Data Processing Addendum
CGE Insights, a service of Pitch Cloud, LLC — GDPR Article 28 processor terms, with a distinct pooled-learning controller provision.
Provider and Processor. Pitch Cloud, LLC, operating CGE Insights, of 1012 W. Eldorado Pkwy, Unit 501, Little Elm, TX 75068.
Customer and Controller. The Customer named in the Order Documentation.
Effective date. The date of the Customer's Order Documentation.
Applies to. Member personal data processed by CGE Insights for the Customer.
Role boundary. This DPA governs CGE Insights' processing of Member personal data on the Customer's instructions. Customer account, billing, support, and feedback data are handled by CGE Insights as controller under the Privacy Policy. Section 14 separately addresses cross-organization pooled learning, for which CGE Insights is also a controller.
1. Scope and order of precedence
This Data Processing Addendum ("DPA") forms part of the agreement between the Customer and Pitch Cloud, LLC for CGE Insights (the "Agreement"). It applies when CGE Insights processes Member personal data on behalf of the Customer.
If this DPA conflicts with the Agreement on the protection or processing of personal data, this DPA controls. Any applicable Standard Contractual Clauses control over both documents for matters they govern.
2. Definitions
- "Applicable Data Protection Law" means the privacy and data-protection law that applies to the processing, including the GDPR where applicable.
- "Customer Personal Data" means Member personal data processed by CGE Insights on the Customer's behalf under this DPA.
- "Personal Data Breach" means a security breach that leads to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data.
- "Sub-processor" means another processor engaged by CGE Insights to process Customer Personal Data.
Terms defined in the Terms of Service — Customer, Member, Services, Order Documentation, Strategy Advisor, and Pooled Summaries — have the same meaning here and are not restated.
3. Roles and instructions
For Customer Personal Data, the Customer is the controller and CGE Insights is the processor. The Customer determines the purposes and essential means of the Member processing. CGE Insights processes the data to provide the service under the Customer's documented instructions in the Agreement, its Order Documentation, this DPA, and Customer configuration.
CGE Insights will process Customer Personal Data only on documented instructions, including instructions concerning transfers, unless applicable law requires otherwise. If law requires processing outside the Customer's instructions, CGE Insights will inform the Customer before processing unless the law prohibits notice.
CGE Insights will promptly inform the Customer if, in its reasonable view, an instruction violates Applicable Data Protection Law, and may pause the affected processing while the parties address it.
4. Customer obligations
The Customer represents that it has the authority, notices, lawful bases, and consents required to collect and provide Customer Personal Data and to instruct CGE Insights to process it. The Customer is responsible for the accuracy, quality, and lawfulness of that data and for the instructions it gives.
Unless the parties separately agree in writing and applicable law permits the processing, the Customer must not upload special-category or similarly sensitive data, including but not limited to health information, religious beliefs, political affiliation, or trade union membership. The Customer is responsible for the arbitrary columns it includes in CSV enrichment uploads.
This restriction is a contractual obligation of the Customer and is not represented as a technical control — CSV enrichment accepts the columns the Customer chooses, and CGE Insights does not inspect, validate, or block them.
Unlawful or nonconsensual data. The Customer warrants that it has not collected, and will not provide, Customer Personal Data that was obtained unlawfully or without a consent or other lawful basis required for its collection. As between the parties, CGE Insights is not responsible or liable to the Customer for data the Customer collected unlawfully or without the required consent, and the Customer will defend and indemnify CGE Insights against third-party claims arising from such data. This allocates responsibility between the parties and does not limit either party's obligations under Applicable Data Protection Law.
The Customer is responsible for website notices and for obtaining any consent required to place or access the durable localStorage visitor identifier. The tracker is designed to require consent before storing an identifier, in every jurisdiction, and exposes an interface the Customer's consent-management platform can call to grant or withdraw permission. Until the Customer connects that interface, the Customer controls when the script loads.
5. Confidentiality and personnel
CGE Insights will limit access to Customer Personal Data to personnel and contractors who need access to provide, secure, support, or maintain the service, and those persons will be subject to confidentiality duties. CGE Insights remains responsible for its personnel's processing within the scope of this DPA.
