Data Processing Addendum
Last Updated: September 28, 2026
Effective date: September 28, 2026. Version: 1.5.
This Data Processing Addendum (“DPA”) supplements the First Gear AI Terms of Service (the “Agreement”) between First Gear AI LLC, a Texas limited liability company (“FGAI”), and the client named on the order (“Client”). It is effective as of the Agreement’s effective date. Capitalized terms not defined here have the meanings given in the Agreement. Business customers who need a countersigned copy can request one at hello@firstgear.ai.
1. Roles and What This DPA Covers
1.1 For the personal data described in Annex A (“Covered Data”), Client is the controller (or business) and FGAI is the processor (or service provider).
1.2 For FGAI’s own account, billing, website, and marketing data, FGAI is an independent controller and the Privacy Policy governs. That data is not Covered Data.
1.3 FGAI provisions a dedicated Supabase project for Client, inside FGAI’s own Supabase organization, and FGAI pays for that project. The data in it is Client’s. Because the project sits in FGAI’s organization, FGAI hosts and operates it. Client Business Data is locked on Client’s device, with a key FGAI never holds, before it is stored. FGAI can see that the account exists, when Client signed in, and how much storage is used. FGAI cannot see what Client saved. Processing is on the terms in Section 3.
Client Business Data becomes Covered Data when it enters that project and stays Covered Data for as long as FGAI holds it in any form. There are two consecutive phases, and both are covered:
(a) Active phase. While Client’s workspace is active, FGAI processes Client Business Data for the full set of purposes in Section 4.
(b) Departure Window. On termination or expiry the same project stays live for the period in Section 11 so Client can export its data, and FGAI processes Client Business Data in it for the purposes in Section 4 exactly as during the active phase. FGAI makes no readable copy of Client Business Data at any point. After the Departure Window FGAI keeps a locked copy in storage only, free of charge, until Client instructs deletion under Section 11.5. FGAI cannot see what Client saved in that copy.
Client Business Data ceases to be Covered Data when FGAI has deleted it under Section 11. Exporting data does not end that status for what is still in the project: an export puts a second copy in Client’s hands, and this DPA governs FGAI’s side only.
2. Definitions
“Client Business Data” means all data Client and its authorized users put into, or generate within, the database FGAI hosts for Client, including any personal data of Client’s own customers stored there. “Departure Window” means the period after termination during which FGAI keeps Client’s project live and exportable under Section 11, before it closes and FGAI keeps only the locked copy. “Data Protection Laws” means all applicable privacy and data-protection laws, including the CCPA/CPRA, the Texas Data Privacy and Security Act, other US state comprehensive privacy laws, and, where applicable, the GDPR and UK GDPR. “Personal Data,” “controller,” “processor,” “business,” “service provider,” “sell,” “share,” “data subject,” and “consumer” have the meanings given by applicable Data Protection Laws.
3. Hosting and What FGAI Can See
3.1 The dedicated Supabase project runs inside FGAI’s Supabase organization and FGAI pays for it. Client Business Data is locked with Client’s key before it reaches the project. FGAI can see that the account exists, when Client signed in, and how much storage is used. FGAI cannot see what Client saved. FGAI states that plainly.
3.2 FGAI operates the hosting so the Service stays up, secure, and backed up. FGAI does not see what Client saved. If the law requires FGAI to produce what it holds, FGAI can produce only the account details above and the locked data it cannot read. FGAI does not sell Client Business Data, does not share or disclose it for anyone’s advertising, and does not use it to train AI models.
3.3 Access is limited to the FGAI personnel who need it to do that work, on named per-user accounts under least privilege, and kept to the minimum the job requires.
3.4 FGAI maintenance changes to Client’s instance are recorded in an append-only log inside Client’s own instance, readable by Client at any time, and each FGAI change is reviewed before release and carries its recorded undo path. The log records what FGAI changed in Client’s system, never the content of Client Business Data.
3.5 While the workspace is active, Client can export all Client Business Data at any time in a standard format, self-serve, from the download in Client’s own desk. That does not require FGAI’s permission, notice to FGAI, or any act by FGAI. Client cannot move the Supabase project itself, because the project belongs to FGAI and FGAI pays for it. What Client controls instead is the processing: on termination the project enters the Departure Window in Section 1.3(b) and is then deleted, and on Client’s instruction FGAI deletes Client Business Data under Section 11 at any time.
3.6 FGAI will not materially expand the scope of its access or use beyond Section 3.2 without treating the change as a material change to this DPA, with notice and objection rights per Section 15.
4. Processing Instructions
FGAI processes Covered Data only: (a) to provide, maintain, secure, and support the Service per the Agreement; (b) on Client’s documented instructions, including this DPA; and (c) as required by law, in which case FGAI informs Client of the legal requirement before processing unless the law prohibits it. FGAI will inform Client if, in its opinion, an instruction infringes Data Protection Laws. During the Departure Window in Section 1.3(b), (a) is limited to keeping the project running, secure, and available to Client for export.
