Data Processing Agreement (DPA)
Last updated: 24 July 2026
This DPA forms part of the Terms of Service where we process personal data contained in Customer Data on your behalf. For that data you are the controller and we are the processor (or, under applicable US laws, the business and service provider).
1. Scope and roles
We process personal data only to provide the Service and per your documented instructions (which include these terms and your use of the Service). We do not sell personal data and do not use Customer Data to train shared AI models.
2. Subprocessors
We use vetted subprocessors to deliver the Service: DigitalOcean (hosting and managed database), Anthropic (AI processing), and Twilio SendGrid (transactional email). Each processes data only as needed. We remain responsible for their performance and will give notice of material changes to this list.
3. Security
We maintain technical and organizational measures appropriate to the risk, including encryption in transit and at rest, role-based access controls, and an append-only audit trail. See the Security Policy.
4. International transfers
Where personal data is transferred across borders, we rely on appropriate safeguards (such as Standard Contractual Clauses) as required by applicable law.
5. Data subject requests
We will assist you, taking into account the nature of processing, in responding to requests to access, correct, delete, or port personal data.
6. Breach notification
We will notify you without undue delay after becoming aware of a personal-data breach affecting Customer Data.
7. Deletion and return
On termination we will delete or return Customer Data as described in the Privacy Policy, subject to short backup-cycle windows and legal obligations.
8. Audits
We will make available information reasonably necessary to demonstrate compliance and, for enterprise customers under contract, support reasonable audits subject to confidentiality.
Questions about this document? Contact [email protected]. See all policies in the Legal Center.