How this DPA works: This agreement is incorporated by reference into the main service agreement between Glass Pyramid Group and each client. By signing a service agreement or commencing use of a Glass Pyramid OS system, the client and Glass Pyramid Group agree to be bound by this DPA. A separate signature is not required unless requested by either party.
This Data Processing Agreement (“DPA”) is entered into between:
- Data Processor: Global Connect & Partners S.L. (NIF: ES-B 269 939 72), trading as Glass Pyramid Group, CL. Pizarro 41, 1 · 29670 San Pedro Alcántara, Marbella, España (“Processor”).
- Data Controller: The client entity identified in the service agreement (“Controller”).
1. Definitions
- “Personal Data” — any information relating to an identified or identifiable natural person, as defined in GDPR Art. 4(1).
- “Processing” — any operation performed on Personal Data, including storage, retrieval, use, disclosure, or deletion.
- “GDPR” — EU General Data Protection Regulation (Regulation 2016/679).
- “Services” — the software systems, operational portals, and related services provided by the Processor to the Controller under the service agreement.
- “Sub-processor” — a third party engaged by the Processor to carry out Processing activities on behalf of the Controller.
2. Subject Matter and Duration
The Processor provides the Services to the Controller, which may involve Processing Personal Data on behalf of the Controller. This DPA covers all Personal Data processed by the Processor in connection with delivering the Services, for the duration of the service agreement plus any legally required retention periods.
3. Nature and Purpose of Processing
The Processor processes Personal Data solely to:
- Operate, maintain, and support the Controller's deployed software system.
- Store and retrieve data entered by the Controller or its authorised users.
- Send automated communications (invoices, notifications, onboarding documents) on behalf of the Controller where configured.
- Provide technical support when requested by the Controller.
The Processor does not process Personal Data for any other purpose, including its own commercial, marketing, or analytical purposes.
4. Categories of Data Subjects and Personal Data
Depending on the Services used, the Controller's data may include:
- Clients / customers of the Controller — name, email, phone, address, company details, financial information.
- Employees or team members of the Controller — name, role, contact information, work hours, HR records.
- Prospects and leads — name, email, company, communication history.
- Suppliers or partners — company name, contact details, financial data.
5. Obligations of the Processor
The Processor shall:
- Process Personal Data only on documented instructions from the Controller, and notify the Controller promptly if it believes an instruction infringes applicable data protection law.
- Ensure that all personnel with access to Personal Data are bound by confidentiality obligations.
- Implement appropriate technical and organisational security measures pursuant to GDPR Art. 32, including encryption in transit (HTTPS/TLS), database-level row security, and access controls.
- Not engage any Sub-processor without the Controller's prior general or specific authorisation. Current Sub-processors are listed in Annex B. The Controller is deemed to have given general authorisation to those listed at the time of signing. The Processor will notify the Controller of intended changes at least 14 days in advance.
- Assist the Controller in responding to data subject rights requests (access, rectification, erasure, portability, restriction, objection) where the Controller cannot act directly.
- Notify the Controller without undue delay (and within 72 hours where feasible) upon becoming aware of a Personal Data breach involving the Controller's data.
- Assist the Controller with Data Protection Impact Assessments (DPIAs) where required.
- At the Controller's election upon termination of the service agreement, delete or return all Personal Data and delete existing copies, unless EU or member state law requires continued storage.
- Make available all information necessary to demonstrate compliance with GDPR Art. 28 obligations and allow for audits conducted by the Controller or its designated auditor, subject to reasonable notice and confidentiality protections.
6. Obligations of the Controller
The Controller shall:
- Ensure it has a valid legal basis for Processing the Personal Data it shares with or through the Processor.
- Provide complete and accurate instructions regarding the Processing of Personal Data.
- Promptly notify the Processor of any changes to Processing requirements that may affect the Services.
- Be solely responsible for the accuracy, quality, and legality of Personal Data entered into the system.
- Ensure appropriate privacy notices are provided to data subjects whose data will be processed through the system.
7. International Data Transfers
The Processor uses Sub-processors based outside the EEA (see Annex B). All international transfers are protected by:
- EU Standard Contractual Clauses (SCCs) incorporated in Sub-processor agreements.
- Adequacy decisions where applicable (EU-US Data Privacy Framework).
- Preference for EU-region infrastructure where technically available (Supabase: Frankfurt; Vercel: EU edge).
8. Security Measures
The Processor maintains the following measures at minimum:
- All data in transit encrypted via HTTPS/TLS 1.2 or higher.
- Database-level row security (Supabase RLS) ensuring logical separation between Controller instances.
- Authentication via signed JWTs with appropriate expiry.
- File upload validation (MIME type and size limits).
- No logging of Personal Data in application logs.
- Environment secrets stored securely via Vercel (never in source code).
- Regular review of Sub-processor security certifications (SOC 2, ISO 27001 where available).
9. Liability
Each party's liability under this DPA is subject to the limitations set out in the main service agreement. The Processor is liable for damages caused by Processing where it has not complied with GDPR obligations specifically directed to processors, or where it has acted outside or contrary to the Controller's lawful instructions. The Controller is liable for damages caused by non-compliant instructions or its own obligations under GDPR.
10. Governing Law
This DPA is governed by the laws of Spain. Disputes arising under this DPA are subject to the exclusive jurisdiction of the courts of Marbella, Spain, unless the applicable GDPR supervisory authority requires otherwise.
Annex A — Processing Details
Processor: Global Connect & Partners S.L. (Glass Pyramid Group)
Nature of processing: Storage, retrieval, display, and automated transmission of business data.
Purpose: Operation of a custom business operating system (CRM, invoicing, HR, documents, communication) on behalf of the Controller.
Duration: For the term of the service agreement plus any legal retention obligations.
Annex B — Authorised Sub-processors
The following sub-processors are authorised at the time of signing. The Controller will be notified of any changes with 14 days' notice.
- Supabase Inc. (USA) — Database hosting and authentication. Data stored in EU region (Frankfurt, AWS eu-central-1). Privacy policy.
- Vercel Inc. (USA) — Application hosting and edge delivery. EU region used. Covered by EU-US DPF. Privacy policy.
- Resend Inc. (USA) — Transactional email delivery (invoices, notifications, document links). Privacy policy.
- Anthropic PBC (USA) — AI-assisted document processing where enabled. Zero retention policy applied; data is not used for training. Privacy policy.
- Google LLC (USA) — Gmail/Calendar integration (if configured) and Google Drive (if configured). Governed by Google Workspace DPA. Privacy policy.
Annex C — Security Incident Response
In the event of a confirmed or suspected Personal Data breach:
- The Processor will notify the Controller by email within 72 hours of becoming aware of the breach.
- The notification will include: the nature of the breach; the categories and approximate number of data subjects affected; the categories and approximate number of records affected; the likely consequences; and measures taken or proposed to address the breach.
- The Processor will cooperate fully with the Controller's investigation and remediation efforts.
- The Controller is responsible for notifying the relevant supervisory authority and affected data subjects where required by GDPR.
Security incidents are reported to: info@glasspyramidgroup.com
DPA Version 1.0 · August 2026 · Glass Pyramid Group · Global Connect & Partners S.L. · NIF: ES-B 269 939 72
For a countersigned PDF copy of this DPA, contact info@glasspyramidgroup.com.