Data Processing Agreement

This Data Processing Agreement ("DPA") forms part of, and is subject to, the Terms of Service between Code Crafters ("Processor", "we", "us"; registered at No. 44, Galle Road, Colombo 03, Sri Lanka) and the customer agreeing to those Terms ("Controller", "you") for use of the Sheet Intelligence Google Sheets add-on, browser Microsoft Excel add-in and related website/dashboard (the "Service"). It reflects the parties' agreement on the processing of Personal Data under Regulation (EU) 2016/679 ("GDPR"), the UK GDPR, and the Data Protection Act 2018, as applicable. Where it conflicts with the Terms on the subject of data protection, this DPA controls.

1. Definitions

Terms such as "Personal Data", "Processing", "Controller", "Processor", "Data Subject", "Sub-processor", "Personal Data Breach", and "Supervisory Authority" have the meanings given in the GDPR. "Data Protection Laws" means the GDPR, the UK GDPR, and other applicable privacy laws. "Customer Personal Data" means Personal Data contained in the content you submit to the Service (principally the cell values, formulas, and notes in the spreadsheets you open the Service in) and related usage records that we process on your behalf. We act as a separate controller for account administration, billing, fraud prevention and legal compliance where we determine those purposes, as explained in our Privacy Policy.

2. Roles and scope of processing

For Customer Personal Data, you are the Controller and we are the Processor. Where you are yourself a processor for a third party, we are your Sub-processor and you warrant you have the authority to engage us. We process Customer Personal Data only on your documented instructions — including as set out in this DPA, the Terms, and your configuration and use of the Service — unless required by law (in which case we will inform you unless legally prohibited). The subject matter, duration, nature, purpose, types of Personal Data, and categories of Data Subjects are described in Annex 1. We will inform you if, in our opinion, an instruction infringes Data Protection Laws.

3. Confidentiality

We ensure that personnel authorized to process Customer Personal Data are bound by an appropriate duty of confidentiality and process the data only as necessary to provide the Service.

4. Security

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk (Art. 32), as described in Annex 2. We regularly review these measures.

5. Sub-processors

You provide general written authorization for us to engage Sub-processors to process Customer Personal Data. Our current Sub-processors are listed at https://sheetintelligence.app/subprocessors.html (including currently Anthropic, PBC under its applicable zero-retention/no-training arrangement and Amazon Web Services for the backend), with their processing purpose and region. We impose on each Sub-processor, by written contract, data-protection obligations at least as protective as those in this DPA, and we remain fully liable to you for each Sub-processor's performance. We give you advance notice of any intended addition or replacement of a Sub-processor and a reasonable opportunity to object on legitimate data-protection grounds; if we cannot reasonably accommodate a well-founded objection, you may terminate the affected Service, without limiting remedies or refunds required by law or an applicable commitment.

Eligible Google routes are limited to Anthropic, OpenAI and paid Gemini, under reviewed non-training conditions. Google Workspace content and derived data must not be transferred to Kimi/DeepSeek or used for generalized model training. Microsoft routes may additionally use approved Kimi/DeepSeek services after the notice and authorization process. Pending providers do not receive Customer Personal Data until their contractual and transfer safeguards are established.

We do not authorize generalized model training on Customer Personal Data merely through this DPA, a user's sign-in, or a general Terms checkbox. Any Microsoft training-capable arrangement requires a separate documented instruction from an authorized Controller, an appropriate lawful basis for affected individuals, suitable recipient terms and transfer safeguards, and the user's distinct optional permission. Otherwise we use a non-training route. Withdrawal prevents subsequent training-capable transfers. No such arrangement is enabled at the date of this version.

6. International transfers

Where processing involves a transfer of Customer Personal Data outside the UK/EEA (including the United States, where Anthropic and AWS process data), such transfers are made under an appropriate transfer mechanism — the EU-US Data Privacy Framework where the recipient is certified, and/or the 2021 EU Standard Contractual Clauses and the UK International Data Transfer Addendum, together with a transfer risk assessment and supplementary measures where required.

7. Assistance to the Controller

Data-subject rights. Taking account of the nature of the processing, we assist you by appropriate technical and organizational measures, insofar as possible, to fulfil your obligation to respond to requests to exercise Data-Subject rights (Arts. 15–22). The Service provides self-serve export and erasure tooling; where a request reaches us directly, we will refer the Data Subject to you unless you instruct otherwise. Security, breach, DPIA. We assist you in ensuring compliance with Arts. 32–36, taking into account the nature of processing and the information available to us.

8. Personal Data Breach

We notify you without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, with the information reasonably available to us to help you meet your Art. 33/34 obligations. Our notification is not an acknowledgement of fault.

9. Deletion or return

On termination or expiry of the Service, and at your choice, we delete or return Customer Personal Data and delete existing copies within a commercially reasonable period, unless retention is required by law. The Service's erasure path removes backend copies within the timeframe stated in the Privacy Policy.

10. Audits

We make available to you information reasonably necessary to demonstrate compliance with Art. 28 and allow for and contribute to audits, subject to reasonable confidentiality, security, frequency, and cost conditions. We may satisfy this by providing our security documentation and third-party certifications/reports where available.

11. Liability, term, and governing law

Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms, subject to mandatory rights. This version applies when accepted under the Service agreement and continues for as long as we process Customer Personal Data on your behalf. It is governed by the law and subject to the jurisdiction stated in the Terms (Sri Lanka / Colombo, Sri Lanka), except where Data Protection Laws require otherwise. Questions about this DPA: info@sheetintelligence.app.

Annex 1 — Details of processing

Subject matterProvision of the Sheet Intelligence AI assistant for Google Sheets and browser Microsoft Excel.
DurationFor the term of the Service, plus the deletion/return period in §9.
Nature and purposeReading, analyzing, and (with the Controller's per-change approval) editing the Controller's spreadsheets to provide the AI assistant's features; account, authentication, billing, support, and security.
Types of Personal DataAny Personal Data the Controller includes in the content it submits — principally cell values, formulas, and notes across the tabs of the workbook the Service is opened in, and images of a selected range — plus account email and usage/audit metadata. The Controller controls what its spreadsheets contain.
Special-category dataNot intentionally processed. Do not submit special-category or regulated data unless the Controller has a lawful basis, has assessed the risk, and the required written arrangements and approved provider route are in place.
Categories of Data SubjectsDetermined by the Controller's spreadsheet content (e.g. its customers, employees, contacts), plus the Controller's authorized users.
Sub-processors and other service recipientsSee the register for actual scope, applicable roles and supported but pending AI routes. Current services include Anthropic, AWS, Vercel, Zoho Mail, restricted Cloudflare operator access and Lemon Squeezy as transaction merchant. Each receives only data relevant to its stated purpose.

Annex 2 — Technical and organizational measures (Art. 32)