Effective 2 September 2026 · Version 1.1 ·
Data Processing Addendum
GARUNA GROUP — Enhanced Due Diligence ("EDD")
| Field | Value |
|---|---|
| Document | Data Processing Addendum ("DPA") |
| Provider / Processor | Garuna Group ("Garuna", "Provider", "we") — Garuna Inc., a corporation incorporated under the laws of the Province of Ontario and operating as "Garuna Group", with registered office at 10 Thornmount Drive, Toronto, Ontario M1B 3J4, Canada |
| Client / Controller | The organisation that has entered into the Terms |
| Governing law | Province of Ontario and the federal laws of Canada applicable therein |
| Primary privacy regime | PIPEDA (federal Canada); GDPR / UK GDPR where Subjects are in the EEA / United Kingdom; Quebec Law 25 where applicable |
| Effective date / Last updated | 2026-09-02 |
| Version | 1.1 |
| Data-protection contact | [email protected] |
This DPA forms part of, and is incorporated by reference into, the Master Services Agreement / Terms of Service between Garuna and the Client (the "Terms"). Capitalised terms not defined here have the meanings given in the Terms. In the event of conflict between this DPA and the body of the Terms on any matter concerning the processing of Personal Data, this DPA prevails (see §13).
1. Definitions
The following definitions apply to this DPA, in addition to those in the Terms. They are framed to align with PIPEDA and, where Subjects are located in the EEA or the United Kingdom, with the GDPR and UK GDPR. Where the two regimes use different vocabulary for the same concept (e.g. "Personal Information" / "personal data"; "organization" / "controller"), the terms are used interchangeably to the extent the context permits.
- "Applicable Data Protection Law" means all laws relating to the protection of Personal Data applicable to the processing under this DPA, including: (a) the Personal Information Protection and Electronic Documents Act (Canada) ("PIPEDA") and applicable provincial privacy legislation (including Quebec's Act respecting the protection of personal information in the private sector, as amended by Law 25); (b) where Subjects are in the EEA, Regulation (EU) 2016/679 (the "GDPR"); and (c) where Subjects are in the United Kingdom, the UK GDPR and the Data Protection Act 2018 ("UK GDPR").
- "Effective Date" means 2026-06-27, being the date this DPA and the Terms take effect, or, if later, the date on which the Client first enters into the Terms.
- "Controller" means the party that, alone or jointly, determines the purposes and means of the processing of Personal Data; under PIPEDA, the "organization" accountable for the Personal Information. The Client is the Controller of Subject Personal Data.
- "Processor" means the party that processes Personal Data on behalf of and on the documented instructions of the Controller; equivalent to a "service provider" under PIPEDA accountability principles. Garuna is the Processor of Subject Personal Data (subject to §2.4, which addresses Client/Authorised-User account data).
- "Personal Data" / "Personal Information" means information about an identifiable individual processed under this DPA, including Subject Inputs, collected open-source material about a Subject, and any Personal Data contained within a Report.
- "Data Subject" means the identifiable individual to whom Personal Data relates, including a Subject who is a natural person and any identifiable individual appearing in collected source material. "Data Subject" is the GDPR/UK GDPR-vocabulary equivalent of the natural-person Subject and incidental individuals referred to in the Terms.
- "Subject", "Subject Inputs", "Sweep", "Report", "Authorised User", "Investigation Session", "Session State", "Deep Mode" and "Independent / Public Source" have the meanings given in the Terms.
- "Documented Instructions" means the Client's written instructions to Garuna regarding the processing of Personal Data, comprising the Terms, this DPA, the Client's configuration of the Service, and each Sweep the Client initiates.
- "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data processed by Garuna under this DPA.
- "Standard Contractual Clauses" / "SCCs" means (a) for the GDPR, the standard contractual clauses adopted by the European Commission in Implementing Decision (EU) 2021/914, including Module Two (controller-to-processor) and Module Three (processor-to-processor); and (b) for the UK GDPR, the UK International Data Transfer Addendum to the EU SCCs ("UK IDTA") issued by the UK Information Commissioner.
- "Sub-processor" means a third party engaged by Garuna that processes Personal Data on Garuna's behalf in delivering the Service, as listed in Annex 3. For the avoidance of doubt, an Independent / Public Source (a third-party public-record, registry, or open-source service, or an independent platform, that Garuna queries with Subject identifiers and that acts as an independent controller of its own data) is not a Sub-processor.
2. Roles of the Parties
2.1 The parties acknowledge and agree that, with respect to the processing of Personal Data under the Service:
(a) the Client is the Controller (the accountable "organization" under PIPEDA) of Subject Personal Data. The Client determines the purposes and means of each Sweep, selects each Subject, and bears the obligation to ensure a lawful basis and authority for the processing.
(b) Garuna is the Processor of Subject Personal Data. Garuna processes such Personal Data only on the Client's Documented Instructions and does not determine the purposes of any Sweep. Garuna does not use Subject Personal Data for its own purposes.
2.2 Each party shall comply with its respective obligations under Applicable Data Protection Law. This DPA does not relieve the Controller of any obligation owed directly to a Data Subject or a supervisory/regulatory authority.
2.3 Where the GDPR or UK GDPR applies, this DPA constitutes the Controller's written instructions and the mandatory terms required by Article 28 GDPR / Article 28 UK GDPR.
