Effective 14 August 2026
Data Processing Addendum
This Data Processing Addendum forms part of the agreement between a business customer and Guildcores Pte. Ltd. whenever Guildcores processes personal data on that customer's behalf through the Guildcores service.
Guildcores Pte. Ltd. is incorporated in Singapore and has its registered office at 68 Circular Road, #02-01, Singapore 049422. Data protection communications can be sent to info@guildcores.com.
1. Scope and order of precedence
This addendum applies to personal data contained in customer content where the customer determines the purpose and essential means of processing and Guildcores processes the data to provide the service. The customer is the controller and Guildcores is the processor. If a customer acts as a processor for another controller, Guildcores acts as that customer's subprocessor and the customer confirms that its instructions are authorised by the relevant controller.
This addendum is incorporated only when a signed order form or other written acceptance identifies this addendum and its version date. Guildcores does not currently operate an in-product clickwrap for this document, so the written acceptance record must be retained with the customer agreement.
If this addendum conflicts with another part of the agreement about processing customer personal data, this addendum controls. The applicable transfer terms control over this addendum for a restricted transfer. Commercial liability terms in the agreement continue to apply unless this addendum expressly says otherwise.
2. Definitions
"Applicable Data Protection Law" means the privacy and data protection law that applies to the relevant processing, including Singapore's Personal Data Protection Act 2012, the European Union General Data Protection Regulation, and the United Kingdom GDPR where applicable.
"Customer Personal Data" means personal data in customer content that Guildcores processes on the customer's behalf.
"Personal Data Breach" means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Personal Data.
"Restricted Transfer" means a transfer of Customer Personal Data that requires a recognised transfer mechanism under Applicable Data Protection Law.
"Subprocessor" means a third party appointed by Guildcores to process Customer Personal Data for the service.
Terms such as controller, processor, personal data, processing, and supervisory authority have the meanings given by Applicable Data Protection Law.
3. Customer instructions and responsibilities
Guildcores will process Customer Personal Data only:
- to provide, secure, support, and maintain the service described in the agreement;
- through features, settings, and connected services selected by authorised users;
- as stated in this addendum and the customer's documented instructions;
- as required by law, after informing the customer before processing unless the law prohibits notice.
The agreement, product configuration, support requests, and authorised use of the service are the customer's documented instructions. Guildcores will notify the customer if, in its reasonable opinion, an instruction infringes Applicable Data Protection Law and may pause the affected processing while the parties address it.
The customer is responsible for the lawfulness, accuracy, and quality of Customer Personal Data, required notices and consents, its instructions, user permissions, and responding to individuals as controller. The customer must not instruct Guildcores to process data in a way that violates law or the agreement.
4. Confidentiality and personnel
Guildcores will limit access to Customer Personal Data to personnel who need it to operate, secure, support, or comply with obligations for the service. Those personnel are subject to contractual, professional, or statutory confidentiality duties and receive instructions appropriate to their role.
Guildcores remains responsible for its personnel's compliance with this addendum. The customer authorises ordinary access needed to investigate support requests, security incidents, service failures, and documented customer instructions.
5. Security measures
Guildcores will maintain reasonable technical and organisational measures appropriate to the nature of Customer Personal Data, the service, implementation costs, and the risks to individuals. Current measures include:
- Google single sign-on for the Guildcores instance;
- role and feature permissions, with restricted notebook and document visibility;
- HTTPS for supported browser traffic;
- production hosting in a controlled virtual server environment;
- authentication, access, change, and AI action records retained for up to 400 days;
- human approval records for AI proposed task and relationship changes;
- recurring database and uploaded-file backups;
- version control review, automated application tests, system tests, static security analysis, and dependency review;
- limited production and connected-service administration;
- data export and deletion procedures.
The current service does not provide application-level field encryption for most Customer Personal Data, end-to-end encryption, a Guildcores SOC 2 or ISO 27001 certification, independent penetration testing, or automated security anomaly alerts. These limits are described on the Security page and are part of the customer's security assessment. Guildcores will not materially reduce the safeguards for a paid service during an active term without reasonable notice, except where required for security, law, or urgent provider changes.