5. CCPA Service-Provider Terms
FGAI will not: sell or share Covered Data; retain, use, or disclose it for any purpose other than the business purposes in Annex A or as permitted by the CCPA; retain, use, or disclose it outside the direct business relationship with Client; or combine it with personal data received from other sources except as the CCPA permits. FGAI certifies it understands and will comply with these restrictions, will provide the same level of privacy protection the CCPA requires of businesses, will notify Client if it can no longer meet its obligations, and grants Client the right, upon notice, to take reasonable and appropriate steps to stop and remediate unauthorized use of Covered Data. Retention through the Departure Window is retention for the Section 11 business purpose of letting Client take its own data with it, and for no other purpose.
6. Confidentiality
Persons FGAI authorizes to process Covered Data are bound by written or statutory confidentiality obligations and access it on a least-privilege, need-to-know basis.
7. Security
FGAI implements and maintains the technical and organizational measures in Annex B, appropriate to the volume and nature of Covered Data, and will not materially degrade them during the term or the Departure Window. See also the Security Overview.
8. Subprocessors
8.1 Client provides general authorization for the subprocessors listed at firstgear.ai/subprocessors. FGAI will give at least 30 days’ notice, by email plus an update to that page, before adding or replacing a subprocessor. Client may object on reasonable data-protection grounds, and if the parties cannot resolve the objection, Client may terminate the affected Service with a pro-rata refund of prepaid unused fees.
8.2 FGAI binds each subprocessor by written contract to obligations no less protective than this DPA and remains responsible for their performance.
8.3 Client’s own vendors are not FGAI subprocessors. Anthropic is Client’s own direct vendor for the Claude subscription: that subscription is between Client and Anthropic and conversations run under Client’s own account. Anthropic is separately FGAI’s subprocessor in two places FGAI operates on its own account, both listed on the subprocessor page: the assistant on FGAI’s public website, when a request does not run on Cloudflare, and the assistant inside shared rooms in the portal. Neither of those processes Client Business Data. Supabase is the opposite case. Supabase is FGAI’s subprocessor and stays FGAI’s subprocessor, because the dedicated project sits in FGAI’s Supabase organization on FGAI’s account, for as long as FGAI holds Client Business Data, which ends when the project is deleted under Section 11. Data Client has exported and put somewhere of its own choosing is outside this DPA, and Client’s agreement with that provider applies to it. Anthropic publishes a standard data processing agreement at anthropic.com, and Client can obtain it there directly.
9. Assistance with Rights Requests and Compliance
Taking into account the nature of the processing, FGAI will: (a) assist Client with responses to data-subject and consumer requests concerning Covered Data, including locating, exporting, correcting, or deleting records inside the hosted database on Client’s instruction; (b) assist Client with security, breach-notification, and data-protection impact-assessment obligations under Data Protection Laws, including providing information necessary for Client’s assessments; and (c) forward to Client without undue delay any request FGAI receives that concerns Client’s data subjects, without responding except to direct the requester to Client. This assistance covers the Departure Window: if a rights request reaches Client after termination but before the project is deleted, FGAI will locate, export, correct, or delete inside the project on Client’s instruction. Once the project is deleted there is nothing left for FGAI to search.
10. Personal Data Breach
FGAI will notify Client without undue delay, and no later than 48 hours, after confirming a personal data breach affecting Covered Data. The notice will describe, to the extent known: the nature of the breach; categories and approximate numbers of data subjects and records; likely consequences; measures taken or proposed; and a contact point. FGAI will cooperate with Client’s notification obligations and will not characterize Client’s obligations publicly without Client’s consent. This obligation runs for as long as FGAI holds Covered Data, the Departure Window included.
11. Departure, the Departure Window, and Deletion
11.1 The export is Client’s own. While the project exists, Client can export all of Client Business Data in a standard format at any time, self-serve, without notice to FGAI and without any act by FGAI. Taking that export is Client’s own responsibility.
11.2 On termination or expiry the project does not stop. It stays live, and Client’s export stays available, for the Departure Window: 30 days from the day Client cancels, and never less than the remainder of the period Client has already paid for. FGAI makes no readable copy of Client Business Data, at this point or any other.
11.3 At the end of the Departure Window the live project closes and FGAI keeps a locked copy of Client Business Data in storage only, free of charge, so Client can retrieve it or return. Only Client’s key opens it; FGAI cannot see what Client saved in it. FGAI keeps that copy until Client instructs deletion under Section 11.5. There is no readable archive of Client Business Data.
11.4 FGAI will normally email the account owner around seven days before the Departure Window closes, at the address on the account. That notice is a practice and not a promise: FGAI does not guarantee that any message is delivered, read, or received, delivery is not a condition of Section 11.3, and Client must not rely on it. Client is responsible for taking its export.
11.5 Client can instruct FGAI to delete Client Business Data at any time, whether before termination or during the Departure Window. On that instruction, including for the locked copy after the Departure Window, FGAI deletes it within 30 days and deletes remaining copies, including backups, within 90 days. Where the law requires FGAI to retain something, FGAI isolates and protects it and deletes it when the requirement lapses.