2.4 Account data (Garuna as Controller). The role allocation in §2.1 concerns Subject Personal Data only. With respect to the account, contact, authentication, and billing data of the Client and its Authorised Users (e.g. names, work email addresses, login credentials, and usage/audit records that Garuna processes to provision and secure the Service), Garuna is the Controller, and processes such data as described in the Privacy Policy (Part A). This mirrors the Controller/Processor allocation in the Terms and the Privacy Policy and does not alter Garuna's status as Processor of Subject Personal Data.
3. Subject-Matter, Duration, Nature and Purpose of Processing
3.1 Subject-matter. The processing of Personal Data necessary to provide the Service — namely the compilation, through one or more Sweeps, of an open-source due-diligence Report on a third-party Subject.
3.2 Duration. Processing is per-Sweep with limited retention. Subject Personal Data is processed for the duration of a Sweep; the resulting Report is retained for a limited period (currently thirty (30) days) so the Client can retrieve it, and is then deleted automatically (see Annex 2). Where the Client enables continued monitoring, the Subject identifiers needed to re-run the search are retained for the life of the monitoring entry; where the Client orders a paid record check, the inputs supplied for it are retained until the check is fulfilled or cancelled. Residual, transient records are described in §12.3, Annex 1 and Annex 2 (short-lived operational logs and temporary working files created during a Sweep, deleted in the ordinary course). This DPA itself continues for the term of the Terms.
3.3 Nature. Collection, retrieval, organisation, structuring, analysis, identity resolution, scoring, AI-assisted synthesis, and streaming delivery of Personal Data, as described in the Service description in the Terms.
3.4 Purpose. To enable the Client to conduct lawful due diligence on a Subject (including KYC/KYB/AML, vendor/counterparty/third-party risk, fraud and integrity investigations, litigation support, and lawful pre-employment screening that is not used as a consumer report), and for no other purpose. Garuna processes solely to deliver the Service on the Client's Documented Instructions.
3.5 The details required by Article 28(3) GDPR / UK GDPR are set out in Annex 1.
4. Types of Personal Data and Categories of Data Subjects
4.1 Categories of Data Subjects. Primarily the Subjects of investigations (third-party natural persons, or the natural persons connected to a Subject entity such as officers, directors, beneficial owners, and persons with significant control), and any identifiable individuals incidentally appearing in collected open-source source material. Subjects are third parties, are not the user, and are generally unaware of the Sweep.
4.2 Types of Personal Data. May include: identifiers and Subject Inputs (legal full name, jurisdiction, email, phone, alias/username, domain, free-text context); publicly available open-source material (web results, news/adverse-media references, social and digital-footprint signals, account-existence indicators, public engagement-graph data); and public-record / registry data.
4.3 Possible special categories and sensitive data. Because the Subject of an investigation may surface in public records and adverse-media sources, the Personal Data processed in a Sweep may incidentally include: (a) data relating to criminal convictions, offences, allegations, litigation, court and tribunal records, and regulatory/enforcement matters (Article 10 GDPR data; sensitive under Applicable Data Protection Law); (b) sanctions / watchlist screening results, which are name-based and indicative only; and (c) other special-category data within the meaning of Article 9 GDPR (e.g. data revealing political opinions, religious beliefs, health, or sexual orientation) where such data is present in public sources. The Service does not seek special-category data, but cannot exclude its incidental presence in open-source material. Where the GDPR / UK GDPR applies, the Controller is responsible for ensuring an applicable Article 9 / Article 10 condition for any such processing.
5. Controller Instructions and Warranties
5.1 Documented Instructions. The Client instructs Garuna to process Personal Data only as set out in the Documented Instructions and as necessary to provide the Service. Each Sweep the Client initiates constitutes an instruction to process the Personal Data of the relevant Subject for that Sweep.
5.2 Lawful basis and authority (Client warranty). The Client warrants and undertakes that, for each Subject and each Sweep:
(a) it has a valid lawful basis and authority under Applicable Data Protection Law to process the Subject's Personal Data without the Subject's consent or knowledge, including, where it relies on PIPEDA, the applicable collection/use/disclosure-without-consent grounds for investigation, fraud prevention / detection, breach-of-agreement investigation, and business-transaction / due-diligence purposes (including PIPEDA ss. 7(1)–7(3) and related provisions);
(b) where a Subject is in the EEA or United Kingdom, it has identified and recorded an appropriate Article 6 lawful basis (typically Article 6(1)(f) legitimate interests) and has carried out and documented the required legitimate-interests / balancing assessment, and has identified an applicable Article 9 / Article 10 condition for any special-category, criminal-offence, or litigation data that may be processed;
(c) it is, and remains, responsible for any transparency / notice obligations owed to the Subject under Applicable Data Protection Law (including determining the availability of any exemption, such as Article 14(5) GDPR, where Personal Data is not collected directly from the Subject), Garuna assisting only as Processor; and
(d) its Documented Instructions, and the processing it instructs, are and will remain lawful and will not cause Garuna to breach Applicable Data Protection Law.
5.3 Accurate inputs and permitted use. The Client warrants that Subject Inputs are accurate to the best of its knowledge and that it will use the Output only for the Authorised Purposes and not for any prohibited purpose (including, for clarity, not as a "consumer report" or for any FCRA-regulated or provincial consumer-reporting eligibility decision), as set out in the Terms and the Acceptable Use Policy.
5.4 No warranty by Garuna of the Client's basis. Garuna processes on the Client's instruction and does not determine, verify, or warrant the Client's lawful basis or authority for any Subject or Sweep.
5.5 Instructions conflicting with law. Garuna shall, where required and permitted by Applicable Data Protection Law, inform the Client if, in its opinion, an instruction infringes Applicable Data Protection Law. Garuna may suspend the affected processing pending resolution, without liability for such suspension.