6. Subprocessors
The customer gives Guildcores general written authorisation to use the subprocessors listed on the Subprocessors page. Guildcores will use a subprocessor for Customer Personal Data only under the provider terms or another written agreement applicable to that processing. Public links to provider terms do not establish that a separate vendor Data Processing Addendum or transfer instrument has been executed. The applicable order form or transfer schedule must record any customer-specific transfer requirement before the restricted processing begins.
Guildcores remains responsible for a subprocessor's performance to the extent required by Applicable Data Protection Law and the agreement.
Guildcores will give at least 30 days' advance notice before adding or replacing a material subprocessor, unless an urgent security or legal reason makes advance notice impractical. A customer may object during the notice period on reasonable data protection grounds. The parties will work in good faith on a commercially reasonable alternative. If no alternative is available, either party may terminate the affected service without penalty for the unused prepaid period. An emergency change may proceed where needed to protect data or keep processing lawful, with notice as soon as reasonably possible.
7. Individual rights
Taking into account the nature of the processing, Guildcores will provide reasonable assistance for the customer to respond to a lawful request to access, correct, delete, restrict, object to, or export Customer Personal Data.
If Guildcores receives a request directly about Customer Personal Data, it will direct the requester to the customer where practical and will not respond substantively without the customer's instruction, unless law requires a response. The customer may use available administrator tools and structured exports before requesting additional assistance. Guildcores may charge reasonable costs for unusual or extensive assistance where law permits and the need was not caused by Guildcores' breach.
8. Personal Data Breaches
Guildcores will notify the customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data and, where feasible, within 72 hours of that awareness. Guildcores will not wait to confirm every fact before giving the first notice. Notification will include the information reasonably available about:
- the nature of the breach and affected data or people;
- likely consequences;
- containment, investigation, and remediation steps;
- a contact for follow-up.
Guildcores may provide information in phases as the investigation develops. Notification is not an admission of fault or liability. Guildcores will take reasonable steps to contain and remediate a breach and will preserve available evidence.
The customer remains responsible for deciding whether to notify an authority or individual and for meeting deadlines that apply to it as controller. Guildcores will provide reasonable assistance with those duties. Guildcores may notify an authority directly where law requires it to do so.
9. Compliance assistance and information
Taking into account the nature of processing and information available to it, Guildcores will provide reasonable assistance with data protection impact assessments, prior consultations with authorities, security reviews, and records needed for the customer to demonstrate compliance.
Guildcores will make available the information reasonably necessary to show compliance with this addendum. No more than once in any 12 month period, the customer may request a remote review of relevant documentation. If that is not reasonably sufficient, the customer may request an audit by an independent qualified auditor bound by confidentiality, on at least 30 days' notice, during normal business hours, and without unreasonable disruption. Additional audits are permitted after a confirmed breach or where an authority requires one.
The customer bears reasonable audit costs unless the audit identifies a material breach by Guildcores. Audits must not expose another customer's data, compromise security, or require access to information protected by law or another confidentiality obligation. Guildcores may satisfy a request with current third party reports when such reports become available.
10. International transfers
The customer authorises processing in Singapore, Japan, the United States, and other countries used by the authorised subprocessors, subject to Applicable Data Protection Law. Guildcores will maintain an appropriate mechanism for a Restricted Transfer where one is required.
For a transfer governed by the European Union GDPR, the European Commission Standard Contractual Clauses adopted by Implementing Decision 2021/914 apply only when the parties execute or otherwise validly enter into the relevant clauses before the restricted transfer. The order form or transfer schedule must record the selected module and completed annex information. When entered into:
- Module Two applies where the customer is a controller and Guildcores is a processor.
- Module Three applies where the customer is a processor and Guildcores is a subprocessor.
- Docking applies as permitted by the clauses.
- Optional Clause 7 applies. For Clause 9, Option 2 and a 30 day notice period apply.
- The supervisory authority is determined under Clause 13. The clauses are governed by the law of Ireland where a European Union member state choice is required, and Irish courts are selected under Clause 18.
- Annex information is supplied by the agreement, this addendum, the schedules below, and the Subprocessors and Security pages.
