Data Processing Agreement

Effective date: 5 June 2026

This Data Processing Agreement (“DPA”) is entered into between AgentOS (“Processor”) and the Customer (“Data Controller”) and governs the processing of personal data on behalf of the Data Controller in connection with the AgentOS platform. This DPA is incorporated into the Terms of Service. Questions: bernabranco@agentos-ai.dev.


1. Definitions

  • Personal Data — any information relating to an identified or identifiable natural person.
  • Processing — any operation performed on personal data, such as collection, recording, organisation, use, transmission, or deletion.
  • Data Subject — the individual to whom personal data relates.
  • Sub-processor — a natural or legal person engaged by the Processor to process personal data on its behalf.
  • Data Breach — a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data.

2. Scope and purpose

The Processor processes personal data only on documented instructions from the Data Controller and in accordance with this DPA, the Privacy Policy, and applicable data protection laws (including the GDPR, CCPA, and other equivalent regulations).

Personal data processed includes: email addresses, workspace member information, OAuth tokens (encrypted), and any personal data embedded in agent content, run logs, or uploaded resources by the Data Controller.


3. Processor obligations

The Processor shall:

  • Process personal data only on documented instructions from the Data Controller.
  • Ensure that persons authorised to process personal data are committed to confidentiality or under an appropriate legal obligation of confidentiality.
  • Implement technical and organisational measures to ensure a level of security appropriate to the risk, including encryption at rest and in transit, access controls, and regular security audits.
  • Assist the Data Controller in ensuring compliance with data subject rights (access, deletion, portability, etc.).
  • Delete or return all personal data after termination of the service, unless retention is required by law.
  • Make available all information necessary to demonstrate compliance and allow for audits.

4. Sub-processors

The Processor may engage sub-processors to process personal data. The Processor shall inform the Data Controller of any changes concerning the addition or replacement of sub-processors. The Data Controller may object to a sub-processor on reasonable grounds within 10 days of notification. If the Data Controller objects, the Processor shall either adopt the objection or offer the Data Controller the right to suspend or terminate the affected service.

The following sub-processors are authorised to process personal data:

Sub-processorPurposeLocationDPA Status
Supabase (Supabase Inc.)Database, authentication, storageUS (EU region available)DPA in place
Vercel (Vercel Inc.)Application hosting, edge functionsUS / Global CDNDPA in place
Stripe (Stripe Inc.)Payment processingUSStripe Data Processing Addendum
Anthropic (Anthropic PBC)Claude AI model inference (API)USAnthropic Enterprise Agreement
OpenAI (OpenAI LP)GPT model inference (API)USOpenAI DPA available
Composio (Composio Inc.)OAuth token relay, integration dispatchUSDPA in place
Serper (Serper Global Inc.)Web search results for agent toolsUSTerms of Service include processor obligations

5. Data subject rights

The Processor shall assist the Data Controller in fulfilling data subject requests, including:

  • Access to personal data (export via /api/v1/workspaces/export)
  • Correction of inaccurate personal data
  • Deletion of personal data (via workspace deletion or account closure)
  • Data portability in a machine-readable format (JSON export)
  • Objection to processing or restriction of processing

The Data Controller is responsible for submitting and responding to data subject requests. The Processor will provide reasonable assistance within 15 business days.


6. Data security and confidentiality

The Processor shall implement and maintain:

  • Encryption of personal data in transit (TLS 1.2+) and at rest (AES-256-GCM).
  • OAuth tokens encrypted with AES-256-GCM; never logged or transmitted in plain text.
  • Access controls limiting personal data access to authorised personnel on a need-to-know basis.
  • Row-level security policies ensuring multi-tenant isolation.
  • Regular security testing, vulnerability scanning, and penetration testing.
  • Incident response procedures and breach notification within 72 hours.

7. Data breach notification

In the event of a personal data breach affecting the Data Controller's data, the Processor shall:

  • Notify the Data Controller without undue delay, and in any case within 72 hours.
  • Provide details of the breach, affected data categories, and likely consequences.
  • Cooperate fully with the Data Controller and relevant supervisory authorities.
  • Assist the Data Controller in fulfilling its legal notification obligations.

Breach notifications will be sent to the emergency contact registered with the workspace, and to bernabranco@agentos-ai.dev.


8. Audit and compliance

The Processor shall, upon reasonable request and no more than once per year, make available to the Data Controller:

  • Proof of compliance with this DPA (certifications, audits, SOC 2 reports).
  • Access to relevant information to demonstrate compliance.
  • Reasonable assistance with audits or assessments by the Data Controller or its auditors.

The Data Controller may request a SOC 2 Type II report, ISO 27001 certification, or independent security audit at any time.


9. Data retention and deletion

Upon termination of the service or at the Data Controller's request, the Processor shall:

  • Delete or return all personal data within 30 days, unless deletion is prohibited by law.
  • Provide a written confirmation of deletion or return of personal data within 10 days.
  • Note: personal data embedded in run logs or archived data may be deleted according to the retention policy in the Privacy Policy (7 days free, 30 days paid).

10. International data transfers

Personal data may be transferred outside the Data Controller's country of origin to the United States and other countries where AgentOS and its sub-processors operate. The Processor shall ensure such transfers comply with applicable data protection laws, including the GDPR. Where required, the Processor shall implement appropriate safeguards such as:

  • Standard Contractual Clauses (SCCs) as approved by the relevant authorities.
  • Adequacy decisions where applicable.
  • Supplementary technical and organisational measures.

11. Limitation of liability

Each party's liability for breach of this DPA is subject to the limitation of liability provisions in the Terms of Service. In the event of a breach of this DPA by the Processor, the Data Controller's sole remedy is termination of the service and damages recovery as permitted by law.


12. Term and termination

This DPA is effective as of the Effective Date and continues for so long as the Processor processes personal data on behalf of the Data Controller, unless earlier terminated.

Either party may terminate this DPA with 30 days' written notice. Termination of the Terms of Service automatically terminates this DPA. Termination obligations (deletion, return of data) survive termination.


13. Amendments

AgentOS may amend this DPA to comply with changes in law or to reflect updates to our security practices. AgentOS will notify Data Controllers of material changes at least 30 days in advance. Continued use of the service constitutes acceptance.


14. Governing law

This DPA is governed by the laws of Portugal, consistent with the Terms of Service. Disputes shall be resolved in accordance with the dispute resolution provisions of the Terms of Service.


15. Contact

For questions about data processing or to request a copy of this DPA in a specific format (e.g. with customer company name, specific terms): bernabranco@agentos-ai.dev