6. Processor Obligations
Garuna shall, in respect of Subject Personal Data:
6.1 Process only on Documented Instructions. Process Personal Data only on the Client's Documented Instructions, including with regard to international transfers, unless required to do otherwise by a law to which Garuna is subject, in which case Garuna shall, where that law permits, inform the Client of that legal requirement before processing.
6.2 Confidentiality of personnel. Ensure that persons authorised by Garuna to process the Personal Data are bound by an appropriate obligation of confidentiality and process the Personal Data only as instructed.
6.3 Security measures. Implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the nature of the processing and the protective architecture of the Service. These measures are set out in Annex 2 and include, in particular: time-limited retention of Reports with automatic deletion at the end of the retention period; no standing, searchable database of Subjects; the Session State invariant (Investigation Session authentication state for browser-based platform sessions held in process memory only, never written to disk, never logged beyond a cookie count, and never serialised into a Report or export — subject to the carve-out in Annex 2 §2 for the optional authenticated-lookup credential (the analyst's own credential, not Subject data), whose credential file persists on disk); and access-controlled, short-lived operational logs.
6.4 Sub-processors. Engage Sub-processors only in accordance with §9 (Sub-processors).
6.5 Assistance with Data-Subject rights. Taking into account the nature of the processing, assist the Client by appropriate technical and organisational measures, insofar as possible, in responding to requests by Data Subjects to exercise their rights under Applicable Data Protection Law. The parties acknowledge that, because Reports are retained only for a limited period, Garuna holds a record of a Subject only while a Report, monitoring entry, or pending record check exists; such requests are addressed by the Client as Controller (see §6.6 and the Privacy Policy), with Garuna assisting — including by deleting a retained Report on the Client's instruction — to the extent any relevant Personal Data remains within its control.
6.6 Routing of Data-Subject requests. If Garuna receives a request directly from a Data Subject relating to Personal Data processed under this DPA, Garuna shall, unless legally prohibited, promptly forward the request to the Client and shall not respond to it directly except on the Client's documented instruction or as required by law.
6.7 Assistance with DPIAs and consultations. Taking into account the nature of the processing and the information available to Garuna, provide reasonable assistance to the Client with: data protection impact assessments and prior consultations with a supervisory authority (Articles 35–36 GDPR / UK GDPR); legitimate-interests / balancing assessments and transfer-impact assessments insofar as the Service architecture is relevant; and the Client's obligations regarding security and Personal Data Breaches (§§6.3, 8).
6.8 Demonstrating compliance and audits. Make available to the Client information reasonably necessary to demonstrate compliance with this DPA and, subject to the conditions in §10 (Audits), allow for and contribute to audits, including inspections, conducted by the Client or an auditor mandated by the Client.
6.9 No independent use. Not sell, retain, use, or disclose Subject Personal Data for any purpose other than providing the Service under the Documented Instructions, and not combine Subject Personal Data with other data for Garuna's own purposes.
7. Independent / Public Sources and Authenticated Platform Sessions (Clarification)
7.1 Independent / Public Sources. In delivering the Service, Garuna queries Independent / Public Sources (the public-record, registry, open-source, and platform services listed in Annex 3) with Subject identifiers (including, depending on configuration and Subject Inputs, the Subject's name, email, phone, username, or domain). Each such source acts as an independent controller of its own data and is not a Sub-processor of Garuna; Garuna does not control or direct its processing. These sources are disclosed in Annex 3 and in the Privacy Policy for transparency and cross-border-transfer purposes only.
7.2 Investigation Sessions. Where an Authorised User establishes an Investigation Session, the Service reuses only a session the Authorised User created by signing in themselves to their own or a duly authorised account; the Service never cracks, guesses, or bypasses authentication. The Service supports authenticated Investigation Sessions on X, Instagram, Reddit, LinkedIn, and Facebook. A connected session may be reused both to read the Subject's public engagement graph (currently on X and Instagram) and to retrieve authenticated profile photographs (on any connected platform, including LinkedIn) as part of identity disambiguation. Each platform queried is an independent platform, not a Sub-processor. The Authorised User is solely responsible for ensuring any account used is their own or duly authorised and for compliance with the relevant platform's terms of service; certain platforms (notably LinkedIn and the Meta properties Instagram and Facebook) prohibit automated access and investigation / "burner" accounts outright, so use may breach their terms. This responsibility rests with the Client / Authorised User as set out in the Terms and the Acceptable Use Policy and is acknowledged at the in-app gate for the specific platform connected.
7.3 Authenticated account lookup against a major email/account provider. Where enabled and the Authorised User has independently authenticated a session with a major email/account provider for the Service's optional authenticated-lookup capability, the Service may send the Subject's email address to that provider to surface the existence and public surface of an associated account (e.g. account identifier, public profile name/photo, enabled services, public review count). The provider acts as an independent platform / controller of its own data and is listed in Annex 3. The authentication credentials for this capability persist on disk in the Provider's local environment (see Annex 2 §2); this is the sole carve-out to the Session State "never written to disk" invariant, and the Authorised User is responsible for using only their own or a duly authorised account and for compliance with that provider's terms of service.
8. Personal Data Breach
8.1 Notification to the Client. Garuna shall notify the Client without undue delay, and in any event no later than forty-eight (48) hours after becoming aware of a Personal Data Breach affecting Personal Data processed under this DPA, so as to enable the Client to meet its own notification obligations (including the 72-hour obligation under GDPR / UK GDPR Article 33 and the "as soon as feasible" obligation under PIPEDA's breach-of-security-safeguards regime).