For a transfer governed by the United Kingdom GDPR, the parties will execute or otherwise validly enter into the United Kingdom International Data Transfer Addendum to the European Commission clauses or the United Kingdom International Data Transfer Agreement, as applicable, before the restricted transfer. The United Kingdom mechanism is separate from the European Union clauses and must be completed using the agreement and schedules below.
If a transfer mechanism is invalidated, the parties will cooperate to adopt another lawful mechanism. Nothing in this section reduces a party's duty to assess a transfer under the law that applies to it.
11. Return and deletion
During the term, an authorised administrator can request or generate an available structured export. At the end of the service, the customer may choose whether Guildcores returns or deletes Customer Personal Data. The customer must give that instruction before termination or during the 30 day post-termination period. If the customer chooses return, Guildcores will provide an available structured export before deleting the active copy. If the customer gives no instruction by the end of that period, the default is deletion. Guildcores will schedule active Customer Personal Data for deletion within 30 days after termination or a valid deletion instruction, unless law or the agreement requires retention.
After return or when deletion is selected, Guildcores will delete all remaining copies unless applicable law requires continued storage. Server backup copies age out after 14 days. Designated operator backup copies age out after up to 30 days. Expired and downloaded export archives are purged by a recurring process. Residual backup copies remain protected, are not returned to ordinary service use, and are deleted as they age out. Guildcores may retain limited information needed for legal claims, billing, fraud prevention, or compliance, subject to applicable law. Any legally retained copy remains isolated from ordinary service use and is deleted when the retention reason ends.
12. Liability and termination
Liability arising from this addendum is subject to the exclusions and caps in the agreement, except to the extent Applicable Data Protection Law does not permit that limitation. A material uncured breach of this addendum is a material breach of the agreement. Rights and obligations that must continue to protect retained Customer Personal Data survive termination.
Schedule 1: Processing details
| Item | Description |
|---|---|
| Subject matter | Hosting and operation of the Guildcores project management, relationship, meeting, document, search, connected-service, and AI assistance features selected by the customer |
| Duration | The service term, the 30 day post-termination deletion period, and the limited backup or legal retention period described in this addendum |
| Nature of processing | Collection, recording, organisation, storage, retrieval, consultation, search, transcription, analysis, generation, extraction, transmission to authorised providers, export, restriction, and deletion |
| Purpose | To provide, secure, support, and maintain the contracted service under the customer's documented instructions |
| Frequency | Continuous or event-driven according to authorised user activity, configured connections, and recurring service jobs |
Schedule 2: People and data
| Item | Description |
|---|---|
| Data subjects | Customer users and staff, contacts, talent, brand representatives, counterparties, clients, vendors, meeting participants, people named in documents or communications, and other people whose data the customer lawfully submits |
| Account data | Name, work email, profile image, role, team, language, professional profile, account identifiers, permissions, and sign-in information |
| Business and relationship data | Contact details, organisation, role, professional history, relationship type and strength, skills, introductions, interaction history, reminders, and notes |
| Project and content data | Projects, tasks, dates, status, documents, notebooks, source excerpts, meeting notes, transcripts, contracts, invoices, comments, feedback, prompts, messages, and generated output |
| Files and media | Uploaded files, images, avatars, voice recordings, audio transcripts, and associated metadata |
| Technical data | IP address, user agent, timestamps, request information, identifiers, integration scopes and credentials, audit records, errors, and service usage information |
| Sensitive data | Not required for ordinary use. Free text, recordings, and uploads may contain sensitive or special category data selected by the customer. The customer must not submit it unless necessary, lawful, and covered by appropriate safeguards and instructions. |
Schedule 3: Approved subprocessors and safeguards
The current approved providers, purposes, data categories, and principal locations are listed on the Subprocessors page. The current technical and organisational measures, including known limitations, are listed on the Security page. Those pages are incorporated into this addendum as maintained records. A change remains subject to Section 6 and may not materially reduce the protection required by this addendum.
Contact
Guildcores Pte. Ltd. 68 Circular Road, #02-01 Singapore 049422 info@guildcores.com