GFoundry Intelligence — Privacy and Data Protection (OpenAI & Google Gemini)

Legal · GFoundry Intelligence

GFoundry Intelligence — Privacy & Data Protection

Version 2.1Last updated October 3, 2026Responsible entity GFoundry Lda

GFoundry Intelligence brings together AI features, agents and intelligence services for learning design, voice or written role-play, workplace assistance and talent analysis. Talent Strategist is the talent analysis agent; People Intelligence and Talent Insights are complementary intelligence services. OpenAI and Google Gemini act as AI subprocessors for the features that use their services. This policy describes personal-data processing and safeguards under the GDPR and the applicable Data Processing Agreements (DPAs).

1Entity responsible for processing

GFoundry Lda, headquartered in Valença (Portugal), at Avenida Tito Flores, nº 71, with a share capital of €55,000.00, registered at the Odivelas Registrar of Companies under single registration and VAT number PT510809510, hereinafter referred to as GFOUNDRY, is the entity responsible for GFoundry Intelligence. This policy outlines how GFOUNDRY ensures the protection, privacy, and security of personal data processed via GFoundry Intelligence, in compliance with the General Data Protection Regulation (GDPR).

2Scope of GFoundry Intelligence

GFoundry Intelligence covers content generation, knowledge-based assistance, role-play and talent intelligence. The data needed depends on the feature, the organisation’s configuration and access permissions.

  • Content and assistance: client documents, prompts and available organisational knowledge may be used to prepare learning material or answers. Users should avoid including personal data that is not needed for the task.
  • Practice and talent intelligence: voice role-play may process audio and transcriptions; analytical features may process authorised profile, review, development, learning and recognition data. External tools connected through MCP have their own terms; queries and actions in GFoundry follow configured permissions.

3Collection and processing of personal data

GFOUNDRY processes personal data strictly necessary for:

  • Providing information and operating GFoundry Intelligence.
  • Processing documents, knowledge, practice sessions and authorised analytical data to operate the selected features.

Data processed may include direct or indirect identifiers, document content, prompts, audio, transcriptions and authorised talent data, depending on the feature. Access controls and data minimisation apply. Pseudonymisation is used where appropriate; it does not mean that all processing is anonymous. Users or clients are informed of the data required for the features they use.

4Legal basis for data processing

GFOUNDRY ensures that personal data is processed lawfully under the following conditions:

  • With the explicit consent of the data subject.
  • For the performance of a contract to which the data subject is a party.
  • In compliance with legal obligations.
  • To protect vital interests of the data subject or another person.
  • For tasks carried out in the public interest or in the exercise of official authority.

5Data protection measures

GFOUNDRY employs robust technical and organizational measures to protect personal data, including:

  • Encryption of data in transit and at rest.
  • Access controls and authentication measures.
  • Regular security audits and vulnerability assessments.
  • Data minimisation and deletion according to the purpose, configured retention and applicable obligations.

6User rights

Data subjects have the following rights under GDPR: right to access, rectification, erasure, restriction of processing, data portability, and objection. Requests to exercise these rights can be addressed to the Data Protection Officer at GFOUNDRY through the contact details below.

7Data retention and deletion

GFOUNDRY retains personal data only for as long as needed for the relevant purpose and applicable obligations. Source documents, generated content, conversations, transcriptions and operational records can have different retention needs, according to the feature and organisation’s configuration. Deletion in GFoundry and retention by AI subprocessors are distinct: provider retention depends on the service, endpoint, contractual terms and enabled controls. There is no universal promise of immediate deletion or zero retention for every feature.

8International data transfers

Any transfer of personal data to third countries or international organizations complies with GDPR requirements, including the use of Standard Contractual Clauses (SCCs) and other legally approved mechanisms.

GFoundry uses European Union cloud infrastructure for its platform storage. Storage location does not imply that every AI operation is processed exclusively in the EU. Data transmitted to AI subprocessors is limited to what the selected feature needs, with minimisation or pseudonymisation where appropriate. Processing locations, retention and restrictions on use for training follow the applicable provider terms, DPAs and enabled controls; international transfers use the safeguards described above.