8.2 Content of notification. The notification shall, to the extent then known and as further information becomes available, describe: (a) the nature of the Personal Data Breach, including, where possible, the categories and approximate number of Data Subjects and Personal Data records concerned; (b) the likely consequences of the breach; (c) the measures taken or proposed to address it and to mitigate its possible adverse effects; and (d) a contact point for further information. Garuna shall provide further updates to the Client as additional information becomes available.
8.3 Cooperation. Garuna shall take reasonable steps to mitigate and, where possible, remediate the breach, and shall reasonably assist the Client in meeting the Client's own breach-notification and record-keeping obligations to Data Subjects and to supervisory / regulatory authorities (including the Office of the Privacy Commissioner of Canada under PIPEDA's breach-of-security-safeguards regime, and supervisory authorities under the GDPR / UK GDPR). Garuna shall not notify any Data Subject, supervisory authority, or other third party of a breach on the Client's behalf without the Client's prior instruction, unless required to do so by a law to which Garuna is subject.
8.4 The parties acknowledge that the data-minimising architecture of the Service (time-limited Report retention with automatic deletion, no standing Subject database, Session State held in memory only save for the authenticated-lookup credential carve-out in §7.3 / Annex 2 §2) materially reduces the population of Personal Data exposed to any server-side breach; this does not limit the obligations in this §8.
9. Sub-processors
9.1 General authorisation. The Client provides general written authorisation for Garuna to engage Sub-processors to process Personal Data in delivering the Service. The Sub-processors authorised as at the Effective Date are listed in Annex 3 (the Sub-processor List), which mirrors the data-flow inventory in the Terms / specification. A given Client deployment may use only a subset of the listed Sub-processors; in a fully-local configuration (self-hosted private meta-search plus on-device AI models), a Sweep can run with minimal third-party transfer, and certain Sub-processors (notably the Deep-Mode cloud AI synthesis & verification provider) are engaged only when the corresponding mode or backend is configured and used.
9.2 Flow-down obligations. Where Garuna engages a Sub-processor to carry out processing on the Client's behalf, Garuna shall impose on that Sub-processor, by written contract, data-protection obligations no less protective than those in this DPA, to the extent applicable to the Sub-processor's processing, including appropriate security measures and (where relevant) international-transfer mechanisms. Garuna remains liable to the Client for the performance of each such Sub-processor's data-protection obligations.
9.3 Notice of changes and objection. Garuna shall maintain the Sub-processor List (Annex 3) and shall give the Client prior notice of the addition or replacement of a Sub-processor (by updating the list and/or notifying the Client through the mechanism stated in the Terms), giving the Client the opportunity to object on reasonable data-protection grounds within thirty (30) days of the notice. If the Client reasonably objects and the parties cannot resolve the objection within thirty (30) days, Garuna shall, at its option, either (a) refrain from engaging the proposed Sub-processor for the Client's processing or continue providing the affected Service component using the existing Sub-processor; or (b) if neither is reasonably practicable, the Client may terminate the affected Service component (and, if the affected component is material to the Service as a whole, the Terms) on written notice, and shall receive a pro-rata refund of any prepaid fees for the terminated component covering the period after the effective date of termination. This is the Client's sole remedy for a Sub-processor objection that cannot be accommodated.
9.4 Independent / Public Sources excluded. For the avoidance of doubt, Independent / Public Sources and independent platforms (§7) are not Sub-processors and are not subject to §§9.1–9.3; they are listed in Annex 3 separately, for transparency and cross-border-transfer disclosure only.
10. Audits
10.1 Garuna shall make available to the Client information reasonably necessary to demonstrate compliance with this DPA. On the Client's reasonable written request (no more than once in any twelve-month period except where required by a supervisory authority or following a Personal Data Breach affecting the Client's processing), Garuna shall allow for and contribute to an audit of its compliance with this DPA.
10.2 Any audit is subject to reasonable conditions, including: reasonable advance written notice; conduct during normal business hours; minimal disruption to Garuna's operations; the auditor (and the Client) being bound by confidentiality obligations at least as protective as those in the Terms; scope limited to systems, records, and measures relevant to the processing of the Client's Personal Data; and no access to other clients' data, Garuna's trade secrets, or Personal Data of third parties. The parties shall bear their own costs, save that the Client shall bear Garuna's reasonable costs of supporting an on-site audit that goes beyond the provision of existing documentation. Garuna may satisfy an audit request, where reasonable, by providing existing reports, certifications, or written responses.
11. International Transfers
11.1 Disclosure. Cross-border transfer of Personal Data occurs only when Sub-processors, Independent / Public Sources, or authenticated platforms located outside Canada are used, as identified in Annex 3 (which discloses, in particular, that the Subject's email is sent to an email / identity reputation source and to a major email/account provider via the optional authenticated-lookup capability; the Subject's email and/or phone is sent to data-breach & credential-exposure intelligence sources where keyed; and the Subject's name, identifiers, or domain are sent to various US- and other foreign-based sources and platforms). In a fully-local configuration (§9.1), a Sweep can run with minimal third-party transfer.
11.2 Where the GDPR / UK GDPR applies. For transfers of Personal Data of Subjects in the EEA or United Kingdom to a country not benefiting from an adequacy decision, an appropriate Article 46 transfer mechanism must be in place before any such transfer occurs.