6. Security
CGE Insights will maintain the technical and organizational measures in Schedule 3. The parties agree these measures are intended to provide a level of security appropriate to the processing described here. CGE Insights may update the measures over time, and may determine the means by which the required level of protection is maintained, provided the overall level of protection is not materially reduced.
7. Sub-processors
The Customer gives general written authorization for CGE Insights to use the Sub-processors listed in Schedule 2. CGE Insights will enter into written terms with each Sub-processor imposing data-protection obligations appropriate to its services, and remains responsible to the Customer for the Sub-processor's performance to the extent required by Applicable Data Protection Law.
Changes. CGE Insights will give at least 30 days' advance notice before adding or replacing a Sub-processor. Notice goes by email to the Customer's designated contact, and the current list is also published in the CGE Insights Trust Center. Notice is by email; the Trust Center is the public record.
Objection. Within the notice period the Customer may object on reasonable data-protection or security grounds. The parties will work in good faith toward a resolution, which may include a commercially reasonable alternative. "Commercially reasonable alternative" does not include re-architecting the service.
Core Sub-processors. The providers identified as Core in Schedule 2 are approved as of the effective date and are not subject to objection. The service cannot be provided without them.
Remedy. If a reasonable objection to a non-Core Sub-processor cannot be resolved, the Customer's exclusive remedy is to terminate the affected subscription with a pro-rata refund of prepaid fees for the unused portion of the term.
Emergency changes. Where a Sub-processor must be replaced urgently for security, legal, or continuity reasons, CGE Insights may act first and give notice as soon as practical afterward.
8. Data-subject requests
Taking into account the nature of the processing, CGE Insights will provide reasonable assistance to help the Customer respond to requests from Members exercising rights under Applicable Data Protection Law.
If CGE Insights receives a request concerning Customer Personal Data directly from a Member, it will not independently respond to the substance unless authorized or legally required. It will direct the Member to the Customer or forward the request, as appropriate.
Intake and response. Requests are sent to privacy@cgeinsights.com. CGE Insights will acknowledge a request within 2 business days and will verify that the requester is acting for the Customer before acting on it.
No completion target is stated in this DPA. Assistance is provided within a reasonable period appropriate to the request and the Customer's own statutory deadline.
9. Personal Data Breaches
CGE Insights will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and will target an initial notice within 48 hours of becoming aware.
Becoming aware means having a reasonable degree of certainty that a security incident has compromised Customer Personal Data. It does not mean the moment an alert fires or a log entry is generated.
The initial notice will describe, to the extent known: the nature of the breach; the categories and approximate number of affected Members and records; likely consequences; measures taken or proposed; and a contact for follow-up. Information not available at the time of the initial notice will follow as it becomes available.
Customer security contact. The Customer must designate and keep current a security contact with a name and email address. Notice goes to that contact by email. If the Customer has not designated a contact, notice to the account administrators on file is sufficient.
CGE Insights will take reasonable steps to contain, investigate, and mitigate the breach, and will provide reasonable cooperation for the Customer's own legal notifications. A notification is not an admission of fault or liability.
10. Impact assessments and regulator consultation
Taking into account the nature of processing and the information available to it, CGE Insights will provide reasonable assistance with a data-protection impact assessment and with prior consultation with a regulator, where the Customer is required to carry one out for the service.
11. Information and audits
CGE Insights will make available information reasonably necessary to demonstrate compliance with its processor obligations, and will respond to reasonable security questionnaires and provide its security documentation.
CGE Insights does not currently hold a SOC 2, ISO 27001, or equivalent independent audit report.
On-site audit. Where Applicable Data Protection Law requires an on-site audit right, the Customer may audit no more than once every 12 months, on 30 days' prior written notice from the Customer, at the Customer's cost, during business hours, under confidentiality, using an auditor who is not a competitor of CGE Insights, and without access to any other Customer's data or to information that would compromise service security. A regulator-mandated audit is not limited by frequency.
