GUNGNIR

Data Processing Agreement

Version 1.2 · Effective date: 7 June 2026 · Governed by the Philippine Data Privacy Act of 2012 (R.A. 10173)

Changelog: v1.2 — Added company-direct (Gungnir for Business) data processing disclosure. · v1.0 — Initial release (29 May 2026).

1. Parties

This Data Processing Agreement ("Agreement") is entered into between:

  • Data Controller — the organisation that creates a Gungnir tenant account ("Controller" or "your firm"), and
  • Data Processor — Gungnir Labs Inc., operator of the Gungnir platform ("Processor" or "Gungnir").

By creating a Gungnir account and checking the DPA acceptance checkbox, the Controller agrees to the terms of this Agreement on behalf of their organisation.

2. Subject Matter and Purpose

Gungnir processes personal data on behalf of the Controller solely to deliver the services described in the Gungnir subscription plan selected by the Controller. Processing activities include but are not limited to:

  • Storing, indexing, and retrieving documents uploaded by the Controller
  • Generating AI-assisted summaries, drafts, and analysis using uploaded documents
  • Recording meeting transcriptions linked to matters or engagements
  • Sending notifications and reminders to Controller-designated personnel
  • Maintaining billing records and invoice history

Gungnir does not process personal data for any purpose beyond service delivery, and does not sell, share, or use Controller data for advertising, profiling, or any third-party benefit.

3. Categories of Personal Data Processed

The Processor may process the following categories of personal data as directed by the Controller:

  • Identity data: full names, email addresses, phone numbers of clients and staff
  • Professional data: matter records, case notes, legal documents, billing entries
  • Communication data: messages, meeting transcriptions, uploaded attachments
  • Technical data: IP addresses, user agent strings (for audit trail purposes only)

The Controller is responsible for ensuring that personal data submitted to Gungnir has been collected lawfully and that data subjects have been informed of its processing.

4. Duration

This Agreement is effective from the date of account creation and remains in force for the duration of the Controller's active subscription. Upon termination of the subscription, data is retained for 30 days to allow export, after which it is permanently deleted from all Gungnir systems, including backups, within 90 days of the deletion request.

5. Processor Obligations

Gungnir commits to:

  • Process only on Controller instruction. Personal data is processed exclusively to deliver the subscribed services. Gungnir staff do not access Controller data except for technical support explicitly requested by the Controller, or as required by law.
  • Maintain confidentiality. All Gungnir personnel with access to infrastructure are bound by confidentiality obligations.
  • Implement appropriate security measures including row-level security isolation, AES-256-GCM encryption for documents and credentials at rest, TLS in transit, and immutable audit logging of all data access events.
  • Assist with data subject rights. Gungnir will assist the Controller in responding to data subject access, correction, and deletion requests within a reasonable timeframe.
  • Notify the Controller of data breaches without undue delay and no later than 72 hours after Gungnir becomes aware of a personal data breach that affects Controller data.
  • Not engage sub-processors for personal data processing without informing the Controller. Current approved sub-processors are listed in Section 8.

6. Controller Obligations

The Controller agrees to:

  • Ensure all personal data submitted to Gungnir has a lawful basis for processing under R.A. 10173 and any applicable local law.
  • Inform data subjects (clients, staff, third parties) that their data is processed by Gungnir as a service provider.
  • Not submit special categories of sensitive personal data (health records, biometrics, criminal records) unless required by the module type (e.g., Medical module) and only after ensuring additional safeguards are in place.
  • Maintain the confidentiality of account credentials and API keys.

7. Data Subject Rights

Data subjects whose personal data is processed through Gungnir may exercise the following rights under R.A. 10173:

  • Right to be informed — data subjects may request disclosure of how their data is used.
  • Right of access — data subjects may request a copy of their personal data held by the Controller.
  • Right to rectification — data subjects may request correction of inaccurate data.
  • Right to erasure — data subjects may request deletion of their data, subject to the Controller's legal retention obligations.
  • Right to object — data subjects may object to processing on grounds of legitimate interest.

The Controller is the primary point of contact for data subject rights requests. Gungnir will assist the Controller in fulfilling requests within 30 days.

