10110010011101001011001101101110101018200.devFrom Enterprise.Systems
Start free
All legal documents

Data Processing Agreement

Effective date: 2026-06-12

In plain language

  • When your connected sources contain personal data, your organization is the controller and we are the processor.
  • We process only on your instructions, only the metadata and permissions your OAuth approval exposes.
  • Five subprocessors, with advance notice before we add one. Breach notice within 48 hours of awareness.
  • EU Standard Contractual Clauses cover international transfers.
  • At termination you can export everything, then we delete it.

1. Parties, scope, and roles

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Enterprise.Systems ("Processor") and the customer organization ("Controller"). It applies whenever Customer Source Data processed on the platform contains personal data within the meaning of the GDPR or similar laws. In case of conflict regarding personal-data processing, this DPA prevails over the Terms.

2. Definitions

"GDPR" means Regulation (EU) 2016/679. "Personal data", "processing", "data subject", "controller", "processor", and "supervisory authority" have the meanings given in the GDPR. "Customer Source Data" has the meaning given in the Terms of Service.

3. Details of processing

  • Subject matter — security posture analysis of the Controller’s connected sources.
  • Duration — the term of the agreement plus the deletion grace period.
  • Nature and purpose — read-only enumeration of resources, permissions, and principals via Controller-approved OAuth scopes; evaluation against security rules; generation of findings and explanations, including AI-assisted analysis.
  • Categories of personal data — resource metadata (names, identifiers, sharing settings) and principal identities (names, email addresses, roles) of the Controller’s users, collaborators, and service/AI agents. No file contents; no special categories are sought, and any present in metadata are incidental.
  • Data subjects — the Controller’s employees, collaborators, and external parties holding permissions in connected sources.

4. Processing on instructions

The Processor processes personal data only on the Controller’s documented instructions — these consist of the Terms, this DPA, and the Controller’s configuration of the platform (which sources to connect, which scopes to approve, retention settings) — unless required by law, in which case the Processor informs the Controller before processing where legally permitted. The Processor will inform the Controller if, in its opinion, an instruction infringes data-protection law.

5. Confidentiality

Persons authorized to process personal data are bound by contractual or statutory confidentiality obligations.

6. Security measures (Art. 32)

The Processor implements and maintains appropriate technical and organizational measures, including:

  • Encryption in transit (TLS 1.2+) and encryption of stored source credentials at rest (AES-256-GCM with a dedicated key-encryption key).
  • Read-only, least-privilege access to connected sources, limited to Controller-approved OAuth scopes.
  • Role-based access control within the platform (owner/admin/viewer) and tenant isolation at the data layer.
  • An append-only audit log of platform actions.
  • Vulnerability management and timely patching of platform dependencies.

7. Subprocessors

The Controller grants general authorization for the subprocessors listed in the Privacy Policy (Anthropic, Cloudflare, RunPod, PayPal, and Resend once email features are active). The Processor imposes data-protection obligations no less protective than this DPA on each subprocessor and remains fully liable for their performance. The Processor gives at least 14 days notice before adding or replacing a subprocessor; the Controller may object on reasonable data-protection grounds, in which case the parties will seek a solution and, failing one, the Controller may terminate the affected service and receive a pro-rata refund of prepaid fees.

8. Assistance with data subject rights

Taking into account the nature of processing, the Processor assists the Controller in responding to data-subject requests, including through the platform’s self-serve export and deletion tooling, and forwards to the Controller without undue delay any request it receives directly.

9. Personal data breach

The Processor notifies the Controller without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Source Data, providing the information reasonably required for the Controller’s obligations under Articles 33–34 GDPR, and cooperates in remediation.

10. International transfers

Transfers of personal data from the EEA, UK, or Switzerland to countries without an adequacy decision are governed by the EU Standard Contractual Clauses (Module 2: controller-to-processor), which are incorporated into this DPA by reference, together with the UK Addendum and Swiss adaptations as applicable. Israel benefits from an EU adequacy decision.

11. Audits

The Processor makes available the information reasonably necessary to demonstrate compliance with this DPA, including summaries of security assessments, and allows audits by the Controller or its mandated auditor no more than once per year on at least 30 days notice, during business hours, under confidentiality, and at the Controller’s expense unless the audit reveals material non-compliance.

12. Return and deletion

Upon termination, the Controller may export Customer Source Data and findings via the platform for 30 days. Thereafter the Processor deletes personal data within 30 days, unless retention is required by law, and confirms deletion on request. Stored source credentials are destroyed immediately upon disconnection or account deletion.

13. Liability and precedence

Liability under this DPA is subject to the limitations in the Terms of Service to the extent permitted by data-protection law. This DPA replaces any prior data-processing terms between the parties.

14. Contact

Data-protection contact: [email protected].