12. Return and deletion
At the end of the services involving Customer Personal Data, CGE Insights will, at the Customer's choice, return or delete Customer Personal Data and delete existing copies, unless applicable law requires continued storage.
Export. The Customer may export reports in PDF and CSV format from the service while the account is active. A complete export of Customer Personal Data is prepared by CGE Insights staff on request.
Frequency. The Customer may request up to two complete exports per calendar year at no charge, and one further complete export at no charge during the post-termination window described below. Additional or unreasonably repetitive requests may be scheduled reasonably and may be subject to a reasonable fee.
These limits do not apply to, and no fee may be charged for, assistance CGE Insights owes under Applicable Data Protection Law, including assistance with a Member's rights request under section 8. A commercial export right and a statutory rights request are separate things.
Timeline. Following a notified termination, the Customer has 30 days to request an export and to reactivate. After that window, Customer Personal Data is deleted from active systems.
- Encrypted form drafts expire on their own short retention and are not included in an export.
- Audit logs are retained for 24 months and survive termination.
- Outcome history linked to a Member is retained for no more than 24 months, after which it is aggregated into non-identifying counts and the underlying rows are deleted.
- Pooled Summaries already produced are retained — see section 14. They contain no personal data and no organization names.
Backups. This DPA makes no backup-retention commitment. See Schedule 3.
13. International transfers
CGE Insights will not make a restricted transfer of Customer Personal Data unless a lawful transfer mechanism applies. Schedule 4 records the processing locations and the mechanism relied upon.
Where the EU Standard Contractual Clauses are required for a controller-to- processor transfer, the parties will use Module 2, with the annexes completed from Schedules 1 to 3. Where UK or Swiss terms are required, the parties will use the UK International Data Transfer Addendum or the applicable approved mechanism.
This applies to a US Customer whose Members are located in the EEA or the UK. CGE Insights accepts such Customers, and the transfer mechanism applies to those Members' data regardless of where the Customer is established.
Where a restricted transfer arises, the applicable clauses are executed with that Customer as a separate international transfer package before the affected Member data is processed. This DPA records the processing locations and identifies the mechanism; it is not itself the executed transfer instrument.
14. Cross-organization pooled learning — a distinct controller activity
The Customer expressly permits CGE Insights to use eligible situation, action, and outcome records derived from Customer Personal Data to create cross-organization pooled learning. For this activity CGE Insights determines the separate purpose and means and acts as a controller, not as the Customer's processor.
This permission does not change the Customer's role as controller for its original Member processing, and does not remove CGE Insights' duty to document its own lawful basis.
Lawful basis. CGE Insights relies on legitimate interests for this activity, supported by a documented assessment. Customer permission in this DPA authorizes the activity contractually; it is not itself a lawful basis, and the two are not treated as equivalent.
All of the following safeguards apply before a finding may influence a recommendation:
- Pooled data carries no personal data and no organization names.
- Records are grouped only by an anonymized situation type and an action type.
- A group must contain at least 50 distinct Members from at least 3 distinct organizations.
- Groups below either threshold are discarded and are not stored in a weaker form.
- Outputs are counts and rates only. These are the Pooled Summaries defined in the Terms of Service.
- CGE Insights staff review findings before use.
CGE Insights will not disclose one Customer's identifiable data to another Customer through pooled learning.
Opt-out — an organization-level choice. An authorized administrator of the Customer may opt the organization out of pooled learning at any time by written request to privacy@cgeinsights.com. It is a single choice made for the organization as a whole, not a per-Member setting. The opt-out takes effect immediately on verification and applies to records not yet aggregated.
The opt-out is reciprocal, which means this: a Customer that stops contributing its records to pooled learning also stops receiving Pooled Summaries derived from other organizations' records. It is a two-way exchange, and declining to contribute is declining to receive. Every other part of the service is unaffected — the Customer's own dashboard, recommendations, outcome history and reports all continue, because they are built from the Customer's own data and never depended on the pool.