8. Sub-processors

Gungnir uses the following approved sub-processors:

  • Supabase Inc. — Database hosting and authentication (AWS ap-northeast-2, Seoul, South Korea)
  • Anthropic PBC — AI language model inference (data not retained by Anthropic per their zero-retention API policy)
  • OpenAI OpCo, LLC — Vector embedding generation for firm memory search (text content only, no metadata). Text content is processed to generate vector embeddings using text-embedding-3-small. OpenAI's API terms prohibit use of API inputs to train models.
  • Vercel Inc. — Web application hosting
  • Railway Corp. — AI service background processing
  • Resend Inc. — Transactional email delivery

Gungnir will notify Controllers via email at least 30 days before adding or replacing a sub-processor. Controllers may object within that period.

9. Company-Direct Services (Gungnir for Business)

Added in DPA v1.2

When a person, company or other legal entity submits a legal work request through Gungnir for Business, Gungnir processes the following categories of personal data as a personal information processor under Republic Act No. 10173 (Data Privacy Act of 2012):

Data categories: name or if a corporation, company name and registration details; name and contact information of the submitting representative; matter description and any supporting documents uploaded; payment transaction reference (payment instrument details are processed exclusively by PayMongo as a separate and independent controller).

Purpose of processing: to match the request to an available partner law firm on the platform; to enable Grimnir to draft the requested document; to facilitate attorney review and delivery of the completed deliverable; to generate and collect platform service fees; to maintain an immutable audit trail of all AI actions and approvals as required by the platform's attorney supervision framework.

The partner law firm assigned to a company-direct matter receives matter data as an authorized recipient for the purpose of fulfilling the legal work request. The assigned firm acts as a separate personal information controller with respect to the attorney-client relationship and its own data processing obligations.

Retention: matter data is retained for five (5) years from the matter close date, consistent with applicable professional records retention requirements. Payment transaction references are retained as required under Bureau of Internal Revenue regulations.

Data subjects who are company clients may exercise their rights under RA 10173, including the right to access, correct, and object to processing, by contacting privacy@gungnir.cloud.

10. Security Measures

Gungnir implements the following technical and organisational measures:

  • Tenant isolation: Row-level security (RLS) on all 57+ database tables ensures one tenant cannot access another tenant's data at the database layer, independent of application code.
  • Document encryption: Uploaded documents are encrypted at rest using AES-256-GCM with a unique per-tenant data encryption key (DEK). The DEK itself is encrypted with a master key held by Gungnir. Even with full database access, raw document content is not readable without the tenant's DEK.
  • Credentials encryption: Payment provider API keys and other sensitive credentials are encrypted at rest using AES-256-GCM before storage.
  • Audit trail: Every action on Controller data is recorded in an immutable append-only audit log. No entry can be edited or deleted by any party, including Gungnir staff. The Controller can view this log at any time via Settings → Audit trail.
  • Transit encryption: All data in transit is encrypted via TLS 1.2+.
  • Access control: Gungnir staff access to production infrastructure is restricted to authorised personnel and logged.

11. International Transfers

Controller data is stored primarily in Seoul, South Korea (Supabase, AWS ap-northeast-2). AI inference requests to Anthropic may transit through the United States. Anthropic operates a zero-data-retention API policy — no prompts or responses are stored or used for model training.

By using Gungnir, the Controller consents to these transfers on the understanding that Gungnir has ensured appropriate contractual safeguards with each sub-processor.

12. Deletion and Return of Data

Upon written request to privacy@gungnir.cloud, Gungnir will:

  • Provide a data export within 14 days (CSV and PDF format).
  • Permanently delete all Controller data from active systems within 30 days.
  • Delete data from backups within 90 days.
  • Provide written confirmation of deletion upon request.

13. Liability

Each party shall be liable for damages caused by processing that does not comply with R.A. 10173 or this Agreement that can be attributed to it. Gungnir's total liability under this Agreement shall not exceed the fees paid by the Controller in the 12 months preceding the event giving rise to the claim, except in cases of gross negligence or wilful misconduct.

14. Governing Law and Dispute Resolution

This Agreement is governed by the laws of the Republic of the Philippines. Disputes shall first be submitted to the National Privacy Commission (NPC) as the competent supervisory authority before any court proceedings.

15. Contact

For data privacy inquiries, breach notifications, or data subject rights requests, contact:

Eric Dela Cruz
Data Protection Officer
privacy@gungnir.cloud