11.6 While the Departure Window is open Client can return to the Service and resume the same project, and the active phase in Section 1.3(a) continues uninterrupted. After the Departure Window Client can still return and restore from the locked copy with its own key, until Client instructs deletion. Once Client Business Data is deleted under Section 11.5 there is nothing to return to and nothing to hand back; returning means starting over in a new project. FGAI commits to no response time on correspondence about any of this, and Client should take its own export under Section 11.1 rather than rely on reaching FGAI afterwards.
12. Audit and Information Rights
12.1 Standing transparency: the in-instance maintenance log described in Section 3.4 is Client’s continuous, self-serve audit surface for FGAI maintenance activity.
12.2 On request, no more than once annually absent cause, FGAI will make available information reasonably necessary to demonstrate compliance with this DPA, in the form of written responses, documentation, and, when FGAI obtains them, third-party audit reports.
12.3 Where Data Protection Laws grant Client a mandatory audit right, or upon a confirmed breach or demonstrated material non-compliance, Client (or an independent auditor bound to confidentiality, not a competitor) may audit FGAI’s relevant controls on 30 days’ notice, during business hours, at Client’s cost, no more than once per year absent cause.
13. Liability
Liability under this DPA is subject to the Agreement’s limitations of liability.
14. International Transfers
Covered Data is processed in the United States. The Service is offered to US businesses. If personal data subject to the GDPR or UK GDPR comes into scope, the parties will put an appropriate transfer mechanism in place before that processing begins, and FGAI will cooperate on transfer impact assessments.
15. Term and Changes
This DPA lasts as long as FGAI processes Covered Data, which includes the Departure Window in Section 1.3(b) and ends when Section 11 deletion is complete. FGAI may update this DPA to reflect changed law or the Section 8 process. Material changes follow the Agreement’s notice process with objection rights per Section 8.1. Conflict order: this DPA controls over the Agreement for its subject matter.
16. Governing Law
This DPA is governed by the laws of the State of Texas, without regard to its conflict of law provisions. Venue for any dispute lies in the state or federal courts located in Travis County, Texas.
Annex A: Processing Details
Subject matter and nature: provision, hosting, maintenance, security, backup, and support of the dedicated Supabase project FGAI runs for Client and the platform layer that runs on it; account-to-instance registry pairing; support handling; and, after termination, keeping that same project running through the Departure Window so Client can export or return.
Duration: two consecutive phases, matching Section 1.3. The active phase runs for the Agreement term, during which FGAI processes Client Business Data for all of the purposes in Section 4. The Departure Window runs from termination or expiry until the live project closes under Section 11, which is 30 days from the day Client cancels and never less than the remainder of the paid period, unless Client instructs deletion sooner; processing in that phase is the same as the active phase, because it is the same project. Deletion runs on the 30 day and 90 day windows in Section 11.5. Account, billing, and support records follow the retention periods stated in the Privacy Policy.
Purposes: those in Section 4(a) only.
Categories of data subjects: Client’s personnel and authorized users; Client’s points of contact; and any individuals whose personal data Client chooses to store in the hosted database, including Client’s own customers and contacts.
Categories of Covered Data: name, business contact details, account identifiers and roles; instance registry pairing records (project reference, template version, connector status); platform maintenance and support records that identify individuals; assent records; and all Client Business Data held in the database FGAI hosts, which is whatever Client puts there, such as tasks, projects, notes, contacts, and workflow records. The Departure Window holds the same categories, because it is the same project still running.
Special categories: none sought. Client agrees not to route special-category data through support channels.
Annex B: Technical and Organizational Measures
Access control: per-user named accounts, least privilege, role scoping, multi-factor authentication on FGAI systems where supported, no shared credentials. Row-level security is enforced on the tables FGAI ships.
Access discipline: FGAI access to Client systems is limited to the purposes in Section 3.2 and restricted to the personnel who need it. FGAI cannot see what Client saved at any point. After the Departure Window FGAI holds only the locked copy in Section 1.3(b), in storage only, and Client can end that at any time by instructing deletion under Section 11.5.
Change discipline: append-only, client-readable maintenance log in each instance; every FGAI change reviewed before release; reversibility with undo paths recorded at execution.
Encryption: Client Business Data locked on Client’s device with a key FGAI never holds; TLS in transit; encryption at rest via the hosting platform, for the whole life of the project, the Departure Window included.
Credential hygiene: no credentials in chat channels, rotation on suspected exposure.
Personnel: confidentiality obligations, security awareness.
Incident response: triage, containment, Section 10 notice, post-incident review.
Vendor management: subprocessor contracts per Section 8.
Certifications: none claimed. This annex states practice, not badges.
Contact Us
To request a countersigned copy of this DPA, or with any question about it, contact us at hello@firstgear.ai.
First Gear AI LLC
5900 Balcones Drive STE 100
Austin, TX 78731