(a) Gating at go-live. The processing of Personal Data of Subjects located in the EEA or United Kingdom is disabled by default and must not be enabled for a Client unless and until completed and executed Standard Contractual Clauses (and, for the United Kingdom, the UK IDTA) are entered into between Garuna and the Client, with the Annexes fully populated as set out in §11.2(b). Until then, the Client must not use the Service to process Personal Data of EEA/UK Data Subjects, and Garuna does not represent that any unexecuted clauses are operative. Nothing in this DPA shall be read as asserting that unexecuted or un-populated clauses already "apply".
(b) SCC / IDTA schedules. Where the Client processes Personal Data of EEA/UK Data Subjects, the parties shall complete and execute, as executable schedules to this DPA at onboarding: the EU SCCs — Module Two (controller-to-processor) for transfers from the Client (or Garuna on its behalf) to Garuna, and Module Three (processor-to-processor) for onward transfers to Sub-processors located in non-adequate countries; and, for the United Kingdom, the UK IDTA. The Annexes to those clauses shall be populated as follows: the parties and competent supervisory authority (to be completed per Client); the description of processing = Annex 1 of this DPA; the technical and organisational measures = Annex 2 of this DPA; and the list of sub-processors = Annex 3 of this DPA. The parties shall also complete and record a transfer-impact assessment for the relevant transfers. For the Early Access programme, processing of EEA/UK Subject Personal Data is disabled by default (§11.2(a)); where a Client requires it, these SCC / IDTA schedules will be completed and executed between the parties at onboarding, before any such processing is enabled, and Garuna will make the template schedules available on request to [email protected].
(c) Where Garuna transfers to a Sub-processor in a non-adequate country, the relevant SCC / IDTA module governs, and Garuna shall flow down equivalent transfer protections to the Sub-processor under §9.2.
11.3 PIPEDA (Canada). For Personal Data subject to PIPEDA, Garuna remains accountable for Personal Data transferred to a Sub-processor for processing and shall use contractual means (per §9.2) to ensure a comparable level of protection while the Personal Data is being processed by the Sub-processor, consistent with PIPEDA's accountability principle and the guidance of the Office of the Privacy Commissioner of Canada on transfers for processing. The parties acknowledge that the Client, as Controller, is responsible for any transparency obligations to Data Subjects regarding such transfers. Independent / Public Sources and independent platforms are not Sub-processors and Garuna does not warrant a comparable level of protection in respect of them; transfers of Subject identifiers to such sources occur on the Client's instruction (§11.4) and the Client is responsible for the lawfulness of those transfers.
11.4 Subject-driven transfers. Where a Sweep itself necessarily sends Subject identifiers to foreign Independent / Public Sources or platforms selected through the Client's configuration and Sweep parameters (including, where enabled, the Subject's email or phone to account-existence discovery tooling and data-breach & credential-exposure intelligence sources, and the Subject's email to a major email/account provider via the optional authenticated-lookup capability), such transfers occur on the Client's instruction; the Client, as Controller, remains responsible for their lawfulness, Garuna disclosing the destinations in Annex 3.
11.5 Deep-Mode AI transfer — access tier. Where Deep Mode is used, collected source text and the Subject name are transmitted to a cloud AI synthesis & verification provider. The parties acknowledge that, as at the Effective Date, the access path is via a consumer-grade endpoint that is not covered by a signed data-processing agreement with that provider with no-training and zero/limited-retention commitments. Accordingly, Deep Mode is off by default (it is an opt-in, per-Sweep mode), and Garuna will not enable or recommend Deep Mode for a Client's regulated processing during the Early Access pilot. For so long as Deep Mode routes through that consumer-grade endpoint, Garuna does not warrant a "comparable level of protection" (PIPEDA) for that flow, and the Client is hereby disclosed that data sent to the cloud AI synthesis & verification provider in Deep Mode may be retained and/or used under that provider's then-current terms applicable to that endpoint. Garuna's stated posture, and the condition for asserting comparable protection / the suite's no-training position in respect of Deep Mode, is to route Deep Mode through an enterprise / API endpoint covered by such a DPA before relying on it for regulated processing. The Client should keep Deep Mode disabled (default / fast mode keeps synthesis on-device, with no AI transfer) unless it accepts this flow.
12. Deletion and Return on Termination
12.1 Limited store; residual transient data. Because the Service retains Reports only for a limited period and maintains no standing, searchable database of Subjects, on expiry or termination of the Terms Garuna deletes any Report, monitoring entry, or pending record-check input still within its retention period (or, on request, first returns the Report to the Client). Residual Subject Personal Data may nonetheless exist transiently in (i) short-lived operational logs and (ii) ephemeral temporary working files created during a Sweep (for example, the temporary output files written and consumed by certain account-discovery tools during a check). These residual records are deleted in the ordinary course — temporary working files at or shortly after the end of the relevant check, and operational logs on log rotation.
12.2 Reports. Each Report is streamed to the Client and may be exported by the Client; once exported, the Client controls that copy and is responsible for its security, retention, and lawful use and deletion. Garuna does not retain a server-side copy.
12.3 Residual operational records. On the Client's written request following termination, Garuna shall, to the extent any of the residual records described in §12.1 remain within its control and to the extent technically feasible, delete or anonymise the Personal Data within them, save where retention is required by law.
12.4 Reference data. The only on-disk cache maintained by the Service for reference data is the public government sanctions & watchlist reference lists (refreshed approximately every 24 hours). This is public reference data, not Subject-specific Personal Data, and is not subject to return or deletion on a per-Client basis. (The credential file used by the optional authenticated-lookup capability, where enabled, is addressed separately in §7.3 and Annex 2 §2 and is the analyst's own credential, not Subject Personal Data.)