9Contact information

For any questions, concerns, or requests related to this policy or the processing of personal data, please contact:

  • Email: [email protected]
  • Address: Rua do Instituto Industrial 16, 1200-225 Lisboa – Portugal

10Updates to this policy

GFOUNDRY may update this Privacy and Data Protection Policy to reflect changes in practices or legal requirements. Updates will be published in relevant channels to ensure transparency and inform Users and Customers.

11OpenAI — specific terms

The following specific terms apply to the use of OpenAI as an AI subprocessor of GFoundry Intelligence, under the Data Processing Agreement (DPA) between GFoundry Lda and OpenAI.

1. Processing requirements

As a Data Processor, OpenAI agrees to: process Customer Data only on the Customer's behalf for the purpose of providing and supporting OpenAI's Services (including insights, reporting, analytics, and abuse/trust and safety monitoring); comply with the Customer's written instructions; provide the level of privacy protection required by Data Protection Laws; inform the Customer promptly if it cannot comply with this DPA; not provide remuneration in exchange for Customer Data; and not "sell" or "share" Personal Data as defined by U.S. Privacy Laws.

2. Notice to Customer

OpenAI will inform the Customer of any legally binding request for disclosure by a law enforcement authority (unless prohibited), any notice/inquiry/investigation by a Supervisory Authority, and any complaint or request from the Customer's data subjects.

3. Assistance to Customer

OpenAI provides reasonable assistance with data-subject requests (access, rectification, erasure, restriction, portability, objection, blocking, deletion), investigating security breaches affecting Customer Data, and preparing data protection impact assessments and consultations with supervisory authorities.

4. Required processing

If required by Data Protection Laws to process Customer Data for a reason unrelated to the Agreement, OpenAI will inform the Customer in advance, unless legally prohibited.

5. Security

OpenAI maintains reasonable and appropriate organizational and technical security measures, ensures its personnel protect the security, privacy and confidentiality of Customer Data, and notifies the Customer of any Personal Data Breach without undue delay.

6. Obligations of Customer

The Customer warrants it has the necessary rights, consents and authorizations to provide the Customer Data; will comply with applicable Data Protection Laws; will cooperate with OpenAI on data-subject requests; and will not provide Customer Data except through agreed mechanisms.

7. International data transfers

OpenAI processes Customer Data originating in the EEA or Switzerland in accordance with the Standard Contractual Clauses adopted by the EU Commission.

8. Term; data return and deletion

The DPA remains in effect while OpenAI processes Customer Data on the Customer's behalf. On termination, OpenAI deletes Customer Data within thirty (30) days, unless prohibited by law.

Exhibit A — List of parties: Data exporter is the Services customer identified on the applicable registration documents; data importer is OpenAI OpCo, LLC. Exhibit B — Technical and organizational measures: describes the information security program and security standards maintained by OpenAI to protect Customer Data.

12Google Gemini — specific terms

GFoundry Intelligence also uses Google's Gemini API (paid tier) as an AI subprocessor for content generation and assistance. Google's processing of personal data is governed by the Gemini API Additional Terms of Service (https://ai.google.dev/gemini-api/terms) and, for paid services, the Data Processing Addendum for Products Where Google is a Data Processor (https://business.safety.google/processorterms/).

1. Processor status

On the paid tier, Google does not use prompts (including system instructions, cached content, and files) or responses to train or improve its products, and processes them as a data processor under the DPA referenced above.

2. Data location and retention

GFoundry platform storage uses cloud infrastructure in the European Union. Data sent to Gemini depends on the selected feature; minimise or pseudonymise it where appropriate. Google’s processing locations and retention follow the applicable Gemini API terms, DPA and configuration. Paid-service restrictions on training do not mean that no data can be retained for operational or abuse-prevention purposes.

3. Security

Google maintains organizational and technical security measures and notifies of any Personal Data Breach without undue delay, as set out in its DPA.

4. International data transfers

Transfers of data originating in the EEA or Switzerland are made under the Standard Contractual Clauses adopted by the EU Commission.

5. References

Gemini API Additional Terms of Service (https://ai.google.dev/gemini-api/terms); Data Processing Addendum for Products Where Google is a Data Processor (https://business.safety.google/processorterms/).

↑ Back to top