Pooled Summaries already produced cannot be withdrawn. The thresholds above make it impossible to trace a Summary back to a contributing organization, so there is nothing to unwind.
Individual objection. A Customer-level opt-out does not discharge an individual Member's right to object to processing based on legitimate interests. An individual objection is handled through the process in section 8.
15. AI processing and automated decisions
- The Strategy Advisor and Help Assistant use Google Gemini 2.5-flash to generate text at request time.
- Prompts may include behavioral signals and derived flags, but not Member names or email addresses.
- Customer data is not used to train or fine-tune a model.
- Statistics and findings are calculated by conventional statistical methods in CGE Insights' own code. AI may phrase a result but does not generate the number.
- Recommendations are advisory and a human decides whether to act. The service does not make a solely automated decision producing legal or similarly significant effects for a Member.
16. Liability and term
Each party's liability under this DPA is subject to the limitation of liability in the Agreement, except where Applicable Data Protection Law or the Standard Contractual Clauses require otherwise. This DPA remains in effect while CGE Insights processes Customer Personal Data.
Schedule 1 — Details of processing
Subject matter. Membership engagement tracking, roster handling, identification, engagement analysis, recommendations, outreach support, reports, exports, and configured integrations.
Duration. The subscription term plus the 30-day post-termination window in section 12.
Nature of processing. Collecting, transmitting, storing, organizing,
matching, linking anonymous browser activity to a Member after identify(),
analyzing, deriving engagement scores and flags, generating advisory text,
displaying, exporting, and transmitting to Customer-configured destinations.
Purpose. To provide CGE Insights to the Customer under the Agreement and Customer configuration.
Data subjects. Members of the Customer.
Frequency. Continuous or periodic website events; Customer-initiated uploads; configured synchronizations; user-initiated analysis, reports, and outreach.
Categories of Customer Personal Data
- Page views and session activity on the Customer's website.
- Reduced page URL: path and hash route; allow-listed query keys (
tab,page,view,section,sort,filter,step) after email-like values are scrubbed and values longer than 64 characters dropped. - Referring domain and first-touch attribution, including UTM parameters,
gclid, andfbclid. - Durable random visitor identifier stored in browser localStorage.
- IP address used in transit for request handling. CGE Insights does not retain IP addresses in its own database. Infrastructure providers may retain them in operational logs under their own retention periods.
- Member email address used through
identify()to link prior browser activity on that browser to the Member. - Name, email, membership type, membership status, join date, renewal date, and engagement history supplied by CSV or Novi AMS.
- Arbitrary additional CSV enrichment columns selected by the Customer, subject to section 4.
- Derived engagement scores, behavioral signals, flags, action records, and outcome history.
Special-category data. Not intended or authorized. Prohibited unless the parties separately agree in writing — see section 4.
Schedule 2 — Authorized Sub-processors
Core — required to provide the service.
- Supabase — Primary database. Member data and Customer account data stored in the service.
- Render — Backend application hosting. Data processed by backend functions, including Member and Customer data needed to provide the service.
- Vercel — Frontend hosting and server-side proxy. Customer-user requests, session-related information, and application data returned through the frontend and proxy.
- Resend — Transactional email. Recipient email address and message content for magic links, notifications, and form submissions. Core because magic-link sign-in depends on it.
- Stripe — Payments and billing. Billing contact and payment information used to process and document charges.
Optional — used only where the Customer enables the relevant feature or integration.
- Google Cloud (Gemini) — AI text generation. Strategy prompts with behavioral signals and derived flags, without Member names or emails; Help Assistant question text.
- Google / Microsoft — Customer-user single sign-on. Customer-user identity and authentication information only. Optional because three sign-in methods exist.
- Mailchimp / Mandrill — Email engagement and outreach. Email engagement data; Member email address and outreach content when the Customer sends through the integration.
- Novi AMS — Member roster synchronization. Roster fields synchronized between Novi AMS and CGE Insights.
- Sentry — Application error monitoring. Application error and diagnostic data; configuration minimizes personal data in error events.
- cron-job.org — Scheduled job triggering. None. It receives authenticated requests that trigger background work.