13. Liability and Order of Precedence
13.1 Precedence. This DPA forms part of the Terms. In the event of any conflict or inconsistency between this DPA and the body of the Terms on any matter concerning the processing of Personal Data, this DPA prevails. On all other matters, the body of the Terms prevails. Where the GDPR / UK GDPR SCCs apply, the SCCs prevail over this DPA to the extent of any conflict, as required by those clauses.
13.2 Liability. Each party's liability arising out of or in connection with this DPA is subject to the exclusions and limitations of liability set out in the Terms, including the aggregate liability cap in Terms §13.2, to the maximum extent permitted by Applicable Data Protection Law. Nothing in this DPA limits any liability that cannot be limited or excluded under Applicable Data Protection Law.
13.3 Allocation. As between the parties, and without prejudice to either party's obligations to Data Subjects or regulators under Applicable Data Protection Law, the Client (as Controller) is responsible for the lawfulness of the processing it instructs (including lawful basis, authority, transparency, use of Output, and any Investigation Session it establishes), and Garuna (as Processor) is responsible for processing in accordance with the Documented Instructions and this DPA.
14. General
14.1 This DPA takes effect on the Effective Date and continues for so long as Garuna processes Personal Data on the Client's behalf under the Terms. Provisions that by their nature should survive termination (including §§6.6, 8, 12, 13) survive.
14.2 This DPA is governed by the Province of Ontario and the federal laws of Canada applicable therein, and is subject to the forum / venue provisions of the Terms, except where the SCCs require a different governing law or forum for transfers to which they apply.
14.3 Notices under this DPA shall be given in accordance with the Terms; data-protection notices (including breach notifications and Sub-processor-change notices) may also be given to the Client's designated privacy contact and may be sent to Garuna at [email protected].
14.4 Except as expressly modified by this DPA, the Terms remain in full force and effect.
Annex 1 — Details of Processing
(Article 28(3) GDPR / UK GDPR; record of processing.)
| Item | Detail |
|---|---|
| Subject-matter | Provision of the Enhanced Due Diligence (EDD) Service: compilation of open-source due-diligence Reports on third-party Subjects via Sweeps. |
| Duration | Per-Sweep with limited retention: Subject Personal Data processed for the duration of each Sweep; the resulting Report retained for a limited period (currently thirty days) and then deleted; monitoring identifiers for the life of a monitoring entry; paid record-check inputs until fulfilment or cancellation. Residual transient records (short-lived operational logs; ephemeral temporary working files created during a Sweep) are deleted in the ordinary course (logs on rotation; temporary files at/after end of check). The DPA endures for the term of the Terms. |
| Nature of processing | Collection, retrieval, organisation, structuring, identity disambiguation and resolution, analysis, risk scoring, citation-enforced AI-assisted synthesis, and streamed delivery of the Report to the requesting Client. |
| Purpose of processing | To enable the Client to conduct lawful due diligence (KYC/KYB/AML, vendor/counterparty/third-party risk, fraud and integrity investigations, litigation support, and lawful pre-employment screening not used as a consumer report). No use as a consumer report or for FCRA / provincial consumer-reporting eligibility decisions; no solely-automated significant decision. |
| Categories of Data Subjects | Subjects of investigations (third-party natural persons; natural persons connected to Subject entities such as officers, directors, beneficial owners, and persons with significant control); identifiable individuals incidentally appearing in collected open-source material. Subjects are generally unaware of the Sweep. |
| Types of Personal Data | Subject Inputs (legal full name, jurisdiction, email, phone, alias/username, domain, free-text context); collected open-source material (web results, news / adverse-media references, social and digital-footprint signals, account-existence indicators, public engagement-graph data); public-record / registry data; risk-scoring and identity-resolution outputs. |
| Special categories / sensitive data | May incidentally include: criminal-conviction, offence, allegation, litigation, court / tribunal, and regulatory / enforcement data (Article 10 GDPR); sanctions / watchlist screening results (name-based, indicative only); and other Article 9 GDPR special-category data where present in public sources. The Service does not seek such data but cannot exclude its incidental presence. Controller responsible for any Article 9 / Article 10 condition. |
| Frequency of processing | On the Client's instruction, per Sweep, as initiated by Authorised Users. |
| Controller | The Client (for Subject Personal Data). Garuna is Controller of Client/Authorised-User account, contact, authentication, and billing data (§2.4). |
| Processor | Garuna Inc. (operating as "Garuna Group"), 10 Thornmount Drive, Toronto, Ontario M1B 3J4, Canada (for Subject Personal Data). |
| Sub-processors | As set out in Annex 3. |
Annex 2 — Technical and Organisational Security Measures
Garuna implements and maintains measures appropriate to the risk, including:
1. Data minimisation and limited retention. - Subject / Personal Data is processed in memory only for the duration of a Sweep. - There is no standing, searchable database of Subjects. Completed Reports are retained for a limited period (currently thirty days) so the requesting Client can retrieve them, then deleted automatically; the Client may export a Report and thereafter controls that copy. - In-process web-search results are cached in memory only (LRU, size-capped, approximately one hour) and are not written to disk. - Residual Subject Personal Data may exist transiently in short-lived operational logs (see §3) and in ephemeral temporary working files created by certain account-discovery tools during a check; such temporary files are consumed and removed in the ordinary course at or shortly after the end of the check. - The only on-disk cache maintained by the Service for reference data is the public government sanctions & watchlist reference lists, downloaded in bulk from the relevant government sanctions & watchlist sources (not a Subject query) and refreshed approximately every 24 hours — public reference data, not Subject-specific. This file is stored in the operating-system temporary directory of Garuna's single-tenant server, to which access is limited to the Service's operating user. It contains public reference data only and no Subject-specific Personal Data, so its file permissions do not expose any Subject data. Garuna may relocate this cache to a hardened path in a future release.
