is the usual example. That is your obligation, not ours, and it is the one customers most often discover late.
5. Subprocessors
You give general authorization for us to use the subprocessors listed on the subprocessors page. We impose data protection terms on each that are no less protective than these, and we remain liable for their performance.
We will give at least 30 days’ notice before adding or replacing one, by email to every administrator on the account. You may object on reasonable data protection grounds within that period; if we cannot resolve it, you may terminate the affected service and receive a pro-rata refund.
6. International transfers
The database is hosted by Neon in AWS us-east-2 (Ohio, United States) and the application by Render. Where personal data is transferred out of the EEA, UK or Switzerland, the transfer is made under the European Commission’s Standard Contractual Clauses of 4 June 2021 (2021/914), together with the UK International Data Transfer Addendum where UK data is involved, and a transfer impact assessment, which are incorporated into this addendum. Module Two applies, controller to processor.
7. Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting your data, and in any case within 48 hours of becoming aware. The notice will describe the nature of the breach, the categories and approximate number of records affected, the likely consequences, the measures taken, and a contact point. Where we do not have all of that at first, we will send what we have and follow up.
Notifying your supervisory authority and your data subjects is your decision and your obligation as controller; we will give you what you need to make it. Our internal procedure is summarized in the security overview.
8. Audit
We will make available the information reasonably necessary to demonstrate compliance with this addendum. You may audit no more than once a year, on reasonable notice, at your cost, during business hours and without disrupting the service, subject to confidentiality. Once an independent audit report exists we will offer it in satisfaction of routine audit rights, which is the usual trade: you get better assurance than a site visit would give, and we do not spend the year hosting them.
9. Return and deletion
You can export your data at any time from within the product, without asking us, and you can delete the whole workspace yourself from the danger zone on the People page — immediately, without asking us either. On termination we delete your workspace and everything in it within 60 days, backups included as they roll off their normal rotation, except where law requires us to keep something — in which case we keep only that, and keep protecting it. That deletion runs automatically once the subscription has been over for that long, after written notice to your administrators a month, a week and a day beforehand — and it does not run at all until one of those notices has been delivered, so an account we cannot reach is kept rather than erased.
10. Data subject requests
If we receive a request directly from one of your people, we will not answer it ourselves except to acknowledge and redirect. We will pass it to you promptly and help you answer it within the statutory deadline. The product includes export and erasure tooling built for exactly this, so answering should not require our involvement at all.
11. Liability
Liability under this addendum is subject to the limitations in the terms of service. Our starting position is a separate cap of three times the annual fees for a breach of this addendum, rather than an unlimited carve-out.