Customer-configured destinations are not Sub-processors. Outbound webhooks and Slack or Microsoft Teams destinations are selected and controlled by the Customer, which decides what is sent and to whom. CGE Insights transmits to the destination the Customer configures; it does not engage those services to process data on the Customer's behalf.
Development tools are not Sub-processors. Software-development tools used to build and maintain the service do not receive Customer Personal Data and are not part of the processing described in Schedule 1.
Processing locations for each provider are recorded in Schedule 4.
Schedule 3 — Technical and organizational measures
Server-side data access All database access is server-side. No browser-side database client exists.
Database authorization Row-level security is enabled with no browser-facing policies, making tables service-role-only.
Backend access path The browser does not call the backend directly. A server-side proxy holds a shared secret; the public site key is not a credential.
Credential protection Third-party credentials and webhook URLs are encrypted at rest using Fernet.
Customer-user access Access to a Customer's data through the product requires an authenticated session and is scoped to that Customer's account. Administrative actions — billing, data export, organization settings — require an administrator role, checked server-side on every request against the account record rather than from a token claim.
Personnel access Access to Customer Personal Data is limited to those who need it to provide, secure, support, or maintain the service. CGE Insights is operated by a single person today and has engaged no contractors. Access to the underlying database is through shared service credentials rather than per-person database accounts, so access is controlled by controlling who holds those credentials. A formal joiner–mover–leaver procedure is not yet documented.
Sessions Idle logout and a hard 12-hour session cap.
Unsaved work Allowed draft fields are encrypted server-side under a field allow-list, with a short expiry.
Webhooks Webhook payloads are HMAC-signed.
Outbound destinations Webhook and Slack / Microsoft Teams destinations are host-restricted and protected against server-side request forgery.
Ingest Events are accepted only for registered site keys; an unrecognized key is refused before any database write.
Auditability Significant operator actions are recorded in audit logs, retained 24 months.
The following are stated as gaps rather than controls. A schedule that lists only strengths misleads, and a gap discovered later costs the Customer more than the gap itself.
Independent assurance None. CGE Insights holds no SOC 2, ISO 27001, or equivalent report.
Backups No backup-retention or restoration commitment is made in this draft. A backup schedule and tested restore procedure are not yet confirmed.
Security monitoring Application error monitoring and operator audit logging only. No intrusion detection, anomaly alerting, or aggregated security log alerting.
Schedule 4 — International transfers
Two entries in this schedule are completed for each Customer at execution rather than here. The competent supervisory authority and the governing law and forum for the Standard Contractual Clauses depend on the exporter and the circumstances of the transfer, so a master document cannot choose them in advance.
All infrastructure that CGE Insights selects a region for is located in the United States. Confirmed 4 August 2026.
CGE Insights establishment Little Elm, Texas, United States
Supabase (database) United States — US East (Virginia)
Render (backend hosting) United States — US West (Oregon)
Vercel (frontend and proxy) United States — US East (Washington DC). Serverless functions run in this region; edge middleware runs on Vercel's global network.
Google Cloud (Gemini) Global endpoint (generativelanguage.googleapis.com). No region selection is available on the Gemini Developer API; the processing location is determined by Google under its published terms. Prompts contain behavioral signals and derived flags only — no Member names or email addresses.
cron-job.org No entry required. It receives no personal data, only authenticated requests that trigger background work, so no transfer of personal data occurs.
Other providers Stripe, Resend, Sentry, Mailchimp / Mandrill, Novi AMS, and the Google and Microsoft single sign-on services process in the locations set out in their own data processing agreements and transfer terms. CGE Insights does not select their processing region.
Transfer mechanism EU Standard Contractual Clauses, Module 2 (controller to processor), with annexes completed from Schedules 1 to 3; UK International Data Transfer Addendum where UK data is involved; applicable Swiss terms where relevant.
Competent supervisory authority To be completed in connection with execution of the SCCs for the applicable Customer.
SCC governing law and forum To be completed in connection with execution of the SCCs for the applicable Customer.