2. Investigation Session ("Session State") controls — and the authenticated-lookup credential carve-out. - For browser-based authenticated platform sessions on mainstream social platforms (such as X, Instagram, Reddit, LinkedIn, and Facebook), captured browser authentication state (cookies) is held in process memory only, is never written to disk, is never logged (only a cookie count is logged), and is never serialised into a Report or export. - The Service interface exposes only booleans and the Authorised User's own account handle in respect of such a session. - A connected session may be reused both for public engagement-graph reads (currently on the platforms that expose such data) and for authenticated profile-photo retrieval (any connected platform), as part of identity disambiguation. - Authentication is never cracked, guessed, or bypassed; sessions are created by the Authorised User signing in themselves and can be disconnected by the Authorised User. - Carve-out — authenticated-lookup credential. Where the optional authenticated-lookup capability against a major email/account provider is enabled, the Authorised User authenticates a session with that provider for the capability separately, and the resulting credentials persist on disk in the Provider's local environment (a credential file under the Provider's home directory). This is the sole exception to the "never written to disk" invariant above. Such credentials are not serialised into a Report or export. The capability ships disabled until the Authorised User completes its one-time login, and Garuna keeps it disabled for the Early Access pilot unless a Client is specifically notified otherwise. The credential file is stored under the Provider's home directory on the single-tenant server, with access limited to the Service's operating user; it relates to the Authorised User's own session with that provider (the analyst's own credential), not to any Subject.
3. Logging and access control. - Operational logs are INFO-level and may transiently record the Subject name, subject type, the sessions / scope used, the Deep-Mode flag, and timing. - Logs are access-controlled and short-lived, are subject to rotation, and do not constitute a Report store.
4. Processing-mode controls. - Deep Mode (which engages a cloud AI synthesis & verification provider, including its verification-fetch component) is optional; in default / fast mode, AI synthesis runs on-device with no AI transfer. The data-protection posture of the Deep-Mode AI transfer is addressed in §11.5. - A fully-local configuration (self-hosted private meta-search plus on-device AI models) enables Sweeps with minimal third-party transfer.
5. Synthesis integrity. - AI synthesis is citation-enforced: every sentence must cite a real numbered source or it is dropped (zero-fabrication design); identity resolution excludes same-name strangers and discloses confidence and excluded rival identities. (This is an accuracy / integrity control, not a guarantee that Output is error-free.)
6. Confidentiality. - Personnel authorised to process Personal Data are bound by confidentiality obligations and process only as instructed.
7. Sub-processor and transfer controls. - Sub-processors are engaged under written contracts with flow-down obligations and, where relevant, international-transfer mechanisms (§9.2, §11).
8. Additional technical and organisational measures. - Encryption in transit — Personal Data in transit is protected using current TLS. - Authentication and access management — access to the Service is controlled by authentication and least-privilege principles, both for Authorised Users and for Garuna personnel who administer the Service. - Network controls — the host is firewalled and, during the Early Access pilot, the Service is reachable only over the Provider's private network (loopback / private mesh VPN) and is not exposed to the open internet. - Change, dependency, and vulnerability management — the Service and its components are kept under change control, and dependencies are monitored for known vulnerabilities. - Logging and monitoring — administrative access is logged and monitored. - Incident response — Garuna maintains a documented incident-response and breach-notification procedure consistent with §8 of this DPA. - Review — Garuna reviews these measures periodically and as the Service evolves toward general availability.
Annex 3 — Sub-processor List
This Annex is the Sub-processor List for this DPA and mirrors the authoritative data-flow inventory in the Terms / specification and the actual processing performed by the Service. It is a living list maintained by Garuna; changes are notified under §9.3. A given Client deployment may use only a subset of the entries below; in a fully-local configuration a Sweep can run with minimal third-party transfer. Independent / Public Sources and independent platforms are listed separately for transparency and cross-border-transfer disclosure and are not Sub-processors.
