Data Processing Addendum
This addendum forms part of the Terms of Service and governs our processing of personal data on your behalf. Where it conflicts with the Terms, this addendum wins for that processing.
Effective 7 September 2026This addendum is offered as-is and has not been reviewed by counsel. If your organisation requires a signed DPA on your own paper, or Standard Contractual Clauses executed as a separate instrument, contact us before you begin processing.
1Roles
You are the controller of the personal data you put through the service. We are the processor, and act only on your documented instructions — your use of the service, and the workflows you build, ARE those instructions.
For your own account data — the email address you signed up with, your sign-in metadata — we are the controller, and the Privacy Policy applies.
2Scope of the processing
Subject matter. Executing the workflows you define, and recording what each run did.
Duration. For the term of your agreement, plus the retention window your plan grants for run data.
Nature and purpose. Storage, transmission, execution of workflow steps, calls to model providers and to systems you connect, and the recording of an execution history for you to inspect.
Categories of data. Whatever your workflows process. We do not restrict it and cannot predict it. It commonly includes identifiers, contact details, message content and business records.
Data subjects. Whoever your workflows are about — your customers, your employees, your users.
The service is not designed for special-category data under Article 9, nor for data subject to HIPAA, PCI-DSS or equivalent sectoral regimes. We hold no certification against any of them and offer no BAA. Do not put that data through the service.
3Our obligations
Process only on your instructions, and tell you if we believe an instruction breaches data protection law.
Keep everyone with access under a duty of confidentiality.
Implement the technical and organisational measures in section 4.
Assist you with data subject requests, and with your obligations under Articles 32 to 36, to the extent the service allows.
Delete or return personal data at the end of the agreement, as section 7 sets out.
Make available the information you reasonably need to demonstrate compliance with Article 28.
4Security measures
The measures actually implemented, stated as what they are:
TLS for data in transit.
AES-256-GCM encryption at rest for connection secrets, with the workspace id bound into the authenticated data so a ciphertext moved between tenants fails to decrypt rather than decrypting for the wrong one.
Workspace scoping enforced at the same boundary for every resource lookup — agents, tools, rosters, runs — failing closed if the check itself errors.
Role-based authorisation enforced server-side, denying writes by default.
An append-only audit log for privileged actions.
Sanitisation at the write boundary, so raw provider responses, stack traces and connection secrets do not reach the event store, the span writer or payload storage.
Retention enforced by deletion rather than by a read-time filter, so expired data is not merely hidden.
None of this has been independently audited. We hold no SOC 2 or ISO 27001 certification, and we have no penetration test report to share. If your procurement requires one, the honest answer today is that we cannot satisfy it.
5Subprocessors
You give general authorisation for us to engage subprocessors. The current list is published at /legal/subprocessors and is incorporated into this addendum by reference. It names every third party this system sends data to, including the model providers, and states what is sent to each. It was last verified against the code on 2026-09-07.
We will give at least 30 days' notice by email before adding a subprocessor. If you reasonably object on data protection grounds within that period, you may terminate the affected part of the service and receive a pro-rated refund of prepaid fees.
We impose data protection obligations on each subprocessor no less protective than these, and remain liable for their performance.
6International transfers
Processing is primarily in the United States. Where we transfer personal data from the EEA, UK or Switzerland, we rely on the European Commission's Standard Contractual Clauses (Decision 2021/914), incorporated here by reference — Module Two where you are a controller and we are your processor, and Module Three where you are yourself a processor. The UK Addendum applies to UK transfers.
The optional clauses are not selected; the governing law and forum are those of Ireland for the EU clauses; and the annexes are populated by sections 2, 4 and 5 of this addendum together with the published subprocessor list.
7Deletion and return
Run data is deleted automatically when its retention window expires. On termination, we delete your workspace data within 30 days. Before then you may export your workflows and run history through the API or by asking us.
Backups are overwritten on their own cycle; personal data in a backup is deleted within 35 days of the primary deletion.
8Incidents
We will notify you without undue delay, and in any event within 72 hours, of becoming aware of a personal data breach affecting your data. The notice will describe what happened, which data was affected as far as we can establish, what we have done, and what we recommend you do.
9Audit
We will answer reasonable written questions about our processing, once a year, at no charge. We do not currently have an audit report to provide in place of that, and we do not offer on-site inspection.
10Contact
Data protection enquiries: susmit@vectorbea.com.