A. On-device / self-hosted — no third-party transfer
| Component category | Data handled | Location |
|---|---|---|
| Self-hosted private meta-search (default search backend) | Subject name + query terms | Garuna server (localhost) |
| On-device AI model (synthesis) | Collected source text + Subject name | Garuna server (on-device) |
| On-device identity adjudication (assist-only) | Ambiguous same-name cluster data | Garuna server (on-device) |
B. Sub-processors — search / infrastructure (receive Subject name + query terms)
| Sub-processor category | Data received | Location / transfer | Mode |
|---|---|---|---|
| Web-search providers (open-web search backends) | Subject name + query terms | US / EU / foreign — cross-border | Configurable; several are key-free, some keyed |
| Commercial web-retrieval / proxy provider | Query terms; target public-page URLs to retrieve (which may embed the Subject name; including trademark top-hit fetches and anti-bot 403 retries) | Foreign — cross-border | Configurable / keyed |
C. Sub-processors — AI synthesis & verification (Deep Mode only; receive collected source text + Subject name)
| Sub-processor category | Data received | Location / transfer | Mode |
|---|---|---|---|
| Cloud AI synthesis & verification provider (including its verification-fetch component, which retrieves third-party page URLs for claim verification) | Collected source text + Subject name; third-party page URLs for claim verification | Foreign (US) — cross-border | Deep Mode only; off by default. Consumer-grade OAuth endpoint not covered by a data-processing agreement with that provider — access-tier / no-comparable-protection disclosure per §11.5 |
D. Independent / Public Sources and independent platforms — queried with Subject identifiers (NOT Sub-processors; independent controllers; listed for transparency / cross-border disclosure)
| Source category | Data sent | Location / transfer | Mode |
|---|---|---|---|
| Government sanctions & watchlists (Canada / UN / UK / US) | None per query — the consolidated public lists are downloaded in bulk and cached on disk ~24h (reference data, not Subject-specific); screening is local fuzzy-match | Bulk download (no per-Subject query) | Key-free; default |
| Aggregated international sanctions / PEP reference | Subject name | Foreign — cross-border | Keyed-optional |
| Court, tribunal & case-law repositories — Canada | Subject name — by-name search of the public search interface, optionally enriched with official-API metadata and neutral citation where an API key is configured (the official API has no by-name search). Results are used on a metadata / link-out basis and attributed to the source repository. Garuna uses such data for the Client's internal due-diligence purpose only and does not redistribute it as a data product. | Canada (domestic) | Default (public search); keyed-optional (API enrichment) |
| Court, tribunal & case-law repositories — United States | Subject name | US — cross-border | Default |
| Securities & corporate-disclosure filings — United States | Subject name | US — cross-border | Default |
| Corporate / business registries & legal-entity identifiers — UK / Australia / global | Entity name / officers | Foreign / UK / AU — cross-border | Some default, some keyed-optional |
| Structured public knowledge graph (nonprofit reference) | Subject name | Foreign — cross-border | Default |
| Global news & media archives | Subject name / keyword | US / foreign — cross-border | Default |
| Official motor-carrier safety & licensing records (US) | Entity name / USDOT / MC | US — cross-border | Key-free / keyed |
| Data-breach & credential-exposure intelligence | Email and/or phone and/or username | Foreign — cross-border | Keyed-optional |
| Email / identity reputation | Email (sent as a one-way hash where the service supports it) | US / foreign — cross-border | Default / keyed-optional |
| Domain registration & certificate-transparency records | Domain (no personal identifiers) | Foreign — cross-border | Default / keyed-optional |
| Patent & trademark registries — US / international | Subject name (owner / applicant of record; a top registry page may additionally be retrieved through the commercial web-retrieval provider — see Group B) | US / foreign — cross-border | Default |
| Public code / developer-platform presence | Username / Subject name | US — cross-border | Default |
| Web archive & historical snapshots (nonprofit) | URLs / domain | US — cross-border | Default |
| Federated and community platforms | Username / handle | US / federated / foreign — cross-border | Default |
| Account-existence discovery tooling | See breakdown below — Subject email, phone, and/or username sent to the relevant target sites to detect account existence | Many foreign sites — cross-border | Default (each gated on its software dependency) |
| Major email/account provider (via an authenticated lookup) | Subject email → resolves the public account surface associated with it (e.g. account identifier, public profile name/photo, enabled services, public review count) | US — cross-border; analyst-authenticated; the provider's credentials persist on disk (Annex 2 §2) | Optional; ships disabled until the Authorised User completes a one-time login to that provider |
| Mainstream social platforms (such as X, Instagram, Reddit, LinkedIn, and Facebook) (via an Investigation Session) | Reads the Subject's public engagement graph (on platforms that expose it) and/or retrieves authenticated profile photos (any connected platform) through the Authorised User's own logged-in session | US / foreign — cross-border | Optional; analyst-initiated. Some platforms (notably LinkedIn, and the Meta properties Instagram/Facebook) prohibit automated access and investigation/"burner" accounts — use may breach their terms (§7.2) |
Account-existence discovery tooling — breakdown. This category uses open-source techniques that query many third-party websites directly to detect whether accounts associated with a Subject identifier exist. Depending on the identifier supplied, the Subject email, phone number, and/or username is sent to the relevant target sites. All checks are key-free and enabled by default, but each is gated on its software dependency being installed; where a tool is absent the Service records a gap rather than transferring data. Each queried site is an independent controller of its own data; cross-border transfer to those foreign sites occurs when this tooling is used.
Notes. - The list reflects a maximal configuration and the actual processing performed by the Service; an individual deployment may use a subset. A fully-local configuration (Section A only) minimises third-party transfer. - The government sanctions & watchlist reference lists are the only on-disk cache for reference data and are public reference data, not Subject-specific. The optional authenticated-lookup capability against a major email/account provider, where enabled, also persists the analyst's own credentials on disk (Annex 2 §2). - Independent / Public Sources and independent platforms (Section D) are independent controllers of their own data and are not Sub-processors; they are listed for transparency and cross-border-transfer disclosure only. The commercial web-retrieval / proxy provider and (where keyed) the data-breach & credential-exposure intelligence sources behave as infrastructure receiving Subject identifiers/queries — the commercial web-retrieval / proxy provider is treated as a Sub-processor (Group B) for the retrieval / unblocking fetches it performs on Garuna's behalf, while the data-breach & credential-exposure intelligence sources are listed here as Independent Sources queried with Subject identifiers. - This Annex must match the actual processing performed by the Service code, not only the specification table; any divergence is resolved in favour of accurate disclosure.
This Data Processing Addendum forms part of the Terms of Service / Master Services Agreement between the Client and Garuna Group and prevails over the body of the Terms on matters concerning the processing of Personal Data. Version 1.0 — Effective 2026-06-27. Data-protection contact: [email protected].